Skip to content

Search for Remote passwords in Text|LogFiles Recursive

pedro ubuntu edited this page Mar 2, 2020 · 16 revisions

Description

This Module allows attackers to Remote Search in 'Text|LogFiles' for password strings (pass, passwd, password) starting in User Input Directory recursive (sub-directorys are also scanned for creds).
[url] Credential Dumping - Mitre ATT&CK T1044

Remark

  • The Module Used in this article requires the Client to be executed with Administrator Privs
  • This article its written using 'new windows terminal', Skip 'step 1' if your not planning to use it.
  • Instructions how to Install 'meterpeter' under new windows terminal can be review <here>

Article Quick Jump List



Config new terminal windows to use meterpeter ('step 1')

1º - Press 'Settings' in new terminal console sd

2º - add the follow line to your 'profiles.json' file shortcut

  • Instructions how to Install meterpeter under new terminal can be review here
  • Jump To Top


Search for password strings in text|logfiles

1º - Sellect meterpeter 'PostExploit' Module post1

2º - Sellect meterpeter 'ListPas' Module
This module will ask attacker to 'input the starting directory' were to start searching inside 'Text|Logs' files 'Recursive' for the strings: 'pass', 'passwd', 'password'. post2

3º - Press 'CTRL+F' in your keyboard to use the 'Search' Function.
This 'new windows terminal' keyboard shortcut allow us to fast identify strings in large files. post3

  • Instructions how to Install meterpeter under new terminal can be review here
  • Jump To Top

  • TODO: Add option to allow users to input a string to search