Insid3Code Posted March 29, 2015 Posted March 29, 2015 Defeating Windows User Account Control from kernelmode.info.Defeating Windows User Account Control by abusing built-in Windows AutoElevate backdoor.http://www.kernelmode.info/forum/viewtopic.php?f=11&t=3643 System Requirementsx86-32/x64 Windows 7/8/8.1/10.Admin account with UAC set on default settings required.UsageRun executable from command line with following keys (watch debug ouput with dbgview or similar for more info):1 - Leo Davidson sysprep method, this will work only on Windows 7 and Windows 8, used in multiple malware;2 - Tweaked Leo Davidson sysprep method, this will work only on Windows 8.1;3 - Leo Davidson method tweaked by WinNT/Pitou developers, works from Windows 7 up to Windows 10 b10041;4 - Application Compatibility Shim RedirectEXE method, from WinNT/Gootkit. Works from Windows 7 up to Windows 8.1;5 - ISecurityEditor WinNT/Simda method, used to turn off UAC, works from Windows 7 up to Windows 10 b10041.6 - Wusa method used by Win32/Carberp, tweaked to work with Windows 8/8.1 also.Note:Methods (1), (2), (3), (5) require process injection, so they won't work from wow64, you need either Heavens gate or use x64 edition of this tool;Method (4) unavailable in 64 bit edition because of Shim restriction.Method (6) unavailable in wow64 environment starting from Windows 8. Also target application absent in recent Windows 10 TP 10041 build.Run examples:akagi32.exe 1akagi64.exe 3WarningUsing (5) method will permanently turn off UAC (after reboot), make sure to do this in test environment or don't forget to re-enable UAC after tool usage;This tool is not intended for AV tests and not tested to work in aggressive AV environment, if you still plan to use it with installed bloatware AV soft - you use it at your own risk.ProtectionUAC turned on maximum level and full awareness about every window it will show;Account without administrative privileges.BuildUACMe comes with full source code, written in C.In order to build from source you need Microsoft Visual Studio 2013 U4 and later versions.Authors© 2014 - 2015 UACMe Projecthttps://github.com/hfiref0x/UACME
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now