We're sorry but this page doesn't work properly without JavaScript enabled. Please enable it to continue.
Feedback

Getting The Goods With smbexec

00:00

Formal Metadata

Title
Getting The Goods With smbexec
Title of Series
Number of Parts
112
Author
License
CC Attribution 3.0 Unported:
You are free to use, adapt and copy, distribute and transmit the work or content in adapted or unchanged form for any legal purpose as long as the work is attributed to the author in the manner specified by the author or licensor.
Identifiers
Publisher
Release Date
Language

Content Metadata

Subject Area
Genre
Abstract
Individuals often upload and execute a payload to a remote system during penetration tests for foot printing, gathering information, and to compromise additional hosts. When trying to remain stealthy, uploading a shell to a target may not be wise. smbexec takes advantage of native Windows functionality and SMB authentication to execute commands on remote Windows systems without having to upload a payload, decreasing the likelihood of being stopped by AntiVirus. The original intent of creating smbexec was to upload and execute obfuscated payloads using samba tools. Since the first PoC, it has expanded its capability to do more, including dumping local and domain cached password hashes, clear text passwords from memory, and stealing the NTDS.dit file from a Windows Domain controller all without the need for a shell on the victim. We will explore the creation of smbexec, the components behind it, and how to leverage its functionality to get the goods from a system without having to use a payload. Eric Milam (@Brav0Hax) is a principal security assessor on the Accuvant LABS enterprise assessment team with over fifteen (15) years of experience in information technology. Eric has performed innumerable consultative engagements including enterprise security and risk assessments, perimeter penetration testing, vulnerability assessments, social engineering, physical security testing, wireless assessments and extensive experience in PCI compliance controls and assessments. Eric is a project steward for the Ettercap project as well as creator and developer of the easy-creds and smbexec projects. IRC J0hnnyBrav0 Materials:
23
65
108
2 (number)Goodness of fitSpeech synthesis
Open sourceText editorSoftware testingCumulative distribution functionSpherical capOpen sourceProjective planeComputer animationMeeting/Interview
Line (geometry)Exploit (computer security)Special unitary groupScripting languageComputer animation
Scripting languagePower (physics)Computer fileWritingScripting languageoutputHash functionPower (physics)Right angleGoogolArithmetic meanMultiplication signClient (computing)Function (mathematics)Computer animation
Computer wormService (economics)InjektivitätStandard deviationModule (mathematics)BlogSoftware testingTwitterComputer wormService (economics)BlogScripting languageInjektivitätModule (mathematics)Multiplication signRight angleComputer animation
Computer wormProxy serverTouchscreenGastropod shellTerm (mathematics)Revision controlTouchscreenComputer fileOffice suiteComputer wormGastropod shellComputer animation
SoftwareWindow functionNormal (geometry)BitComputer animation
Similarity (geometry)Computer wormModule (mathematics)BitComputer wormLoginFlagSystem programmingMultilaterationNeuroinformatikSoftwareCASE <Informatik>Window functionRadical (chemistry)Normal (geometry)Binary codeGastropod shellModal logicComputer animation
Workstation <Musikinstrument>Core dumpHash functionVolumeAcoustic shadowSystem programmingProxy serverServer (computing)Process (computing)Workstation <Musikinstrument>Volume (thermodynamics)System programmingHash functionDrill commandsRight angleType theoryAcoustic shadowSign (mathematics)Proxy serverProcess (computing)Theory of relativityServer (computing)Core dumpComputer animation
Hash functionCache (computing)Windows RegistryFile formatLocal ringWindows RegistryServer (computing)Hash functionAutomationWorkstation <Musikinstrument>Core dumpLocal ringRegulärer Ausdruck <Textverarbeitung>Window functionFile formatDomain-specific languageCache (computing)Computer animation
FlagFunction (mathematics)PasswordMereologyHash functionCodePasswordSoftware testingLine (geometry)Core dumpINTEGRALFlagSemiconductor memoryDifferential equationFunctional (mathematics)Computer-assisted translationComputer animationMeeting/Interview
File formatHash functionVolumeAcoustic shadowAnalog-to-digital converterFunction (mathematics)Internet forumGoogolKey (cryptography)Electronic mailing listDomain-specific languageBlogVolume (thermodynamics)Game controllerAcoustic shadowFunctional (mathematics)Hash functionComputer animation
Demo (music)Demo (music)Computer animation
Hash functionSystem programmingComputer networkMenu (computing)System administratorPasswordPhase transitionDomain-specific languageElectronic mailing listWorkstation <Musikinstrument>BitHash functionFrequencyWindows RegistrySoftware developerMultiplication signServer (computing)CuboidSystem programmingEnumerated typeMappingPasswordLevel (video gaming)
QuicksortComputer animation
System administratorPasswordHash functionDomain-specific languageComputer networkOnline helpQuicksortPlastikkarteDomain-specific languageHash functionCache (computing)Computer animation
Revision controlCache (computing)
Coefficient of determinationPasswordDomain-specific languageComputer animation
PasswordHash functionDomain-specific languageAddress spaceGame controllerIP addressDomain-specific languageCoefficient of determinationGame controllerPasswordWindow function2 (number)
Acoustic shadowVolumeHash functionPasswordGame controllerAddress spaceDomain-specific languageSpacetimeMiniDiscLink (knot theory)Table (information)SpacetimeAcoustic shadowVolume (thermodynamics)MiniDiscComputer fileVirtual machine
Hash functionDomain-specific languageAcoustic shadowDatabaseTable (information)Game controllerHash functionBit
Menu (computing)System programmingEnumerated typeHash functionDomain-specific languageGame controllerHash functionComputer animation
System programmingMenu (computing)Hash functionEnumerated typeKeyboard shortcutWindow functionServer (computing)Right angleDomain-specific languageGame controllerComputer animation
Demo (music)Computer animation
System programmingLocal ringDomain-specific languageSystem administratorLocal ringRight anglePasswordSystem administratorDomain-specific languageSoftware testingComputer animation
Software developerAuthenticationMiniDiscLoginBinary codeMultiplication signMereology2 (number)AuthenticationSystem programmingWindow functionBitSystem administratorFlagOffice suiteServer (computing)Service (economics)Touch typingPlastikkarteTraffic reportingComputer forensicsTracing (software)Computer animation
Software developerModul <Datentyp>Thread (computing)Software frameworkSource codeHacker (term)Module (mathematics)Revision controlComa BerenicesPoint (geometry)Computer animation
BlogInformation securityMessage passingHash functionPatch (Unix)Core dumpWeb-DesignerPatch (Unix)Spherical capElectronic mailing listScripting languageClient (computing)Computer animation
Electronic data interchangeTwitterHacker (term)Multiplication signTwitterComputer animation
Transcript: English(auto-generated)