{"id":384286,"date":"2024-06-29T05:25:20","date_gmt":"2024-06-29T05:25:20","guid":{"rendered":"http:\/\/savepearlharbor.com\/?p=384286"},"modified":"-0001-11-30T00:00:00","modified_gmt":"-0001-11-29T21:00:00","slug":"","status":"publish","type":"post","link":"https:\/\/savepearlharbor.com\/?p=384286","title":{"rendered":"<span>Payment Village at PHDays 11: ATM hacking<\/span>"},"content":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/991\/cb0\/467\/991cb0467ab02004fb69b0d4a0be8cfa.gif\" width=\"1280\" height=\"720\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/991\/cb0\/467\/991cb0467ab02004fb69b0d4a0be8cfa.gif\"\/><\/figure>\n<p>The\u00a0<a href=\"https:\/\/www.phdays.com\/en\/press\/news\/phdays-11-wrap-up-interest-in-information-security-explodes-rutube-attack-investigated-pipeline-shutdown-demo\/\">Positive Hack Days 11 forum<\/a>, which took place May 18\u201319, 2022, was truly epic. The bitterly fought ATM hacking contest featured no fewer than 49 participants. How cool is that? The winner of this year&#8217;s prize fund of 50,000 rubles, with the handle Igor, was the first to hack the virtual machines. And they weren&#8217;t even at the event! \ud83d\ude42<\/p>\n<p>Besides Igor, eight other participants picked up prizes this year for their VM-hacking skills. They were:\u00a0<strong>drd0c<\/strong>,\u00a0<strong>vient<\/strong>,\u00a0<strong>vrazov<\/strong>,\u00a0<strong>durcm<\/strong>,\u00a0<strong>zxcvcxzas7<\/strong>,\u00a0<strong>asg_krd<\/strong>,\u00a0<strong>hundred303<\/strong>, and\u00a0<strong>drink_more_water_dude<\/strong>. A big thank-you to everyone who took part, and for those who weren&#8217;t at PHDays, here are the links to the virtual machines:<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/10wDbWri0wfjH8Azy5FH-dNo6NPd8UkDg\">ATM1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/1ILV5t5nmL9dHcieEgLjJovbH1N1SS7uS\">ATM2<\/a><\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/878\/56a\/770\/87856a7705935dede223b064fe04727a.png\" alt=\"Figure 1. ATM interface\" title=\"Figure 1. ATM interface\" width=\"647\" height=\"696\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/878\/56a\/770\/87856a7705935dede223b064fe04727a.png\"\/><\/p>\n<div><figcaption>Figure 1. ATM interface<\/figcaption><\/div>\n<\/figure>\n<p>As for the tasks, they were identical for the two different virtual machines:<\/p>\n<ol>\n<li>\n<p>Kiosk bypass (solved 34 times)<\/p>\n<\/li>\n<li>\n<p>Windows AppLocker bypass (solved 21 times)<\/p>\n<\/li>\n<li>\n<p>Privilege escalation to the Administrator (solved 12 times)<\/p>\n<\/li>\n<\/ol>\n<p>On the C drive were three files:\u00a0<strong>task_kiosk.exe<\/strong>,\u00a0<strong>task_applocker.exe<\/strong>, and\u00a0<strong>task_escalation.exe<\/strong>, which had to be run to make the task count. <strong>task_kiosk.exe<\/strong> could be run immediately after bypassing the kiosk; <strong>task_applocker.exe<\/strong> was blocked using AppLocker; task_escalation.exe required administrator privileges to run.<\/p>\n<p>This year&#8217;s architectural solutions allowed us to track the number of participants and solved tasks through a Telegram bot, thus providing more detailed statistics (Figure 2).<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/913\/354\/ebb\/913354ebbedb76fe9e9d805effb3fcd4.png\" alt=\"Figure 2. Total number of participants\" title=\"Figure 2. Total number of participants\" width=\"252\" height=\"149\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/913\/354\/ebb\/913354ebbedb76fe9e9d805effb3fcd4.png\"\/><\/p>\n<div><figcaption>Figure 2. Total number of participants<\/figcaption><\/div>\n<\/figure>\n<h2>Task analysis<\/h2>\n<p>We should note that participants this year had much greater scope for activity, and each task on the virtual machine had a large number of solutions. Last year, it took participants a long time to bypass the kiosk, and some simply gave up before completion. This year&#8217;s changes brought results, delivering some interesting solutions that were not envisioned in the original scenario.<\/p>\n<p>Below is an overview of the solutions in <strong>general terms, without reference to specific virtual machines<\/strong>. It will be obvious to participants which solution fits which machine. This is to allow interested readers to solve the tasks for themselves, should they wish to.