daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-double-hop-problem.md (9220B)


      1 ---
      2 title: "Kerberos Double Hop Problem"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/kerberos-double-hop-problem.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/kerberos-double-hop-problem.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Kerberos Double Hop Problem
     14 
     15 ## Introduction
     16 
     17 The Kerberos "Double Hop" problem appears when an attacker attempts to use **Kerberos authentication across two** **hops**, for example using **PowerShell**/**WinRM**.
     18 
     19 When an **authentication** occurs through **Kerberos**, **credentials** **aren't** cached in **memory.** Therefore, if you run mimikatz you **won't find credentials** of the user in the machine even if he is running processes.
     20 
     21 This is because when connecting with Kerberos these are the steps:<sup>[[1]](#references)</sup>
     22 
     23 1. User1 provides credentials and **domain controller** returns a Kerberos **TGT** to the User1.
     24 2. User1 uses **TGT** to request a **service ticket** to **connect** to Server1.
     25 3. User1 **connects** to **Server1** and provides **service ticket**.
     26 4. **Server1** **doesn't** have **credentials** of User1 cached or the **TGT** of User1. Therefore, when User1 from Server1 tries to login to a second server, he is **not able to authenticate**.
     27 
     28 ### Unconstrained Delegation
     29 
     30 If **unconstrained delegation** is enabled in the PC, this won't happen as the **Server** will **get** a **TGT** of each user accessing it. Moreover, if unconstrained delegation is used you probably can **compromise the Domain Controller** from it.\
     31 [**More info in the unconstrained delegation page**](/hacktricks/windows-hardening/active-directory-methodology/unconstrained-delegation).
     32 
     33 ### CredSSP
     34 
     35 Another way to avoid this problem which is [**notably insecure**](https://docs.microsoft.com/en-us/powershell/module/microsoft.wsman.management/enable-wsmancredssp?view=powershell-7) is **Credential Security Support Provider**. From Microsoft:
     36 
     37 > CredSSP authentication delegates the user credentials from the local computer to a remote computer. This practice increases the security risk of the remote operation. If the remote computer is compromised, when credentials are passed to it, the credentials can be used to control the network session.
     38 
     39 It is highly recommended that **CredSSP** be disabled on production systems, sensitive networks, and similar environments due to security concerns. To determine whether **CredSSP** is enabled, the `Get-WSManCredSSP` command can be run. This command allows for the **checking of CredSSP status** and can even be executed remotely, provided **WinRM** is enabled.
     40 
     41 ```bash
     42 Invoke-Command -ComputerName bizintel -Credential ta\redsuit -ScriptBlock {
     43     Get-WSManCredSSP
     44 }
     45 ```
     46 
     47 ### Remote Credential Guard (RCG)
     48 
     49 **Remote Credential Guard** keeps the user's TGT on the originating workstation while still allowing the RDP session to request new Kerberos service tickets on the next hop. Enable **Computer Configuration > Administrative Templates > System > Credentials Delegation > Restrict delegation of credentials to remote servers** and select **Require Remote Credential Guard**, then connect with `mstsc.exe /remoteGuard /v:server1` instead of falling back to CredSSP.
     50 
     51 Microsoft broke RCG for multi-hop access on Windows 11 22H2+ until the **April 2024 cumulative updates** (KB5036896/KB5036899/KB5036894). Patch the client and intermediary server or the second hop will still fail.<sup>[[5]](#references)</sup> Quick hotfix check:
     52 
     53 ```powershell
     54 ("KB5036896","KB5036899","KB5036894") | ForEach-Object {
     55     Get-HotFix -Id $_ -ErrorAction SilentlyContinue
     56 }
     57 ```
     58 
     59 With those builds installed, the RDP hop can satisfy downstream Kerberos challenges without exposing reusable secrets on the first server.
     60 
     61 ## Workarounds
     62 
     63 ### Invoke Command
     64 
     65 To address the double hop issue, a method involving a nested `Invoke-Command` is presented. This does not solve the problem directly but offers a workaround without needing special configurations. The approach allows executing a command (`hostname`) on a secondary server through a PowerShell command executed from an initial attacking machine or through a previously established PS-Session with the first server. Here's how it's done:<sup>[[2]](#references)</sup>
     66 
     67 ```bash
     68 $cred = Get-Credential ta\redsuit
     69 Invoke-Command -ComputerName bizintel -Credential $cred -ScriptBlock {
     70     Invoke-Command -ComputerName secdev -Credential $cred -ScriptBlock {hostname}
     71 }
     72 ```
     73 
     74 Alternatively, establishing a PS-Session with the first server and running the `Invoke-Command` using `$cred` is suggested for centralizing tasks.
