
Lord Of Active Directory - إنشاء Active Directory ضعيف تلقائيًا على AWS

مبني على AWS-Redteam-Lab و OCD GOAD
تبلغ تكلفة تشغيل المختبر لمدة 125 ساعة خلال شهر واحد حوالي 14$. مع الطبقة المجانية تحصل على 750 ساعة من EC2 شهريًا، وهناك 6 أجهزة لذا 125 ساعة. لكنك تحصل على 30 جيجابايت فقط من التخزين. لذا تحتاج إلى تخزين للأجهزة الخمسة الأخرى: 30 جيجابايت * 5 = 150 جيجابايت = 14$ شهريًا
تمامًا مثل مشروع GOAD، يتكون التثبيت من جزأين:
حتى الآن تم اختبار المختبر فقط على جهاز linux، لكنه يجب أن يعمل أيضًا على macOS. لدى Ansible بعض المشاكل مع مضيفي Windows لذا لا أعرف بخصوص ذلك.
لكي يعمل الإعداد بشكل صحيح تحتاج إلى تثبيت:
إذا كنت تريد تنفيذ التهيئة من حاوية docker فيمكنك تشغيل الأمر التالي لتجهيز الحاوية
sudo docker build -t loadansible .
إذا كنت تريد تشغيل ansible من جهازك المضيف فعليك تنفيذ الأوامر التالية:
sudo apt install git
git clone [email protected]:0xBallpoint/LOAD.git
cd LOAD/ansible
sudo apt install python3.8-venv
python3.8 -m virtualenv .venv
source .venv/bin/activate
ansible و pywinrm في .venv
python3 -m pip install --upgrade pip
python3 -m pip install ansible-core==2.12.6
python3 -m pip install pywinrm
ansible-galaxy install -r requirements.yml
تحتاج إلى تثبيت Terraform باتباع دليلهم على موقعهم hashicorp.com
إذا كنت تريد تثبيت Terraform يدويًا على Linux:
sudo apt-get update && sudo apt-get install -y gnupg software-properties-common
# Install the HasiCorp GPG key
wget -O- https://apt.releases.hashicorp.com/gpg | \
gpg --dearmor | \
sudo tee /usr/share/keyrings/hashicorp-archive-keyring.gpg
# Verify the key's fingerprint
gpg --no-default-keyring \
--keyring /usr/share/keyrings/hashicorp-archive-keyring.gpg \
--fingerprint
# It must match E8A0 32E0 94D8 EB4E A189 D270 DA41 8C88 A321 9F7B (from https://www.hashicorp.com/security)
# Add the official HashiCorp repository to your system
echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] \
https://apt.releases.hashicorp.com $(lsb_release -cs) main" | \
sudo tee /etc/apt/sources.list.d/hashicorp.list
# Update, install, verify
sudo apt update
sudo apt install terraform
terraform -help
ستحتاج إلى AWS CLI لتهيئة مفاتيح الوصول الخاصة بك إلى AWS. يجب اتباع دليل التثبيت على موقعهم docs.aws.amazon.com
لأنظمة Linux:
curl "https://awscli.amazonaws.com/awscli-exe-linux-x86_64.zip" -o "awscliv2.zip"
unzip awscliv2.zip
sudo ./aws/install
المجال الافتراضي سيكون middle-earth.local، على الشبكة الفرعية 10.0.1.0/24، وقد تم تخصيص 1CPU وذاكرة 1024MB فقط لكل جهاز (t2.micro). إذا كنت تريد تغيير بعض إعدادات الأداء هذه يمكنك تعديل الملف: terraform/ami-instance.tf
لتشغيل المختبر، هذه هي الأوامر التي يجب عليك تنفيذها:
pwd
/opt/LOAD # place yourself in the LOAD folder (where you cloned the project)
cd terraform # start with AWS configuration
الخطوات التالية توضح لك كيفية تهيئة أجهزتك الافتراضية على AWS:
انسخ var.tf.example إلى var.tf وغيّر القيم:
في وحدة تحكم AWS الخاصة بك، يجب إنشاء مستخدم terraform والحصول على مفاتيح AWS الخاصة بك:
terraformAccess key - Programmatic accessAccess key ID و Secret access keyأضف المفاتيح على جهازك باستخدام AWS CLI:
