HackTheBox - Arctic
Last updated
Was this helpful?
Last updated
Was this helpful?
From Wikipedia, the free encyclopedia. Microsoft RPC (Microsoft Remote Procedure Call) is a modified version of DCE/RPC. Additions include partial support for UCS-2 (but not Unicode) strings, implicit handles, and complex calculations in the variable-length string and structure paradigms already present in DCE/RPC.
Remote Procedure Call (RPC) is a protocol that one program can use to request a service from a program located in another computer on a network without having to understand the network's details. RPC is used to call other processes on the remote systems like a local system.
The webserver is running ColdFusion 8 and we can check for known vulnerabilities using searchsploit.
We can try Arbitrary File Upload module
, as we are not interested in exploiting Cross Site Scripting.
References: https://onecompiler.com/python/3vurkz7hh
Let's upload a cmd.jsp file. You can get the cmd.jsp
file from here.
The webserver is taking a lot of time to process a single request. So it might take some time for uploading the payload.
After the webshell gets uploaded, we can try a simple command to test it out.
Now I will upload a reverse shell instead of running commands on the webshell, as it takes a hell lot of time.