946 B
946 B
Description
This module runs arbitrary Windows commands using the WinRM Service. It needs login credentials to do so.
Verification Steps
- Do:
use auxiliary/scanner/winrm/winrm_cmd - Do:
set CMD [WINDOWS COMMAND] - Do:
set RHOSTS [IP] - Do:
set USERNAME [USERNAME] - Do:
set PASSWORD [PASSWORD] - Do:
run
Scenarios
msf > use auxiliary/scanner/winrm/winrm_cmd
msf auxiliary(scanner/winrm/winrm_cmd) > set CMD hostname
CMD => hostname
msf auxiliary(scanner/winrm/winrm_cmd) > set RHOSTS 1.1.1.10
RHOSTS => 1.1.1.10
msf auxiliary(scanner/winrm/winrm_cmd) > set USERNAME Administrator
USERNAME => Administrator
msf auxiliary(scanner/winrm/winrm_cmd) > set PASSWORD vagrant
PASSWORD => vagrant
msf auxiliary(scanner/winrm/winrm_cmd) > run
[+] vagrant-2008R2
[*] Scanned 1 of 1 hosts (100% complete)
[*] Auxiliary module execution completed
msf auxiliary(scanner/winrm/winrm_cmd) >