Living off the Land

Using the LOLBAS and GTFOBins Project


LOLBAS for Windowsarrow-up-right and GTFOBins for Linuxarrow-up-right are websites where we can search for binaries we can use for different functions.

LOLBAS

To search for download and upload functions in LOLBASarrow-up-right we can use /download or /upload.

Let's use CertReq.exearrow-up-right as an example.

We need to listen on a port on our attack host for incoming traffic using Netcat and then execute certreq.exe to upload a file.

Upload win.ini to our Pwnbox

This will send the file to our Netcat session, and we can copy-paste its contents.

File Received in our Netcat Session

If you get an error when running certreq.exe, the version you are using may not contain the -Post parameter. You can download an updated version herearrow-up-right and try again.

GTFOBins

To search for the download and upload function in GTFOBins for Linux Binariesarrow-up-right, we can use +file download or +file upload.

Let's use OpenSSLarrow-up-right. It's frequently installed and often included in other software distributions, with sysadmins using it to generate security certificates, among other tasks. OpenSSL can be used to send files "nc style."

We need to create a certificate and start a server in our Pwnbox.

Create Certificate in our Pwnbox

Stand up the Server in our Pwnbox

Next, with the server running, we need to download the file from the compromised machine.

Download File from the Compromised Machine

Other Common Living off the Land tools

Bitsadmin Download function

The Background Intelligent Transfer Service (BITS)arrow-up-right can be used to download files from HTTP sites and SMB shares. It "intelligently" checks host and network utilization into account to minimize the impact on a user's foreground work.

File Download with Bitsadmin

PowerShell also enables interaction with BITS, enables file downloads and uploads, supports credentials, and can use specified proxy servers.

Download

Certutil

It is available in all Windows versions and has been a popular file transfer technique, serving as a defacto wget for Windows. However, the Antimalware Scan Interface (AMSI) currently detects this as malicious Certutil usage.

Download a File with Certutil

Last updated