Hacking on Medium
Cybersecurity Breaches & Solutions | Feb 16th, 2022
https://cdn-images-1.medium.com/max/1920/1*7Im7z7Fm9F_cy2gPk1iloA.png
Severe Vulnerabilities on Apple & Moxa, and an Ominous Rise in DDoS Attacks
Continue reading on HUB Security »
Cybersecurity Breaches & Solutions | Feb 16th, 2022
https://cdn-images-1.medium.com/max/1920/1*7Im7z7Fm9F_cy2gPk1iloA.png
Severe Vulnerabilities on Apple & Moxa, and an Ominous Rise in DDoS Attacks
Continue reading on HUB Security »
Medium
Cybersecurity Breaches & Solutions | Feb 16th, 2022
Severe Vulnerabilities on Apple & Moxa, and an Ominous Rise in DDoS Attacks
Hacking on Medium
Hacking? Hacker? What?
https://cdn-images-1.medium.com/max/600/0*aRNF-FSZvouTv2Pe
When someone mentions the term “Hacker” why does the mind directly picture a hooded figure in front of a laptop with a black screen…
Continue reading on Medium »
Hacking? Hacker? What?
https://cdn-images-1.medium.com/max/600/0*aRNF-FSZvouTv2Pe
When someone mentions the term “Hacker” why does the mind directly picture a hooded figure in front of a laptop with a black screen…
Continue reading on Medium »
Medium
Hacking? Hacker? What?
When someone mentions the term “Hacker” why does the mind directly picture a hooded figure in front of a laptop with a black screen…
Hacking Articles Tips Tricks Videos Tutorials
GIF
KitPloit - PenTest Tools!
FakeLogonScreen - Fake Windows Logon Screen To Steal Passwords
http://4.bp.blogspot.com/-20diIlff9Es/Yd0ernCa4RI/AAAAAAAA8j0/mhGTik-X11w_7sfEWP1_uIorfkCZSpDEwCK4BGAYYCw/w640-h400/fakelogonscreen_1_demo-761682.gif
FakeLogonScreen is a utility to fake the Windows logon screen in order to obtain the user's password. The password entered is validated against the Active Directory or local machine to make sure it is correct and is then displayed to the console or saved to disk.
It can either be executed by simply running the .exe file, or using for example Cobalt Strike's
Binaries available from the Releases page.
* FakeLogonScreen.exe: Writes output to console which for example is compatible with Cobalt Strike
* FakeLogonScreenToFile.exe: Writes output to console and
Folders:
* / (root): Built against .NET Framework 4.5 which is installed by default in Windows 8, 8.1 and 10
* DOTNET35: Built against .NET Framework 3.5 which is installed by default in Windows 7
Features
* Primary display shows a Windows 10 login screen while additional screens turn black
* If custom background is configured by the user, shows that background instead of the default one
* Validates entered password before closing the screen
* Username and passwords entered are outputted to console or stored in a file
* Blocks many shortkeys to prevent circumventing the screen
* Minimizes all existing windows to avoid other windows staying on top
Authored by Arris Huijgen (@bitsadmin - https://github.com/bitsadmin/)
Download Fakelogonscreen
FakeLogonScreen - Fake Windows Logon Screen To Steal Passwords
http://4.bp.blogspot.com/-20diIlff9Es/Yd0ernCa4RI/AAAAAAAA8j0/mhGTik-X11w_7sfEWP1_uIorfkCZSpDEwCK4BGAYYCw/w640-h400/fakelogonscreen_1_demo-761682.gif
FakeLogonScreen is a utility to fake the Windows logon screen in order to obtain the user's password. The password entered is validated against the Active Directory or local machine to make sure it is correct and is then displayed to the console or saved to disk.
It can either be executed by simply running the .exe file, or using for example Cobalt Strike's
execute-assemblycommand.Binaries available from the Releases page.
