Jump to content
Nytro

Evilreg v1.0

Recommended Posts

Posted

Evilreg v1.0

Author: github.com/thelinuxchoice

Twitter: twitter.com/linux_choice

Read the license before using any part from this code :)

Reverse shell using Windows Registry file (.reg).

re

Features:

Reverse TCP Port Forwarding using Ngrok.io

Requirements:

Ngrok Authtoken (for TCP Tunneling): Sign up at: https://ngrok.com/signup

Your authtoken is available on your dashboard: https://dashboard.ngrok.com

Install your auhtoken: ./ngrok authtoken <YOUR_AUTHTOKEN>

Target must reboot/re-login after installing the .reg file

Legal disclaimer:

Usage of Evilreg for attacking targets without prior mutual consent is illegal. It's the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

Usage:

git clone https://github.com/thelinuxchoice/evilreg
cd evilreg
bash evilreg.sh

Donate!

Pay a coffee:

Paypal:

https://www.paypal.com/cgi-bin/webscr?cmd=_s-xclick&hosted_button_id=CLKRT5QXXFJY4&source=url

 

Sursa: https://github.com/thelinuxchoice/evilreg

Posted

Da, pare ca scrie acolo, stupid :)) 

Nu ma uitasem prin cod, ma gandeam ca scrie undeva in Registry din care sa rezulte executia "imediata", sau cel putin rapida, nu dupa restart... 

Posted
11 minutes ago, Nytro said:

Probabil, pare ca pentru persistence sa foloseasca acea cheie de registry ca sa ruleze Powershell (11:45).

De tinut minte. Stiu ca mai vazusem un demo in care comanda/fisierul/binaryul se gasea(u) in alti registri.

  • Upvote 1

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...