module
Group Policy Script Execution From Shared Resource
| Disclosed | Created |
|---|---|
| Jan 26, 2015 | May 30, 2018 |
Disclosed
Jan 26, 2015
Created
May 30, 2018
Description
This is a general-purpose module for exploiting systems with Windows Group Policy
configured to load VBS startup/logon scripts from remote locations. This module runs
a SMB shared resource that will provide a payload through a VBS file. Startup scripts
will be executed with SYSTEM privileges, while logon scripts will be executed with the
user privileges. Have into account which the attacker still needs to redirect the
target traffic to the fake SMB share to exploit it successfully. Please note in some
cases, it will take 5 to 10 minutes to receive a session.
configured to load VBS startup/logon scripts from remote locations. This module runs
a SMB shared resource that will provide a payload through a VBS file. Startup scripts
will be executed with SYSTEM privileges, while logon scripts will be executed with the
user privileges. Have into account which the attacker still needs to redirect the
target traffic to the fake SMB share to exploit it successfully. Please note in some
cases, it will take 5 to 10 minutes to receive a session.
Authors
Platform
Windows
Architectures
x86, x64
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.