Bug#960731: ITP: evil-winrm -- Ultimate WinRM shell for hacking/pentesting

Lester Guerzon <[email protected]>
Newsgroups gmane.linux.debian.devel.wnpp
Message-ID <e161796a-1801-48f1-ba06-a5faeff354bd__14798.7419202522$1787482410$gmane$org@guerzon.net>
Hi Pedro,

Are you still working on this ITP? If not, I would like to take over.

Thanks!

On Fri, 15 May 2020 18:58:02 -0300 Pedro Loami Barbosa dos Santos <[email protected]> wrote:
> Package: wnpp
> Severity: wishlist
> Owner: Pedro Loami Barbosa dos Santos <[email protected]>
> 
> * Package name    : evil-winrm
>   Version         : 2.3
>   Upstream Author : Óscar Alfonso Díaz <[email protected]>
> * URL             : https://github.com/Hackplayers/evil-winrm
> * License         : LGPL-3
>   Programming Lang: ruby
>   Description     : Ultimate WinRM shell for hacking/pentesting
> 
>  This shell is the ultimate WinRM shell for hacking/pentesting.
>  .
>  WinRM (Windows Remote Management) is the Microsoft implementation of
>  WS-Management Protocol. A standard SOAP based protocol that allows hardware
>  and operating systems from different vendors to interoperate. Microsoft
>  included it in their Operating Systems in order to make life easier to system
>  administrators.
>  .
>  This program can be used on any Microsoft Windows Servers with this feature
>  enabled (usually at port 5985), of course only if you have credentials and
>  permissions to use it. So it can be said that it could be used in a post-
>  exploitation hacking/pentesting phase. The purpose of this program is to
>  provide nice and easy-to-use features for hacking. It can be used with
>  legitimate purposes by system administrators as well but the most of its
>  features are focused on hacking/pentesting stuff.
> 
> 
> 
>  This program is really useful while performing penetration testing,
>  security auditing, vulnerability analysis, or just playing at some CTF
>  box. With a system credential in hand, accessing winrm is usually an initial 
>  foothold for entering the machine and starting running commands,
>  and for that evil-winrm is great. It also allows other things like,  
>  uploading/downloading files, loading binaries/scripts in memory, using pass-the-hash,etc.
> 
>  It should be a great package to Debian as it's a great tool to
>  a security professional to have on his/her machine.
> 
>  I intend to maintain this package mentored by a friend DD, although any suggestions or contributions will be welcome.  

-- 
Regards,
Lester

[email protected]
OpenPGP: 107B6026A82D044C97D7D8B92100C145E0F3655E
OpenPGP_signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQQe2AmqC0ETJfX2LkhAMFF4PNlXgUCaorPOQAKCRAhAMFF4PNl
XnetAP0TpwhiFQ9M3BEk6TC1Qx7gz6UZNxbJ1LZwaB2UyZ96fgD/X0mAVOxn1xAk
7V2XjKHZllEjeioZGnJM7Oz+xB/rqQ8=
=4Gg5
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.