Coercer

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.

1804
182
Python

A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through many methods.
PyPI GitHub release (latest by date) YouTube Channel Subscribers

Features

  • Core:
    • [x] Lists open SMB pipes on the remote machine (in modes scan authenticated and fuzz authenticated)
    • [x] Tries to connect on a list of known SMB pipes on the remote machine (in modes scan unauthenticated and fuzz unauthenticated)
    • [x] Calls one by one all the vulnerable RPC functions to coerce the server to authenticate on an arbitrary machine.
    • [x] Random UNC paths generation to avoid caching failed attempts (all modes)
    • [x] Configurable delay between attempts with --delay
  • Options:
    • [x] Filter by method name with --filter-method-name, by protocol name with --filter-protocol-name or by pipe name with --filter-pipe-name (all modes)
    • [x] Target a single machine --target or a list of targets from a file with --targets-file
    • [x] Specify IP address OR interface to listen on for incoming authentications. (modes scan and fuzz)
  • Exporting results
    • [x] Export results in SQLite format (modes scan and fuzz)
    • [x] Export results in JSON format (modes scan and fuzz)
    • [x] Export results in XSLX format (modes scan and fuzz)

Installation

You can now install it from pypi (latest version is PyPI) with this command:

sudo python3 -m pip install coercer

Quick start


Contributing

Pull requests are welcome. Feel free to open an issue if you want to add other features.

Credits