Hacking walkthrough: Kartris - trace.axd - Ubiquiti UniFi Video - Apache Tomcat/Coyote 1.1 - Windows 10
Port 80: Microsoft-IIS/10.0 Port 7080: Apache Tomcat/Coyote 1.1 +Ubiquiti UniFi Video Web Application: Kartris Software: Ubiquiti UniFi Video Operating system: Microsoft Windows 10 Build 16299 Vulnerability: CVE-2016-6914 [LPE] Exploit: https://www.exploit-db.com/exploits/43390 Getting inside Kartris Go to http://ip-address/trace.axd , find Admin/Default.aspx , click view details. Under " Form Collectio n", you will see login credentials. Go to http://ip-address/Admin/Default.aspx?page=_Default.aspx . Enter the credentials. Go to http://ip-address/Admin/_GeneralFiles.aspx . Click " Add" button " , you will get an upload box. Getting inside Windows [Initial Shell] Get an aspx web shell ( cmdasp.aspx ) from /usr/share/webshells/aspx/cmdasp.aspx . Upload it to Kartris. Go to http://ip-address/uploads/General/cmdasp.aspx . Now you have a shell and can play around in windows 10. Type " whoami " " systeminfo " ..etc Privilege E...