Skip to main content

Abusing windows accessibility features | sethc.exe | sticky keys | persistence and privilege escalation

https://attack.mitre.org/techniques/T1546/008/

https://www.youtube.com/watch?v=dIuQ2sUsZEo


 sethc.exe resides on windows\system32 folder. in sethc.exe even administrators does not have full access. only the owner of the system which you can say trustedinstaller has the full access. but you can change the trustedinstaller by clicking the Advanced options. you can change the trustedinstaller by clicking the change button and add a local user who has admin rights. 


here action is performed in a domain environment. but you can add your local user as well. as an example i had added my username which is Avi who has admin rights on the system. 

now sethc owner has been changed. as you are owner now of sethc so you can now decide whom you want to give full access. 


 now click on edit. now you can change permissions. give administrators full control permissions. click yes on the popup. 

now you can rename the file. so rename the sethc.exe to sethc.exe.bak

then make a copy of cmd.exe. then you shall get cmd - Copy.exe

now rename cmd - Copy.exe to sethc.exe

done. 

now whenever you press 5 times shift key, a command prompt will open. and will be running of the current user session. if you are login as admin then the command prompt will also launch in the context of that admin rights. during the system is locked then it will run in the context of nt authority\system

it will give you persistency, elevation of privilege because it will still work if the system rebooted, or admin user get disabled or password changed scenario. it is still work if the system is accessed by remotely. 


Detection:


as this is not a malware activity but good AV like windows defender can also detect this behavior change anomaly. however as you are running this as local admin so from the Action setting on defender, you can allow on this device. 


but there is a way where you can specify that threats cannot be allowed on this device. here is how you can tightend up in an enterprise environment.


expand the windows components.


 disabling local list merging. it forces microsoft defender to ignore any configuration changes or exception which have been defined on the local machine by any user. instead it says use the values set on the group policy. once the group policy is updated (gpupdate /force) the exception we added earliar will be deleted from the allowed threats and you cannot make the exception again. 


note:

replacing accessibility feature binaries needs to be digitally signed for x64 systems. the binaries must reside in Windows\System32 folder. and it must be protected by windows file or resource protection (WFP/WRP).




 


Comments

Popular posts from this blog

API hacking lab setup

 Follow the commands to install and configure API hacking lab: 1. Install kali linux and update all the packages.  apt update -y apt upgrade -y or apt dist-upgrade -y or apt full-upgrade -y If you face any problem regarding update, install cloud flare warp in the host machine, then again start updating packages in your kali vm.  2. Install and configure burpsuite professional.  After that open burpsuite and go to Extensions tab. Click on BAppStore. Search for Autorize extension, It will help us to automate authorization testing. Click on Download Jython from the right side. From Jython website click on Jython standalone JAR and save it. Go to Extensios > Extensions settings >  under Core extension settings find out Python environment on the right pane. Select the jython jar file that you just downloaded. Now again go to BAppStore and re-search for Autorize extension. You will see Install option this time after selecting Autorize extension. Install it. You ...

Installing kansa incident response tool

 Kansa is an IR framework. https://github.com/davehull/Kansa For enterprise data collection, you need to do this first from the admin system: Set-NetConnectionProfile -NetworkCategory Private (In private network) Enable-PSRemoting  from powershell on the system where you want to run this tool. This will enable winrm service with port 5985 and 5986. Check: netstat -naob | findstr "5985"   Also allow tcp port 5985 and 5986 for winrm through the network. You can use  GPO. Though winrm is communicating over http and https but authentication will be happened using kerberos in domain environment.  After downloading it  from the github and unzip it, you need to unlock it using powershell. Need powershell v3 or later. ls -r *.ps1 | Unblock-File Powershell policy bypass: Set-ExecutionPolicy AllSigned | RemoteSigned | Unrestricted From FOR508 course: .\kansa.ps1 -OutputPath .\Output\ -TargetList .\hostlist -TargetCount 250 -Verbose -Pushbin -Pushbin is requir...

How to use vim efficiently

  Here every command works in command mode . And if you need to write something then you need to go to Insert mode . Pressing i will take you to the insert mode.  1. Let's say you want to search something. For example you want to find avi keyword. Then first you need to go to the command mode by typing Esc . Now type /avi  (at the bottom) and hit enter. Press small n to forward this search pattern and press Shift N to go reverse.  2. Substitute something: :%s/old string/new string/g    (g for affecting globally) 3. If you want to pick the 1st letter of word then press w and last letter of word then press e .  4. yy means copy a single line. 2yy means copy double lines.  5. Shift P is for paste.  6. Shift D to delete a line or cut a line.  7. Press o to go a new line.  8. Press Home to go to the 1st letter of a line and End to go to the last letter of a line.  9. If you want to save the file then press wq! . 10. If ...