smb-share-webshell

Warn

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill is designed to achieve remote code execution on target servers by generating and uploading multiple types of webshells (PHP, ASPX, ASHX, JSP) to web-accessible directories via SMB shares. It also details lateral movement and privilege escalation techniques using .NET impersonation APIs within PowerShell.
  • [COMMAND_EXECUTION]: The skill performs active network operations and system interactions using CLI tools such as smbclient, netexec (nxc), and curl to identify vulnerable shares and trigger payloads.
  • [CREDENTIALS_UNSAFE]: The methodology recommends writing plaintext passwords to a temporary file at /tmp/claude-1000/cred.txt to bypass shell history expansion issues, which risks exposing sensitive credentials to other processes or users on the local attackbox.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 6, 2026, 09:16 AM
Security Audit — agent-trust-hub — smb-share-webshell