<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Zach Grace</title><link>https://zachgrace.com/</link><description>Recent content on Zach Grace</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 10 Apr 2019 00:00:00 +0000</lastBuildDate><atom:link href="https://zachgrace.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Proxmox Cheat Sheet</title><link>https://zachgrace.com/cheat_sheets/proxmox/</link><pubDate>Wed, 10 Apr 2019 00:00:00 +0000</pubDate><guid>https://zachgrace.com/cheat_sheets/proxmox/</guid><description>&lt;h2 id="importing-vmware-images">Importing VMware Images&lt;/h2>
&lt;p>When exporting a VM from VMware, the image will likely get exported in one of two formats depending on how you exported it, OVF or OVA. Below are the steps for importing each into Proxmox. This was tested on version 5.3-8.&lt;/p>
&lt;h2 id="ovf">OVF&lt;/h2>
&lt;ol>
&lt;li>Transfer the &lt;code>.ovf&lt;/code> and &lt;code>.vmdk&lt;/code> to the host via SCP&lt;/li>
&lt;li>Run &lt;code>qm importovf &amp;lt;vmid&amp;gt; &amp;lt;ovf file&amp;gt; &amp;lt;storage&amp;gt;&lt;/code>, Ex: &lt;code>qm importovf 100 exported.ovf local-lvm&lt;/code>&lt;/li>
&lt;/ol>
&lt;p>Note: if the &lt;code>.vmdk&lt;/code> name differs from what&amp;rsquo;s stated in the manifest, you&amp;rsquo;ll need to rename it to match.&lt;/p></description></item><item><title>Red Team Telemetry Part 1</title><link>https://zachgrace.com/posts/red-team-telemetry-part-1/</link><pubDate>Fri, 01 Jun 2018 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/red-team-telemetry-part-1/</guid><description>&lt;p>After building and releasing &lt;a href="https://github.com/ztgrace/pwnboard">PWNboard&lt;/a>, I got some great feedback from many folks especially &lt;a href="https://twitter.com/vyrus001">Vyrus&lt;/a> (seriously thanks!). Vyrus gave me a little insight into what he and the National CCDC team were prepping which made me realize they were leagues ahead of PWNboard. But it served as pure inspiration.&lt;/p>
&lt;p>I started thinking about Red Ream Telemetry (RTT) beyond CCDC, what lengths could one take it to and how could I use telemetry to convey impact and insights on red team engagements. A few ideas came to mind almost immediately, have better insight into red team operations and have a log of all actions taken against a target/organization help the blue team improve their defenses.&lt;/p></description></item><item><title>About</title><link>https://zachgrace.com/about/</link><pubDate>Thu, 12 Apr 2018 00:00:00 +0000</pubDate><guid>https://zachgrace.com/about/</guid><description>&lt;p>I&amp;rsquo;ve worked in offensive security for nearly a decade focusing on securing financial institutions. I&amp;rsquo;ve been a systems administrator, developer, pen tester and currently lead a team offensive security team at a Fortune 100.&lt;/p>
&lt;p>You might find me at our local &lt;a href="https://www.reddit.com/r/netsec/wiki/meetups/citysec">CitySec&lt;/a> meetup, &lt;a href="http://milsec.org/">MilSec&lt;/a>, or at &lt;a href="https://www.owasp.org/index.php/Milwaukee">OWASP Milwaukee&lt;/a>. I&amp;rsquo;ve also been a member of the Wisconsin CCDC Red Team since 2012.&lt;/p>
&lt;h2 id="speaking-engagements">Speaking Engagements&lt;/h2>
