Search
Social Media - Mubix
Login
« Finding Admin Access | Main | lm2ntlm with John the Ripper »
Tuesday
Oct302012

BypassUAC got a facelift

Dave Kennedy and Kevin Mitnick submitted the "bypassuac" post module to Metasploit a while back (last DerbyCon?). Which is awesome and they did some fantastic work, but I had a few complaints as probably anyone did who used the module on a somewhat modern network.

"Old" module (post/windows/escalate/bypassuac):

Screen Shot 2012 10 30 at 3 03 10 PM

I decided to give it a bit of a face lift:

"New" local exploit module (exploit/windows/local/bypassuac):

Screen Shot 2012 10 30 at 3 07 10 PM

All of the credit for the availability of this module goes to @egyp7 though, without his epic addition of local exploits to Metasploit the majority of the updates to this module wouldn't be possible.

Anywho, on to the new features:

1) You can set any windows payload you want to use now:

Screen Shot 2012 10 30 at 3 38 19 PM

and yes it supports EXE::Custom.

2) It lets you know if it will be able to bypass the current setting of UAC or not:

Screen Shot 2012 10 30 at 3 40 15 PM

Even when you're going overkill with it:

Screen Shot 2012 10 30 at 3 41 31 PM

(ASK module if UAC is disabled will just elevate without any kind of user prompt)

And of course it works as expected if UAC needs bypassing:

Capture 47

One thing I have yet to update is a simple check to make sure you are an admin that can actually bypass UAC. If you aren't, then you'll be leaving this lovely calling card behind for the user:

Capture 48

 

 

Reader Comments (1)

The "lovely calling card" is really a concern, but it is still a good work.

October 30, 2012 | Unregistered CommenterBrute Logic

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>