
Windows 대상에서 NTLM 암호 해시를 사용하여 원격 명령 실행을 위한 SMBExec의 C# 구현으로, 측면 이동 및 패스더해시 공격을 가능하게 합니다.
Kevin Robertsons Invoke-SMBExec PowerShell 스크립트의 네이티브 C# 변환입니다. (https://github.com/Kevin-Robertson/Invoke-TheHash/blob/master/Invoke-SMBExec.ps1)
.NET 3.5용으로 빌드되었습니다.
Sharp-SMBExec.exe hash:"hash" username:"username" domain:"domain.tld" target:"target.domain.tld" command:"command"
이 어셈블리를 사용하면 지정된 사용자의 NTLM 해시를 제공하여 SMB를 통해 대상 머신에서 명령을 실행할 수 있습니다.
Option Description
username* Username to use for authentication
hash* NTLM Password hash for authentication. This module will accept either LM:NTLM or NTLM format
domain Domain to use for authentication. This parameter is not needed with local accounts or when using @domain after the username
target Hostname or IP Address of the target.
command Command to execute on the target. If a command is not specified, the function will check to see if the username and hash provide local admin access on the target
ServiceName Default = 20 Character Random. The Name of the service to create and delete on the target.
-CheckAdmin Check admin access only, don't execute command
-Help (-h) Switch, Enabled debugging [Default='False']
-Debug Print Debugging Information along with output
-ForceSMB1 Force SMB1. The default behavior is to perform SMB Version negotiation and use SMB2 if it's supported by the target [Default='False']
-ComSpec Prepend %COMSPEC% /C to Command [Default='False']