* FakeLogonScreen.exe: Writes output to console which for example is compatible with Cobalt Strike
* FakeLogonScreenToFile.exe: Writes output to console and
%LOCALAPPDATA%\Microsoft\user.dbFolders:
* / (root): Built against .NET Framework 4.5 which is installed by default in Windows 8, 8.1 and 10
* DOTNET35: Built against .NET Framework 3.5 which is installed by default in Windows 7
Features
* Primary display shows a Windows 10 login screen while additional screens turn black
* If custom background is configured by the user, shows that background instead of the default one
* Validates entered password before closing the screen
* Username and passwords entered are outputted to console or stored in a file
* Blocks many shortkeys to prevent circumventing the screen
* Minimizes all existing windows to avoid other windows staying on top
Authored by Arris Huijgen (@bitsadmin - https://github.com/bitsadmin/)
Download Fakelogonscreen
FakeLogonScreen - Fake Windows Logon Screen To Steal Passwords
http://www.kitploit.com/2022/02/fakelogonscreen-fake-windows-logon.html
http://www.kitploit.com/2022/02/fakelogonscreen-fake-windows-logon.html
FakeLogonScreen is a utility to fake the Windows logon screen in order to obtain the user's password. The password entered is validated against the Active Directory (https://www.kitploit.com/search/label/Active%20Directory) or local machine to make sure it is correct and is then displayed to the console (https://www.kitploit.com/search/label/Console) or saved to disk. It can either be executed by simply running the .exe file, or using for example Cobalt Strike's execute-assembly command.
Binaries available from the Releases (https://github.com/bitsadmin/fakelogonscreen/releases) page. FakeLogonScreen.exe: Writes output to console which for example is compatible with Cobalt Strike FakeLogonScreenToFile.exe: Writes output to console and %LOCALAPPDATA%\Microsoft\user.db Folders: / (root): Built against .NET Framework 4.5 which is installed by default in Windows 8, 8.1 and 10 DOTNET35: Built against .NET Framework 3.5 which is installed by default in Windows 7 Features Primary display shows a Windows 10 (https://www.kitploit.com/search/label/Windows%2010) login screen while additional screens turn black If custom background is configured by the user, shows that background instead of the default one Validates entered password before closing the screen Username and passwords (https://www.kitploit.com/search/label/Passwords) entered are outputted to console or stored in a file Blocks many shortkeys to prevent circumventing the screen Minimizes all existing windows to avoid other windows staying on top
Authored by Arris Huijgen (@bitsadmin (https://twitter.com/bitsadmin/) - https://github.com/bitsadmin/)
Download Fakelogonscreen (https://github.com/bitsadmin/fakelogonscreen)
Binaries available from the Releases (https://github.com/bitsadmin/fakelogonscreen/releases) page. FakeLogonScreen.exe: Writes output to console which for example is compatible with Cobalt Strike FakeLogonScreenToFile.exe: Writes output to console and %LOCALAPPDATA%\Microsoft\user.db Folders: / (root): Built against .NET Framework 4.5 which is installed by default in Windows 8, 8.1 and 10 DOTNET35: Built against .NET Framework 3.5 which is installed by default in Windows 7 Features Primary display shows a Windows 10 (https://www.kitploit.com/search/label/Windows%2010) login screen while additional screens turn black If custom background is configured by the user, shows that background instead of the default one Validates entered password before closing the screen Username and passwords (https://www.kitploit.com/search/label/Passwords) entered are outputted to console or stored in a file Blocks many shortkeys to prevent circumventing the screen Minimizes all existing windows to avoid other windows staying on top
Authored by Arris Huijgen (@bitsadmin (https://twitter.com/bitsadmin/) - https://github.com/bitsadmin/)
Download Fakelogonscreen (https://github.com/bitsadmin/fakelogonscreen)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Privilege Escalation: SpoolFool
Windows Privilege Escalation: SpoolFoolIntroduction<o:pOliver Lyak posted a writeup about a Windows Privilege Escalation vulnerability that persisted in Windows systems even after patching of previous vulnerabilities in Print Spooler CVE-2020-1048 and CVE-2020-1337. Oliver was assigned CVE-2022-21999 for this vulnerability and commonly named it as “SpoolFool.” In this article, we will discuss the technical details associated with the same and demonstrate two methods through which an attacker can leverage and gain escalated privileges as NT AUTHORITY\SYSTEM.<o:p
