用于黑客/渗透测试的终极 WinRM 外壳

该外壳是用于黑客/渗透测试的终极 WinRM 外壳。
WinRM(Windows 远程管理)是微软对 WS-Management 协议的实现。它是一种基于 SOAP 的标准协议, 允许来自不同供应商的硬件和操作系统进行互操作。微软将其包含在其操作系统中, 以便让系统管理员的工作更加轻松。
该程序可用于任何启用了此功能(通常位于端口 5985)的 Microsoft Windows 服务器,当然前提是 你拥有使用它的凭据和权限。因此,我们可以说它可用于黑客/渗透测试的后渗透 阶段。该程序的目的是为黑客活动提供友好且易于使用的功能。系统管理员也可以将其用于合法 目的,但其大部分功能都专注于黑客/渗透测试相关的内容。
它主要基于 WinRM Ruby 库,该库自 2.0 版本起改变了其工作方式。现在,它不再使用 WinRM 协议,而是使用 PSRP(PowerShell 远程协议)来初始化运行空间池以及创建和处理管道。
Usage: evil-winrm -i IP -u USER [-s SCRIPTS_PATH] [-e EXES_PATH] [-P PORT] [-a USERAGENT] [-p PASS] [-H HASH] [-U URL] [-S] [-c PUBLIC_KEY_PATH ] [-k PRIVATE_KEY_PATH ] [-r REALM] [-K TICKET_FILE] [--spn SPN_PREFIX] [-l] -S, --ssl Enable ssl -c, --pub-key PUBLIC_KEY_PATH Local path to public key certificate -k, --priv-key PRIVATE_KEY_PATH Local path to private key certificate -r, --realm DOMAIN Kerberos auth, it has to be set also in /etc/krb5.conf file using this format -> CONTOSO.COM = { kdc = fooserver.contoso.com } -K, --ccache TICKET_FILE Path to Kerberos ticket file (ccache or kirbi format, auto-detected) -s, --scripts PS_SCRIPTS_PATH Powershell scripts local path --spn SPN_PREFIX SPN prefix for Kerberos auth (default HTTP) -e, --executables EXES_PATH C# executables local path -i, --ip IP Remote host IP or hostname. FQDN for Kerberos auth (required) -U, --url URL Remote url endpoint (default /wsman) -u, --user USER Username (required if not using kerberos) -p, --password PASS Password -H, --hash HASH NTHash -P, --port PORT Remote host port (default 5985) -a, --user-agent Specify connection user-agent (default Microsoft WinRM Client) -V, --version Show version -n, --no-colors Disable colors -N, --no-rpath-completion Disable remote path completion -l, --log Log the WinRM session -h, --help Display this help message
## 要求
需要 Ruby 2.3 或更高版本。还需要一些 Ruby gem:`winrm >=2.3.7`、`winrm-fs >=1.3.2`、`stringio >=0.0.2`、`logger >= 1.4.3`、`fileutils >= 0.7.2`、`readline ~> 0.0.4`、`readline-ext ~> 0.2.0`。
根据你的安装方法(共有 4 种),可能需要手动安装这些依赖。
另一个仅用于 Kerberos 认证的重要要求是安装用于网络认证的 Kerberos 包。
对于某些基于 Debian 的 Linux(如 Kali、Parrot 等),它被称为 `krb5-user`。对于 BlackArch,它被称为 `krb5`,而在其他 Linux 发行版中可能名称不同。
远程路径补全功能需要原生的 `readline-ext` 绑定,它会作为 Evil-WinRM 的依赖自动安装。某些系统需要额外的开发包才能编译它。更多信息请查看[下面的章节](#Remote-path-completion)。
## 安装与快速开始(4 种方法)
### 方法 1. 直接作为 Ruby gem 安装(依赖将自动安装到你的系统上)
- 步骤 1. 安装它(依赖将自动安装):```gem install evil-winrm```
- 步骤 2. 完成。直接启动即可!```
evil-winrm -i 192.168.1.100 -u Administrator -p 'MySuperSecr3tPass123!' -s '/home/foo/ps1_scripts/' -e '/home/foo/exe_files/'
