Download - Exfiltration

Tool

Updog

updog --ssl --port 9090 --password "exegol4thewin" --directory /opt/resources

Living Off Trusted Sites

Web transfer

Create a Web Server on Linux victim host

Python 3

Python 2.7

PHP

Ruby

Create a web server on a Windows host

Windows - HFS HTTP File Server

Powershell_HttpServer

Download file

SCP

Base64

Windows

Transfer from victim host to attack

SMB

Metasploit - Download

Metasploitchevron-right

SMBclient - get

SMB (445, 139) / RPCchevron-right

smb: \> get prep-prod.txt

Source:

SMBmap - download

SMB (445, 139) / RPCchevron-right

SMB over WebDAV

From Windows to Linux

FTP

From Windows victim to Linux

or

Web exfiltration

Uploadserver

Linux to Linux

Windows victim to Linux

HTTPS => Create Self-Signed Certificate - See Web exfiltration - Linux to Linux

PowerShell Base64 Web Upload

Python

Netcat

nc.exe

Commands

WinRM

RDP

rdesktop

xfreerdp

Remmina

Windows to windows

LOLBAS

CertReq.exe

GTFOBins

Metasploit

Metasploitchevron-right

WinRM

Evil-WinRMchevron-right

Resources

Last updated