<\/p>\n<h3>Kiosk bypass. First method<\/h3>\n<p>Many had no idea how simple it was. To kiosk bypass in one of the virtual machines, they had to use the right mouse button. Surprisingly, participants did not notice that the right mouse button was working and, like last year, tried to find keyboard shortcuts to exit kiosk mode. The kiosk application was a web browser written in Delphi, so the complete kiosk bypass scenario was as follows: right-click \u2192 Print \u2192 Find Printer (Figure 3).<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/43a\/21f\/2c7\/43a21f2c7a68fd3158910a44c4d7cb03.png\" alt=\"Figure 3. Right-click menu\" title=\"Figure 3. Right-click menu\" width=\"254\" height=\"396\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/43a\/21f\/2c7\/43a21f2c7a68fd3158910a44c4d7cb03.png\"\/><\/p>\n<div><figcaption>Figure 3. Right-click menu<\/figcaption><\/div>\n<\/figure>\n<p>     These actions made it possible to open explorer.exe and go to the C drive to run <strong>task_kiosk.exe<\/strong>.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/19b\/411\/3d4\/19b4113d4ca899be2fe5443616230904.png\" alt=\"Figure 4. Executing the first task\" title=\"Figure 4. Executing the first task\" width=\"783\" height=\"409\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/19b\/411\/3d4\/19b4113d4ca899be2fe5443616230904.png\"\/><\/p>\n<div><figcaption>Figure 4. Executing the first task<\/figcaption><\/div>\n<\/figure>\n<h3>Kiosk bypass. Second method<\/h3>\n<p>Things were a bit tricker in the other virtual machine because the right mouse button was disabled, as were the main keys. To exit kiosk mode, a network vector was laid out that required scanning of the ATM ports. After scanning the ports with Nmap, participants may have noticed some kind of service on port 80. The easiest way to find out what was running there was to follow the link <a href=\"http:\/\/atm_adress\/\">http:\/\/&lt;atm_adress>:80<\/a>. There on port 80, it turned out to be a web server specially written for the contest. Every time a user connected to it, it threw an error and opened a browser help page on the virtual machine.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/467\/2a2\/219\/4672a2219609ea4a040c81a88d8047c7.png\" alt=\"Figure 5. Demonstrating the Nmap interface\" title=\"Figure 5. Demonstrating the Nmap interface\" width=\"1434\" height=\"838\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/467\/2a2\/219\/4672a2219609ea4a040c81a88d8047c7.png\"\/><\/p>\n<div><figcaption>Figure 5. Demonstrating the Nmap interface<\/figcaption><\/div>\n<\/figure>\n<p>In this case, the ATM&#8217;s IP was 192.168.56.102, and scanning Nmap showed that port 80 was open. After navigating to that address in the browser, an error appeared, whereupon clicking the OK button opened the Internet Explorer browser.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/77c\/4a0\/28a\/77c4a028ab97664698d587f6db9cc345.png\" alt=\"Figure 6. Embedded error\" title=\"Figure 6. Embedded error\" width=\"1228\" height=\"426\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/77c\/4a0\/28a\/77c4a028ab97664698d587f6db9cc345.png\"\/><\/p>\n<div><figcaption>Figure 6. Embedded error<\/figcaption><\/div>\n<\/figure>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/5b7\/b54\/dca\/5b7b54dca97320165d3c9b8ad987788b.png\" alt=\"Figure 7. Clicking OK opens the browser\" title=\"Figure 7. Clicking OK opens the browser\" width=\"1583\" height=\"868\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/5b7\/b54\/dca\/5b7b54dca97320165d3c9b8ad987788b.png\"\/><\/p>\n<div><figcaption>Figure 7. Clicking OK opens the browser<\/figcaption><\/div>\n<\/figure>\n<p>Exiting the browser is much the same as in the first scenario and can be done through the Internet Explorer Downloads page.<\/p>\n<h3>Bypassing AppLocker. First method<\/h3>\n<p>For unknown reasons, the scenario laid out in one of the virtual machines failed to work at the last moment, for which we apologize ?. The fact is, however, we noticed it too late. Hence, participants were left searching for a non-existent AppLocker bypass and found many different scenarios instead. Some say that to bypass AppLocker suffice it to obtain administrator privileges, then disable it. This is indeed one way to bypass it, but it was originally conceived that the tasks would be completed in order and task_applocker.exe would be run without administrator privileges. The laid-out scenario involved the use of\u00a0<strong>LOLBin<\/strong>\u00a0and was originally described\u00a0<a href=\"https:\/\/twitter.com\/0gtweet\/status\/1493963591745220608?cxt=HBwWgMC5lZX-z7spAAAA&amp;cn=ZmxleGlibGVfcmVjcw%3D%3D&amp;refsrc=email\">here<\/a>.