aws configure --profile terraform
AWS Access Key ID [None]: <access_key_id>
AWS Secret Access Key [None]: <secret_access_key>
cd LOAD
ssh-keygen -t rsa -N "" -b 2048 -C "TerraformKey" -f ./terraform/keys/TerraformKey.pem
terraform init
terraform apply
إذا كنت تريد تدمير مختبرك:
terraform destroy
في كل مرة تبدأ فيها مثيلات EC2 الخاصة بك، يجب عليك تغيير عنوان IP العام الخاص بها في ملف ansible/hosts. أضف ناتج هذا الأمر في نهاية الملف:
aws ec2 describe-instances --profile terraform --region eu-central-1 --query "Reservations[*].Instances[*].{Name:Tags[?Key=='Name'].Value|[],PublicIP:PublicIpAddress}" --filters "Name=instance-state-name,Values=running" --output text |tac |awk 'NR%2 ==0 {print $0}; NR%2 != 0 {print "["tolower(substr($2,5))"]"};'
لتهيئة الأجهزة الافتراضية استخدم الأمر ansible-playbook. الوقت المعتاد للتشغيل: 1h30
ansible-playbook main.yml # this will configure the vms in order to play ansible when the vms are ready
لتشغيل التهيئة من حاوية docker نفّذ (يجب أن تكون في نفس المجلد الذي يحتوي على Dockerfile. لم يتم اختباره بعد):
sudo docker run -ti --rm --network host -h loadansible -v $(pwd):/load -w /load/ansible loadansible ansible-playbook main.yml
في بعض الأحيان قد يحدث خطأ أثناء التثبيت. في معظم الأحيان، يمكنك فقط تشغيل playbook مرة أخرى وسيعمل. لتشغيل playbooks واحدًا تلو الآخر:
# The main.yml playbook is build in multiples parts. each parts can be re-run independently but the play order must be keep in cas you want to play one by one :
ansible-playbook prepare.yml # updates, passwords, dns settings...
ansible-playbook ad-servers.yml # create servers configuration
ansible-playbook ad-trusts.yml # create the trust relationships
ansible-playbook ad-data.yml # import the ad datas : users/groups...
ansible-playbook ad-groups.yml # set the rights and the group domains relations
ansible-playbook servers.yml # create IIS and MSSQL
ansible-playbook adcs.yml # add adcs and adcs templates
ansible-playbook ad-acl.yml # set ACL
ansible-playbook linux.yml # configure linux entrypoint with GLPI
ansible-playbook security.yml # enable or disable windows defender here
ansible-playbook vulnerabilities.yml # specifics vulns linked to the scenario are here
# You can also install wireguard VPN on the linux host, for that check the VPN paragraph
إذا كنت تريد تشغيل جزء محدد فقط من playbook، يمكنك استخدام الوسوم (tags) (ضع دائمًا data كوسم):
ansible-playbook servers.yml
ansible-playbook servers.yml --tags data,iis
ansible-playbook linux.yml --tags data,glpi
بعض الأوامر لمساعدتك في إدارة مختبر AWS الخاص بك (إنها قبيحة لكنها تعمل):
# aws cli profile : terraform
# region : eu-central-1
# Disable instance metadata
for i in $(aws ec2 --profile terraform --region eu-central-1 describe-instances --filters "Name=tag:Name,Values=lab-*" --query 'Reservations[].Instances[].InstanceId' |cut -d '"' -f2); do aws ec2 --profile terraform --region eu-central-1 modify-instance-metadata-options --http-endpoint disabled --instance-id $i --output json --no-cli-pager;done