Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

quahac/Netexec-Module-Info

Folders and files

NameName
Last commit message
Last commit date

Latest commit

History

3 Commits

Repository files navigation

NetExec Module: Info

The Info module of NetExec is designed to check the smb.db file for previously connected sessions. It verifies if the connection was established with System or Administrator rights when accessing the host.

Features

  • Connection Verification: The module checks if both the IP address and hostname exist with Administrator rights.
  • Login Information: It prints the login information in the format -id login. This ID can be used to log in as the displayed user, provided the password is valid.
  • Protocol Support: The module can check various protocols, including:
    • SMB
    • RDP
    • WMI
    • LDAP
    • WinRM

Limitations

Currently, the module only saves login information in the smb.db file. As a result, the output will primarily consist of SMB-related information.

Conclusion

The Info module is a useful tool for checking and managing connections with high-level access. It helps penetration testers retest security assessments to determine if the passwords for Administrator accounts have changed.

Example Usage

┌──(root㉿X)-[~]
└─# nxc -t 512 smb 192.168.56.108
SMB 192.168.56.108 445 DC1 [*] Windows Server 2008 R2 Enterprise 7600 x64 (name:DC1) (domain:domain.com) (signing:True) (SMBv1:True)
┌──(root㉿X)-[~]
└─# nxc -t 512 smb 192.168.56.108 -M info <--
SMB 192.168.56.108 445 DC1 [*] Windows Server 2008 R2 Enterprise 7600 x64 (name:DC1) (domain:domain.com) (signing:True) (SMBv1:True)
INFO 192.168.56.108 445 DC1 [+] (Pwnd3!) domain.com\Administrator:password1 -id=393 <--
┌──(root㉿X)-[~]
└─# nxc -t 512 smb 192.168.56.108 -id=393 <--
SMB 192.168.56.108 445 DC1 [*] Windows Server 2008 R2 Enterprise 7600 x64 (name:DC1) (domain:domain.com) (signing:True) (SMBv1:True)
SMB 192.168.56.108 445 DC1 [+] domain.com\Administrator:password1 (Pwn3d!) 

Example Usage

About

No description or website provided.

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

AltStyle によって変換されたページ (->オリジナル) /