Related advisories: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999<o:p
Related CVEs: CVE-2022-21999, CVE-2020-1030, CVE-2020-1337, CVE-2020-1048<o:p Summary of the Vulnerability<o:pThe vulnerability allows an unprivileged user to create arbitrary and writeable directories by configuring SpoolDirectory attribute on a printer. Since an unprivileged user is allowed to add remote printers, an attacker can create a remote printer and grant EVERYONE right to manage this printer. This would return a handle with PRINTER_ACCESS_ADMINISTER right which can be further used to perform task such as DLL injection.<o:p Print Spooler Basics<o:pPrint spooler is the primary printing process interface. It is a built in EXE file which is loaded at system startup itself. The workflow of a printing process is as follows:<o:p https://blogger.googleusercontent.com/img/a/AVvXsEgzRjHIgyikNwAhv9i5Atndlje5cJxTUg6X4QsfFbB7kWT7EnPL129UqZNmeE9bdjGni9LKNkeJ5jgF4fErgPcpncHU654ttNxANwXkYGaR8hIBqr-ELnWE2LM3c6ZtNXAO1IVsD8-p31_lHaQw2AS41eEPDBU5H1RUPkoVBGe9XlsRbcEzSLOE1DLCyg=s16000 Application: The print application creates a print job by calling Graphics Device Interface (GDI).<o:p GDI: GDI includes both user-mode and kernel-mode components for graphics support.<o:p winspool.drvis the interface that talks to spooler. It provides the RPC stubs required to accessing the server.<o:p spoolsv.exeis the spooler's API server. This module implements message routing to print provider with the help of router (spoolss.dll)<o:p spoolss.dlldetermines which print provider to call, based on a printer name and passes function call to the correct provider.<o:p Spool Directory<o:pWhen a user prints a document, a print job is spooled to a predefined location referred to as the spool directory. The default location is C:\Windows\System32\spool\PRINTERS. This directory is by default writeable by everyone as everyone uses printer (FILE_ADD_FILE permission. Read more here), and the Spool Directory is configurable on each printer.<o:p
<o:p Workflow of the CVE 2020-1030<o:pI would highly recommend reading up Victor Mata’s post here before trying to demonstrate the vulnerability yourself. But for people who don’t like to get into too much of technicality, here is a summary of how the vulnerability shall be exploited.<o:p
· By default, users can add printers without administrator authentication needed.<o:p
· Calling AddPrinter returns a printer handle(I recommend reading what handles are if you have less idea of development) with the PRINTER_ALL_ACCESS right. This grants printing rights to standard and administrative print operations. <o:p https://blogger.googleusercontent.com/img/a/AVvXsEipsvNes1iInJTnQmIPewRtQsg6Pl4NoiYmq1_fk8i8NoaG702Z7dPhV1g4WqSCL4SDqUvmNE0XtO5wk17IymRj-KFfVamGcYSe1PzoUvkIC_ihzV8uCKWsQdNGvl85OO4_vRUvMbgNLl2nK_GGo63MK3rdG5peu6zmfhLUx7-b-CwsM4llak7MMnV2AA=s16000 · However, the caller of the AddPrinter function must have SERVER_ACCESS_ADMINISTERright to the server on which the printer is to be created.<o:p
· An unprivileged user will [...]
Windows Privilege Escalation: SpoolFool
Windows Privilege Escalation: SpoolFoolIntroduction<o:pOliver Lyak posted a writeup about a Windows Privilege Escalation vulnerability that persisted in Windows systems even after patching of previous vulnerabilities in Print Spooler CVE-2020-1048 and CVE-2020-1337. Oliver was assigned CVE-2022-21999 for this vulnerability and commonly named it as “SpoolFool.” In this article, we will discuss the technical details associated with the same and demonstrate two methods through which an attacker can leverage and gain escalated privileges as NT AUTHORITY\SYSTEM.<o:p
Related advisories: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999<o:p
