August 2018
Intermediate to advanced
404 pages
10h 22m
English
So, we managed to upload our web-shell to a Windows web server. It is located at http://192.168.56.14/cmd.aspx. The first thing to do is to figure out which privilege level the web server is running:

As you can see, our user is defaultapppool, from the iis apppool group, which is a very limited one in its default configuration.