Ring0VBA – Getting Ring0 Using a Word Document
disrel.com
disrel.com
He mentions his community on:
https://www.vx-underground.org/
Cool papers, code snippets, nice to spend some time on. Nice gimmik with the banner.
Not only does it require a vulnerable niche driver to be installed, it also requires the user to enable VBA macros on a document of unknown provenance, which everyone by now should know is the digital equivalent of licking the floor of a public bathroom.
In fact, how is "Getting Ring0" even relevant once you're running untrusted code on Windows where in 98% of all cases (and 100% when we're talking about opening Word Documents) there is exactly one user who can access everything interesting on the system?
https://web.dev/usb/#get-access-to-usb-devices
However I suppose that the mere existence of this API means that there could be a way to bypass the request; The browser already does have full access to every device.
I've used a web page to run ADB commands to quickly debloat my phone, so I don't see why fastboot support wouldn't work.
There's even a tool to flash your Android phone through the browser (https://pixelrepair.withgoogle.com/ I believe). Adding "automated LineageOS installer through WebUSB" to my infinitely growing to-do list :)
Do you know of any specific risks when flashing devices w/ WebUSB as opposed to the 'normal' way?
With non-Google devices... these might run into problems when the device expects a certain response latency or minimum bandwidth. YMMV I'd say.
And at that point you can proceed with the same kinds of kernel/driver exploits.
I am not trying to downplay it, it's still a privilege escalation. But is triggering it via Word macros in any way special?
edit:
At my work computer, the setting is "disable all macros with notification". I suspect, but I am not sure that this is the default for a fresh Office install.
With this setting running macros on a random Word document is not much different than running a random .exe file. Of course, privilege escalation is equally serious in both cases.
Group policy can be used to explicitly deny or globally permit. I believe there's also the ability to cryptographically sign macros if required.
Basically, a multi-stage hack:
1) Get RCE on an user's computer in some way (e.g. via a browser exploit chain, yet another exploit in a public reachable Citrix instance, tech support scam)
2) Scan the MRU lists of all users for Excel files on network drives, Onedrive, Dropbox and other common share tools
3) Once the files become accessible (e.g. because the user connected to the VPN), open each file and check if it has macros. If yes, inject spreader payload (e.g. a credential stealer, a miner or a crypter). If no, continue to the next file.
4) Other users now open these Excel files, execute the macros because they expect to be asked that question, and now the payload executes.
I believe there are best practices for office computer security policy.
Using an anti-malware piece of software as a stepping stone to get Ring0 is beyond irony.
I wish for a world where the general public were able to consider all software as malware by default, unless it has been proven "moreless safe" by at least three independent security audits paid with public money.
If you think about it: not really. "Anti-malware" software often uses rootkit technologies to do "its job". In turn it gets handed the keys to the kingdom to do "everything".
Yes, what we need is more roadblocks in there, to ensure software that has captured large segments of their respective markets remain entrenched and make it harder for new developers and projects to dethrone them while giving the government (of which country?) control over what software people can run - no way this will be abused at all X-P.
I think there's room for regulation and forced audits. The important part is that the compliance costs are small compared to development and production costs. That's true in the car industry unless you have really low volume, while airplanes are pushed over the threshold by much lower volume and much higher regulation.
Meanwhile, i don't think i should have to ask permission from the government to make something like, e.g. a map editing tool for a 90s fps, like i did yesterday[0] (the tool, not requesting permission) or a sprite editor[1] or a quick-and-dirty wiki server to take notes in games[2]. Or really anything that doesn't have to do with areas where lives are at stake (which AFAIK is already being done anyway with programs needing to pass conformance tests - something i'm perfectly fine with, at least in theory, as i don't know in practice if these tests really work or are designed to help existing actors stay entrenched).
[0] http://runtimeterror.com/tools/chasmfe/
And again, the original comment above is not "ask permission from the government" but instead "pass independent security audits by neutral auditors before exposing your software to the general public."
> independent security audits paid with public money
The "with public money" part means they are funded and thus controlled by the government.
Not that i think a privately owned megacorp is much better, after all i do not like the scare boxes you see on unsigned (and "lesser signed") programs in Windows and macOS unless you pay the certificate mafia protection money - but at least those do not block you completely.
Daily fines proportional to installed user base, on the basis of confirmed and not yet fixed CVEs. Amount inversely proportional to price of per-user software license (ie. the cheaper the gadget, the heavier the fines). Exception for AGPL-compatible licenses.
Incentives and credits for smaller companies' training and audits. Funded by fines above.
Incentives and credits for companies fixing CVEs on AGPL-compatible software. Funded also by fines above. Amount of incentives proportional to installed user base and severity of CVE.
Audit practices defined by group of international bodies.
What have OpenBSD developers done to you? :-P
I can literally dope silicon and make my own chips, but even I have to trust "the system" to buy food and shelter, etc.
You can draw a line from the invention of the transistor to the eventual necessity of solving the ultimate human problem: how do we get along with each other?
