NetExec icon indicating copy to clipboard operation
NetExec copied to clipboard

[EXP: test with aardwolf] [xfreerdp] Open pandorabox...

Open XiaoliChan opened this issue 2 years ago • 11 comments

U know what that means...

Comparison: image

XiaoliChan avatar Sep 09 '23 04:09 XiaoliChan

@XiaoliChan What exactly is the point of adding an alternative RDP procotol? From the looks of it this is just a popen to xfreerdp which doesn't make much sense to add in. Protocols should be as low level as possible, but this just hooks another very high level tool.

Marshall-Hallenbeck avatar Sep 09 '23 13:09 Marshall-Hallenbeck

@Marshall-Hallenbeck This is a simple test, because I found "aardwolf" will miss lots of RDP targets when I use it in real-world attack, I should convert this PR to a draft

@NeffIsBack Hope you can play with it.

XiaoliChan avatar Sep 09 '23 13:09 XiaoliChan

@XiaoliChan I think we should focus on fixing that with aardwolf, or some other low level library, then. The problem with this, is it creates a dependency on another binary, xfreerdp, and that won't work on Windows or MacOS...

Marshall-Hallenbeck avatar Sep 09 '23 19:09 Marshall-Hallenbeck

@Marshall-Hallenbeck yes, you are right, so this PR also can use compare the results with aardwolf’s results, that why I mark it as “test”

XiaoliChan avatar Sep 10 '23 01:09 XiaoliChan

@XiaoliChan That sounds good to me

Marshall-Hallenbeck avatar Sep 10 '23 01:09 Marshall-Hallenbeck

You can use xfreerdp for Windows - wfreerdp. I use it often.

bongobongoland avatar Sep 17 '23 02:09 bongobongoland

by the looks of it, rdp can't bruteforce older Windows hosts and can't connect to some of them (.131)?

bongobongoland avatar Oct 06 '23 02:10 bongobongoland

by the looks of it, rdp can't bruteforce older Windows hosts and can't connect to some of them (.131)?

I test it, it can brute force the older windows hosts

XiaoliChan avatar Oct 06 '23 04:10 XiaoliChan

I'm referring to your screenshot. xfreerdp can connect to .131 , but nxc can't connect and also can't bruteforce .130

bongobongoland avatar Oct 06 '23 04:10 bongobongoland

I'm referring to your screenshot. xfreerdp can connect to .131 , but nxc can't connect and also can't bruteforce .130

Ah, yes, aardwolf is not stable, so it can't bruteforce 130, but xfreerdp can

XiaoliChan avatar Oct 06 '23 09:10 XiaoliChan

@Marshall-Hallenbeck I think it can be like core argument in rdp protocol nxc rdp 192.168.1.1 -u xiaoli -p 111qqq... --core xfreerdp

XiaoliChan avatar Oct 07 '23 09:10 XiaoliChan