&lt;p>I&amp;rsquo;ve had the privilege to present at the follwing events. In my presentations, I like to do demos, be educational and have something for all skill levels.&lt;/p></description></item><item><title>CCDC Red Team PWNboard</title><link>https://zachgrace.com/posts/ccdc_red_team_pwnboard/</link><pubDate>Sun, 04 Mar 2018 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/ccdc_red_team_pwnboard/</guid><description>&lt;p>I built an operations tool for our &lt;a href="http://www.cssia.org/ccdc/">Midwest CCDC&lt;/a> Red Team called &lt;a href="https://github.com/ztgrace/pwnboard">PWNboard&lt;/a>. Our biggest challenge in these competitions is that we’re in a virtual environment where teams can revert the machines at any point and essentially kill our access. So monitoring the checkins and backdoors is essential to maintaining access for the duration of the event. And that’s why I made PWNboard, an operational board that monitors our implants and backdoors. As &lt;a href="https://twitter.com/malcomvetter">Tim MalcomVetter&lt;/a> put it, it&amp;rsquo;s &lt;a href="https://twitter.com/malcomvetter/status/970327699909521408">offensive inventory management&lt;/a>.&lt;/p></description></item><item><title>Hybrid Cobalt Strike Redirectors</title><link>https://zachgrace.com/posts/cobalt_strike_redirectors/</link><pubDate>Tue, 20 Feb 2018 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/cobalt_strike_redirectors/</guid><description>&lt;p>Working for an organization with a strict data security policy puts a few challenges on a Red Team, especially when it comes to building robust infrastructure. &lt;a href="https://twitter.com/m0ther_">m0ther_&lt;/a> and I set out to build a robust, multi-redirector infrastructure similar to what &lt;a href="https://twitter.com/armitagehacker">Raphael Mudge&lt;/a> described in his blog post, &lt;a href="https://blog.cobaltstrike.com/2014/01/14/cloud-based-redirectors-for-distributed-hacking/">Cloud-based Redirectors for Distributed Hacking&lt;/a>, except we wanted to host the team server on-prem. The post below describes two iterations of infrastructure we built to meet our needs.&lt;/p></description></item><item><title>Experts Need Not Apply</title><link>https://zachgrace.com/posts/experts_need_not_apply/</link><pubDate>Sat, 09 Sep 2017 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/experts_need_not_apply/</guid><description>&lt;p>Recently, I tried to hire an AppSec contractor to add some capacity to our team. The request went out to some contracting firms and we received six resumes just a few days after posting. Now, the problem is that my team and I don&amp;rsquo;t have the capacity to interview that many candidates or even a subset of candidates. So I decided to send all of the candidates a few relatively straight forward web app vulnerability challenges, or at least I thought they should have been straight forward or relatively simple to solve. The experiment showed us that the consultants, all of which claim to have 5+ years AppSec experience, couldn&amp;rsquo;t identify major flaws in some stripped down CTF challenges. Their responses left me completely baffled and disheartened. I fear for our industry.&lt;/p></description></item><item><title>Vulnerability Scanning - A False Sense of Security</title><link>https://zachgrace.com/posts/2017-03-12-vuln_scanning-a_false_sense_of_security/</link><pubDate>Sun, 12 Mar 2017 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/2017-03-12-vuln_scanning-a_false_sense_of_security/</guid><description>&lt;p>As I tell my 6 year old daughter, be a problem solver, not a complainer.&lt;/p>
&lt;p>So I s
Seriously&amp;hellip;WebSpehre&lt;/p>
&lt;p>During a recent test&lt;/p>
&lt;h2 id="references">References&lt;/h2>
&lt;ul>
&lt;li>&lt;a href="https://github.com/ztgrace/changeme">https://github.com/ztgrace/changeme&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>Backdooring Node.js Express Apps via SSJI</title><link>https://zachgrace.com/posts/backdooring-nodejs-express-apps/</link><pubDate>Wed, 01 Mar 2017 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/backdooring-nodejs-express-apps/</guid><description>&lt;p>&lt;em>Updated: 2017.03.03&lt;/em>&lt;/p>