Related CVEs: CVE-2022-21999, CVE-2020-1030, CVE-2020-1337, CVE-2020-1048<o:p Summary of the Vulnerability<o:pThe vulnerability allows an unprivileged user to create arbitrary and writeable directories by configuring SpoolDirectory attribute on a printer. Since an unprivileged user is allowed to add remote printers, an attacker can create a remote printer and grant EVERYONE right to manage this printer. This would return a handle with PRINTER_ACCESS_ADMINISTER right which can be further used to perform task such as DLL injection.<o:p Print Spooler Basics<o:pPrint spooler is the primary printing process interface. It is a built in EXE file which is loaded at system startup itself. The workflow of a printing process is as follows:<o:p https://blogger.googleusercontent.com/img/a/AVvXsEgzRjHIgyikNwAhv9i5Atndlje5cJxTUg6X4QsfFbB7kWT7EnPL129UqZNmeE9bdjGni9LKNkeJ5jgF4fErgPcpncHU654ttNxANwXkYGaR8hIBqr-ELnWE2LM3c6ZtNXAO1IVsD8-p31_lHaQw2AS41eEPDBU5H1RUPkoVBGe9XlsRbcEzSLOE1DLCyg=s16000 Application: The print application creates a print job by calling Graphics Device Interface (GDI).<o:p GDI: GDI includes both user-mode and kernel-mode components for graphics support.<o:p winspool.drvis the interface that talks to spooler. It provides the RPC stubs required to accessing the server.<o:p spoolsv.exeis the spooler's API server. This module implements message routing to print provider with the help of router (spoolss.dll)<o:p spoolss.dlldetermines which print provider to call, based on a printer name and passes function call to the correct provider.<o:p Spool Directory<o:pWhen a user prints a document, a print job is spooled to a predefined location referred to as the spool directory. The default location is C:\Windows\System32\spool\PRINTERS. This directory is by default writeable by everyone as everyone uses printer (FILE_ADD_FILE permission. Read more here), and the Spool Directory is configurable on each printer.<o:p
<o:p Workflow of the CVE 2020-1030<o:pI would highly recommend reading up Victor Mata’s post here before trying to demonstrate the vulnerability yourself. But for people who don’t like to get into too much of technicality, here is a summary of how the vulnerability shall be exploited.<o:p
· By default, users can add printers without administrator authentication needed.<o:p
· Calling AddPrinter returns a printer handle(I recommend reading what handles are if you have less idea of development) with the PRINTER_ALL_ACCESS right. This grants printing rights to standard and administrative print operations. <o:p https://blogger.googleusercontent.com/img/a/AVvXsEipsvNes1iInJTnQmIPewRtQsg6Pl4NoiYmq1_fk8i8NoaG702Z7dPhV1g4WqSCL4SDqUvmNE0XtO5wk17IymRj-KFfVamGcYSe1PzoUvkIC_ihzV8uCKWsQdNGvl85OO4_vRUvMbgNLl2nK_GGo63MK3rdG5peu6zmfhLUx7-b-CwsM4llak7MMnV2AA=s16000 · However, the caller of the AddPrinter function must have SERVER_ACCESS_ADMINISTERright to the server on which the printer is to be created.<o:p
· An unprivileged user will [...]
Hacked Dutch Government Website. All I got was this l̶o̶u̶s̶y̶ cool T-Shirt.
https://medium.com/@chander.romesh/hacked-dutch-government-website-all-i-got-was-this-l%CC%B6o%CC%B6u%CC%B6s%CC%B6y%CC%B6-cool-t-shirt-4fd62ed3e734?source=rss------bug_bounty-5
https://medium.com/@chander.romesh/hacked-dutch-government-website-all-i-got-was-this-l%CC%B6o%CC%B6u%CC%B6s%CC%B6y%CC%B6-cool-t-shirt-4fd62ed3e734?source=rss------bug_bounty-5
They are right. Persistence is the key !Continue reading on Medium » (https://medium.com/@chander.romesh/hacked-dutch-government-website-all-i-got-was-this-l%CC%B6o%CC%B6u%CC%B6s%CC%B6y%CC%B6-cool-t-shirt-4fd62ed3e734?source=rss------bug_bounty-5)
Bug Report; Bypassing Weekly Limits In Basic (Free) LinkedIn Account
https://ashok314.medium.com/bug-report-bypassing-weekly-limits-in-basic-free-linkedin-account-f5265ac0418a?source=rss------bug_bounty-5
https://ashok314.medium.com/bug-report-bypassing-weekly-limits-in-basic-free-linkedin-account-f5265ac0418a?source=rss------bug_bounty-5
Publishing my first Security Vulnerability report for LinkedIn.Below is the report that I have submitted to LinkedIn Information Security…Continue reading on Medium » (https://ashok314.medium.com/bug-report-bypassing-weekly-limits-in-basic-free-linkedin-account-f5265ac0418a?source=rss------bug_bounty-5)
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Windows Privilege Escalation: SpoolFool
IntroductionOliver Lyak posted a write-up about a Windows Privilege Escalation vulnerability that persisted in Windows systems even after patching of previous vulnerabilities in Print Spooler CVE-2020-1048 and CVE-2020-1337. Oliver was assigned CVE-2022-21999 for this vulnerability and commonly named it “SpoolFool.” In this article, we will discuss the technical details associated with the same and demonstrate two methods through which an attacker can leverage and gain escalated privileges as NT AUTHORITY\SYSTEM.
