Jump to content

jokre

Members
  • Posts

    1
  • Joined

  • Last visited

Recent Profile Visitors

The recent visitors block is disabled and is not being shown to other users.

jokre's Achievements

Newbie

Newbie (1/14)

  1. Please note that the "key=clear" part of the netsh command (in the a.cmd file for this payload) requires local admin privileges on the specific Windows box to get anything out of it. I.e. the logged on user on the PC has to be a local admin, otherwise key=clear will produce nada... So... that part will be "step 1" to verify. If the tests of the payload is executed in a lab environment (or on a PC where you can get access to the box the "correct" way), then logon and run the netsh command in the way it is specified in the a.cmd file of the payload. If netsh throws back an error telling you that it needs to be executed with admin privileges, then the current logged in user has no rights to issue this command with the key=clear "switch". The payload could perhaps be enhanced to catch the error that the command throws back at you and if it says you need admin rights, then the payload could either blink a sequence telling that the execution went bad or put the status in a file on the local storage of the bunny (or both). If working on boxes with a language other than English, the "error catch part" of the payload has to be adjusted so that it can handle error messages in the appropriate system language as well.
×
×
  • Create New...