<\/p>\n<p><code>wlrmdr.exe -s 3600 -f 0 -t Click me! -m To run calculator -a 10 -u C:\\task_applocker.exe<\/code><\/p>\n<p>The above command for bypassing AppLocker should have shown a notification which, when clicked, caused task_applocker.exe to start. But for some reason this did not happen, nor did the AppLocker warning appear.<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/516\/103\/00c\/51610300c62c304077e0a98228d2a329.png\" alt=\"Figure 8. The wlrmdr.exe notification (keys in the Start bar)\" title=\"Figure 8. The wlrmdr.exe notification (keys in the Start bar)\" width=\"500\" height=\"69\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/516\/103\/00c\/51610300c62c304077e0a98228d2a329.png\"\/><\/p>\n<div><figcaption>Figure 8. The wlrmdr.exe notification (keys in the Start bar)<\/figcaption><\/div>\n<\/figure>\n<h2>Bypassing AppLocker. Second method<\/h2>\n<p>As for the second AppLocker bypass, everything worked fine. The hash of the EXE file was checked using the rules, making the bypass as simple as can be (solution suggested by <strong>hx0day<\/strong>).<\/p>\n<p>We create the empty file 0.txt and execute the command copy \/b task_applocker.exe+0.txt notepad.exe, giving us the notepad.exe file \u2014 essentially a copy of task_applocker.exe with a different hash. We run it and get a ready solution.<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/19a\/961\/702\/19a961702264de872f0d8d0013ba3a27.png\" alt=\"Figure 9. Executing task_applocker.exe\" title=\"Figure 9. Executing task_applocker.exe\" width=\"448\" height=\"203\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/19a\/961\/702\/19a961702264de872f0d8d0013ba3a27.png\"\/><\/p>\n<div><figcaption>Figure 9. Executing task_applocker.exe<\/figcaption><\/div>\n<\/figure>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/8d4\/8a1\/51b\/8d48a151b2a03bc789349243a82f7060.png\" alt=\"Figure 10. AppLocker rules\" title=\"Figure 10. AppLocker rules\" width=\"528\" height=\"371\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/8d4\/8a1\/51b\/8d48a151b2a03bc789349243a82f7060.png\"\/><\/p>\n<div><figcaption>Figure 10. AppLocker rules<\/figcaption><\/div>\n<\/figure>\n<h3>Privilege escalation. First method<\/h3>\n<p>Elevating privileges was easy enough in one of the virtual machines. The scenario envisioned searching the PowerShell history. Often, administrators who use this software forget to erase the history of entered commands. The PowerShell history, in turn, is available without administrator privileges, so information left there can be exploited by hackers. In our case, in one of the virtual machines, the history contained an administrator&#8217;s username and password in cleartext. They could be found at the following path:<\/p>\n<p><code>C:\\Users\\ATM\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadline\\ConsoleHost_history.txt<\/code><\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/a72\/a62\/086\/a72a6208637d891ef337a49c147d15e8.png\" alt=\"Figure 11. Administrator's username and password in cleartext\" title=\"Figure 11. Administrator's username and password in cleartext\" width=\"1148\" height=\"978\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a72\/a62\/086\/a72a6208637d891ef337a49c147d15e8.png\"\/><\/p>\n<div><figcaption>Figure 11. Administrator&#8217;s username and password in cleartext<\/figcaption><\/div>\n<\/figure>\n<h3>Privilege escalation. Second method<\/h3>\n<p>Another (highly non-standard) way to elevate privileges was to use the runas command and look for a shortcut on the administrator&#8217;s desktop to open the command-line interpreter with full privileges. This command makes it possible to run EXE files with administrator privileges. This is because some command arguments, such as \/<strong>savecard<\/strong><em>,<\/em> allow saving the administrator&#8217;s username and password, so that applications can then be run without entering these credentials.<\/p>\n<p>r<code>unas \/user:Admin \/savecard cmd.exe<\/code><\/p>\n<p>Here, too, there are subtleties: the following command opens the console, which, as can be seen, is running as an administrator, but a closer inspection reveals that the necessary privileges are missing. At the same time, however, we are able to go to the administrator&#8217;s desktop, where we need to run a shortcut.