Offsec Proving Grounds Walkthrough – Fish

Walkthrough of the machine called “Fish” in the OffSec Proving Grounds…this is a Windows machine rated as intermediate. In this video we utilize a directory traversal exploit for Glassfish Server to obtain clear text credentials for SynaMan and then RDP into the machine for a foothold. After spending a ton of time trying to figure out my next steps I realized that the Glassfish Server didn’t require credentials when visiting via the localhost so we deployed and msfvenom WAR file via Glassfish to escalate our privs to NT Authority System.