2023-10-04 06:35:53 +02:00
2023-10-04 06:28:27 +02:00
2022-07-17 23:27:27 +02:00
2022-11-30 12:07:36 +01:00
2022-12-15 09:10:57 +01:00
2023-10-04 06:35:53 +02:00
2022-12-16 09:54:17 +01:00
2022-11-30 12:32:10 +01:00
2023-10-04 06:35:53 +02:00

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.
PyPI GitHub release (latest by date) YouTube Channel Subscribers

Features

  • Core:
    • Lists open SMB pipes on the remote machine (in modes scan authenticated and fuzz authenticated)
    • Tries to connect on a list of known SMB pipes on the remote machine (in modes scan unauthenticated and fuzz unauthenticated)
    • Calls one by one all the vulnerable RPC functions to coerce the server to authenticate on an arbitrary machine.
    • Random UNC paths generation to avoid caching failed attempts (all modes)
    • Configurable delay between attempts with --delay
  • Options:
    • Filter by method name with --filter-method-name, by protocol name with --filter-protocol-name or by pipe name with --filter-pipe-name (all modes)
    • Target a single machine --target or a list of targets from a file with --targets-file
    • Specify IP address OR interface to listen on for incoming authentications. (modes scan and fuzz)
  • Exporting results
    • Export results in SQLite format (modes scan and fuzz)
    • Export results in JSON format (modes scan and fuzz)
    • Export results in XSLX format (modes scan and fuzz)

Installation

You can now install it from pypi (latest version is PyPI) with this command:

sudo python3 -m pip install coercer

Quick start


Contributing

Pull requests are welcome. Feel free to open an issue if you want to add other features.

Credits

S
Description
Automated archival mirror of github.com/p0dalirius/Coercer
Readme GPL-2.0
12 MiB
Languages
Python 97.1%
PowerShell 2.4%
Makefile 0.5%