Это PoC реализция SMB-бэкдора, основанная на собственном исследовании ядра Windows и механизма SMB. Так как это всего лишь PoC, особого функционала нету. В будущем планируется поддержка базового функционала:
| Функция | Статус |
|---|---|
| Heresy's Gate инъекция кода | ✔️ |
| Чтение SMB тега | ✔️ |
| Прямое чтение/запись вирутальной памяти | ✔️ |
| Выполнение произвольного Usermode-шеллкода | ✔️ |
| Передача Usermode-шеллкода в SMB пакете | ✔️ |
Также планирутеся подробное описание работы данного механизма и оптимизация кода. На текущий момент стабильно работает на:
- Windows 10 1809
- Windows 10 2004
- Windows 10 21H2
Вдохновлено проектом smbdoor
На текущий момент бэкдор обладает возможно выполнять произвольный Usermode-шеллкод путем инжекта и создания потока в целевом процессе (по умолчанию explorer.exe). Были протестированы кастомные calc-шеллкоды и шеллкоды от Metasploit (стейджер), ограничения на размер шеллкода - 4000 байт (при большем размере может работать нестабильно, но ограничение можно изменить в коде). Шеллкод достаточно скопировать в файл shellcode.h в проекте ping (он должен быть в формате строки). Если хотите чтобы у шеллкода были SYSTEM-привилегии, то инжект делайте в winlogon.exe. Все функции протестированы в x64, в x86 системах что то может вовсе не работать.
This is a PoC implementation of an SMB backdoor based on our own research into the Windows kernel and the SMB mechanism. Since this is just a PoC, there is no special functionality. In the future, it is planned to support the basic functionality:
- Arbitrary read/write memory
- Shellcode execution
- Etc.
A detailed description of the operation of this mechanism is also planned. Currently working stably on:
- Windows 10 1809
- Windows 10 21H2
Inspired by the smbdoor project
At the moment, the backdoor has the ability to execute an arbitrary Usermode shellcode by injecting and creating a thread in the target process (explorer.exe by default). Custom calc shellcodes and shellcodes from Metasploit (stager) were tested, the shellcode size limit is 4000 bytes (it can be unstable with a larger size, but the limit can be changed in the code). It is enough to copy the shellcode to the shellcode.h file in the ping project (it must be in string format). If you want the shellcode to have SYSTEM privileges, then inject it in winlogon.exe. All functions are tested in x64, in x86 systems something may not work at all.
https://blog.zecops.com/research/smbleedingghost-writeup-part-iii-from-remote-read-smbleed-to-rce