Skip to content

SharpLocker not having focus, taking veeery long to transmit without lightspeed (v0.2.3-beta) #58

@ge0rg

Description

@ge0rg

When running the !sharplock command on a Windows 10 victim machine, the fake login "Form1" window is displayed in front of all other windows, however the last focused window remains in focus and receives the user's password as input.

Tapping the window or pressing Alt+Tab will give it focus.

Furthermore, without LIGHTSPEED, the transmission of the !sharplock shellcode takes roughly two minutes, as measured by the console traffic on the LOGITacker console. However, the fake lockscreen already appears on the victim screen after one minute, so I assume the first minute is the actual transmission of the payload, and the second minute is merely the echo from the covert channel console. If there is an easy way to suppress the echo during payload transmission, that could reduce the time to 50%! :)

Thanks for the awesome work, BTW!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions