[Query] Pentesting 10-30-2016, 02:55 AM
#1
I just want to pick your brains on something.
I want to remotely access a client that's not on my network. I may not be authorized to do pentesting here but I wanted to have a real-life setup where I don't have anything but a couple of details about the user and the client PC instead of setting up my own network infrastructure for testing. This is to beef up my skills too I guess.
Any session would be okay
File Access would be good
Remote Desktop (if possible)
Passwords would be fantastic
The client PC is quite far from my lab (few blocks away) but I connected to their connection (Wifi using android) in the past so when I walk by, I get connected automatically.
I used Zanti on my phone and can see the whole network map (all devices connected to the wifi including the router). I was thinking to leave my phone there for a day and control it using Airdroid from my lab.
Sitting by close by the house with my laptop would look suspicious. In short, I can be on their network anytime but only through Android.
Zanti has a lot of options available which is great but some of which are not applicable for me.
Scan open port and connect to it
SSH is not an option as most Windows PCs are not shipped with it enabled
Telnet may also not be enabled on the machine
Sniff packets
Redirect traffic
Capture download (Doesn't download on the internet that much)
Replace download (Doesn't download on the internet that much
SSL strip (SSL strip may not work on most websites with HTTPS as default. This only works for HTTP sites that get REDIRECTED to HTTPS)
RAT is not the go-to since I want to exhaust all my resources before taking this path.
I guess, my question is, how do I create a session for myself to take control of the system without the user doing anything i.e executing a suspicious looking payload.
I want to remotely access a client that's not on my network. I may not be authorized to do pentesting here but I wanted to have a real-life setup where I don't have anything but a couple of details about the user and the client PC instead of setting up my own network infrastructure for testing. This is to beef up my skills too I guess.
Any session would be okay
File Access would be good
Remote Desktop (if possible)
Passwords would be fantastic
The client PC is quite far from my lab (few blocks away) but I connected to their connection (Wifi using android) in the past so when I walk by, I get connected automatically.
I used Zanti on my phone and can see the whole network map (all devices connected to the wifi including the router). I was thinking to leave my phone there for a day and control it using Airdroid from my lab.
Sitting by close by the house with my laptop would look suspicious. In short, I can be on their network anytime but only through Android.
Zanti has a lot of options available which is great but some of which are not applicable for me.
Scan open port and connect to it
SSH is not an option as most Windows PCs are not shipped with it enabled
Telnet may also not be enabled on the machine
Sniff packets
Redirect traffic
Capture download (Doesn't download on the internet that much)
Replace download (Doesn't download on the internet that much
SSL strip (SSL strip may not work on most websites with HTTPS as default. This only works for HTTP sites that get REDIRECTED to HTTPS)
RAT is not the go-to since I want to exhaust all my resources before taking this path.
Code:
More details:
PC
OS: Windows 10
Security: No user account password afaik but has UAC enabled
Antivirus: Possibly AVG/Avast cracked
Firewall: Possibly disabled
User:
Casual user of the PC, Possibly 4-5 hours a day from usually after work
Habit (that requires internet):
Spotify
uTorrent (download movies)
Chrome (stream movies)
Habit (that doesn't require the internet):
MS Office
PDF Viewer
VLCI guess, my question is, how do I create a session for myself to take control of the system without the user doing anything i.e executing a suspicious looking payload.





![[+]](https://sinister.li/images/modern/collapse_collapsed.png)










