WINDOWS XP - REMOTE ALTERATION OF FILE CONTENT AND MAC TIMESTAMPS
- Layout for this exercise:
data:image/s3,"s3://crabby-images/3484d/3484df974f1213d8b1058be64c78560141e83d62" alt=""
- One of the interesting post exploitation attacks that Meterpreter can help to perform is altering content and MAC (Modified - Accessed - Created) timestamp of files on the victim's machine.
- Let's create a new folder called HELLO on the victim:
data:image/s3,"s3://crabby-images/a3f63/a3f63c451588f785371596476bbbf7ace73e8605" alt=""
- Moving inside the folder:
data:image/s3,"s3://crabby-images/30f94/30f94a866aeff441e60b03d4f18acb68fb10f04a" alt=""
- Meterpreter execute command runs diverse actions, for instance cmd.exe, which spawns a remote shell:
data:image/s3,"s3://crabby-images/9c60a/9c60a03d3731ba317d708908aea8746aa030f54a" alt=""
data:image/s3,"s3://crabby-images/780d8/780d8fe81cfca1065be786457ff30583bd75a2a4" alt=""
- A new text file is created inside that folder, and some content is added:
data:image/s3,"s3://crabby-images/939ad/939ad93db665a662841fc49dcb4c6929b03b20fc" alt=""
- Checking the existence and content of the new text file on the victim :
data:image/s3,"s3://crabby-images/bdf87/bdf87b5986df5f60ffc689c84e9371909d331768" alt=""
- Exiting the cmd on Meterpreter:
data:image/s3,"s3://crabby-images/650d4/650d4929e701fe2c6e457f0a68e7688801b521f4" alt=""
- The text file is downloaded on the attacker's side to be altered:
data:image/s3,"s3://crabby-images/c8180/c8180fd4c5cd2a797041e41bef8c46756c6dc509" alt=""
- Checking its current content:
data:image/s3,"s3://crabby-images/a600b/a600b607712559dd4223df1557e36413decd0938" alt=""
- Opening the text file, its content is altered on the attacker's machine:
data:image/s3,"s3://crabby-images/ae66b/ae66b8e805b1d861492c6da1946e8d4665cc50fe" alt=""
- Uploading the already altered text file from the attacker to the original folder on the victim:
data:image/s3,"s3://crabby-images/32f74/32f74f257d1c9ed839111a298d66c58b34f905ff" alt=""
data:image/s3,"s3://crabby-images/f0ea9/f0ea9420fef4ee08916db75b5399c736f60d7841" alt=""
- The attack has been successful, as can be proved checking on the victim's side the altered content of the text file.
data:image/s3,"s3://crabby-images/1cdce/1cdcec51d79f168b772081c853a10389a9072661" alt=""
- Finally, let's alter the MACE attributes of the text file. The current values:
data:image/s3,"s3://crabby-images/5ef59/5ef59a3855fe59109f2c9c36101dd88620775280" alt=""
- Meterpreter timestomp command provides some options to alter the MACE attributes. For instance -b option blank the attributes, altering them to random values:
data:image/s3,"s3://crabby-images/1fa3d/1fa3d6780161b67da6fa0376108370bdebeb4f1e" alt=""
data:image/s3,"s3://crabby-images/75acc/75acce018fe19995fe455348811691e00674aef3" alt=""