Helpdesk
PG Practice Helpdesk writeup
Last updated
PG Practice Helpdesk writeup
Last updated
Port 8080 root page lands us on a login page for ManageEngine ServiceDesk plus.
This is running version 7.6.0 as per the information available on screen. Looking up default credentials on Google shows we can try administrator:admininistrator
. This proves successful and are able to login.
Research exploits for this particular version we come across CVE-2014-5301.
Description:
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
Looking for available exploits we come to: https://github.com/PeterSufliarsky/exploits/blob/master/CVE-2014-5301.py
As per the exploit instructions contained in the script generate a WAR file with msfvenom
:
Then execute with the following syntax:
A shell should be received on a netcat
listener running as SYSTEM.
If you get a java heap error on the shell revert the machine and try again.