daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

escape-breakout.md (7738B)


      1 ---
      2 title: "Kiosk Escape and Jail Breakout"
      3 section: "Cheatsheets"
      4 sectionSlug: "cheatsheets"
      5 sourcePath: "docs/cheatsheets/escape-breakout.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/escape-breakout.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kiosk Escape and Jail Breakout
     12 
     13 ## Summary
     14 
     15 * [Methodology](#methodology)
     16 * [Gaining a command shell](#gaining-a-command-shell)
     17 * [Sticky Keys](#sticky-keys)
     18 * [Dialog Boxes](#dialog-boxes)
     19     * [Creating new files](#creating-new-files)
     20     * [Open a new Windows Explorer instance](#open-a-new-windows-explorer-instance)
     21     * [Exploring Context Menus](#exploring-context-menus)
     22     * [Save as](#save-as)
     23     * [Input Boxes](#input-boxes)
     24     * [Bypass file restrictions](#bypass-file-restrictions)
     25 * [Internet Explorer](#internet-explorer)
     26 * [Shell URI Handlers](#shell-uri-handlers)
     27 * [References](#references)
     28 
     29 ## Tools
     30 
     31 * [kiosk.vsim.xyz](https://kiosk.vsim.xyz/) - Tooling for browser-based, Kiosk mode testing.
     32 * [break.yxz.red](https://break.yxz.red/) - Breakout Kit for Web Browser / Kiosk breakout Assessments.
     33 
     34 ## Methodology
     35 
     36 * Display global variables and their permissions: `export -p`
     37 * Switch to another user using `sudo`/`su`
     38 * Basic privilege escalations such as CVE, sudo misconfiguration, etc. Comprehensive list at [Linux](/internal/redteam/escalation/linux-privilege-escalation) / [Windows](/internal/redteam/escalation/windows-privilege-escalation)
     39 * List default commands in the restricted shell: `compgen -c`
     40 * Container escape if it's running inside a `Docker`/`LXC` container
     41 * Pivot onto the network
     42     * Scan other machines on the network or attempt SSRF exploitation
     43     * Metadata for Cloud assets, see `cloud/aws` and `cloud/azure`
     44 * Use globbing capability built inside the shell: `echo *`, `echo .*`, `echo /*`
     45 
     46 ## Gaining a command shell
     47 
     48 * **Shortcut**
     49     * [Window] + [R] -> cmd
     50     * [CTRL] + [SHIFT] + [ESC] -> Task Manager
     51     * [CTRL] + [ALT] + [DELETE] -> Task Manager
     52 * **Access through file browser**: Browsing to the folder containing the binary (i.e. `C:\windows\system32\`), we can simply right click and `open` it
     53 * **Drag-and-drop**: dragging and dropping any file onto the cmd.exe
     54 * **Hyperlink**: `file:///c:/Windows/System32/cmd.exe`
     55 * **Task Manager**: `File` > `New Task (Run...)` > `cmd`
     56 * **MSPAINT.exe**
     57     * Open MSPaint.exe and set the canvas size to: `Width=6` and `Height=1` pixels
     58     * Zoom in to make the following tasks easier
     59     * Using the colour picker, set pixels values to (from left to right):
     60 
     61         ```ps1
     62         1st: R: 10,  G: 0,   B: 0
     63         2nd: R: 13,  G: 10,  B: 13
     64         3rd: R: 100, G: 109, B: 99
     65         4th: R: 120, G: 101, B: 46
     66         5th: R: 0,   G: 0,   B: 101
     67         6th: R: 0,   G: 0,   B: 0
     68         ```
     69 
     70     * Save it as 24-bit Bitmap (*.bmp;*.dib)
     71     * Change its extension from bmp to bat and run
     72     * The generated file is also available for download: [escape-breakout-mspaint.bmp](https://raw.githubusercontent.com/swisskyrepo/InternalAllTheThings/203bb0c0b290/docs/cheatsheets/files/escape-breakout-mspaint.bmp)
     73 
     74 ## Sticky Keys
     75 
     76 * Spawn the sticky keys dialog
     77     * Via Shell URI : `shell:::{20D04FE0-3AEA-1069-A2D8-08002B30309D}`
     78     * Hit 5 times [SHIFT]
     79 * Visit "Ease of Access Center"
     80 * You land on "Setup Sticky Keys", move up a level on "Ease of Access Center"
     81 * Start the OSK (On-Screen-Keyboard)
     82 * You can now use the keyboard shortcut (CTRL+N)
     83 
     84 ## Dialog Boxes
     85 
     86 ### Creating new files
     87 
     88 * Batch files – Right click > New > Text File > rename to .BAT (or .CMD) > edit > open
     89 * Shortcuts – Right click > New > Shortcut > `%WINDIR%\system32`
     90 
     91 ## Open a new Windows Explorer instance
     92 
     93 * Right click any folder > select `Open in new window`
     94 
     95 ## Exploring Context Menus
     96 
     97 * Right click any file/folder and explore context menus