     75 
     76 ### Register PSSession Configuration
     77 
     78 A solution to bypass the double hop problem involves using `Register-PSSessionConfiguration` with `Enter-PSSession`. This method requires a different approach than `evil-winrm` and allows for a session that does not suffer from the double hop limitation.<sup>[[3]](#references)[[4]](#references)</sup>
     79 
     80 ```bash
     81 Register-PSSessionConfiguration -Name doublehopsess -RunAsCredential domain_name\username
     82 Restart-Service WinRM
     83 Enter-PSSession -ConfigurationName doublehopsess -ComputerName TARGET_PC -Credential domain_name\username
     84 klist
     85 ```
     86 
     87 ### PortForwarding
     88 
     89 For local administrators on an intermediary target, port forwarding allows requests to be sent to a final server. Using `netsh`, a rule can be added for port forwarding, alongside a Windows firewall rule to allow the forwarded port.<sup>[[2]](#references)</sup>
     90 
     91 ```bash
     92 netsh interface portproxy add v4tov4 listenport=5446 listenaddress=10.35.8.17 connectport=5985 connectaddress=10.35.8.23
     93 netsh advfirewall firewall add rule name=fwd dir=in action=allow protocol=TCP localport=5446
     94 ```
     95 
     96 #### winrs.exe
     97 
     98 `winrs.exe` can be used for forwarding WinRM requests, potentially as a less detectable option if PowerShell monitoring is a concern.<sup>[[2]](#references)</sup> The command below demonstrates its use:
     99 
    100 ```bash
    101 winrs -r:http://bizintel:5446 -u:ta\redsuit -p:2600leet hostname
    102 ```
    103 
    104 ### OpenSSH
    105 
    106 Installing OpenSSH on the first server enables a workaround for the double-hop issue, particularly useful for jump box scenarios. This method requires CLI installation and setup of OpenSSH for Windows. When configured for Password Authentication, this allows the intermediary server to obtain a TGT on behalf of the user.<sup>[[2]](#references)</sup>
    107 
    108 #### OpenSSH Installation Steps
    109 
    110 1. Download and move the latest OpenSSH release zip to the target server.
    111 2. Unzip and run the `Install-sshd.ps1` script.
    112 3. Add a firewall rule to open port 22 and verify SSH services are running.
    113 
    114 To resolve `Connection reset` errors, permissions might need to be updated to allow everyone read and execute access on the OpenSSH directory.
    115 
    116 ```bash
    117 icacls.exe "C:\Users\redsuit\Documents\ssh\OpenSSH-Win64" /grant Everyone:RX /T
    118 ```
    119 
    120 ### LSA Whisperer CacheLogon (Advanced)
    121 
    122 **LSA Whisperer** (2024) exposes the `msv1_0!CacheLogon` package call so you can seed an existing *network logon* with a known NT hash instead of creating a fresh session with `LogonUser`. By injecting the hash into the logon session that WinRM/PowerShell already opened on hop #1, that host can authenticate to hop #2 without storing explicit credentials or generating extra 4624 events.<sup>[[6]](#references)</sup>
    123 
    124 1. Get code execution inside LSASS (either disable/abuse PPL or run on a lab VM you control).
    125 2. Enumerate logon sessions (e.g. `lsa.exe sessions`) and capture the LUID corresponding to your remoting context.
    126 3. Pre-compute the NT hash and feed it to `CacheLogon`, then clear it when done.
    127 
    128 ```powershell
    129 lsa.exe cachelogon --session 0x3e4 --domain ta --username redsuit --nthash a7c5480e8c1ef0ffec54e99275e6e0f7
    130 lsa.exe cacheclear --session 0x3e4
    131 ```
    132 
    133 After the cache seed, rerun `Invoke-Command`/`New-PSSession` from hop #1: LSASS will reuse the injected hash to satisfy Kerberos/NTLM challenges for the second hop, neatly bypassing the double hop constraint. The trade-off is heavier telemetry (code execution in LSASS) so keep it for high-friction environments where CredSSP/RCG are disallowed.
    134 
    135 ## References
    136 
    137 - [1] [Understanding Kerberos Double Hop - Microsoft Community Hub](https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/understanding-kerberos-double-hop/ba-p/395463?lightbox-message-images-395463=102145i720503211E78AC20)
    138 - [2] [Kerberos Double-Hop Workarounds](https://posts.slayerlabs.com/double-hop/)
    139 - [3] [Another solution to multi-hop PowerShell remoting](https://learn.microsoft.com/en-gb/archive/blogs/sergey_babkins_blog/another-solution-to-multi-hop-powershell-remoting)
    140 - [4] [Solve the PowerShell multi-hop problem without using CredSSP](https://4sysops.com/archives/solve-the-powershell-multi-hop-problem-without-using-credssp/)
    141 - [5] [April 9, 2024—KB5036896 (OS Build 17763.5696)](https://support.microsoft.com/en-au/topic/april-9-2024-kb5036896-os-build-17763-5696-efb580f1-2ce4-4695-b76c-d2068a00fb92)
    142 - [6] [LSA Whisperer](https://specterops.io/blog/2024/04/17/lsa-whisperer/)