<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/30c\/397\/799\/30c39779989c9b7fd12e1ce96d028094.png\" alt=\"Figure 12. Running the command and starting the console as an administrator\" title=\"Figure 12. Running the command and starting the console as an administrator\" width=\"515\" height=\"183\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/30c\/397\/799\/30c39779989c9b7fd12e1ce96d028094.png\"\/><\/p>\n<div><figcaption>Figure 12. Running the command and starting the console as an administrator<\/figcaption><\/div>\n<\/figure>\n<p>We try to run task_escalation.exe and see the following error:<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/a66\/af9\/c3c\/a66af9c3c0137c2c6b1c3fb983de87db.png\" alt=\"Figure 13. No administrator privileges\" title=\"Figure 13. No administrator privileges\" width=\"381\" height=\"174\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/a66\/af9\/c3c\/a66af9c3c0137c2c6b1c3fb983de87db.png\"\/><\/p>\n<div><figcaption>Figure 13. No administrator privileges<\/figcaption><\/div>\n<\/figure>\n<p>Next, we run the shortcut aministrator_cmd.lnk located at C:\\Users\\Admin\\Desktop.<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/d36\/243\/679\/d36243679b32a66def0cde2a04bbd794.png\" alt=\"Figure 14. Starting the console\" title=\"Figure 14. Starting the console\" width=\"494\" height=\"345\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d36\/243\/679\/d36243679b32a66def0cde2a04bbd794.png\"\/><\/p>\n<div><figcaption>Figure 14. Starting the console<\/figcaption><\/div>\n<\/figure>\n<p>Once that is done, we can run <strong>task_escalation.exe<\/strong> with full administrator privileges to finally complete this task.<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/38e\/4a0\/2c6\/38e4a02c6f361e2ed69d2ed93bb2fcd0.png\" alt=\"Figure 15. Running task_escalation.exe\" title=\"Figure 15. Running task_escalation.exe\" width=\"440\" height=\"203\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/38e\/4a0\/2c6\/38e4a02c6f361e2ed69d2ed93bb2fcd0.png\"\/><\/p>\n<div><figcaption>Figure 15. Running task_escalation.exe<\/figcaption><\/div>\n<\/figure>\n<h2>Additional tasks   <\/h2>\n<p>Now let&#8217;s take a look at the additional tasks. Recall that the ATM interface was a web page located at <a href=\"http:\/\/bank.paymentvillage.org\/\">http:\/\/bank.paymentvillage.org<\/a>. It is still up. The tasks are classified as additional because they are indirectly related to ATMs and involve searching for typical web vulnerabilities. For convenience and to make hacking easier, PHP errors are among the bugs.<\/p>\n<figure class=\"\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/f2a\/b83\/100\/f2ab831008f0a0438ebd0b1b3e17e760.png\" alt=\"Figure 16. PHP error\" title=\"Figure 16. PHP error\" width=\"491\" height=\"343\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/f2a\/b83\/100\/f2ab831008f0a0438ebd0b1b3e17e760.png\"\/><\/p>\n<div><figcaption>Figure 16. PHP error<\/figcaption><\/div>\n<\/figure>\n<p>Just a handful of participants tried to hack the ATM web interface, and we received reports of the scenarios laid out. The first vulnerability, found by participant vient, was Path Traversal. We happily gave them a T-shirt.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/872\/d70\/1f2\/872d701f2317b6379769ef4524750cd6.png\" alt=\"Figure 17. Source code of the Index.php page\" title=\"Figure 17. Source code of the Index.php page\" width=\"755\" height=\"371\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/872\/d70\/1f2\/872d701f2317b6379769ef4524750cd6.png\"\/><\/p>\n<div><figcaption>Figure 17. Source code of the Index.php page<\/figcaption><\/div>\n<\/figure>\n<p><code>curl --path-as-is http:\/\/bank.paymentvillage.org\/favicon.ico\/..\/index.php<\/code><\/p>\n<p>The above command had to be run to view the source code.<\/p>\n<p>By the way, the error shown in Figure 16 pointed to another inherent vulnerability, but, unfortunately, none of the participants found it. The thing is that the Delphi-based ATM code constantly read the file \u0421:\\Atm\\atmkey.txt. This file contained atmkey, a unique ATM identifier that enabled us to monitor task execution. Next, atmkey was inserted automatically into every request in the form of an ATM header, and was used for authorization in the ATM. This header is needed, among other things, for dispensing money at the relevant ATM (virtual machine). This made it possible to exploit self-xss by passing malicious JS code in the ATM header.