
Ferramenta de escalada de privilégio local que explora conexões WSUS inseguras no Windows através de um proxy man-in-the-middle, permitindo execução de comandos com privilégios de SYSTEM.
Este é um programa de prova de conceito para escalar privilégios em um host Windows abusando do WSUS. Detalhes neste post do blog: https://www.gosecure.net/blog/2020/09/08/wsus-attacks-part-2-cve-2020-1013-a-windows-10-local-privilege-escalation-1-day/ Foi inspirado no projeto WSuspect proxy: https://github.com/ctxis/wsuspect-proxy
Módulo de escalação de privilégios escrito por Maxime Nadeau da GoSecure
Muitos agradecimentos a:
A ferramenta foi testada em máquinas Windows 10 (10.0.17763 e 10.0.18363) em diferentes ambientes de domínio.
Usage: WSuspicious [OPTION]...
Ex. WSuspicious.exe /command:"" - accepteula - s - d cmd / c """"echo 1 > C:\\wsuspicious.txt"""""" /autoinstall
Creates a local proxy to intercept WSUS requests and try to escalate privileges.
If launched without any arguments, the script will simply create the file C:\\wsuspicious.was.here
/exe The full path to the executable to run
Known payloads are bginfo and PsExec. (Default: .\PsExec64.exe)
/command The command to execute (Default: -accepteula -s -d cmd /c ""echo 1 > C:\\wsuspicious.was.here"")
/proxyport The port on which the proxy is started. (Default: 13337)
/downloadport The port on which the web server hosting the payload is started. (Sometimes useful for older Windows versions)
If not specified, the server will try to intercept the request to the legitimate server instead.
/debug Increase the verbosity of the tool
/autoinstall Start Windows updates automatically after the proxy is started.
/enabletls Enable HTTPS interception. WARNING. NOT OPSEC SAFE.
This will prompt the user to add the certificate to the trusted root.
/help Display this help and exit

A dependência ILMerge pode ser usada para compilar a aplicação em um arquivo .exe independente. Para compilar e compilar a aplicação, simplesmente use o seguinte comando:
dotnet msbuild /t:Restore /t:Clean /t:Build /p:Configuration=Release /p:DebugSymbols=false /p:DebugType=None /t:ILMerge /p:TrimUnusedDependencies=true