kerberos-double-hop-problem.md (9220B)
1 --- 2 title: "Kerberos Double Hop Problem" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/kerberos-double-hop-problem.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/kerberos-double-hop-problem.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Kerberos Double Hop Problem 14 15 ## Introduction 16 17 The Kerberos "Double Hop" problem appears when an attacker attempts to use **Kerberos authentication across two** **hops**, for example using **PowerShell**/**WinRM**. 18 19 When an **authentication** occurs through **Kerberos**, **credentials** **aren't** cached in **memory.** Therefore, if you run mimikatz you **won't find credentials** of the user in the machine even if he is running processes. 20 21 This is because when connecting with Kerberos these are the steps:<sup>[[1]](#references)</sup> 22 23 1. User1 provides credentials and **domain controller** returns a Kerberos **TGT** to the User1. 24 2. User1 uses **TGT** to request a **service ticket** to **connect** to Server1. 25 3. User1 **connects** to **Server1** and provides **service ticket**. 26 4. **Server1** **doesn't** have **credentials** of User1 cached or the **TGT** of User1. Therefore, when User1 from Server1 tries to login to a second server, he is **not able to authenticate**. 27 28 ### Unconstrained Delegation 29 30 If **unconstrained delegation** is enabled in the PC, this won't happen as the **Server** will **get** a **TGT** of each user accessing it. Moreover, if unconstrained delegation is used you probably can **compromise the Domain Controller** from it.\ 31 [**More info in the unconstrained delegation page**](/hacktricks/windows-hardening/active-directory-methodology/unconstrained-delegation). 32 33 ### CredSSP 34 35 Another way to avoid this problem which is [**notably insecure**](https://docs.microsoft.com/en-us/powershell/module/microsoft.wsman.management/enable-wsmancredssp?view=powershell-7) is **Credential Security Support Provider**. From Microsoft: 36 37 > CredSSP authentication delegates the user credentials from the local computer to a remote computer. This practice increases the security risk of the remote operation. If the remote computer is compromised, when credentials are passed to it, the credentials can be used to control the network session. 38 39 It is highly recommended that **CredSSP** be disabled on production systems, sensitive networks, and similar environments due to security concerns. To determine whether **CredSSP** is enabled, the `Get-WSManCredSSP` command can be run. This command allows for the **checking of CredSSP status** and can even be executed remotely, provided **WinRM** is enabled. 40 41 ```bash 42 Invoke-Command -ComputerName bizintel -Credential ta\redsuit -ScriptBlock { 43 Get-WSManCredSSP 44 } 45 ``` 46 47 ### Remote Credential Guard (RCG) 48 49 **Remote Credential Guard** keeps the user's TGT on the originating workstation while still allowing the RDP session to request new Kerberos service tickets on the next hop. Enable **Computer Configuration > Administrative Templates > System > Credentials Delegation > Restrict delegation of credentials to remote servers** and select **Require Remote Credential Guard**, then connect with `mstsc.exe /remoteGuard /v:server1` instead of falling back to CredSSP. 50 51 Microsoft broke RCG for multi-hop access on Windows 11 22H2+ until the **April 2024 cumulative updates** (KB5036896/KB5036899/KB5036894). Patch the client and intermediary server or the second hop will still fail.<sup>[[5]](#references)</sup> Quick hotfix check: 52 53 ```powershell 54 ("KB5036896","KB5036899","KB5036894") | ForEach-Object { 55 Get-HotFix -Id $_ -ErrorAction SilentlyContinue 56 } 57 ``` 58 59 With those builds installed, the RDP hop can satisfy downstream Kerberos challenges without exposing reusable secrets on the first server. 60 61 ## Workarounds 62 63 ### Invoke Command 64 65 To address the double hop issue, a method involving a nested `Invoke-Command` is presented. This does not solve the problem directly but offers a workaround without needing special configurations. The approach allows executing a command (`hostname`) on a secondary server through a PowerShell command executed from an initial attacking machine or through a previously established PS-Session with the first server. Here's how it's done:<sup>[[2]](#references)</sup> 66 67 ```bash 68 $cred = Get-Credential ta\redsuit 69 Invoke-Command -ComputerName bizintel -Credential $cred -ScriptBlock { 70 Invoke-Command -ComputerName secdev -Credential $cred -ScriptBlock {hostname} 71 } 72 ``` 73 74 Alternatively, establishing a PS-Session with the first server and running the `Invoke-Command` using `$cred` is suggested for centralizing tasks. 