&lt;p>One of the interesting things about &lt;a href="https://nodejs.org/en/">Node.js&lt;/a> (server-side JavaScript) apps/APIs is that they&amp;rsquo;re event driven. As an attacker, this means there are new options for post-exploitation code execution, so I wrote a little PoC to demonstrate that.&lt;/p>
&lt;p>In the scenario below, we&amp;rsquo;re going to assume we&amp;rsquo;ve already identified Server-Side JavaScript Injection (SSJI) in the app. This is not a new vulnerability in Express, but an experiment in post-exploitation. There are many posts on how to exploit SSJI in which they show how to read files with &lt;code>require(‘fs’).readFile&lt;/code> or execute commands with &lt;code>require('child_process').spawn&lt;/code>. But what if we could add our own event through the SSJI? We could modify the running app&amp;rsquo;s behavior without touching disk and have it harvest sensitive information or perform other nefarious activities.&lt;/p></description></item><item><title>Docker Cheat Sheet</title><link>https://zachgrace.com/cheat_sheets/docker/</link><pubDate>Thu, 16 Feb 2017 00:00:00 +0000</pubDate><guid>https://zachgrace.com/cheat_sheets/docker/</guid><description>&lt;p>Install docker on a debian-based system: &lt;code>apt-get install docker.io&lt;/code>&lt;/p>
&lt;p>Download an Ubuntu 14.04 image: &lt;code>docker pull ubuntu:14.04&lt;/code>&lt;/p>
&lt;p>Download many Ubuntu-based images: &lt;code>docker pull ubuntu&lt;/code>&lt;/p>
&lt;p>Run bash in Ubuntu: &lt;code>docker run -it ubuntu /bin/bash&lt;/code>&lt;/p>
&lt;p>View running containers: &lt;code>docker ps&lt;/code>&lt;/p>
&lt;p>Attach to a running container: &lt;code>docker attach b80939864b33&lt;/code>&lt;/p>
&lt;pre>&lt;code>root@Docker:~# docker run -it ubuntu:14.04 /bin/bash
root@01a82e993d47:/# ls
bin boot dev etc home lib lib64 media mnt opt proc root run sbin srv sys tmp usr var
root@01a82e993d47:/# touch TEST
root@01a82e993d47:/# ls
TEST bin boot dev etc home lib lib64 media mnt opt proc root run sbin srv sys tmp usr var
root@Docker:~# docker commit -m "Test" -a "ztg" 01a82e993d47 foobar/ubuntu:v2
10a437b18b7f5aa3ee657b536505ff4bb5dd956a8611cb2324b24b03b9800f4c
root@Docker:~# docker run -it foobar/ubuntu:v2
root@0233b5a1119a:/# ls
TEST bin boot dev etc home lib lib64 media mnt opt proc root run sbin srv sys tmp usr var&lt;/code>&lt;/pre>
&lt;p>View available docker images:&lt;/p></description></item><item><title>Acing Your Security Headers</title><link>https://zachgrace.com/posts/2016-10-13-security-headers/</link><pubDate>Thu, 13 Oct 2016 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/2016-10-13-security-headers/</guid><description>&lt;p>Mozilla recently released a security header grading site, &lt;a href="https://observatory.mozilla.org/">https://observatory.mozilla.org/&lt;/a>. Of course I had to plug my site into the scanner and found that I got an F. Not good for a security guy.&lt;/p>
&lt;p>&lt;img src="https://zachgrace.com/assets/img/observatory_F.png" alt="Observatory F Rating" />&lt;/p>
&lt;p>According to &lt;a href="https://medium.com/mozilla-tech/promoting-security-best-practices-with-observatory-7b164a190425#.5gj02ihca">April King&lt;/a> of Mozilla, the Observatory &lt;em>&amp;ldquo;grading is set very aggressively to promote best practices in web security&amp;rdquo;&lt;/em>. And by looking at the scores, we can see that the far majority of sites fail the Observatory tests.&lt;/p></description></item><item><title>Fixing Frame Check Sequence with Scapy</title><link>https://zachgrace.com/posts/2016-09-13-fixing-fcs/</link><pubDate>Tue, 13 Sep 2016 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/2016-09-13-fixing-fcs/</guid><description>&lt;pre>&lt;code class="language-python">[20:03:53-160913][kali:~]# scapy
INFO: Can&amp;rsquo;t import python gnuplot wrapper . Won&amp;rsquo;t be able to plot.
