This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Tricky way to use the SEC to execute/schedule a program on a remote endpoint

A Sophos engineer a few years ago showed us a trick that could have allowed us to run an executable on a remote endpoint by using the SEC messages. I didn't document it at the time as I thought we had other tools to do that and didn't need another one. But now we have an endpoint that lost its trust with the domain, has the local admin account disabled, and is in an unreachable physical location so nobody can login into it remotely or even onsite to re-install Windows.

As Sophos is the only application that is still working on the device... if we can figure out how to use the message router to run a command remotely on the endpoint we'll be able to regain access.

Does anyone know how we could do that?



This thread was automatically locked due to age.
Parents
  • Hello RobertoF,

    I'm not aware that RMS (and SEC) ever allowed custom messages that moreover resulted in the execution of arbitrary commands.

    in an nreachable physical location - but doing some useful and perhaps important work? And running Windows [:P]? Guess you wouldn't try to re-install Windows remotely. Whatever action you'd take you have likely just one try.

    Christian 

  • Hi Christian,

     

    I confirm it's possible - we had Sophos Professional Services onsite for two weeks during our initial Sophos rollout, and he proudly showed us an undocumented trick that allowed us to do just that. I think it involved using one of the functions of the SEC to deploy a script that was then executed on the endpoint... if I could just remember!

    Too bad it's actually not an XP machine, otherwise we could have used one of the un-patcheable exploits to get in! It's a Windows 7 patched to the latest publicly available updates, and all my Metasploit attempts to break in have been unsuccessful so far.

     

    Roberto

  • SEC scheduled a task to run straight away which runs setup.exe from the CID.  Did they replace setup.exe in the CID with a customer setup.exe that did what you needed?

Reply Children
No Data