xsspresso
xsspresso
Tags/ WebDAV

WebDAV

3 writeups tagged with WebDAV

ADHardWindows

HTB — Flight

LFI via lang parameter captures NTLM hash with Responder. Password spray, IIS WebDAV shell upload, RunasCs for lateral movement to Domain Admin.

#AD#LFI#NTLM
Jan 21, 2025HackTheBox
WebEasyWindows

HTB — Grandpa

IIS 6.0 WebDAV buffer overflow (CVE-2017-7269) for initial access. Token kidnapping / churrasco escalates to SYSTEM.

#IIS#WebDAV#CVE-2017-7269
Jun 3, 2022HackTheBox
WebEasyWindows

HTB — Granny

WebDAV file upload with extension spoofing deploys an ASPX shell. Token impersonation via churrasco/juicy potato for SYSTEM.

#WebDAV#ASPX#Token Impersonation
May 26, 2022HackTheBox