WARNING: No route found for IPv6 destination :: (no default route?)
Welcome to Scapy (2.2.0)
&amp;gt;&amp;gt;&amp;gt; packets = rdpcap(&amp;ldquo;ctf.pcap&amp;rdquo;)
&lt;/code>&lt;/pre>
&lt;blockquote>
&lt;blockquote>
&lt;blockquote>
&lt;p>packets[7]
&lt;Ether dst=52:54:00:12:35:02 src=08:00:27:ac:98:99 type=0x800 |&lt;IP version=4L ihl=5L tos=0x0 len=138 id=52810 flags=DF frag=0L ttl=64 proto=tcp chksum=0xc6eb src=10.0.2.15 dst=216.58.192.238 options=[] |&lt;TCP sport=46516 dport=http seq=1386647494 ack=64002 dataofs=5L reserved=0L flags=PA window=29200 chksum=0xa5b4 urgptr=0 options=[] |&lt;Raw load='GET /watch?v=dQw4w9WgXcQ HTTP/1.1\r\nHost: www.youtube.com\r\nUser-Agent: curl/7.46.0\r\nAccept: */*\r\n\r\n' |>&amp;gt;&amp;gt;&amp;gt;&lt;/p></description></item><item><title>X11 Hacking</title><link>https://zachgrace.com/training/x11/</link><pubDate>Fri, 13 May 2016 00:00:00 +0000</pubDate><guid>https://zachgrace.com/training/x11/</guid><description>&lt;h2 id="setup">Setup&lt;/h2>
&lt;p>This tutorial is based on the X11 server in the &lt;a href="https://github.com/ztgrace/pwn_lab">PWN Lab&lt;/a> project. To install the VM, follow the instructions in the pwn_lab README, then execute the commands below. This VM will take a while to finish installing and configuring as it needs to download and install the ubuntu-desktop packages.&lt;/p>
&lt;div class="highlight">&lt;pre tabindex="0" style="color:#93a1a1;background-color:#002b36;-moz-tab-size:4;-o-tab-size:4;tab-size:4;">&lt;code class="language-bash" data-lang="bash">&lt;span style="display:flex;">&lt;span>git clone https://github.com/ztgrace/pwn_lab.git
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>&lt;span style="color:#b58900">cd&lt;/span> pwn_lab/x11
&lt;/span>&lt;/span>&lt;span style="display:flex;">&lt;span>vagrant up
&lt;/span>&lt;/span>&lt;/code>&lt;/pre>&lt;/div>&lt;p>If all goes well, you should have a VM running that looks like this:&lt;/p></description></item><item><title>Projects</title><link>https://zachgrace.com/projects/</link><pubDate>Wed, 11 May 2016 00:00:00 +0000</pubDate><guid>https://zachgrace.com/projects/</guid><description>&lt;h2 id="changeme">changeme&lt;/h2>
&lt;p>&lt;a href="https://github.com/ztgrace/changeme">changeme&lt;/a> is a default credential scanner. I wrote changeme out of frustration with commercial vulnerability scanners missing common default credentials. Getting default credentials added to commercial scanners is often difficult and slow. changeme is designed to be simple to add new credentials without having to write any code or modules.&lt;/p>
&lt;h2 id="pwn-lab">PWN Lab&lt;/h2>
