Target IP: retro.thm (Requires /etc/hosts entry)
Difficulty: Hard (Rated), but Easy if you know the reference.
Objective: User (wade) & Root (root.txt) Flags
1. Executive Summary
“Retro” is a Windows Server machine hosting an IIS web server. Initial access relies heavily on OSINT and pop-culture knowledge (Ready Player One) rather than technical exploitation. We identify the username wade from the web application and successfully guess his password based on the blog’s theme. Privilege escalation utilizes CVE-2019-1388, a logic flaw in the Windows Certificate Dialog that allows a user to spawn a System shell via Internet Explorer, bypassing UAC.
Key TTPs (MITRE ATT&CK):
- T1598 (Phishing for Information): Guessing credentials based on context/theme.
- T1078 (Valid Accounts): Logging in via RDP.
- T1068 (Exploitation for Privilege Escalation): Exploiting the Windows Certificate Dialog (CVE-2019-1388).
2. Enumeration
A. Network Scanning
Your Nmap scan identified the layout:
- 80/tcp (HTTP): Microsoft IIS 10.0.
- 3389/tcp (RDP): Windows Remote Desktop.
B. Web Enumeration
- Directory Fuzzing: Standard tools usually find the
/retrodirectory. - The Blog: Visiting
http://retro.thm/retroreveals a WordPress-style blog about “Retro Gaming.” - Username: The posts are written by the user
Wade. - Context Clues: The blog discusses Ready Player One. In the book/movie, the protagonist Wade Watts uses the avatar name Parzival.
- User:
wade - Password:
parzival(Note: Often needs to be all lowercase).
3. Initial Access: RDP
With valid credentials, we connect directly via RDP.
xfreerdp /u:wade /p:parzival /v:retro.thm- User Flag: Located on the Desktop
user.txt.
4. Privilege Escalation: The “Clicky” Exploit
A. Enumeration
On the Desktop (or checking Chrome Bookmarks as you mentioned), there is a reference to CVE-2019-1388.
There is usually an executable file in the Recycle Bin or on the Desktop named hhupd.exe (an old Windows Help updater) which is signed by Microsoft but vulnerable.
B. The Exploit (CVE-2019-1388)
This is a logic flaw in how Windows handles User Account Control (UAC) when viewing certificates. It allows you to open a browser instance as SYSTEM, from which you can spawn a shell.
The Steps (The “EZ” Path):
- Trigger UAC: Run
hhupd.exe(Run as Administrator). - Don’t click Yes/No: Instead, click “Show information about this publisher’s certificate”.
- Certificate Details:
- Go to the “Issued by” link (usually Symantec or VeriSign).
- This action spawns an Internet Explorer window running as SYSTEM (because the UAC prompt runs as SYSTEM).
- The Breakout:
- In the IE window, go to File -> Save As.
- In the file dialog, navigate to
C:\Windows\System32\. - Find
cmd.exe. - Right-click
cmd.exeand select Open.
Result:
A command prompt opens running as NT AUTHORITY\SYSTEM.
C:\Windows\system32> whoami
nt authority\systemRoot Flag: C:\Users\Administrator\Desktop\root.txt.txt.
5. Remediation (Blue Team)
- Patch Management:
- This vulnerability (CVE-2019-1388) was patched by Microsoft in November 2019. Ensure the server is updated to a build newer than that.
- RDP Security:
- Do not expose RDP (3389) to the internet. Use a VPN or Gateway.
- Enforce Network Level Authentication (NLA).
- Credential Policies:
parzivalis a weak password derived from the user’s interests. Implement complexity requirements and blocklists for common pop-culture terms.