Хорошая "плюшка". На след. неделе проверю в сетке. Очень похоже на виндовый runhash - тоже "веСЧь"!
Давно точу зуб на главный корпоративный сервер! Надо продумать только маскировку, чтоб не запалили. Хотя и на этот случай есть отмазка: пентест корпоративной сети.RunhAsh v1.0 (x86)
Since our tools are so effective, various social media have decided to classify them as dangerous code. We've therefore chosen to remove the public links. Don't worry though!
Tool to inject password hash in a process. It is used to impersonate the owner of the password hash when getting access to network resources. Size: 81 KB
Instruction
USAGE
runhash PWDUMP_STRING CMD_LINE [CMD_ARG1 [...]]
runhash -p PWDUMP_STRING, not implemented in this release
PARAMETERS
-p (not implemented in this release)
Change credentials in the parent process, the one that run runhash
PWDUMP_STRING
A complete password hash string in pwdump format, see example below
CMD_LINE
The command to run with the given hash credentials
CMD_ARGn
Any number of arguments to the CMD_LINE command
EXAMPLE PWDUMP_STRING
dmn\usr::aad3b435b51404eeaad3b435b51404ec:
aad3b435aaaaaaeeaad3b435b51404eb:::
usr@dmn::aad3b435b51404eeaad3b435b51404ec:
aad3b435aaaaaaeeaad3b435b51404eb:::
Комментарии
3