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/d0f\/bd6\/5b7\/d0fbd65b761028b7005bb0e8d5024a1d.png\" alt=\"Figure 18. Sending a request\" title=\"Figure 18. Sending a request\" width=\"686\" height=\"226\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/d0f\/bd6\/5b7\/d0fbd65b761028b7005bb0e8d5024a1d.png\"\/><\/p>\n<div><figcaption>Figure 18. Sending a request<\/figcaption><\/div>\n<\/figure>\n<p>No one discovered the next vulnerability either, although they could have simply by changing the contents of the file C:\\Atm\\atmkey.txt. It was not even necessary to use tools for MITM attacks. Here&#8217;s how it looks:<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/22f\/ddb\/f20\/22fddbf20a67d9c9472625cb6b3fa75c.png\" alt=\"Figure 19. XSS exploitation\" title=\"Figure 19. XSS exploitation\" width=\"564\" height=\"516\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/22f\/ddb\/f20\/22fddbf20a67d9c9472625cb6b3fa75c.png\"\/><\/p>\n<div><figcaption>Figure 19. XSS exploitation<\/figcaption><\/div>\n<\/figure>\n<p>This year&#8217;s scenarios also included ARP spoofing, which we will not analyze in depth, since an example of such an attack has already been <a href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/579516\/?\">described.<\/a>\u00a0Basically, participants had to fake the response <a href=\"http:\/\/bank.paymentvillage.org\/payout?atmid=%3cyour_atm_id\">http:\/\/bank.paymentvillage.org\/payout?atmid=&lt;your_atm_id<\/a>> to get the application C:\\Atm\\payout.exe to run on the second virtual machine, simulating a cash withdrawal. The ATM queries this address every five seconds and waits for the response &#171;true&#187; before dispensing money.<\/p>\n<p>There are, of course, vulnerabilities in the scenarios that are best kept secret so as not to kill the intrigue.<\/p>\n<h2>Conclusion<\/h2>\n<p>This year&#8217;s scenarios turned out to be very simple for the participants. Many came well prepared.    <\/p>\n<p>We understand the need to strike the right balance as regards complexity, and have put together a set of takeaways for implementation next year. At the same time, many participants failed to grasp the true scale of the contest and completed only the main tasks.<\/p>\n<p>Certificates were sent to the participants, and the first feedback is already in. We hope all prizes have been received by the time this post is published. One of the participants (thanks for the feedback, <strong>durcm<\/strong>!) agreed to let us publish a photo of their certificate.<\/p>\n<figure class=\"full-width\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/habrastorage.org\/r\/w1560\/getpro\/habr\/upload_files\/c65\/efc\/bc3\/c65efcbc3e2b169d5caa33aa327453a0.png\" width=\"717\" height=\"1060\" data-src=\"https:\/\/habrastorage.org\/getpro\/habr\/upload_files\/c65\/efc\/bc3\/c65efcbc3e2b169d5caa33aa327453a0.png\"\/><\/figure>\n<p>Lastly, a huge thank-you goes out to all our international participants, in particular Boschko. For several years now, he has been sharing walkthroughs of our VMs with his readers:<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/boschko.ca\/atm-kiosk-hacking-labs\/\">ATM\/Kiosk Hacking<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/boschko.ca\/atm-kiosk-hacking-phd2022\/\">ATM\/Kiosk Hacking (Reloaded)<\/a><\/p>\n<\/li>\n<\/ul>\n<p>Find more information about Payment Village in\u00a0<a href=\"https:\/\/t.me\/paymentvillage\">Telegram<\/a>. See you soon! \ud83d\ude42<\/p>\n<p>Author: @yurasikhacker<\/p>\n<\/p>\n<\/div>\n<\/div>\n<\/div>\n<p><!----><!----><\/div>\n<p><!----><!----><br \/> \u0441\u0441\u044b\u043b\u043a\u0430 \u043d\u0430 \u043e\u0440\u0438\u0433\u0438\u043d\u0430\u043b \u0441\u0442\u0430\u0442\u044c\u0438 <a href=\"https:\/\/habr.com\/ru\/articles\/688372\/\"> https:\/\/habr.com\/ru\/articles\/688372\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div><!--[--><!--]--><\/div>\n<div id=\"post-content-body\">\n<div>\n<div class=\"article-formatted-body article-formatted-body article-formatted-body_version-2\">\n<div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\">\n<figure class=\"full-width\"><\/figure>\n<p>The\u00a0<a href=\"https:\/\/www.phdays.com\/en\/press\/news\/phdays-11-wrap-up-interest-in-information-security-explodes-rutube-attack-investigated-pipeline-shutdown-demo\/\">Positive Hack Days 11 forum<\/a>, which took place May 18\u201319, 2022, was truly epic. The bitterly fought ATM hacking contest featured no fewer than 49 participants. How cool is that? The winner of this year&#8217;s prize fund of 50,000 rubles, with the handle Igor, was the first to hack the virtual machines. And they weren&#8217;t even at the