xsspresso
xsspresso
Tags/ Token Impersonation

Token Impersonation

3 writeups tagged with Token Impersonation

WebEasyWindows

HTB — Grandpa

IIS 6.0 WebDAV buffer overflow (CVE-2017-7269) for initial access. Token kidnapping / churrasco escalates to SYSTEM.

#IIS#WebDAV#CVE-2017-7269
Jun 3, 2022HackTheBox
WebEasyWindows

HTB — Artic

ColdFusion 8 arbitrary file upload RCE (CVE-2009-2265). MS10-059 (Chimichurri) token impersonation for privilege escalation.

#ColdFusion#CVE-2009-2265#File Upload
May 30, 2022HackTheBox
WebEasyWindows

HTB — Granny

WebDAV file upload with extension spoofing deploys an ASPX shell. Token impersonation via churrasco/juicy potato for SYSTEM.

#WebDAV#ASPX#Token Impersonation
May 26, 2022HackTheBox