Linux version of Mimikaz

Source: Internet
Author: User
Tags ftp client

A tool to dump the login password from the current Linux desktop user. Adapted from the idea behind the popular Windows tool Mimikatz.

Https://github.com/huntergregal/mimipenguin

Details

Takes advantage of cleartext credentials in memory by dumping the process and extracting lines that has a high probabilit Y of containing cleartext passwords. Would attempt to calculate each word's probability by checking hashes In/etc/shadow, hashes in memory, and regex searches.

Requires

    • Root Permissions
Supported/tested Systems

    • Kali 4.3.0 (rolling) x64 (GDM3)
    • Ubuntu Desktop 12.04 LTS x64 (Gnome Keyring 3.18.3-0UBUNTU2)
    • Ubuntu Desktop 16.04 LTS x64 (Gnome Keyring 3.18.3-0UBUNTU2)
    • Xubuntu Desktop 16.04 x64 (Gnome Keyring 3.18.3-0UBUNTU2)
    • ArchLinux x64 Gnome 3 (Gnome Keyring 3.20)
    • OpenSUSE Leap 42.2 x64 (Gnome Keyring 3.20)
    • VSFTPd 3.0.3-8+b1 (Active FTP client connections)
    • Apache2 2.4.25-3 (active/old HTTP BASIC AUTH Sessions) [Gcore dependency]
    • Openssh-server 1:7.3p1-1 (Active SSH connections-sudo usage)
Notes

    • Password moves in Memory-still honing in on 100% effectiveness
    • Plan on expanding support and other credential locations
    • Working on expanding to non-desktop environments
    • Known bug-sometimes Gcore hangs the script, this was a problem with Gcore
    • Open to pull requests and community
    • LDAP (NSCLD Winbind etc) planned for the future
Development Roadmap

Mimipenguin is slowly being ported to multiple languages to support all possible post-exploit scenarios. The roadmap below was suggested by Kingsabri to track the various versions and features. An ' X ' denotes full support while a ' ~ ' denotes a feature with known bugs.

Contact

    • Twitter: @huntergregal
    • Website:huntergregal.com
    • Github:huntergregal
Licence

CC by 4.0 licence-https://creativecommons.org/licenses/by/4.0/

Special Thanks

    • The-useless-one for Remove Gcore as a dependency, cleaning up tabs, adding output option, and a full Python3 port
    • Gentilkiwi for Mimikatz, the inspiration and the Twitter shoutout
    • pugilist for cleaning up PID extraction and testing
    • Ianmiell for cleaning up some of my messy code
    • W0RM for identifying printf error when special chars is involved
    • BENICHMT1 for identifying multiple authenticate users issue
    • Chaitanyaharitash for identifying special char edge case issues
    • Imawizardlizard for cleaning up the pattern matches with a for loop
    • COREB1T for Python3 checks, arch support, other fixes
    • N1nj4sec for a python2 port and support
    • Kingsabri for the Roadmap proposal
    • Bourgouinadrien for linking Https://github.com/koalaman/shellcheck

Linux version of Mimikaz

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.