&lt;p>&lt;a href="https://github.com/ztgrace/pwn_lab">PWN Lab&lt;/a> is a collection of Vagrant scripts and boxes to create security training environments. Getting a running environment is as easy as cloning the repository and running vagrant up.&lt;/p></description></item><item><title>radare2 Cheat Sheet</title><link>https://zachgrace.com/cheat_sheets/radare2/</link><pubDate>Sat, 05 Mar 2016 00:00:00 +0000</pubDate><guid>https://zachgrace.com/cheat_sheets/radare2/</guid><description>&lt;p>Here&amp;rsquo;s a few commands I&amp;rsquo;ve found useful while learning the radare2 tool set.&lt;/p>
&lt;h2 id="radare2r2">radare2/r2&lt;/h2>
&lt;p>List functions&lt;/p>
&lt;p>&lt;code>afl&lt;/code>&lt;/p>
&lt;p>Disassemble function:&lt;/p>
&lt;p>&lt;code>aa&lt;/code>&lt;/p>
&lt;p>&lt;code>pdr@main&lt;/code>&lt;/p>
&lt;p>Print call graph:&lt;/p>
&lt;p>&lt;code>agc &amp;gt; /tmp/foo.dot&lt;/code>
&lt;code>xdot /tmp/foo.dot&lt;/code>&lt;/p>
&lt;p>Print a detailed graph:&lt;/p>
&lt;p>&lt;code>ag $$ &amp;gt; /tmp/c2.dot&lt;/code>&lt;/p>
&lt;p>Disassemble instruction:&lt;/p>
&lt;p>&lt;code>pD 2&lt;/code>&lt;/p>
&lt;p>Seek to a specific memory location:&lt;/p>
&lt;p>&lt;code>s 0x08048470&lt;/code>&lt;/p>
&lt;p>Write hex value:&lt;/p>
&lt;p>&lt;code>wx eb&lt;/code>&lt;/p>
&lt;h2 id="debuggingvisual-mode">Debugging/Visual Mode&lt;/h2>
&lt;p>&lt;a href="https://radare.gitbooks.io/radare2book/content/introduction/basic_debugger_session.html">https://radare.gitbooks.io/radare2book/content/introduction/basic_debugger_session.html&lt;/a>&lt;/p>
&lt;p>&lt;code>r2 -d ./file&lt;/code>&lt;/p>
&lt;p>Set breakpoint&lt;/p>
&lt;p>&lt;code>db 0x00401383&lt;/code>&lt;/p>
&lt;p>Remove breakpoint&lt;/p>
&lt;p>&lt;code>db -0x00401383&lt;/code>&lt;/p>
&lt;p>List breakpoints&lt;/p></description></item><item><title>GDB Cheat Sheet</title><link>https://zachgrace.com/cheat_sheets/gdb/</link><pubDate>Sat, 04 Jul 2015 00:00:00 +0000</pubDate><guid>https://zachgrace.com/cheat_sheets/gdb/</guid><description>&lt;p>This is a collection of commands I&amp;rsquo;ve found useful when working with GDB.&lt;/p>
&lt;hr>
&lt;p>Run an executable with args:&lt;/p>
&lt;p>&lt;code>gdb --args path/to/executable -every -arg you can=think &amp;lt; of&lt;/code>&lt;/p>
&lt;p>&lt;code>gdb -q --args ./bof $(/opt/metasploit-framework/tools/pattern_create.rb 1000)&lt;/code>&lt;/p>
&lt;hr>
&lt;p>Set a breakpoint:&lt;/p>
&lt;p>&lt;code>break main&lt;/code>&lt;/p>
&lt;p>&lt;code>b main&lt;/code>&lt;/p>
&lt;hr>
&lt;p>Set a breakpoint at an instruction:&lt;/p>
&lt;p>&lt;code>b *0x80484b5&lt;/code>&lt;/p>
&lt;hr>
&lt;p>Disassemble a function:&lt;/p>
&lt;p>&lt;code>disassemble main&lt;/code>&lt;/p>
&lt;p>&lt;code>disas main&lt;/code>&lt;/p>
&lt;hr>
&lt;p>Show registers:&lt;/p>
&lt;p>&lt;code>info registers&lt;/code>&lt;/p>
&lt;p>&lt;code>i r&lt;/code>&lt;/p>
&lt;hr>
&lt;p>Show a specific register:&lt;/p>
&lt;p>&lt;code>info registers eip&lt;/code>&lt;/p>
&lt;p>&lt;code>i r eip&lt;/code>&lt;/p></description></item><item><title>Creating Vagrant Boxes</title><link>https://zachgrace.com/posts/2015-06-28-creating-vagrant-boxes/</link><pubDate>Sun, 28 Jun 2015 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/2015-06-28-creating-vagrant-boxes/</guid><description>&lt;pre>&lt;code class="language-bash">sudo visudo -f /etc/sudoers.d/vagrant
