PrinterBug-printerbug
NEWprinterbug.py (shipped with dirkjanm's krbrelayx toolkit) abuses the MS-RPRN Print System Remote Protocol (the SpoolSample / PrinterBug technique) by calling RpcRemoteFindFirstPrinterChangeNotificationEx on the target's spooler service, forcing the target machine account to authenticate back to an attacker-controlled host over SMB or HTTP. The captured machine-account authentication is then relayed with ntlmrelayx or krbrelayx (e.g. for RBCD or ADCS abuse). The target is given as a domain/user:password@target connection string followed by the attacker host. Requires a valid domain account and a running Print Spooler on the target. Command Reference: Target IP: 10.10.10.1 Listener IP: 10.10.10.2 Domain: test.local Username: john Password: password123