     98 * Clicking `Properties`, especially on shortcuts, can yield further access via `Open File Location`
     99 
    100 ### Save as
    101 
    102 * "Save as" / "Open as" option
    103 * "Print" feature – selecting "print to file" option (XPS/PDF/etc)
    104 * `\\127.0.0.1\c$\Windows\System32\` and execute `cmd.exe`
    105 
    106 ### Input Boxes
    107 
    108 Many input boxes accept file paths; try all inputs with UNC paths such as `//attacker–pc/` or `//127.0.0.1/c$` or `C:\`
    109 
    110 ### Bypass file restrictions
    111 
    112 Enter *.* or *.exe or similar in `File name` box
    113 
    114 ## Internet Explorer
    115 
    116 ### Download and Run/Open
    117 
    118 * Text files -> opened by Notepad
    119 
    120 ### Menus
    121 
    122 * The address bar
    123 * Search menus
    124 * Help menus
    125 * Print menus
    126 * All other menus that provide dialog boxes
    127 
    128 ### Accessing filesystem
    129 
    130 Enter these paths in the address bar:
    131 
    132 * file://C:/windows
    133 * C:/windows/
    134 * %HOMEDRIVE%
    135 * \\127.0.0.1\c$\Windows\System32
    136 
    137 ### Unassociated Protocols
    138 
    139 It is possible to escape a browser based kiosk with other protocols than usual `http` or `https`.
    140 If you have access to the address bar, you can use any known protocol (`irc`, `ftp`, `telnet`, `mailto`, etc.)
    141 to trigger the *open with* prompt and select a program installed on the host.
    142 The program will than be launched with the uri as a parameter, you need to select a program that will not crash when recieving it.
    143 It is possible to send multiple parameters to the program by adding spaces in your uri.
    144 
    145 Note: This technique required that the protocol used is not already associated with a program.
    146 
    147 Example - Launching Firefox with a custom profile:
    148 
    149 This is a nice trick since Firefox launched with the custom profile may not be as much hardened as the default profile.
    150 
    151 0. Firefox need to be installed.
    152 1. Enter the following uri in the address bar: `irc://127.0.0.1 -P "Test"`
    153 2. Press enter to navigate to the uri.
    154 3. Select the firefox program.
    155 4. Firefox will be launched with the profile `Test`.
    156 
    157 In this example, it's the equivalent of running the following command:
    158 
    159 ```ps1
    160 firefox irc://127.0.0.1 -P "Test"
    161 ```
    162 
    163 ## Shell URI Handlers
    164 
    165 A URI (Uniform Resource Identifier) handler is a software component that enables a web browser or operating system to pass a URI to an appropriate application for further handling.
    166 
    167 For example, when you click on a "mailto:" link in a webpage, your device knows to open your default email application. This is because the "mailto:" URI scheme is registered to be handled by an email application. Similarly, "http:" and "https:" URIs are typically handled by a web browser.
    168 
    169 In essence, URI handlers provide a bridge between web content and desktop applications, allowing for a seamless user experience when navigating between different types of resources.
    170 
    171 The following URI handlers might trigger application on the machine:
    172 
    173 * shell:DocumentsLibrary
    174 * shell:Librariesshell:UserProfiles
    175 * shell:Personal
    176 * shell:SearchHomeFolder
    177 * shell:System shell:NetworkPlacesFolder
    178 * shell:SendTo
    179 * shell:Common Administrative Tools
    180 * shell:MyComputerFolder
    181 * shell:InternetFolder
    182 
    183 ## References
    184 
    185 * [PentestPartners - Breaking out of Citrix and other restricted desktop environments](https://www.pentestpartners.com/security-blog/breaking-out-of-citrix-and-other-restricted-desktop-environments/)
    186 * [Breaking Out! of Applications Deployed via Terminal Services, Citrix, and Kiosks - Scott Sutherland - May 22nd, 2013](https://blog.netspi.com/breaking-out-of-applications-deployed-via-terminal-services-citrix-and-kiosks/)
    187 * [Escaping from KIOSKs - HackTricks](https://book.hacktricks.xyz/physical-attacks/escaping-from-gui-applications)
    188 * [Breaking out of Windows Kiosks using only Microsoft Edge - Firat Acar - May 24, 2022](https://blog.nviso.eu/2022/05/24/breaking-out-of-windows-kiosks-using-only-microsoft-edge/)
    189 * [HOW TO LAUNCH COMMAND PROMPT AND POWERSHELL FROM MS PAINT - 2022-05-14 - Rickard](https://tzusec.com/how-to-launch-command-prompt-and-powershell-from-ms-paint/)