
C# में SMBExec का कार्यान्वयन, NTLM पासवर्ड हैश का उपयोग करके विंडोज लक्ष्यों पर दूरस्थ कमांड निष्पादन के लिए, जो पार्श्व गति और पास-द-हैश हमलों को सक्षम करता है।
Kevin Robertsons के Invoke-SMBExec पावरशेल स्क्रिप्ट का एक मूल C# रूपांतरण। (https://github.com/Kevin-Robertson/Invoke-TheHash/blob/master/Invoke-SMBExec.ps1)
.NET 3.5 के लिए बनाया गया
Sharp-SMBExec.exe hash:"hash" username:"username" domain:"domain.tld" target:"target.domain.tld" command:"command"
यह असेंबली आपको निर्दिष्ट उपयोगकर्ता के लिए NTLM हैश प्रदान करके SMB का उपयोग करके लक्ष्य मशीन पर एक कमांड निष्पादित करने की अनुमति देगी।
Option Description
username* Username to use for authentication
hash* NTLM Password hash for authentication. This module will accept either LM:NTLM or NTLM format
domain Domain to use for authentication. This parameter is not needed with local accounts or when using @domain after the username
target Hostname or IP Address of the target.
command Command to execute on the target. If a command is not specified, the function will check to see if the username and hash provide local admin access on the target
ServiceName Default = 20 Character Random. The Name of the service to create and delete on the target.
-CheckAdmin Check admin access only, don't execute command
-Help (-h) Switch, Enabled debugging [Default='False']
-Debug Print Debugging Information along with output
-ForceSMB1 Force SMB1. The default behavior is to perform SMB Version negotiation and use SMB2 if it's supported by the target [Default='False']
-ComSpec Prepend %COMSPEC% /C to Command [Default='False']