Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests and 2 members online
 
Advertisement

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow AV Bypass
EH-Net
May 20, 2013, 10:20:42 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: AV Bypass  (Read 794 times)
0 Members and 1 Guest are viewing this topic.
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« on: March 12, 2013, 08:07:21 AM »

Hi,
Thought I would share my recent blogpost..enjoy:
http://sector876.blogspot.com/2013/03/av-bypass-symantec-endpoint-protection.html
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« Reply #1 on: March 12, 2013, 08:50:07 AM »

Nice post. I'm getting back into C++ myself and appreciate the sample code.

For whatever reason, Symantec only has an attack signature for Meterpreter's reverse_tcp payload: http://www.symantec.com/security_response/attacksignatures/ It's the stupidest thing in the world. Bind_tcp, reverse_https like you used, etc. work just fine.

Depending on the configuration, you are sometimes unable to disable smc in that manner (I believe this is functionality that can be disabled via the management console), so it's good to know about the alternate payloads.

Also, SEP was catching default msfvenom exes, but using the -t option with pslist.exe got around that. Sometimes it's just too easy.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #2 on: March 12, 2013, 01:33:58 PM »

That's funny, I was also on a recent engagement with a similar issue. The client was running SEP with various features enabled. I could get my payload on but the network detection piece would block me each time, and I thought I did try reverse_https as well as others with no luck. I already had credentials at this point so ended up modifying gsecdump and WCE and just used psexec to maneuver around and obtain more credentials Smiley Worked perfectly.

Nice write-up though, thanks. I'm going to take a closer look at this and do some playing around later.
Logged
Dark_Knight
Sr. Member
****
Offline Offline

Posts: 292


View Profile WWW
« Reply #3 on: March 12, 2013, 03:21:25 PM »

Yeah so....I actually used the reverse_tcp meterpreter payload and not https. Also I didn't stop the Smc.exe process. That is still running.

Stopping the Smc.exe process is <path>\smc -stop

As opposed to a <path>\smc -disable -ntp that targets the ntp. And ntp doesnt stay dead for very long. It comes back online in 5 minutes. I timed it Smiley

However even when it does it won't kill your meterpreter session Smiley

I tell you though I havn't looked at c++ in a while though......
Logged

CEH, OSCP, GPEN, GWAPT, GCIA
http://sector876.blogspot.com
m0wgli
Full Member
***
Offline Offline

Posts: 248


View Profile
« Reply #4 on: March 12, 2013, 04:25:44 PM »

Interesting post. Thanks for sharing. New bookmark acquired!  Smiley
Logged

Security + | OSWP | eCPPT | CSTA
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.076 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.