&lt;/code>&lt;/pre>
&lt;pre>&lt;code class="language-bash">vagrant ALL=(ALL) NOPASSWD:ALL
&lt;/code>&lt;/pre>
&lt;pre>&lt;code class="language-bash">mkdir -p /home/vagrant/.ssh
chmod 0700 /home/vagrant/.ssh
wget &amp;ndash;no-check-certificate &lt;br />
 &lt;a href="https://raw.github.com/mitchellh/vagrant/master/keys/vagrant.pub">https://raw.github.com/mitchellh/vagrant/master/keys/vagrant.pub&lt;/a> &lt;br />
 -O /home/vagrant/.ssh/authorized_keys
chmod 0600 /home/vagrant/.ssh/authorized_keys
chown -R vagrant /home/vagrant/.ssh
&lt;/code>&lt;/pre>
&lt;h2 id="ubuntu">Ubuntu&lt;/h2>
&lt;p>Older training VMs use&lt;/p>
&lt;pre>&lt;code class="language-bash">sudo sed -i -re &amp;rsquo;s/([a-z]{2}.)?archive.ubuntu.com|security.ubuntu.com/old-releases.ubuntu.com/g&amp;rsquo; /etc/apt/sources.list
&lt;/code>&lt;/pre>
&lt;h2 id="references">References&lt;/h2>
&lt;ul>
&lt;li>&lt;a href="https://blog.engineyard.com/2014/building-a-vagrant-box">Building a Vagrant Box from Start to Finish&lt;/a>&lt;/li>
&lt;li>&lt;a href="http://askubuntu.com/questions/91815/how-to-install-software-or-upgrade-from-an-old-unsupported-release">How to Install Software or Upgrade From an Old Unsupported Release (Ubuntu)&lt;/a>&lt;/li>
&lt;/ul></description></item><item><title>Attacking ECB</title><link>https://zachgrace.com/posts/attacking-ecb/</link><pubDate>Fri, 17 Apr 2015 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/attacking-ecb/</guid><description>&lt;p>On a recent engagement, I came across &lt;a href="http://en.wikipedia.org/wiki/Block_cipher_mode_of_operation#Electronic_Codebook_.28ECB.29">Electronic Code Book (ECB)&lt;/a> encrypted data. While there&amp;rsquo;s a plethora of documentation about performing bit flipping in ECB, I couldn&amp;rsquo;t find any decent writeups on how to perform adaptive chosen plaintext attacks to recover ciphertext.&lt;/p>
&lt;p>In ECB mode, each block of plaintext is encrypted independently with the key as illustrated by the diagram below.&lt;/p>
&lt;img alt="ECB encryption.svg" title="ECB encryption - Wikipedia" src="//upload.wikimedia.org/wikipedia/commons/thumb/d/d6/ECB_encryption.svg/601px-ECB_encryption.svg.png" width="601" height="242" srcset="//upload.wikimedia.org/wikipedia/commons/thumb/d/d6/ECB_encryption.svg/902px-ECB_encryption.svg.png 1.5x, //upload.wikimedia.org/wikipedia/commons/thumb/d/d6/ECB_encryption.svg/1202px-ECB_encryption.svg.png 2x" data-file-width="601" data-file-height="242">
(Source: Wikipedia)
