ebe6665412 | ||
---|---|---|
.. | ||
README.md | ||
addadmin.txt |
README.md
Back Door Account
Add an account to an unlocked PC before the keystrokes are caught
Simple script that adds an administrative user for later access. Only works, of course, if the PC is unlocked. However this is a nice complement to the SkeletonKey payload: just add the new user when you unlock the PC.
The payload was tested on Windows 10.
Setup
- Connect the Key Croc and place into arming mode
- Place
addadmin.txt
in the payloads directory - Change the
BACKDOOR_USER
variable to something that will blend into the environment - Change the
BACKDOOR_PASS
variable to a reasonably strong password - Optionally change the MATCH string to a unique passphrase of your choice
- Eject the Key Croc safely
The Key Croc is ready for deployment.
Deploy
- Connect the Key Croc to target in attack configuration
- If you are lucky enough to find yourself at an unlocked screen, type
__addadmin
- With some luck, your user name and password will be added
Cleanup
- Remove the user from the admin group:
net localgroup administrators officeadmin /delete
- Remove the user from the system:
net users officeadmin /delete
What’s up with the name SaintCrossbow? Most of it is because it wasn’t taken. Other than that, I’m a big fan of the literary Saint by Leslie Charteris: a vigilante type who very kindly takes on problem people, serves his own justice, and has a great deal of fun doing it. Also, I just can’t help but think that crossbows are cool.