If you like this project, consider purchasing licenses of OctoPwn, our full pentesting suite that runs in your browser!
For notifications on new builds/releases and other info, hop on to our Discord
This project is aimed to play around the RDP and VNC protocols.
Project contains no GUI, for a GUI client please check out aardwolfgui
This project, alongside with many other pentester tools runs in the browser with the power of OctoPwn!
Check out the community version at OctoPwn - Live
This is a headless client, for GUI functionality use the aardwolfgui
package.
- Supports credssp auth via NTLM/Kerberos.
- Built-in proxy client allows SOCKS/HTTP proxy tunneling without 3rd part software
- PtH via CredSSP+Restricted admin mode
- Scriptable Keyboard, Mouse input and Clipboard input/output
- Can run in headless mode, no GUI required (read: no need for Qt)
- Support for Duckyscript files to emulate keystrokes
ardpscan
Multi-purpose scanner for RDP and VNC protocols. (screenshot/capabilities/login scanner)
As usual the scripts take the target/scredentials in URL format. Below some examples
rdp+kerberos-password://TEST\Administrator:[email protected]/?dc=10.10.10.2&proxytype=socks5&proxyhost=127.0.0.1&proxyport=1080
CredSSP (akaHYBRID
) auth using Kerberos auth + password viasocks5
towin2016ad.test.corp
, the domain controller (kerberos service) is at10.10.10.2
. The socks proxy is on127.0.0.1:1080
rdp+ntlm-password://TEST\Administrator:[email protected]
CredSSP (akaHYBRID
) auth using NTLM auth + password connecting to RDP server10.10.10.103
rdp+ntlm-password://TEST\Administrator:<NThash>@10.10.10.103
CredSSP (akaHYBRID
) auth using Pass-the-Hash (NTLM) auth connecting to RDP server10.10.10.103
rdp+plain://Administrator:[email protected]
Plain authentication (No SSL, encryption is RC4) using password connecting to RDP server10.10.10.103
vnc+plain://[email protected]
VNC client with VNC authentication using password connecting to RDP server10.10.10.103
vnc+plain://[email protected]
VNC client with VNC authentication using password connecting to RDP server10.10.10.103
vnc+plain://:admin:[email protected]
VNC client with VNC authentication using passwordadmin:aaa
connecting to RDP server10.10.10.103
. Note that if the password contains:
char you will have to prepend the password with:
- Sylvain Peyrefitte (@citronneur)
rdpy
. The decompression code and the QT image magic was really valuable. - Marc-André Moreau (@awakecoding) for providing suggestions on fixes