Skip to content

Having trouble booting from pxe #23

@Alexsaurus-D

Description

@Alexsaurus-D

I am trying to test this against a real machine.
I am able to do all the steps to create the bcd as per the grab-bcd-smb.gif though I do need to manually set the IP of the target with netsh interface ip set address "Ethernet" static 10.13.37.69 255.255.255.0 10.13.37.1.
I note that the create-bcd.bat asks "Do you want to move the file to the SMB server on 10.13.37.1 (Y/[N])?" I assume this should read 10.13.37.100.
The next step in the instructions says to "Start the TFTP server in exploit mode" with ./start-server.sh exploit <interface> though this command doesn't exist and I believe is mean to read ./start-server.sh pxe <interface>.
My main question is how this is run relative to the prior command.? Do I open a new terminal and run it or am I meant to close the smb server first? Am I meant to get the modified-bcd file from the smb first? Where is that file stored on the attacking machine?

As it is I have tried both but it seems to fail with the target ending up with a blank blue screen and then shutting down.

Below is the log from the pxe when I try to boot via pxe:
└─$ ./start-server.sh pxe eth0 [sudo] password for user: Error: ipv4: Address already assigned. [+] Info: Interface eth0 has IP address 10.13.37.100/24 [+] Info: Killing all dnsmasq processes... dnsmasq: no process found [+] Info: Starting dnsmasq... dnsmasq: started, version 2.91 cachesize 150 dnsmasq: compile time options: IPv6 GNU-getopt DBus no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC loop-detect inotify dumpfile dnsmasq-dhcp: DHCP, IP range 10.13.37.100 -- 10.13.37.101, lease time 1h dnsmasq-tftp: TFTP root is /home/user/bitpixie/pxe-server dnsmasq: no servers found in /etc/resolv.conf, will retry dnsmasq: read /etc/hosts - 7 names dnsmasq-dhcp: DHCPDISCOVER(eth0) b4:b6:86:da:c8:2e dnsmasq-dhcp: DHCPOFFER(eth0) 10.13.37.101 b4:b6:86:da:c8:2e dnsmasq-dhcp: DHCPREQUEST(eth0) 10.13.37.101 b4:b6:86:da:c8:2e dnsmasq-dhcp: DHCPACK(eth0) 10.13.37.101 b4:b6:86:da:c8:2e dnsmasq-tftp: error 8 User aborted the transfer received from 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: error 0 TFTP Aborted received from 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/Boot/BCD to 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/Boot/BCD to 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/Policies/SbcpFlightToken.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SecureBootPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SkuSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/WinSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/ATPSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SkuSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/WinSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/ATPSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/SkuSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/WinSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/ATPSiPolicy.p7b not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/en-US/bootmgfw.efi.MUI not found for 10.13.37.101 dnsmasq-tftp: error 0 TFTP Aborted received from 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: sent /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/bootmgfw.efi to 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/FveTcg_2.log not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/segoe_slboot.ttf not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/segmono_boot.ttf not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/wgl4_boot.ttf not found for 10.13.37.101 dnsmasq-tftp: file /home/user/bitpixie/pxe-server/EFI/Microsoft/Boot/fonts/wgl4_boot.ttf not found for 10.13.37.101

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions