CoCalc provides the best real-time collaborative environment for Jupyter Notebooks, LaTeX documents, and SageMath, scalable from individual users to large groups and classes!
CoCalc provides the best real-time collaborative environment for Jupyter Notebooks, LaTeX documents, and SageMath, scalable from individual users to large groups and classes!
Path: blob/master/documentation/modules/post/windows/gather/credentials/halloy_irc.md
Views: 1904
Vulnerable Application
This post-exploitation module extracts clear text credentials from the Halloy IRC Client.
The Halloy IRC Client is avaialble from (https://github.com/squidowl/halloy).
This module extracts information from the config.toml file in the "AppData\Roaming\Halloy" directory.
This module extracts server information such as server, port, nickname, password and proxy password.
Verification Steps
Start MSF console
Get a Meterpreter session on a Windows system
use post/windows/gather/credentials/halloy_irc
Set SESSION 1
enter 'run' to extract credentials from all applications
Options
VERBOSE
By default verbose is turned off. When turned on, the module will show information on files which aren't extracted and information that is not directly related to the artifact output.
STORE_LOOT
This option is turned on by default and saves the stolen artifacts/files on the local machine, this is required for also extracting credentials from files using regexp, JSON, XML, and SQLite queries.
EXTRACT_DATA
This option is turned on by default and will perform the data extraction using the predefined regular expression. The 'Store loot' options must be turned on in order for this to take work.