Related advisories: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999
Related CVEs: CVE-2022-21999, CVE-2020-1030, CVE-2020-1337, CVE-2020-1048 Summary of the VulnerabilityThe vulnerability allows an unprivileged user to create arbitrary and writeable directories by configuring the SpoolDirectory attribute on a printer. Since an unprivileged user is allowed to add remote printers, an attacker can create a remote printer and grant EVERYONE the right to manage this printer. This would return a handle with PRINTER_ACCESS_ADMINISTER right which can be further used to perform tasks such as DLL injection. Print Spooler BasicsPrint spooler is the primary printing process interface. It is a built-in EXE file that is loaded at system startup itself. The workflow of a printing process is as follows:
https://blogger.googleusercontent.com/img/a/AVvXsEgzRjHIgyikNwAhv9i5Atndlje5cJxTUg6X4QsfFbB7kWT7EnPL129UqZNmeE9bdjGni9LKNkeJ5jgF4fErgPcpncHU654ttNxANwXkYGaR8hIBqr-ELnWE2LM3c6ZtNXAO1IVsD8-p31_lHaQw2AS41eEPDBU5H1RUPkoVBGe9XlsRbcEzSLOE1DLCyg=s16000
Application: The print application creates a print job by calling Graphics Device Interface (GDI).
GDI: GDI includes both user-mode and kernel-mode components for graphics support.
winspool.drv is the interface that talks to the spooler. It provides the RPC stubs required to access the server.
spoolsv.exe is the spooler’s API server. This module implements message routing to print provider with the help of router (spoolss.dll)
spoolss.dll determines which print provider to call, based on a printer name and passes function call to the correct provider. Spool DirectoryWhen a user prints a document, a print job is spooled to a predefined location referred to as the spool directory. The default location is C:\Windows\System32\spool\PRINTERS. This directory is by default writeable by everyone as everyone uses the printer (FILE_ADD_FILE permission. Read more here), and the Spool Directory is configurable on each printer.
Workflow of the CVE 2020-1030
I would highly recommend reading Victor Mata’s post here before trying to demonstrate the vulnerability yourself. But for people who don’t like to get into too much technicality, here is a summary of how the vulnerability shall be exploited.
* By default, users can add printers without administrator authentication needed.
* Calling AddPrinter returns a printer handle (I recommend reading what handles are if you have less idea of development) with the PRINTER_ALL_ACCESS right. This grants printing rights to standard and administrative print operations.
https://blogger.googleusercontent.com/img/a/AVvXsEipsvNes1iInJTnQmIPewRtQsg6Pl4NoiYmq1_fk8i8NoaG702Z7dPhV1g4WqSCL4SDqUvmNE0XtO5wk17IymRj-KFfVamGcYSe1PzoUvkIC_ihzV8uCKWsQdNGvl85OO4_vRUvMbgNLl2nK_GGo63MK3rdG5peu6zmfhLUx7-b-CwsM4llak7MMnV2AA=s16000
* However, the caller of the AddPrinter function must have SERVER_ACCESS_ADMINISTER right to the server on which the printer is to be created.
* An unprivileged user will not have these rights and hence, can’t add a new printer with PRINTER_ALL_ACCESS right.
* However, the “INTERACTIVE” group has the manage server permissions enabled which correspond to
https://blogger.googleusercontent.com/img/a/AVvXsEjNCSl-n_[...]
Windows Privilege Escalation: SpoolFool
IntroductionOliver Lyak posted a write-up about a Windows Privilege Escalation vulnerability that persisted in Windows systems even after patching of previous vulnerabilities in Print Spooler CVE-2020-1048 and CVE-2020-1337. Oliver was assigned CVE-2022-21999 for this vulnerability and commonly named it “SpoolFool.” In this article, we will discuss the technical details associated with the same and demonstrate two methods through which an attacker can leverage and gain escalated privileges as NT AUTHORITY\SYSTEM.
