<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Tricky way to use the SEC to execute/schedule a program on a remote endpoint</title><link>https://community.sophos.com/on-premise-endpoint/f/sophos-enterprise-console/122498/tricky-way-to-use-the-sec-to-execute-schedule-a-program-on-a-remote-endpoint</link><description>A Sophos engineer a few years ago showed us a trick that could have allowed us to run an executable on a remote endpoint by using the SEC messages. I didn&amp;#39;t document it at the time as I thought we had other tools to do that and didn&amp;#39;t need another one</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Tricky way to use the SEC to execute/schedule a program on a remote endpoint</title><link>https://community.sophos.com/thread/445577?ContentTypeID=1</link><pubDate>Sat, 22 Aug 2020 17:51:20 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7697ea01-73cc-4d5b-a140-cfe81e55c1f5</guid><dc:creator>jak</dc:creator><description>&lt;p&gt;AutoUpdate will not pull down any old file added to the CID but the deployment workflow from SEC schedules a Windows task to run setup.exe from the CID.&amp;nbsp; That&amp;#39;s just a Windows Scheduled Task once created and will run the setup.exe it points at.&lt;/p&gt;
&lt;p&gt;Of course this deployment workflow doesn&amp;#39;t use RMS, just DCOM to create the remote scheduled task and the computer needs to be on at the time of creation, so if you can do it in SEC, you don&amp;#39;t really need SEC but maybe it&amp;#39;s a convenient way of performing the task on a number of machines in a particular group for example or in a specific state in SEC.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tricky way to use the SEC to execute/schedule a program on a remote endpoint</title><link>https://community.sophos.com/thread/445542?ContentTypeID=1</link><pubDate>Fri, 21 Aug 2020 17:57:11 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:de5712fa-f1d8-4354-9288-93abe906a5a7</guid><dc:creator>FormerMember</dc:creator><description>&lt;p&gt;the scripting calls in SEC are not meant to alter the OS - they are for our own components.&lt;/p&gt;
&lt;p&gt;In theory, you could deploy a PS script (not sure how you would get it onto the box if there is no trust) but based on what you are describing I have little hope of success. A domain trust break can be indicative of some serious problems on the box (HDD sectors failing, corrupted memory, amongst other things). However, you could try unjoining it -&amp;gt; have the script output a log -&amp;gt; check the log for success -&amp;gt; then try a join. There will be a reboot (maybe two) in there so that&amp;#39;s a risk.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;It would be very risky. If I was you, I would get my hands on the device before attempting anything.&lt;/p&gt;
&lt;p&gt;SEC will not be able to help you here. If you just throw a file in the CID that won&amp;#39;t do anything - the endpoints only download files that are signed and part of their manifest - you can&amp;#39;t use SEC to infiltrate a system.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tricky way to use the SEC to execute/schedule a program on a remote endpoint</title><link>https://community.sophos.com/thread/445537?ContentTypeID=1</link><pubDate>Fri, 21 Aug 2020 17:08:40 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:a2f6bfb1-6377-468a-94c7-e1dea40944b9</guid><dc:creator>jak</dc:creator><description>&lt;p&gt;SEC scheduled a task to run straight away which runs setup.exe from the CID.&amp;nbsp; Did they replace setup.exe in the CID with a customer setup.exe that did what you needed?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tricky way to use the SEC to execute/schedule a program on a remote endpoint</title><link>https://community.sophos.com/thread/445517?ContentTypeID=1</link><pubDate>Fri, 21 Aug 2020 13:20:39 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:eeff2fee-0570-4a1c-a84c-47c7b7b5aa32</guid><dc:creator>RobertoF</dc:creator><description>&lt;p&gt;Hi Christian,&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I confirm it&amp;#39;s possible - we had Sophos Professional Services onsite for two weeks during our initial Sophos rollout, and he proudly showed us an undocumented trick that allowed us to do just that. I think it involved using one of the functions of the SEC to deploy a script that was then executed on the endpoint... if I could just remember!&lt;/p&gt;
&lt;p&gt;Too bad it&amp;#39;s actually &lt;em&gt;not&lt;/em&gt; an XP machine, otherwise we could have used one of the un-patcheable exploits to get in! It&amp;#39;s a Windows 7 patched to the latest publicly available updates, and all my Metasploit attempts to break in have been unsuccessful so far.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Roberto&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Tricky way to use the SEC to execute/schedule a program on a remote endpoint</title><link>https://community.sophos.com/thread/445516?ContentTypeID=1</link><pubDate>Fri, 21 Aug 2020 13:10:53 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:96509b42-3d85-47fa-a8ce-e1c186b9e5d6</guid><dc:creator>QC</dc:creator><description>&lt;p&gt;Hello &lt;span class="field-item-name label"&gt;RobertoF&lt;/span&gt;,&lt;/p&gt;
&lt;p&gt;I&amp;#39;m not aware that RMS (and SEC) ever allowed custom messages that moreover resulted in the execution of arbitrary commands.&lt;/p&gt;
&lt;p&gt;&lt;span style="color:#008000;"&gt;&lt;em&gt;&lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;in an nreachable physical location&lt;/span&gt;&lt;/em&gt;&lt;/span&gt; - but doing some useful and perhaps important work? And running Windows [:P]? Guess you wouldn&amp;#39;t try to&amp;nbsp;&lt;span style="color:#008000;"&gt;&lt;em&gt;&lt;span id="fragment-1537280418_QuoteText" class="field-item-description user-defined-markup"&gt;re-install Windows&lt;/span&gt;&lt;/em&gt;&lt;/span&gt; remotely. Whatever action you&amp;#39;d take you have likely just one try.&lt;/p&gt;
&lt;p&gt;Christian&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>