event! \ud83d\ude42<\/p>\n<p>Besides Igor, eight other participants picked up prizes this year for their VM-hacking skills. They were:\u00a0<strong>drd0c<\/strong>,\u00a0<strong>vient<\/strong>,\u00a0<strong>vrazov<\/strong>,\u00a0<strong>durcm<\/strong>,\u00a0<strong>zxcvcxzas7<\/strong>,\u00a0<strong>asg_krd<\/strong>,\u00a0<strong>hundred303<\/strong>, and\u00a0<strong>drink_more_water_dude<\/strong>. A big thank-you to everyone who took part, and for those who weren&#8217;t at PHDays, here are the links to the virtual machines:<\/p>\n<ul>\n<li>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/10wDbWri0wfjH8Azy5FH-dNo6NPd8UkDg\">ATM1<\/a><\/p>\n<\/li>\n<li>\n<p><a href=\"https:\/\/drive.google.com\/file\/d\/1ILV5t5nmL9dHcieEgLjJovbH1N1SS7uS\">ATM2<\/a><\/p>\n<\/li>\n<\/ul>\n<figure class=\"full-width\">\n<div><figcaption>Figure 1. ATM interface<\/figcaption><\/div>\n<\/figure>\n<p>As for the tasks, they were identical for the two different virtual machines:<\/p>\n<ol>\n<li>\n<p>Kiosk bypass (solved 34 times)<\/p>\n<\/li>\n<li>\n<p>Windows AppLocker bypass (solved 21 times)<\/p>\n<\/li>\n<li>\n<p>Privilege escalation to the Administrator (solved 12 times)<\/p>\n<\/li>\n<\/ol>\n<p>On the C drive were three files:\u00a0<strong>task_kiosk.exe<\/strong>,\u00a0<strong>task_applocker.exe<\/strong>, and\u00a0<strong>task_escalation.exe<\/strong>, which had to be run to make the task count. <strong>task_kiosk.exe<\/strong> could be run immediately after bypassing the kiosk; <strong>task_applocker.exe<\/strong> was blocked using AppLocker; task_escalation.exe required administrator privileges to run.<\/p>\n<p>This year&#8217;s architectural solutions allowed us to track the number of participants and solved tasks through a Telegram bot, thus providing more detailed statistics (Figure 2).<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 2. Total number of participants<\/figcaption><\/div>\n<\/figure>\n<h2>Task analysis<\/h2>\n<p>We should note that participants this year had much greater scope for activity, and each task on the virtual machine had a large number of solutions. Last year, it took participants a long time to bypass the kiosk, and some simply gave up before completion. This year&#8217;s changes brought results, delivering some interesting solutions that were not envisioned in the original scenario.<\/p>\n<p>Below is an overview of the solutions in <strong>general terms, without reference to specific virtual machines<\/strong>. It will be obvious to participants which solution fits which machine. This is to allow interested readers to solve the tasks for themselves, should they wish to.<\/p>\n<h3>Kiosk bypass. First method<\/h3>\n<p>Many had no idea how simple it was. To kiosk bypass in one of the virtual machines, they had to use the right mouse button. Surprisingly, participants did not notice that the right mouse button was working and, like last year, tried to find keyboard shortcuts to exit kiosk mode. The kiosk application was a web browser written in Delphi, so the complete kiosk bypass scenario was as follows: right-click \u2192 Print \u2192 Find Printer (Figure 3).<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 3. Right-click menu<\/figcaption><\/div>\n<\/figure>\n<p>     These actions made it possible to open explorer.exe and go to the C drive to run <strong>task_kiosk.exe<\/strong>.<\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 4. Executing the first task<\/figcaption><\/div>\n<\/figure>\n<h3>Kiosk bypass. Second method<\/h3>\n<p>Things were a bit tricker in the other virtual machine because the right mouse button was disabled, as were the main keys. To exit kiosk mode, a network vector was laid out that required scanning of the ATM ports. After scanning the ports with Nmap, participants may have noticed some kind of service on port 80. The easiest way to find out what was running there was to follow the link <a href=\"http:\/\/atm_adress\/\">http:\/\/&lt;atm_adress>:80<\/a>. There on port 80, it turned out to be a web server specially written for the contest. Every time a user connected to it, it threw an error and opened a browser help page on the virtual machine.<\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 5. Demonstrating the Nmap interface<\/figcaption><\/div>\n<\/figure>\n<p>In this case, the ATM&#8217;s IP was 192.168.56.102, and scanning Nmap showed that port 80 was open. After navigating to that address in the browser, an error appeared, whereupon clicking the OK button opened the Internet Explorer browser.