How so? The best usable homemade transistor project that I’m aware of, consisted of something on the order of 100 amplifiers/transistors on a chip. And even then, the author had access to professionally made silicon wafers, and likely a whole lot of expensive/dangerous chemicals and equipment. This is very far outside the realm of a casual hacker.
Making even the simplest 6502 equivalent by yourself is impossible, forget more complex projects. I feel like this should be urgently addressed, given how important computing is.
Sam Zeloof is doing great things: http://sam.zeloof.xyz/
> Making even the simplest 6502 equivalent by yourself is impossible, forget more complex projects. I feel like this should be urgently addressed, given how important computing is.
I've thought about this, more in the context of post-apocalyptic computing rather than trust, FWIW.
If I were really going to make my own computers from scratch I think clockwork (Clock of the Long Now) or fluidics would probably be the way to go. Maybe electro-mechanical (relays, etc.) or vacuum tubes? We did pretty well with the abacus and the slide rule, eh?
> I've thought about this, more in the context of post-apocalyptic computing rather than trust, FWIW.
Post-apocalyptic computing is one possible motivation to look at this, but other reduced-tech settings like a fully independent Mars colony also simply cannot function without a way to fab simple IC logic. That, or we’re happy to go back to early Apollo era tech levels.
RE: computers from scratch in the absence of IC fabrication. I think our best chance is vacuum tubes. Mechanical relay computers seem to have been phased out in favour of vacuum tube solutions pretty quickly, so I guess there must have been some compelling reasons to do so (my guess - speed and failure rate of individual switching components). Couple that with old-school electromechanical tech for IO/industrial sequencing, several K of delay line/core/Williams Tube memory, and you’re golden.
The exploit suddenly looks much less impressive if it relies on the user having installed something like that.
The truth of the matter is that if you are local admin you can already ruin the system in many ways. Once you are admin the game is already over.
Whose fault is it?
Clearly not
If I could wish a world into existence, I would choose one where all criminals disappeared in a puff of smoke, letting the rest of us enjoy a key-less password-less worry-free life.
No, personal responsibility and community trust is infinitely preferable to corporate authoritarianism.
Microsoft would need to blacklist the known vulnerable drivers to solve this problem, but then devices will stop working.
List of vulnerable drivers: https://github.com/eclypsium/Screwed-Drivers/blob/master/DRI...
Or are you implying that Linux is immune to this? Because it's not. This is equivalent to running a bash script downloaded from internet with root privileges and then writing that you pwned Linux. Remember, VBA IS!!! a programming language, having the same access as any other programming language (tied to your user).
Now if this guy would've ran this macro using a normal user and then the computer would've been pwned, now that's a privilege escalation.
Macros were another billion dollar mistake: https://www.zdnet.com/article/the-cost-of-ransomware-around-...
So even if we say that Office Macros were responsible for half of all ransomware infections, I'm not convinced the world economy doesn't benefit more than $20 billion per year from Office Macros. Many businesses basically run on macro-enhanced Excel spreadsheets.
It could retrieve work from a server to start long running processes that mine cryptocurrency. And scan every IP/port on your local network and use metasploit to send matching exploits to everything it sees. And then hijack a local process running under a different user with disk write permissions.
I would like to see macros restricted similar to Javascript in the browser. You can still run code and manipulate local data, but you don't get any direct access to the host OS. No disk access, no registry access, no way to create a process, only able to calculate things and change the document itself. And there must be no checkbox to disable these protections.
1- For network privileges you can restrict user to strict network location and nothing else.
2 - For scanning it also needs privileges that can be restricted using policies.
3 - Can't send anything if it doesn't have the correct privileges.
Who's stopping you to create your own version of VBA, release it and replace Microsoft Office suite with your own defined version as you said. And in the process of doing this you'll become billionaire too.
Until then, a correctly configured Windows system is immune to all of the above.
>Who's stopping you to create your own version of VBA, release it and replace Microsoft Office suite with your own defined version as you said.
I'm stopping myself because nobody would use it :)
And of course, you have not only device drivers, but also "drivers" for various other capabilities, some of which Linux doesn't have at all. Anti-malware tools started off in the 90s by using drivers to just hotpatch kernel functions, until Microsoft made official APIs for the desired capabilities and started putting defensive measures against code modification into the kernel.
Given that most drivers are software written by hardware companies and, as soon as the device is sold, are just a liability, is this really going to be a huge barrier? How often do drivers get updated, say 1 or 2 years post release?
Same thing as many non-subscription wireless routers.
Sure, they can unilaterally kill any software on their platform, it's perhaps an important thing to note about it and other platforms where this is true. (Answering questions of ownership and user rights that inherently arise from this and other similar facts are left as an exercise to the reader). However, that also comes at the cost of disabling the hardware that the driver serves, at least until it's fixed.
I've had to use VBA many times to work around abhorrent user controls that prevented work from being done.
VBA seems like it, but there is a HUGE amount of negative externalities that are never accounted for when people talk about how great VBA is for business
In some ways it is like CO2 Emissions on Climate change. You enjoy the benefits today of VBA but the technical debt and other externalities cost the business far more in the future
Use an OS with Admin/root privileges and then complaining why you can pwn said computer is stupidity, isn't it?