Giter Site home page Giter Site logo

rdpthief's Issues

Crashes RDP upon injection

Running into an issue when Cobalt Strike injects the .tmp file, it crashes RDP. Has this been patched?

Never see the injection happen

victim is a windows 10 (local admin user) - seems like the injection is never done. RDP is turned on, and I can RDP into the machine from another machine...

beacon> sleep 0
[*] Tasked beacon to become interactive
[+] host called home, sent: 16 bytes
beacon> rdpthief_enable
[+] RdpThief enabled

[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
[+] host called home, sent: 12 bytes
beacon> rdpthief_disable
[+] Disabling RdpThief
beacon> rdpthief_dump
[*] Tasked beacon to run: type %temp%\data.bin
[+] host called home, sent: 51 bytes
[+] received output:
The system cannot find the file specified.

Issue hooking mstsc.exe on windows 10 1903

I compiled the DLL (RdpThief.dll) and injected it into mstsc.exe process. It is able to hook ADVAPI32!CredIsMarshaledCredentialW but is unable to hook SSPICLI!SspiPrepareForCredRead and dpapi!cryptprotectmemory. I was able to verify this by attaching a debugger and looking at the assembly. Only the CredIsMarshaledCredentialW function has jump into the loaded dll. Any pointers on how do I debug this issue or have you encountered this before?

Are some DLLs immune to hooking?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.