Target IP: retro.thm (Requires /etc/hosts entry) Difficulty: Hard (Rated), but Easy if you know the reference. Objective: User (wade) & Root (root.txt) Flags

1. Executive Summary

“Retro” is a Windows Server machine hosting an IIS web server. Initial access relies heavily on OSINT and pop-culture knowledge (Ready Player One) rather than technical exploitation. We identify the username wade from the web application and successfully guess his password based on the blog’s theme. Privilege escalation utilizes CVE-2019-1388, a logic flaw in the Windows Certificate Dialog that allows a user to spawn a System shell via Internet Explorer, bypassing UAC.

Key TTPs (MITRE ATT&CK):

  • T1598 (Phishing for Information): Guessing credentials based on context/theme.
  • T1078 (Valid Accounts): Logging in via RDP.
  • T1068 (Exploitation for Privilege Escalation): Exploiting the Windows Certificate Dialog (CVE-2019-1388).

2. Enumeration

A. Network Scanning

Your Nmap scan identified the layout:

  • 80/tcp (HTTP): Microsoft IIS 10.0.
  • 3389/tcp (RDP): Windows Remote Desktop.

B. Web Enumeration

  1. Directory Fuzzing: Standard tools usually find the /retro directory.
  2. The Blog: Visiting http://retro.thm/retro reveals a WordPress-style blog about “Retro Gaming.”
  3. Username: The posts are written by the user Wade.
  4. Context Clues: The blog discusses Ready Player One. In the book/movie, the protagonist Wade Watts uses the avatar name Parzival.
  • User: wade
  • Password: parzival (Note: Often needs to be all lowercase).

3. Initial Access: RDP

With valid credentials, we connect directly via RDP.

xfreerdp /u:wade /p:parzival /v:retro.thm
  • User Flag: Located on the Desktop user.txt.

4. Privilege Escalation: The “Clicky” Exploit

A. Enumeration

On the Desktop (or checking Chrome Bookmarks as you mentioned), there is a reference to CVE-2019-1388. There is usually an executable file in the Recycle Bin or on the Desktop named hhupd.exe (an old Windows Help updater) which is signed by Microsoft but vulnerable.

B. The Exploit (CVE-2019-1388)

This is a logic flaw in how Windows handles User Account Control (UAC) when viewing certificates. It allows you to open a browser instance as SYSTEM, from which you can spawn a shell.

The Steps (The “EZ” Path):

  1. Trigger UAC: Run hhupd.exe (Run as Administrator).
  2. Don’t click Yes/No: Instead, click “Show information about this publisher’s certificate”.
  3. Certificate Details:
  • Go to the “Issued by” link (usually Symantec or VeriSign).
  • This action spawns an Internet Explorer window running as SYSTEM (because the UAC prompt runs as SYSTEM).
  1. The Breakout:
  • In the IE window, go to File -> Save As.
  • In the file dialog, navigate to C:\Windows\System32\.
  • Find cmd.exe.
  • Right-click cmd.exe and select Open.

Result: A command prompt opens running as NT AUTHORITY\SYSTEM.

C:\Windows\system32> whoami
nt authority\system

Root Flag: C:\Users\Administrator\Desktop\root.txt.txt.


5. Remediation (Blue Team)

  1. Patch Management:
  • This vulnerability (CVE-2019-1388) was patched by Microsoft in November 2019. Ensure the server is updated to a build newer than that.
  1. RDP Security:
  • Do not expose RDP (3389) to the internet. Use a VPN or Gateway.
  • Enforce Network Level Authentication (NLA).
  1. Credential Policies:
  • parzival is a weak password derived from the user’s interests. Implement complexity requirements and blocklists for common pop-culture terms.