Related advisories: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21999
Related CVEs: CVE-2022-21999, CVE-2020-1030, CVE-2020-1337, CVE-2020-1048 Summary of the VulnerabilityThe vulnerability allows an unprivileged user to create arbitrary and writeable directories by configuring the SpoolDirectory attribute on a printer. Since an unprivileged user is allowed to add remote printers, an attacker can create a remote printer and grant EVERYONE the right to manage this printer. This would return a handle with PRINTER_ACCESS_ADMINISTER right which can be further used to perform tasks such as DLL injection. Print Spooler BasicsPrint spooler is the primary printing process interface. It is a built-in EXE file that is loaded at system startup itself. The workflow of a printing process is as follows:
https://blogger.googleusercontent.com/img/a/AVvXsEgzRjHIgyikNwAhv9i5Atndlje5cJxTUg6X4QsfFbB7kWT7EnPL129UqZNmeE9bdjGni9LKNkeJ5jgF4fErgPcpncHU654ttNxANwXkYGaR8hIBqr-ELnWE2LM3c6ZtNXAO1IVsD8-p31_lHaQw2AS41eEPDBU5H1RUPkoVBGe9XlsRbcEzSLOE1DLCyg=s16000
Application: The print application creates a print job by calling Graphics Device Interface (GDI).
GDI: GDI includes both user-mode and kernel-mode components for graphics support.
winspool.drv is the interface that talks to the spooler. It provides the RPC stubs required to access the server.
spoolsv.exe is the spooler’s API server. This module implements message routing to print provider with the help of router (spoolss.dll)
spoolss.dll determines which print provider to call, based on a printer name and passes function call to the correct provider. Spool DirectoryWhen a user prints a document, a print job is spooled to a predefined location referred to as the spool directory. The default location is C:\Windows\System32\spool\PRINTERS. This directory is by default writeable by everyone as everyone uses the printer (FILE_ADD_FILE permission. Read more here), and the Spool Directory is configurable on each printer.
Workflow of the CVE 2020-1030
I would highly recommend reading Victor Mata’s post here before trying to demonstrate the vulnerability yourself. But for people who don’t like to get into too much technicality, here is a summary of how the vulnerability shall be exploited.
* By default, users can add printers without administrator authentication needed.
* Calling AddPrinter returns a printer handle (I recommend reading what handles are if you have less idea of development) with the PRINTER_ALL_ACCESS right. This grants printing rights to standard and administrative print operations.
https://blogger.googleusercontent.com/img/a/AVvXsEipsvNes1iInJTnQmIPewRtQsg6Pl4NoiYmq1_fk8i8NoaG702Z7dPhV1g4WqSCL4SDqUvmNE0XtO5wk17IymRj-KFfVamGcYSe1PzoUvkIC_ihzV8uCKWsQdNGvl85OO4_vRUvMbgNLl2nK_GGo63MK3rdG5peu6zmfhLUx7-b-CwsM4llak7MMnV2AA=s16000
* However, the caller of the AddPrinter function must have SERVER_ACCESS_ADMINISTER right to the server on which the printer is to be created.
* An unprivileged user will not have these rights and hence, can’t add a new printer with PRINTER_ALL_ACCESS right.
* However, the “INTERACTIVE” group has the manage server permissions enabled which correspond to
https://blogger.googleusercontent.com/img/a/AVvXsEjNCSl-n_[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles Windows Privilege Escalation: SpoolFool IntroductionOliver Lyak posted a write-up about a Windows Privilege Escalation vulnerability that persisted in Windows systems even after patching of previous vulnerabilities in Print Spooler CVE-2020…
Ezy-4PpHM_J-PbTTa3ufPHLAyiViUhzW_TKnolUbaxfGv1cxgG1fPoACkYy1VHK4R-9ipE2_M4qK2gY4m_pVHdRvL-PkrjEoAC77sTocqBHPA256akst8eoGr-xDvQvcQpHSKLSnMK8b1o_iQKzJydN0k_JVZ4Ej61zDHWcy7v3_e2pG4Aew=s16000
* Thus, members in the interactive group can add a printer with SERVER_ACCESS_ADMINISTER
* INTERACTIVE GROUP: SID S-1-5-4 NT Authority\Interactive is a system group that gets automatically added when a user logs on to the system locally or via RDP. Removing this group would mean restricting logging access in older systems, however, in newer Windows, it gets re-added on restart. In short, it symbolizes an actual physical user that is interacting with the machine. This group is absent on Active Directory systems as permissions are only managed by DC in such environments.
