
Strumento di escalation dei privilegi locali che sfrutta connessioni WSUS insicure su Windows tramite un proxy man-in-the-middle, consentendo l'esecuzione di comandi con privilegi SYSTEM.
Questo è un programma proof of concept per escalare i privilegi su un host Windows abusando di WSUS. Dettagli in questo post del blog: https://www.gosecure.net/blog/2020/09/08/wsus-attacks-part-2-cve-2020-1013-a-windows-10-local-privilege-escalation-1-day/ È stato ispirato dal progetto proxy WSuspect: https://github.com/ctxis/wsuspect-proxy
Modulo di escalation dei privilegi scritto da Maxime Nadeau di GoSecure
Un ringraziamento speciale a:
Lo strumento è stato testato su macchine Windows 10 (10.0.17763 e 10.0.18363) in diversi ambienti di dominio.
Usage: WSuspicious [OPTION]...
Ex. WSuspicious.exe /command:"" - accepteula - s - d cmd / c """"echo 1 > C:\\wsuspicious.txt"""""" /autoinstall
Creates a local proxy to intercept WSUS requests and try to escalate privileges.
If launched without any arguments, the script will simply create the file C:\\wsuspicious.was.here
/exe The full path to the executable to run
Known payloads are bginfo and PsExec. (Default: .\PsExec64.exe)
/command The command to execute (Default: -accepteula -s -d cmd /c ""echo 1 > C:\\wsuspicious.was.here"")
/proxyport The port on which the proxy is started. (Default: 13337)
/downloadport The port on which the web server hosting the payload is started. (Sometimes useful for older Windows versions)
If not specified, the server will try to intercept the request to the legitimate server instead.
/debug Increase the verbosity of the tool
/autoinstall Start Windows updates automatically after the proxy is started.
/enabletls Enable HTTPS interception. WARNING. NOT OPSEC SAFE.
This will prompt the user to add the certificate to the trusted root.
/help Display this help and exit

La dipendenza ILMerge può essere utilizzata per compilare l'applicazione in un file .exe standalone. Per compilare l'applicazione, utilizzare il seguente comando:
dotnet msbuild /t:Restore /t:Clean /t:Build /p:Configuration=Release /p:DebugSymbols=false /p:DebugType=None /t:ILMerge /p:TrimUnusedDependencies=true