&lt;p>Since each block of plaintext is encrypted with the key independently, identical blocks of plaintext will yield identical blocks of ciphertext. The classic and poignant example of this property is an encrypted image of the Linux mascot, Tux. Below are three images, the original Tux image, an ECB encrypted Tux and a CBC encrypted Tux. The ECB encrypted Tux leaves visible artifacts whereas the CBC encrypted Tux looks like random data.&lt;/p></description></item><item><title>Hunting Sticky Keys Backdoors</title><link>https://zachgrace.com/posts/hunting-sticky-keys-backdoors/</link><pubDate>Mon, 23 Mar 2015 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/hunting-sticky-keys-backdoors/</guid><description>&lt;p>The &amp;ldquo;sticky keys&amp;rdquo; backdoor method has been a favorite for hackers for years and it&amp;rsquo;s been gaining popularity as a malware-free persistence method. This backdoor method gives an attacker pre-authentication, SYSTEM-level access to a target remotely over RDP or locally via the console.&lt;/p>
&lt;p>The backdoor can be installed in one of two ways:&lt;/p>
&lt;ol>
&lt;li>Copy &lt;em>cmd.exe&lt;/em> over &lt;em>sethc.exe&lt;/em> or &lt;em>utilman.exe&lt;/em>&lt;/li>
&lt;li>Set &lt;em>cmd.exe&lt;/em> as the debugger for &lt;em>sethc.exe&lt;/em> or &lt;em>utilman.exe&lt;/em>&lt;/li>
&lt;/ol>
&lt;p>The &lt;em>sethc.exe&lt;/em> backdoor can be triggered by pressing the shift key five times in rapid succession. The &lt;em>utilman.exe&lt;/em> backdoor can be triggered by pressing windows+u.&lt;/p></description></item><item><title>Exploiting MS14-068 with PyKEK and Kali</title><link>https://zachgrace.com/posts/exploiting-ms14-068/</link><pubDate>Sun, 14 Dec 2014 00:00:00 +0000</pubDate><guid>https://zachgrace.com/posts/exploiting-ms14-068/</guid><description>&lt;p>Here’s a quick writeup of exploiting MS14-068 using &lt;a href="https://github.com/bidord/pykek">PyKEK&lt;/a> and &lt;a href="https://www.kali.org/">Kali&lt;/a>.&lt;/p>
&lt;h2 id="kali-prepwork">Kali Prepwork&lt;/h2>
&lt;h3 id="install-and-configure-kerberos">Install and Configure Kerberos&lt;/h3>
&lt;p>Install kerberos:&lt;/p>
&lt;p>&lt;code>apt-get install krb5-user krb5-config&lt;/code>&lt;/p>
&lt;p>Create relevant kerberos config changes in &lt;code>/etc/krb5.conf&lt;/code>:&lt;/p>
&lt;pre>[libdefaults]
 default_realm = pwn3d.local
[realms]
 pwn3d.local = {
 kdc = dc1.pwn3d.local
 admin_server = dc1.pwn3d.local
 default_domain = pwn3d.local
}&lt;/pre>
&lt;p>Point DNS to the DNS Server/domain controller so SRV records (e.g. _kerberos._tcp.*) will resolve correctly in &lt;code>/etc/resolv.conf&lt;/code>.&lt;/p>
&lt;p>According to the TrustedSec &lt;a href="https://www.trustedsec.com/december-2014/ms14-068-full-compromise-step-step/">blog&lt;/a>, you&amp;rsquo;ll need to sync time with the domain controller. During my testing I didn&amp;rsquo;t perform any syncing and had no issues.&lt;/p></description></item><item><title>Page Not Found</title><link>https://zachgrace.com/404.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://zachgrace.com/404.html</guid><description/></item></channel></rss>