* Therefore, the attack was not found to be working with service accounts (like IIS or MSSQL$)
* If the user who runs the exploit is a member of INTERACTIVE, then AddPrinter now will return a handle with PRINTER_ALL_ACCESS We will use this handle’s permission to modify the spool directory. In C#, SetPrinterDataEx function can modify spool directory. Here, we are creating a directory C:\Windows\System32\spool\drivers\x64\4
To create this spool, we have the necessary rights PRINTER_ALL_ACCESS (returned to the handle hPrinter)
https://blogger.googleusercontent.com/img/a/AVvXsEiPYSMrIHzpupvTZgUJqbb_TwgOLUSdoGozIwWgbaJiZz-YVvS-SvWzdwcMGyHuVA8A4zb_R6SQteF-CYExoMJXsamkbgFFBQ_CafyKeIoO_Ol84aZJRD9HAhpksP_wFv0MnaJ1ALgfNuuXd4o3H7srKAeVpxFTdsStTvwg6Q7UtXk9_WeMZPLPg6lphg=s16000
As you can see the intended directory in the pszData variable doesn’t exist already.
https://blogger.googleusercontent.com/img/a/AVvXsEg4U1ar501WL-g2lcEDv0lpKyoFDvhgmIealdkwFt_9BycQ2PCkNL2UsPkfqdtlKdilE55UIyMwXJm5Egf_AqAAqnj24sfErE_iH_1OGe7aHoChE4FlBBI7WGGockRJX3h8-jeXNOXnBK0fSaiGwzHI2YZRTQ29YD7SlbSUMDO2tMnJoi5mZlbeIHmbKQ=s16000
* Re-initialize the print spooler service by calling AppVTerminator.dll
* Spool Directory C:\Windows\System32\spool\drivers\x64 created with write permissions to EVERYONE.
* A malicious DLL is created and loaded in that directory. It gets validated and CopyFiles\\ will trigger that DLL and load it into the printer process (spoolsv.exe)
https://blogger.googleusercontent.com/img/a/AVvXsEiJv3jyQuITxv1sAULxrhXkPiPhoDhMkTcKK8c0m9wFYhGU904wtLn8dcl28yZpLidwQG-19Q0hNoYylIPb9W2ah7HjdkCPOvnZ85owcmufJBW3v8j29PFKjUoptjeN4aMavP0w_-djfw-B49lBJ-qTnUWMszAiXV6196D69Z6m9Sjdj1ds0LbiPtBdog=s16000 Diagramatic Workflow of CVE 2020-1030It could be understood in simpler terms like this:
https://blogger.googleusercontent.com/img/a/AVvXsEjq9LpYFT2U6NAKfqKdaJNHTRyRvSuZHXRE3wN2W6nNQsMkubzYvJJBtPIfDnhltWODy0m0Ul2ALeYxM01ogu6ChDFvp9EcXNbWG0zYntduEOuoDZE7Z7BpghDto6mUXXmuwPXnfGWIEktkY8I8ufEG-_JX8bRs3tlttw2YtzTgi4lsTzfgjNV58ecnxg=s16000 Incoming CVE 2022-21999After the issue was patched by Microsoft, Oliver Lyak in his post here mentions Microsoft’s patches and how he circumvented them. Thus, he proposed the following two enhancements for this vulnerability patch and was assigned CVE 2022-21999:
1. He states that a user not in the INTERACTIVE group can still add a remote printer and gain PRINTER_ACCESS_ADMINISTER rights.
“If a user adds a remote printer, the printer will inherit the security properties of the shared printer from the printer server. As such, if the remote printer server allows EVERYONE to manage the printer, then it’s possible to obtain a handle to the printer with the PRINTER_ACCESS_ADMINISTER access right, and SetPrinterDataEx would update the local registry as usual”
1. Microsoft added directory creation/access validation on the user level to restrict the creation of spool directories. So, in his exploit, he used reparse Basically, the following things happen:
* We create a temporary directory (C:\TEMP\xyzxyzxyz) and set it as SpoolDirectory
* The validation set by Microsoft gets passed and SpoolDirectory is set to this temporary directo[...]
* Thus, members in the interactive group can add a printer with SERVER_ACCESS_ADMINISTER
* INTERACTIVE GROUP: SID S-1-5-4 NT Authority\Interactive is a system group that gets automatically added when a user logs on to the system locally or via RDP. Removing this group would mean restricting logging access in older systems, however, in newer Windows, it gets re-added on restart. In short, it symbolizes an actual physical user that is interacting with the machine. This group is absent on Active Directory systems as permissions are only managed by DC in such environments.
