Spartacus DLL/COM 入侵工具包
[!CAUTION] This repo is unmaintained, visit https://github.com/sadreck/Spartacus for the latest version.
If you have seen the film Spartacus from 1960, you will remember the scene where the Romans are asking for Spartacus to give himself up. The moment the real Spartacus stood up, a lot of others stood up as well and claimed to be him using the "I AM SPARTACUS" phrase.
When a process that is vulnerable to DLL Hijacking is asking for a DLL to be loaded, it's kind of asking "WHO IS VERSION.DLL?" and random directories start claiming "I AM VERSION.DLL" and "NO, I AM VERSION.DLL". And thus, Spartacus.
DllMain. This technique was inspired and implemented from the walkthrough described at https://www.redteam.cafe/red-team/dll-sideloading/dll-sideloading-not-by-dllmain, by Shantanu Khandelwal.[Defence] Monitoring mode trying to identify running applications proxying calls, as in "DLL Hijacking in progress". This is just to get any low hanging fruit and should not be relied upon.Find and download the latest version of Spartacus under Releases. Otherwise simply clone this repository and build from source.
Below is a description of each of the modes that Spartacus supports.
Note: Command line arguments have significantly changed from v1 to v2.
The original functionality of Spartacus was solely finding DLL hijacking vulnerabilities. The way it works is:
CreateFile..dll.procmon.exe or procmon64.exe.Drop Filtered Events to ensure minimum PML output size.Auto Scroll.ENTER.ENTER.Collect all events and save them into C:\Data\logs.pml. All vulnerable DLLs will be saved as C:\Data\VulnerableDLLFiles.csv and all proxy DLLs solutions in C:\Data\Solutions.
--mode dll --procmon C:\SysInternals\Procmon.exe --pml C:\Data\logs.pml --csv C:\Data\VulnerableDLLFiles.csv --solution C:\Data\Solutions --verbose
Parse an existing PML event log output, save output to CSV, and generate proxy Visual Studio solutions.
--mode dll --existing --pml C:\MyData\SomeBackup.pml --csv C:\Data\VulnerableDLLFiles.csv --solution C:\Data\Solutions --verbose
A new functionality of Spartacus is to identify local COM hijacking vulnerabilities. The way it works is:
RegOpenKey.procmon.exe or procmon64.exe.Drop Filtered Events to ensure minimum PML output size.Auto Scroll.ENTER.ENTER.InprocServer32 and its result is NAME_NOT_FOUND.HKEY_CURRENT_USER, search for its GUID under HKEY_CLASSES_ROOT and include its details in the export CSV (if found).proxy mode.For COM hijacking Spartacus also supports scanning the local system for misconfigured COM entries:
HKEY_CLASSES_ROOT, HKEY_CURRENT_USER, and HKEY_LOCAL_MACHINE.InProcServer, InProcServer32, LocalServer, or LocalServer32.Collect all events and save them into C:\Data\logs.pml. All vulnerable COM information will be saved as C:\Data\VulnerableCOM.csv.
--mode com --procmon C:\SysInternals\Procmon.exe --pml C:\Data\logs.pml --csv C:\Data\VulnerableCOM.csv --verbose
Process an existing PML file to identify vulnerable COM entries.
--mode com --existing --pml C:\Data\logs.pml --csv C:\Data\VulnerableCOM.csv --verbose
Enumerate the local system registry to identify missing/misconfigured COM libraries and executables.
--mode com --acl --csv C:\Data\VulnerableCOM.csv --verbose
Spartacus supports generating Visual Studio solutions by creating skeleton projects for you to use, based on the DLL you wish to exploit.
DllMain function.DllMain.version.dll you could run your implant from GetFileVersionInfoExW if that function is called by the vulnerable application.Generate a solution that redirects all exports (no function proxying).
--mode proxy --dll C:\Windows\System32\version.dll --solution "C:\data\tmp\refactor-version" --overwrite --verbose --external-resources
It is possible to input multiple DLLs at once.
--mode proxy --dll C:\Windows\System32\version.dll --dll C:\Windows\System32\\userenv.dll --solution "C:\data\tmp\dll-collection" --overwrite --verbose --external-resources
Create proxies for as many functions as possible (based on Ghidra's output).
--mode proxy --ghidra C:\ghidra\support\analyzeHeadless.bat --dll C:\Windows\System32\\userenv.dll --solution C:\Projects\spartacus-userenv --overwrite --verbose
Same as above, but use external asset files to generate the solution (if you need to modify them).
--mode proxy --ghidra C:\ghidra\support\analyzeHeadless.bat --dll C:\Windows\System32\\userenv.dll --solution C:\Projects\spartacus-userenv --overwrite --verbose --external-resources
Utilise pre-generated function prototypes for functions which Ghidra was unable to extract function definitions for.
--mode proxy --ghidra C:\ghidra\support\analyzeHeadless.bat --dll C:\Windows\System32\\userenv.dll --solution C:\Projects\spartacus-userenv --overwrite --verbose --external-resources --prototypes C:\data\prototypes.csv
Generate proxies only for functions GetFileVersionInfoExW and GetFileVersionInfoExA.
--mode proxy --ghidra C:\ghidra\support\analyzeHeadless.bat --dll C:\Windows\System32\version.dll --solution C:\Projects\spartacus-version --verbose --overwrite --external-resources --only "GetFileVersionInfoExW, GetFileVersionInfoExA"
Generate a function prototype database from existing *.h files, assisting in generating proxy functions for ones that Ghidra was not able to extract its function definition.
--mode proxy --action prototypes --path "C:\Program Files (x86)\Windows Kits" --csv C:\data\prototypes.csv --verbose
List DLL's exports and check if each function has a pre-generated prototype.
--mode proxy --action exports --dll C:\Windows\System32\version.dll --dll C:\Windows\System32\amsi.dll --prototypes ./Assets/prototypes.csv
Spartacus now supports generating self-signed certificates (while copying attributes from existing files), and signing DLL files.
Create a signing certificate, using properties from C:\Windows\System32\version.dll (has to be signed DLL).
--mode sign --action generate --pfx "C:\Output\certificate.pfx" --password "Welcome1" --not-before "2022-12-31 00:00:55" --not-after "2026-01-01 00:00:01" --copy-from C:\Windows\System32\version.dll --verbose
Sign a DLL using an existing/generated certificate.
--mode sign --action sign --pfx "C:\Output\certificate.pfx" --password "Welcome1" --path "C:\Input\MyFakeVersion.dll" --algorithm SHA256 --verbose
Spartacus also has a --detect mode, which tries to identify active DLL proxying. The logic behind it is:
To use this feature, simply run Spartacus with --detect.
Spartacus supports the --sign mode which allows you to both generate self-signed certificates, but also sign compiled DLLs with them.
Generate a self-signed certificate, copying the Issuer/Subject from an existing file:
--mode sign --action generate --pfx "C:\Output\myCertificate.pfx" --password "Welcome1" --not-before "2023-01-01 00:00:04" --not-after "2025-01-01 00:00:42" --copy-from C:\Windows\System32\version.dll --verbose
And use that certificate to sign your compiled file:
--mode sign --action sign -
暂无开放 Issues,或尚未同步最近议题。