View Issue Details

IDProjectCategoryView StatusLast Update
0000302Kali Linux[All Projects] New Tool Requestspublic2014-06-04 15:23
Reporterdookie Assigned Torhertzog  
PrioritynormalSeverityminorReproducibilityhave not tried
Status resolvedResolutionfixed 
Product Version 
Target VersionFixed in Version 
Summary0000302: Add the pass the hash toolkit
DescriptionThis site hosts the patches, scripts, and random flotsum associated with our BlackHat USA 2012 presentation "Still Passing the Hash 15 Years Later?"

http://code.google.com/p/passing-the-hash/downloads/list

Activities

dookie

2013-04-24 22:05

administrator   ~0000402

Added wmis_4.0.0tp4-1kali0.
Only works on 32-bit, though

saberzaid

2013-04-25 09:18

reporter   ~0000404

is the desktop file there? cant find it on kali menu, ammm ill run it from the terminal

muts

2013-04-25 09:58

administrator   ~0000405

Looking into building the PSH toolkit from source.

dookie

2013-04-25 11:56

administrator   ~0000406

saberzaid: There is no desktop file for wmis and there won't be one. We don't want the menu to be too cluttered.

rhertzog

2013-06-21 12:47

administrator   ~0000581

Packaging passing-the-hash is mostly done, albeit only in kali-dev for now because it heavily depends on samba 4 whose packaging has not been well tested and which is still in flux on the Debian side.

That said, I created a "winexe" source package and a "wmi" source package that builds the corresponding tools from sources.

I also created a "passing-the-hash" source packages which provides pth-* binaries that can be used in place of the normal binaries and that should provide the "hash passing feature". For most of the commands, those are actually simple wrappers around the normal binary.

Passing-the-hash still rebuilds 3 sources packages (curl, freetds, wmi) because there was no simple possibility to wrap them.

Now some testing is welcome...

rhertzog

2013-06-21 13:09

administrator   ~0000582

BTW, the patched firefox is missing from this first version of passing-the-hash. I'm waiting on feedback from the iceweasel maintainer to see if there's a nicer way to achieve what we want without forking iceweasel.

Issue History

Date Modified Username Field Change
2013-04-24 21:31 dookie New Issue
2013-04-24 21:31 dookie Status new => assigned
2013-04-24 21:31 dookie Assigned To => dookie
2013-04-24 22:05 dookie Note Added: 0000402
2013-04-25 09:18 saberzaid Note Added: 0000404
2013-04-25 09:58 muts Note Added: 0000405
2013-04-25 11:56 dookie Note Added: 0000406
2013-06-21 12:47 rhertzog Note Added: 0000581
2013-06-21 12:47 rhertzog Assigned To dookie => rhertzog
2013-06-21 12:47 rhertzog Status assigned => resolved
2013-06-21 12:47 rhertzog Resolution open => fixed
2013-06-21 13:09 rhertzog Note Added: 0000582
2014-06-29 19:52 vichet Issue cloned: 0001491