-
Notifications
You must be signed in to change notification settings - Fork 25
Description
I am trying to test this against a real machine.
I am able to do all the steps to create the bcd as per the grab-bcd-smb.gif though I do need to manually set the IP of the target with netsh interface ip set address "Ethernet" static 10.13.37.69 255.255.255.0 10.13.37.1.
I note that the create-bcd.bat asks "Do you want to move the file to the SMB server on 10.13.37.1 (Y/[N])?" I assume this should read 10.13.37.100.
The next step in the instructions says to "Start the TFTP server in exploit mode" with ./start-server.sh exploit <interface> though this command doesn't exist and I believe is mean to read ./start-server.sh pxe <interface>.
My main question is how this is run relative to the prior command.? Do I open a new terminal and run it or am I meant to close the smb server first? Am I meant to get the modified-bcd file from the smb first? Where is that file stored on the attacking machine?
As it is I have tried both but it seems to fail with the target ending up with a blank blue screen and then shutting down.
Below is the log from the pxe when I try to boot via pxe:
└─$ ./start-server.sh pxe eth0 [sudo] password for user: Error: ipv4: Address already assigned. [+] Info: Interface eth0 has IP address 10.13.37.100/24 [+] Info: Killing all dnsmasq processes... dnsmasq: no process found [+] Info: Starting dnsmasq... dnsmasq: started, version 2.91 cachesize 150 dnsmasq: compile time options: IPv6 GNU-getopt DBus no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC loop-detect inotify dumpfile dnsmasq-dhcp: DHCP, IP range 10.13.37.100 -- 10.13.37.101, lease time 1h dnsmasq-tftp: TFTP root is /home/user/bitpixie/pxe-server dnsmasq: no servers found in /etc/resolv.conf, will retry dnsmasq: read /etc/hosts - 7 names dnsmasq-dhcp: DHCPDISCOVER(eth0) b4:b6:86:da:c8:2e dnsmasq-dhcp: DHCPOFFER(eth0) 10.13.37.101 b4:b6:86:da:c8:2e dnsmasq-dhcp: DHCPREQUEST(eth0) 10.13.37.101 b4:b6:86:da:c8:2e dnsmasq-dhcp: DHCPACK(eth0) 10.13.37.101 b4:b6:86:da:c8:2e dnsmasq-tftp: error 8 User aborted the transfer received from 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: error 0 TFTP Aborted received from 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/Boot/BCD to 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/Boot/BCD to 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/Policies/SbcpFlightToken.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SecureBootPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SkuSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/WinSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/ATPSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SkuSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/WinSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/ATPSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SkuSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/WinSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/ATPSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/en-US/bootmgfw.efi.MUI not found for 10.13.37.101 dnsmasq-tftp: error 0 TFTP Aborted received from 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/FveTcg_2.log not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/segoe_slboot.ttf not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/segmono_boot.ttf not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/wgl4_boot.ttf not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/wgl4_boot.ttf not found for 10.13.37.101