3gstudent

Elite
@3gstudent

good in study,attitude and health.

Pentest-and-Development-Tips. A collection of pentest and development tips

1.1k

Homework-of-Python. Python codes of my blog.

412

Homework-of-C-Language. C/C++ code examples of my blog.

408

Worse-PDF. Turn a normal PDF file into malicious.Use to steal Net-NTLM Hashes from windows machines.

344

Eventlogedit-evtx--Evolution. Remove individual lines from Windows XML Event Log (EVTX) files

272

List-RDP-Connections-History. Use powershell to list the RDP Connections History of logged-in users or all users

262

Inject-dll-by-APC. Asynchronous Procedure Calls

247

Javascript-Backdoor. Learn from Casey Smith @subTee

238

Invoke-BuildAnonymousSMBServer. Use to build an anonymous SMB file server.

231

pyKerbrute. Use python to perform Kerberos pre-auth bruteforcing

210

Homework-of-C-Sharp. C Sharp codes of my blog.

192

msbuild-inline-task.

187

CLR-Injection. Use CLR to inject all the .NET apps

184

SharpRDPCheck. Use to check the valid account of the Remote Desktop Protocol(Support plaintext and ntlmhash)

166

Inject-dll-by-Process-Doppelganging. Process Doppelgänging

164

backup-3gstudent.github.io. old blog

152

Smbtouch-Scanner. Automatically scan the inner network to detect whether they are vulnerable.

138

ntfsDump. Use to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures.

119

Homework-of-Powershell. powershell codes of my blog.

105

HiddenNtRegistry. Use NT Native Registry API to create a registry that normal user can not query.

93

Use-COM-objects-to-bypass-UAC. C++

91

Windows-EventLog-Bypass. Use subProcessTag Value From TEB to identify Event Log Threads

88

pyXSSPlatform. Used to build an XSS platform on the command line.

80

3gstudent.github.io. Blog

79

Office-Persistence. Use powershell to test Office-based persistence methods

76

Windows-User-Clone. Create a hidden account

75

APT34-Jason. Use to perform Microsoft exchange account brute-force.

73

CreateRemoteThread. From 32-bit process to 64-bit process

69

bitsadminexec. Use bitsadmin to maintain persistence and bypass Autoruns

67

CVE-2017-8464-EXP. Support x86 and x64

66

Hook-PasswordChangeNotify. Stealing passwords every time they change

66

Code-Execution-and-Process-Injection. Powershell to CodeExecution and ProcessInjection

65

test. just test

65

Shellcode-Generater. No inline asm,support x86/x64

65

PasswordFilter. 2 ways of Password Filter DLL to record the plaintext password

65

Dump-Clear-Password-after-KB2871997-installed. PowerShell

62

COM-Object-hijacking. use COM Object hijacking to maintain persistence.(Hijack CAccPropServicesClass and MMDeviceEnumerator)

61

NinjaCopy. Powershell to copy ntds.dit

61

signtools. From Windows SDK

59

ewsManage. My exercise of using Exchange Web Service(EWS)

56

From-System-authority-to-Medium-authority. Penetration test

56

Bypass-Windows-AppLocker. C

55

Waitfor-Persistence. Use Waitfor.exe to maintain persistence

55

Winpcap_Install. Auto install WinPcap on Windows(command line)

55

Homework-of-Go. Go code examples of my blog.

51

PNG-Steganography. Steganography Payload

47

easBrowseSharefile. Use to browse the share file by eas(Exchange Server ActiveSync)

46

Eventlogedit-evt--General. Remove individual lines from Windows Event Viewer Log (EVT) files

45

GadgetToJScript. (Small change to make it easier to test the payload and combine it with SILENTTRINITY.)A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS based scripts.

43

Bypass-McAfee-Application-Control--Code-Execution. source&exe

39

Smallp0wnedShell. Small modification version of p0wnedShell

39

ListInstalledPrograms. List the programs that the current Windows system has installed

37

GetExpiredDomains. Search for available domain from expireddomains.net

36

AutoIt-Keylogger. AutoIt

35

fuzzbunch. NSA finest tool

32

Use-msxsl-to-bypass-AppLocker. Learn from Casey Smith@subTee

29

p0wnedShell-DarkVersion. Add my own POC to test Visual Studio trick to run code when building

22

Writeup. interesting analysis

16

LaZagne. Credentials recovery project

13
59
Apply