Just finished the Retro machine on TryHackMe and wrote this clean walkthrough.
In short: I found three independent ways to land SYSTEM on Windows Server 2016 :
WordPress web path (credentials in blog comments → PHP reverse shell)
RDP route using those same creds followed by a kernel exploit (CVE-2017-0213)
Clever Certificate Publisher / UAC UI trick that spawns SYSTEM-level Internet Explorer and gives you cmd.exe from the Save dialog.
Full play-by-play and commands in the writeup.
0 comments