
Lokales Privilegieneskalationstool, das unsichere WSUS-Verbindungen unter Windows über einen Man-in-the-Middle-Proxy ausnutzt und die Ausführung von Befehlen mit SYSTEM-Berechtigungen ermöglicht.
Dies ist ein Proof-of-Concept-Programm, um durch Missbrauch von WSUS Privilegien auf einem Windows-Host zu erhöhen. Details in diesem Blogbeitrag: https://www.gosecure.net/blog/2020/09/08/wsus-attacks-part-2-cve-2020-1013-a-windows-10-local-privilege-escalation-1-day/ Es wurde vom WSuspect-Proxy-Projekt inspiriert: https://github.com/ctxis/wsuspect-proxy
Privilegieneskalationsmodul geschrieben von Maxime Nadeau von GoSecure
Großer Dank an:
Das Tool wurde auf Windows 10 Maschinen (10.0.17763 und 10.0.18363) in verschiedenen Domänenumgebungen getestet.
Usage: WSuspicious [OPTION]...
Ex. WSuspicious.exe /command:"" - accepteula - s - d cmd / c """"echo 1 > C:\\wsuspicious.txt"""""" /autoinstall
Creates a local proxy to intercept WSUS requests and try to escalate privileges.
If launched without any arguments, the script will simply create the file C:\\wsuspicious.was.here
/exe The full path to the executable to run
Known payloads are bginfo and PsExec. (Default: .\PsExec64.exe)
/command The command to execute (Default: -accepteula -s -d cmd /c ""echo 1 > C:\\wsuspicious.was.here"")
/proxyport The port on which the proxy is started. (Default: 13337)
/downloadport The port on which the web server hosting the payload is started. (Sometimes useful for older Windows versions)
If not specified, the server will try to intercept the request to the legitimate server instead.
/debug Increase the verbosity of the tool
/autoinstall Start Windows updates automatically after the proxy is started.
/enabletls Enable HTTPS interception. WARNING. NOT OPSEC SAFE.
This will prompt the user to add the certificate to the trusted root.
/help Display this help and exit

Die ILMerge-Abhängigkeit kann verwendet werden, um die Anwendung in eine eigenständige .exe-Datei zu kompilieren. Um die Anwendung zu kompilieren, verwenden Sie einfach den folgenden Befehl:
dotnet msbuild /t:Restore /t:Clean /t:Build /p:Configuration=Release /p:DebugSymbols=false /p:DebugType=None /t:ILMerge /p:TrimUnusedDependencies=true