* Therefore, the attack was not found to be working with service accounts (like IIS or MSSQL$)
* If the user who runs the exploit is a member of INTERACTIVE, then AddPrinter now will return a handle with PRINTER_ALL_ACCESS We will use this handle’s permission to modify the spool directory. In C#, SetPrinterDataEx function can modify spool directory. Here, we are creating a directory C:\Windows\System32\spool\drivers\x64\4
To create this spool, we have the necessary rights PRINTER_ALL_ACCESS (returned to the handle hPrinter)
https://blogger.googleusercontent.com/img/a/AVvXsEiPYSMrIHzpupvTZgUJqbb_TwgOLUSdoGozIwWgbaJiZz-YVvS-SvWzdwcMGyHuVA8A4zb_R6SQteF-CYExoMJXsamkbgFFBQ_CafyKeIoO_Ol84aZJRD9HAhpksP_wFv0MnaJ1ALgfNuuXd4o3H7srKAeVpxFTdsStTvwg6Q7UtXk9_WeMZPLPg6lphg=s16000
As you can see the intended directory in the pszData variable doesn’t exist already.
https://blogger.googleusercontent.com/img/a/AVvXsEg4U1ar501WL-g2lcEDv0lpKyoFDvhgmIealdkwFt_9BycQ2PCkNL2UsPkfqdtlKdilE55UIyMwXJm5Egf_AqAAqnj24sfErE_iH_1OGe7aHoChE4FlBBI7WGGockRJX3h8-jeXNOXnBK0fSaiGwzHI2YZRTQ29YD7SlbSUMDO2tMnJoi5mZlbeIHmbKQ=s16000
* Re-initialize the print spooler service by calling AppVTerminator.dll
* Spool Directory C:\Windows\System32\spool\drivers\x64 created with write permissions to EVERYONE.
* A malicious DLL is created and loaded in that directory. It gets validated and CopyFiles\\ will trigger that DLL and load it into the printer process (spoolsv.exe)
https://blogger.googleusercontent.com/img/a/AVvXsEiJv3jyQuITxv1sAULxrhXkPiPhoDhMkTcKK8c0m9wFYhGU904wtLn8dcl28yZpLidwQG-19Q0hNoYylIPb9W2ah7HjdkCPOvnZ85owcmufJBW3v8j29PFKjUoptjeN4aMavP0w_-djfw-B49lBJ-qTnUWMszAiXV6196D69Z6m9Sjdj1ds0LbiPtBdog=s16000 Diagramatic Workflow of CVE 2020-1030It could be understood in simpler terms like this:
https://blogger.googleusercontent.com/img/a/AVvXsEjq9LpYFT2U6NAKfqKdaJNHTRyRvSuZHXRE3wN2W6nNQsMkubzYvJJBtPIfDnhltWODy0m0Ul2ALeYxM01ogu6ChDFvp9EcXNbWG0zYntduEOuoDZE7Z7BpghDto6mUXXmuwPXnfGWIEktkY8I8ufEG-_JX8bRs3tlttw2YtzTgi4lsTzfgjNV58ecnxg=s16000 Incoming CVE 2022-21999After the issue was patched by Microsoft, Oliver Lyak in his post here mentions Microsoft’s patches and how he circumvented them. Thus, he proposed the following two enhancements for this vulnerability patch and was assigned CVE 2022-21999:
1. He states that a user not in the INTERACTIVE group can still add a remote printer and gain PRINTER_ACCESS_ADMINISTER rights.
“If a user adds a remote printer, the printer will inherit the security properties of the shared printer from the printer server. As such, if the remote printer server allows EVERYONE to manage the printer, then it’s possible to obtain a handle to the printer with the PRINTER_ACCESS_ADMINISTER access right, and SetPrinterDataEx would update the local registry as usual”
1. Microsoft added directory creation/access validation on the user level to restrict the creation of spool directories. So, in his exploit, he used reparse Basically, the following things happen:
* We create a temporary directory (C:\TEMP\xyzxyzxyz) and set it as SpoolDirectory
* The validation set by Microsoft gets passed and SpoolDirectory is set to this temporary directo[...]