quadrado51
Market Demand Exploiter
2
MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1
400 XP
data:image/s3,"s3://crabby-images/53d7d/53d7dcbd7713a9417f212395f2b88565b73d02c7" alt="Cityscape-Listing-Presentation-1.png"
Hey Folks, in this tutorial we will discuss the working methods through which we can bypass (UAC) user account control enforcement facility of the window machine and get administrative level privileges. We will discuss about UAC before jumping straight to the methods of exploitation.
UAC ( User Account Control )
User Account Control is a mandatory access control enforcement facility of the window machine that helps to prevent malware from damaging a PC. They are typically marked by a security shield icon with the 4 colors of the Windows logo. Letās talk about the tasks that we can do after get administrator privileges.
- Running an Application as an Administrator
- Changes to system-wide settings
- Installing and uninstalling applications
- Installing device drivers
- Changing settings for Windows Firewall
- Adding or removing user accounts
- Changing a userās account name or type
- Change Registry Values
- More ā¦
As you can see above how many unwanted actions we can take after getting administrator privileges, hence in this tutorial we will tell you about all the possible ways through which we can easily bypass UAC (User Account Control) and get administrator privileges.
Lets take a look
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: š"
Compromised
As you can see that we have already compromised to the victim machine ( window 10 ). If you want to know about the complete process of taking a meterpreter session of the victim machine then you can click here.
data:image/s3,"s3://crabby-images/87d99/87d9955187cdbd0a435ae7f27aba44b636aecc4c" alt="1-11.png"
Privileges
You can see in the image below that we have a meterpreter session but without much privilege. Letās try to get admin access along with metasploit modules.
getprivs
getuid12getprivsgetuid
data:image/s3,"s3://crabby-images/85c24/85c243efeca01629ad8bec5ebe02137f0369debb" alt="2-11.png"
Bypass Window 10 UAC via Fodhelper
This module will bypass Windows 10 UAC by hijacking a special key in the Registry under the current user hive, and inserting a custom command that will get invoked when the Windows fodhelper.exe application is launched. All you have to do is change the session ID and execute all the commands. After doing this the meterpreter session will come as you can in the image below. Letās see whether the meterpreter has comes with admin privileges or not.
data:image/s3,"s3://crabby-images/4ae96/4ae964e51e73fc5d1daae2fd73d69cc63f6e82cb" alt="3-11.png"
Great
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: š"
data:image/s3,"s3://crabby-images/2f5db/2f5db36be35b835235d3a14f41ef0e6b1583a923" alt="4-11.png"
Bypass Window 10 UAC via Silentcleanup
Basically thereās a task in the Windows Task Scheduler called āSilentCleanupā which, while itās executed as Users, automatically runs with elevated privileges. When it runs, it executes the file %windir%\system32\cleanmgr.exe. Since it runs as Users, and we can control userās environment variables, %windir% (normally pointing to C:\Windows) can be changed to point to whatever we want, and itāll run as admin. To run this module just you need to execute the following command but make sure change the session id.
use exploit/windows/local/bypassuac_silentcleanup
set session < id >
run123useexploit/windows/local/bypassuac_silentcleanupset session<id>run
data:image/s3,"s3://crabby-images/199b9/199b9ade5490fecbd288e2a7744130ebb8fd91e0" alt="5-12.png"
Check Privileges
Done
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: š"
data:image/s3,"s3://crabby-images/e327a/e327ae9217be077cba9612ae8c96de3601aa3652" alt="6-12.png"
Bypass Window 10 UAC via RunAs
This module will attempt to elevate execution level using the ShellExecute undocumented RunAs flag to bypass low UAC settings.
After receiving the victim machineās meterpreter session then all you need to do is execute the given command on multi handler of metasploit but make sure change the session ID that you got.
use exploit/windows/local/ask
set session < id >
run123useexploit/windows/local/askset session<id>run
data:image/s3,"s3://crabby-images/7ed24/7ed247dff66d250bf71764669c596ccb5ff8138e" alt="7-11.png"
Wait
data:image/s3,"s3://crabby-images/a0dd6/a0dd67a17ec8b6e6bcb45d7047f3d9bfe87084bb" alt="Slightly smiling face :slight_smile: š"
data:image/s3,"s3://crabby-images/1e4e4/1e4e41b22655bec4c3e4fbb3d697f9904f6d8173" alt="8-10.png"
Good
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: š"
data:image/s3,"s3://crabby-images/78014/7801483974662d61a0db6744845b164b1c4f543e" alt="9-7.png"
Nice
data:image/s3,"s3://crabby-images/e8e8f/e8e8f10ee7969490cfdc1dc1612ff37bbd0ae6f5" alt="Face with tongue :stuck_out_tongue: š"
data:image/s3,"s3://crabby-images/8cc21/8cc214b0f51f00a56e2e9a5842afa5eca7dcc2e1" alt="10-6.png"
Credit : Wikipedia& Rapid7
About the AuthorShubham Goyal Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.