75 76 ### Register PSSession Configuration 77 78 A solution to bypass the double hop problem involves using `Register-PSSessionConfiguration` with `Enter-PSSession`. This method requires a different approach than `evil-winrm` and allows for a session that does not suffer from the double hop limitation.<sup>[[3]](#references)[[4]](#references)</sup> 79 80 ```bash 81 Register-PSSessionConfiguration -Name doublehopsess -RunAsCredential domain_name\username 82 Restart-Service WinRM 83 Enter-PSSession -ConfigurationName doublehopsess -ComputerName TARGET_PC -Credential domain_name\username 84 klist 85 ``` 86 87 ### PortForwarding 88 89 For local administrators on an intermediary target, port forwarding allows requests to be sent to a final server. Using `netsh`, a rule can be added for port forwarding, alongside a Windows firewall rule to allow the forwarded port.<sup>[[2]](#references)</sup> 90 91 ```bash 92 netsh interface portproxy add v4tov4 listenport=5446 listenaddress=10.35.8.17 connectport=5985 connectaddress=10.35.8.23 93 netsh advfirewall firewall add rule name=fwd dir=in action=allow protocol=TCP localport=5446 94 ``` 95 96 #### winrs.exe 97 98 `winrs.exe` can be used for forwarding WinRM requests, potentially as a less detectable option if PowerShell monitoring is a concern.<sup>[[2]](#references)</sup> The command below demonstrates its use: 99 100 ```bash 101 winrs -r:http://bizintel:5446 -u:ta\redsuit -p:2600leet hostname 102 ``` 103 104 ### OpenSSH 105 106 Installing OpenSSH on the first server enables a workaround for the double-hop issue, particularly useful for jump box scenarios. This method requires CLI installation and setup of OpenSSH for Windows. When configured for Password Authentication, this allows the intermediary server to obtain a TGT on behalf of the user.<sup>[[2]](#references)</sup> 107 108 #### OpenSSH Installation Steps 109 110 1. Download and move the latest OpenSSH release zip to the target server. 111 2. Unzip and run the `Install-sshd.ps1` script. 112 3. Add a firewall rule to open port 22 and verify SSH services are running. 113 114 To resolve `Connection reset` errors, permissions might need to be updated to allow everyone read and execute access on the OpenSSH directory. 115 116 ```bash 117 icacls.exe "C:\Users\redsuit\Documents\ssh\OpenSSH-Win64" /grant Everyone:RX /T 118 ``` 119 120 ### LSA Whisperer CacheLogon (Advanced) 121 122 **LSA Whisperer** (2024) exposes the `msv1_0!CacheLogon` package call so you can seed an existing *network logon* with a known NT hash instead of creating a fresh session with `LogonUser`. By injecting the hash into the logon session that WinRM/PowerShell already opened on hop #1, that host can authenticate to hop #2 without storing explicit credentials or generating extra 4624 events.<sup>[[6]](#references)</sup> 123 124 1. Get code execution inside LSASS (either disable/abuse PPL or run on a lab VM you control). 125 2. Enumerate logon sessions (e.g. `lsa.exe sessions`) and capture the LUID corresponding to your remoting context. 126 3. Pre-compute the NT hash and feed it to `CacheLogon`, then clear it when done. 127 128 ```powershell 129 lsa.exe cachelogon --session 0x3e4 --domain ta --username redsuit --nthash a7c5480e8c1ef0ffec54e99275e6e0f7 130 lsa.exe cacheclear --session 0x3e4 131 ``` 132 133 After the cache seed, rerun `Invoke-Command`/`New-PSSession` from hop #1: LSASS will reuse the injected hash to satisfy Kerberos/NTLM challenges for the second hop, neatly bypassing the double hop constraint. The trade-off is heavier telemetry (code execution in LSASS) so keep it for high-friction environments where CredSSP/RCG are disallowed. 134 135 ## References 136 137 - [1] [Understanding Kerberos Double Hop - Microsoft Community Hub](https://techcommunity.microsoft.com/t5/ask-the-directory-services-team/understanding-kerberos-double-hop/ba-p/395463?lightbox-message-images-395463=102145i720503211E78AC20) 138 - [2] [Kerberos Double-Hop Workarounds](https://posts.slayerlabs.com/double-hop/) 139 - [3] [Another solution to multi-hop PowerShell remoting](https://learn.microsoft.com/en-gb/archive/blogs/sergey_babkins_blog/another-solution-to-multi-hop-powershell-remoting) 140 - [4] [Solve the PowerShell multi-hop problem without using CredSSP](https://4sysops.com/archives/solve-the-powershell-multi-hop-problem-without-using-credssp/) 141 - [5] [April 9, 2024—KB5036896 (OS Build 17763.5696)](https://support.microsoft.com/en-au/topic/april-9-2024-kb5036896-os-build-17763-5696-efb580f1-2ce4-4695-b76c-d2068a00fb92) 142 - [6] [LSA Whisperer](https://specterops.io/blog/2024/04/17/lsa-whisperer/)