sudo gem install winrm winrm-fs stringio logger fileutils readline readline-extgit clone https://github.com/Hackplayers/evil-winrm.git### 方法 3:使用 bundler(依赖不会安装到你的系统中,仅用于使用 evil-winrm)
- 步骤 1. 安装 bundler:`gem install bundler`
- 步骤 2. 克隆仓库:`git clone https://github.com/Hackplayers/evil-winrm.git`
- 步骤 3. 使用 bundler 安装依赖:`cd evil-winrm && bundle install --path vendor/bundle`
- 步骤 4. 使用 bundler 启动它:```
bundle exec evil-winrm.rb -i 192.168.1.100 -u Administrator -p 'MySuperSecr3tPass123!' -s '/home/foo/ps1_scripts/' -e '/home/foo/exe_files/'
## 文档
### 明文密码
如果你不想以明文形式输入密码,可以选择不设置 `-p` 参数,系统会提示你输入密码,且不会显示在屏幕上。
### IPv6
要使用 IPv6,必须将地址添加到 /etc/hosts 中。只需在 `-i` 参数后填入已设置的主机名,而不是 IP 地址。
### 基本命令
- **upload**:本地文件可以使用 Tab 键自动补全。
- 用法:`upload local_filename` 或 `upload local_filename destination_filename`
- **download**:
- 用法:`download remote_filename` 或 `download remote_filename destination_filename`
__关于路径的说明(upload/download)__:
下载/上传时不允许使用相对路径。请使用当前目录下的文件名或绝对路径。
如果你在 docker 环境中使用 Evil-WinRM,请记住所有本地路径都应位于 `/data`,并确保你已将其映射为卷,以便能够访问下载的文件或从本地主机操作系统上传文件。
- **services**:列出所有服务,并显示你的账户是否对每个服务拥有权限。使用此功能无需管理员权限。
- **menu**:加载 `Invoke-Binary`、`Dll-Loader` 和 `Donut-Loader` 函数,我们将在下面进行说明。当加载 ps1 文件时,其所有函数都会显示出来。
- **clear** 或 **cls**:清除终端屏幕。你也可以使用 `Ctrl+L` 键盘快捷键来清除屏幕。
- **exit** 或 **quit**:关闭 Evil-WinRM 会话。你也可以使用 `Ctrl+D` 键盘快捷键。```
*Evil-WinRM* PS C:\> menu
,. ( . ) " ,. ( . ) .
(" ( ) )' ,' ( ' (" ) )' ,' . ,)
.; ) ' (( (" ) ;(, . ;) " )" .; ) ' (( (" ) );(, )((
_".,_,.__).,) (.._( ._), ) , (._..( '.._"._, . '._)_(..,_(_".) _( _')
\_ _____/__ _|__| | (( ( / \ / \__| ____\______ \ / \
| __)_\ \/ / | | ;_)_') \ \/\/ / |/ \| _/ / \ / \
| \\ /| | |__ /_____/ \ /| | | \ | \/ Y \
/_______ / \_/ |__|____/ \__/\ / |__|___| /____|_ /\____|__ /
\/ \/ \/ \/ \/
By: CyberVaca, OscarAkaElvis, Jarilaos, Arale61 @Hackplayers
[+] Dll-Loader
[+] Donut-Loader
[+] Invoke-Binary
[+] Bypass-4MSI
[+] services
[+] upload
[+] download
[+] clear
[+] cls
[+] menu
[+] exit
要加载 ps1 文件,只需输入文件名(支持使用 Tab 键自动补全)。脚本必须位于通过 -s 参数设置的路径中。再次输入 menu 即可查看已加载的函数。非常大的文件可能需要较长时间才能加载完成。```
Evil-WinRM PS C:> PowerView.ps1
Evil-WinRM PS C:> menu
,. ( . ) " ,. ( . ) .
(" ( ) )' ,' ( ' (" ) )' ,' . ,)
.; ) ' (( (" ) ;(, . ;) " )" .; ) ' (( (" ) );(, )((
".,,.).,) (..( .), ) , (...( '.."., . '.)(..,(".) ( ')
_ / _|| | (( ( / \ / _| _ \ /
| __)\ / / | | ;)') \ // / |/ | / / \ /
| \ /| | | // \ /| | | \ | / Y
/_____ / _/ |__|/ _/\ / ||| /__| /__| /
/ / / / /
By: CyberVaca, OscarAkaElvis, Jarilaos, Arale61 @Hackplayers