<\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 6. Embedded error<\/figcaption><\/div>\n<\/figure>\n<figure class=\"full-width\">\n<div><figcaption>Figure 7. Clicking OK opens the browser<\/figcaption><\/div>\n<\/figure>\n<p>Exiting the browser is much the same as in the first scenario and can be done through the Internet Explorer Downloads page.<\/p>\n<h3>Bypassing AppLocker. First method<\/h3>\n<p>For unknown reasons, the scenario laid out in one of the virtual machines failed to work at the last moment, for which we apologize ?. The fact is, however, we noticed it too late. Hence, participants were left searching for a non-existent AppLocker bypass and found many different scenarios instead. Some say that to bypass AppLocker suffice it to obtain administrator privileges, then disable it. This is indeed one way to bypass it, but it was originally conceived that the tasks would be completed in order and task_applocker.exe would be run without administrator privileges. The laid-out scenario involved the use of\u00a0<strong>LOLBin<\/strong>\u00a0and was originally described\u00a0<a href=\"https:\/\/twitter.com\/0gtweet\/status\/1493963591745220608?cxt=HBwWgMC5lZX-z7spAAAA&amp;cn=ZmxleGlibGVfcmVjcw%3D%3D&amp;refsrc=email\">here<\/a>.<\/p>\n<p><code>wlrmdr.exe -s 3600 -f 0 -t Click me! -m To run calculator -a 10 -u C:\\task_applocker.exe<\/code><\/p>\n<p>The above command for bypassing AppLocker should have shown a notification which, when clicked, caused task_applocker.exe to start. But for some reason this did not happen, nor did the AppLocker warning appear.<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 8. The wlrmdr.exe notification (keys in the Start bar)<\/figcaption><\/div>\n<\/figure>\n<h2>Bypassing AppLocker. Second method<\/h2>\n<p>As for the second AppLocker bypass, everything worked fine. The hash of the EXE file was checked using the rules, making the bypass as simple as can be (solution suggested by <strong>hx0day<\/strong>).<\/p>\n<p>We create the empty file 0.txt and execute the command copy \/b task_applocker.exe+0.txt notepad.exe, giving us the notepad.exe file \u2014 essentially a copy of task_applocker.exe with a different hash. We run it and get a ready solution.<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 9. Executing task_applocker.exe<\/figcaption><\/div>\n<\/figure>\n<figure class=\"full-width\">\n<div><figcaption>Figure 10. AppLocker rules<\/figcaption><\/div>\n<\/figure>\n<h3>Privilege escalation. First method<\/h3>\n<p>Elevating privileges was easy enough in one of the virtual machines. The scenario envisioned searching the PowerShell history. Often, administrators who use this software forget to erase the history of entered commands. The PowerShell history, in turn, is available without administrator privileges, so information left there can be exploited by hackers. In our case, in one of the virtual machines, the history contained an administrator&#8217;s username and password in cleartext. They could be found at the following path:<\/p>\n<p><code>C:\\Users\\ATM\\AppData\\Roaming\\Microsoft\\Windows\\PowerShell\\PSReadline\\ConsoleHost_history.txt<\/code><\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 11. Administrator&#8217;s username and password in cleartext<\/figcaption><\/div>\n<\/figure>\n<h3>Privilege escalation. Second method<\/h3>\n<p>Another (highly non-standard) way to elevate privileges was to use the runas command and look for a shortcut on the administrator&#8217;s desktop to open the command-line interpreter with full privileges. This command makes it possible to run EXE files with administrator privileges. This is because some command arguments, such as \/<strong>savecard<\/strong><em>,<\/em> allow saving the administrator&#8217;s username and password, so that applications can then be run without entering these credentials.<\/p>\n<p>r<code>unas \/user:Admin \/savecard cmd.exe<\/code><\/p>\n<p>Here, too, there are subtleties: the following command opens the console, which, as can be seen, is running as an administrator, but a closer inspection reveals that the necessary privileges are missing. At the same time, however, we are able to go to the administrator&#8217;s desktop, where we need to run a shortcut.<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 12. Running the command and starting the console as an administrator<\/figcaption><\/div>\n<\/figure>\n<p>We try to run task_escalation.exe and see the following error:<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 13. No administrator privileges<\/figcaption><\/div>\n<\/figure>\n<p>Next, we run the shortcut aministrator_cmd.lnk located at C:\\Users\\Admin\\Desktop.