smb-share-webshell
Warn
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill is designed to achieve remote code execution on target servers by generating and uploading multiple types of webshells (PHP, ASPX, ASHX, JSP) to web-accessible directories via SMB shares. It also details lateral movement and privilege escalation techniques using .NET impersonation APIs within PowerShell.
- [COMMAND_EXECUTION]: The skill performs active network operations and system interactions using CLI tools such as
smbclient,netexec(nxc), andcurlto identify vulnerable shares and trigger payloads. - [CREDENTIALS_UNSAFE]: The methodology recommends writing plaintext passwords to a temporary file at
/tmp/claude-1000/cred.txtto bypass shell history expansion issues, which risks exposing sensitive credentials to other processes or users on the local attackbox.
Audit Metadata