ad-tricks.md (1954B)
1 --- 2 title: "Active Directory - Tricks" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-tricks.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-tricks.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Active Directory - Tricks 12 13 ## Kerberos Clock Synchronization 14 15 In Kerberos, time is used to ensure that tickets are valid. To achieve this, the clocks of all Kerberos clients and servers in a realm must be synchronized to within a certain tolerance. The default clock skew tolerance in Kerberos is `5 minutes`, which means that the difference in time between the clocks of any two Kerberos entities should be no more than 5 minutes. 16 17 * Detect clock skew automatically with `nmap` 18 19 ```powershell 20 $ nmap -sV -sC 10.10.10.10 21 clock-skew: mean: -1998d09h03m04s, deviation: 4h00m00s, median: -1998d11h03m05s 22 ``` 23 24 * Compute yourself the difference between the clocks 25 26 ```ps1 27 nmap -sT 10.10.10.10 -p445 --script smb2-time -vv 28 ``` 29 30 * Fix #1: Modify your clock 31 32 ```ps1 33 sudo date -s "14 APR 2015 18:25:16" # Linux 34 net time /domain /set # Windows 35 ``` 36 37 * Fix #2: Fake your clock 38 39 ```ps1 40 faketime -f '+8h' date 41 ``` 42 43 ## References 44 45 * [BUILDING AND ATTACKING AN ACTIVE DIRECTORY LAB WITH POWERSHELL - @myexploit2600 & @5ub34x](https://1337red.wordpress.com/building-and-attacking-an-active-directory-lab-with-powershell/) 46 * [Becoming Darth Sidious: Creating a Windows Domain (Active Directory) and hacking it - @chryzsh](https://chryzsh.gitbooks.io/darthsidious/content/building-a-lab/building-a-lab/building-a-small-lab.html) 47 * [Chump2Trump - AD Privesc talk at WAHCKon 2017 - @l0ss](https://github.com/l0ss/Chump2Trump/blob/master/ChumpToTrump.pdf) 48 * [How to build a SQL Server Virtual Lab with AutomatedLab in Hyper-V - October 30, 2017 - Craig Porteous](https://www.sqlshack.com/build-sql-server-virtual-lab-automatedlab-hyper-v/)