<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 14. Starting the console<\/figcaption><\/div>\n<\/figure>\n<p>Once that is done, we can run <strong>task_escalation.exe<\/strong> with full administrator privileges to finally complete this task.<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 15. Running task_escalation.exe<\/figcaption><\/div>\n<\/figure>\n<h2>Additional tasks   <\/h2>\n<p>Now let&#8217;s take a look at the additional tasks. Recall that the ATM interface was a web page located at <a href=\"http:\/\/bank.paymentvillage.org\/\">http:\/\/bank.paymentvillage.org<\/a>. It is still up. The tasks are classified as additional because they are indirectly related to ATMs and involve searching for typical web vulnerabilities. For convenience and to make hacking easier, PHP errors are among the bugs.<\/p>\n<figure class=\"\">\n<div><figcaption>Figure 16. PHP error<\/figcaption><\/div>\n<\/figure>\n<p>Just a handful of participants tried to hack the ATM web interface, and we received reports of the scenarios laid out. The first vulnerability, found by participant vient, was Path Traversal. We happily gave them a T-shirt.<\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 17. Source code of the Index.php page<\/figcaption><\/div>\n<\/figure>\n<p><code>curl --path-as-is http:\/\/bank.paymentvillage.org\/favicon.ico\/..\/index.php<\/code><\/p>\n<p>The above command had to be run to view the source code.<\/p>\n<p>By the way, the error shown in Figure 16 pointed to another inherent vulnerability, but, unfortunately, none of the participants found it. The thing is that the Delphi-based ATM code constantly read the file \u0421:\\Atm\\atmkey.txt. This file contained atmkey, a unique ATM identifier that enabled us to monitor task execution. Next, atmkey was inserted automatically into every request in the form of an ATM header, and was used for authorization in the ATM. This header is needed, among other things, for dispensing money at the relevant ATM (virtual machine). This made it possible to exploit self-xss by passing malicious JS code in the ATM header.<\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 18. Sending a request<\/figcaption><\/div>\n<\/figure>\n<p>No one discovered the next vulnerability either, although they could have simply by changing the contents of the file C:\\Atm\\atmkey.txt. It was not even necessary to use tools for MITM attacks. Here&#8217;s how it looks:<\/p>\n<figure class=\"full-width\">\n<div><figcaption>Figure 19. XSS exploitation<\/figcaption><\/div>\n<\/figure>\n<p>This year&#8217;s scenarios also included ARP spoofing, which we will not analyze in depth, since an example of such an attack has already been <a href=\"https:\/\/habr.com\/ru\/company\/pt\/blog\/579516\/?\">described.<\/a>\u00a0Basically, participants had to fake the response <a href=\"http:\/\/bank.paymentvillage.org\/payout?atmid=%3cyour_atm_id\">http:\/\/bank.paymentvillage.org\/payout?atmid=&lt;your_atm_id<\/a>> to get the application C:\\Atm\\payout.exe to run on the second virtual machine, simulating a cash withdrawal. The ATM queries this address every five seconds and waits for the response &#171;true&#187; before dispensing money.<\/p>\n<p>There are, of course, vulnerabilities in the scenarios that are best kept secret so as not to kill the intrigue.<\/p>\n<h2>Conclusion<\/h2>\n<p>This year&#8217;s scenarios turned out to be very simple for the participants. Many came well prepared.    <\/p>\n<p>We understand the need to strike the right balance as regards complexity, and have put together a set of takeaways for implementation next year. At the same time, many participants failed to grasp the true<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-384286","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/384286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=384286"}],"version-history":[{"count":0,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=\/wp\/v2\/posts\/384286\/revisions"}],"wp:attachment":[{"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=384286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=384286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/savepearlharbor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=384286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}