Version 1.7.0

-Landed @leftp's PR for user and machine certificate private key extraction
-Added cert triage to the "triage" and "machinetriage" commands
-Using /password:X now causes the DPAPI masterkey cache to be output
This commit is contained in:
harmj0y
2020-05-06 12:29:35 -07:00
parent 09e3a628f1
commit ea8abe46f2
11 changed files with 252 additions and 44 deletions
+1 -1
View File
@@ -7,7 +7,7 @@ namespace SharpDPAPI.Commands
public class Certificate : ICommand
{
public static string CommandName => "certificate";
public static string CommandName => "certificates";
public void Execute(Dictionary<string, string> arguments)
{
+20 -4
View File
@@ -10,13 +10,29 @@ namespace SharpDPAPI.Commands
public void Execute(Dictionary<string, string> arguments)
{
Console.WriteLine("\r\n[*] Action: Machine DPAPI Credential and Vault Triage\r\n");
Console.WriteLine("\r\n[*] Action: Machine DPAPI Credential, Vault, and Certificate Triage\r\n");
arguments.Remove("triage");
Dictionary<string, string> mappings = Triage.TriageSystemMasterKeys();
Triage.TriageSystemCreds(mappings);
Triage.TriageSystemVaults(mappings);
if (!Helpers.IsHighIntegrity())
{
Console.WriteLine("[X] Must be elevated to triage SYSTEM DPAPI Credentials!");
}
else
{
Dictionary<string, string> mappings = Triage.TriageSystemMasterKeys();
Console.WriteLine("\r\n[*] SYSTEM master key cache:\r\n");
foreach (KeyValuePair<string, string> kvp in mappings)
{
Console.WriteLine("{0}:{1}", kvp.Key, kvp.Value);
}
Console.WriteLine();
Triage.TriageSystemCreds(mappings);
Triage.TriageSystemVaults(mappings);
Triage.TriageSystemCerts(mappings);
}
}
}
}
+1
View File
@@ -61,6 +61,7 @@ namespace SharpDPAPI.Commands
{
Triage.TriageUserCreds(masterkeys, server);
Triage.TriageUserVaults(masterkeys, server);
Triage.TriageUserCerts(masterkeys, server);
Console.WriteLine();
if (masterkeys.Count == 0)
{
+2 -1
View File
@@ -27,6 +27,7 @@ Machine/SYSTEM Triage:
machinemasterkeys - triage all reachable machine masterkey files (elevates to SYSTEM to retrieve the DPAPI_SYSTEM LSA secret)
machinecredentials - use 'machinemasterkeys' and then triage machine Credential files
machinevaults - use 'machinemasterkeys' and then triage machine Vaults
machinecerts - use 'machinemasterkeys' and then triage machine certificate stores
machinetriage - run the 'machinecredentials' and 'machinevaults' commands
@@ -37,7 +38,7 @@ User Triage:
SharpDPAPI masterkeys </pvk:BASE64... | /pvk:key.pvk>
Arguments for the credentials|vaults|rdg|triage|blob|ps commands:
Arguments for the certificates|credentials|vaults|rdg|triage|blob|ps commands:
Decryption:
/unprotect - force use of CryptUnprotectData() for 'ps', 'rdg', or 'blob' commands
+1 -1
View File
@@ -4,6 +4,6 @@ namespace SharpDPAPI
{
public static class Version
{
public static string version = "1.6.1";
public static string version = "1.7.0";
}
}
+4
View File
@@ -62,8 +62,10 @@
<ItemGroup>
<Compile Include="Commands\Backupkey.cs" />
<Compile Include="Commands\Blob.cs" />
<Compile Include="Commands\Certificate.cs" />
<Compile Include="Commands\Credentials.cs" />
<Compile Include="Commands\ICommand.cs" />
<Compile Include="Commands\MachineCertificates.cs" />
<Compile Include="Commands\Masterkeys.cs" />
<Compile Include="Commands\Machinecredentials.cs" />
<Compile Include="Commands\Machinemasterkeys.cs" />
@@ -79,6 +81,7 @@
<Compile Include="Domain\Info.cs" />
<Compile Include="Domain\Version.cs" />
<Compile Include="lib\Backup.cs" />
<Compile Include="lib\BigInteger.cs" />
<Compile Include="lib\Crypto.cs" />
<Compile Include="lib\Dpapi.cs" />
<Compile Include="lib\Helpers.cs" />
@@ -86,6 +89,7 @@
<Compile Include="lib\LSADump.cs" />
<Compile Include="lib\PBKDF2.cs" />
<Compile Include="lib\Triage.cs" />
<Compile Include="lib\Tuple.cs" />
<Compile Include="Program.cs" />
<Compile Include="Properties\AssemblyInfo.cs" />
</ItemGroup>
-25
View File
@@ -1,25 +0,0 @@
Microsoft Visual Studio Solution File, Format Version 12.00
# Visual Studio 15
VisualStudioVersion = 15.0.28307.168
MinimumVisualStudioVersion = 10.0.40219.1
Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "SharpDPAPI", "SharpDPAPI.csproj", "{5F026C27-F8E6-4052-B231-8451C6A73838}"
EndProject
Global
GlobalSection(SolutionConfigurationPlatforms) = preSolution
Debug|Any CPU = Debug|Any CPU
Release|Any CPU = Release|Any CPU
EndGlobalSection
GlobalSection(ProjectConfigurationPlatforms) = postSolution
{5F026C27-F8E6-4052-B231-8451C6A73838}.Debug|Any CPU.ActiveCfg = Debug|Any CPU
{5F026C27-F8E6-4052-B231-8451C6A73838}.Debug|Any CPU.Build.0 = Debug|Any CPU
{5F026C27-F8E6-4052-B231-8451C6A73838}.Release|Any CPU.ActiveCfg = Release|Any CPU
{5F026C27-F8E6-4052-B231-8451C6A73838}.Release|Any CPU.Build.0 = Release|Any CPU
EndGlobalSection
GlobalSection(SolutionProperties) = preSolution
HideSolutionNode = FALSE
EndGlobalSection
GlobalSection(ExtensibilityGlobals) = postSolution
SolutionGuid = {09F62083-4525-408F-BE92-6DE7AA2A22BD}
EndGlobalSection
EndGlobal
+17
View File
@@ -117,6 +117,23 @@ namespace SharpDPAPI
}
}
if (!String.IsNullOrEmpty(password))
{
if (mappings.Count == 0)
{
Console.WriteLine("\n[!] No master keys decrypted!\r\n");
}
else
{
Console.WriteLine("\n[*] User master key cache:\r\n");
foreach (KeyValuePair<string, string> kvp in mappings)
{
Console.WriteLine("{0}:{1}", kvp.Key, kvp.Value);
}
Console.WriteLine();
}
}
Console.WriteLine();
return mappings;
}