Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
OUned — El proyecto OUned automatiza la explotación de las ACL de Unidades Organizativas de Active Directory mediante envenenamiento de gPLink. | Kitploit
Herramientas/GitHubGitHub/synacktiv/ouned
Escalada de PrivilegiosExplotaciónMovimiento LateralPruebas de PenetraciónAutenticaciónMala Configuración
GitHubsynacktiv/ouned

OUned

El proyecto OUned automatiza la explotación de las ACL de Unidades Organizativas de Active Directory mediante envenenamiento de gPLink.

Ver Repositorio
16114hace 9 mesesRevisado por Kitploit

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

OUned

El proyecto OUned, una herramienta de explotación que automatiza el abuso de las ACL de Unidades Organizativas mediante la manipulación de gPLink.

Para una explicación detallada sobre el principio en el que se basa el ataque, la configuración necesaria y el uso de la herramienta, puede consultar el artículo asociado: https://www.synacktiv.com/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory

Instalación

La instalación se puede realizar clonando el repositorio e instalando las dependencias:

root@kitploit:~
$ git clone https://github.com/synacktiv/OUned
$ python3 -m pip install -r requirements.txt

Archivo de configuración

Los argumentos de OUned se proporcionan a través de un archivo de configuración; en el repositorio se incluye un archivo de ejemplo, config.example.ini.

Cada entrada se describe mediante un comentario, pero para obtener instrucciones de configuración detalladas, consulte el artículo mencionado en la introducción.

root@kitploit:~
[GENERAL]
# The target domain name
domain=corp.com

# The target DC. If not specified, defaults to the domain name
#dc=192.168.123.10

# The Distinguished Name of the target container
containerDN=OU=SERVERS,DC=corp,DC=com

# The username and password of the user having write permissions on the gPLink attribute of the target container
username=naugustine
password=Password1

# The IP address of the attacker machine on the internal network
attacker_ip=192.168.123.16

# The command that should be executed by child objects. Specifying a command will inject an immediate Scheduled Task
command=whoami > C:\poc.txt
# Alternatively to the 'command' option, you can provide a module file with the GroupPolicyBackdoor syntax - see https://github.com/synacktiv/GroupPolicyBackdoor/wiki. 'Command' and 'module' are mutually exclusive
# module=Scheduledtask_add_computer.ini

# The kind of objects targeted ("computer" or "user")
target_type=computer


[LDAP]
# The IP address of the dummy domain controller that will act as an LDAP server
ldap_ip=192.168.125.245

# Optional (used for sanity checks) - the hostname of the dummy domain controller
ldap_hostname=WIN-TTEBC5VH747

# The username and password of a domain administrator on the dummy domain controller 
ldap_username=ldapadm
ldap_password=Password1!

# The ID of the GPO (can be empty, only needs to exist) on the dummy domain controller
gpo_id=7B7D6B23-26F8-4E4B-AF23-F9B9005167F6

# The machine account name and password on the target domain that will be used to fake the LDAP server delivering the GPC
ldap_machine_name=OUNED$
ldap_machine_password=some_very_long_random_password

[SMB]
# The SMB mode can be embedded or forwarded depending on the kind of object targeted
smb_mode=embedded

# The name of the SMB share. Can be anything for embedded mode, should match an existing share on SMB dummy domain controller for forwarded mode
share_name=synacktiv

# The IP address of the dummy domain controller that will act as a SMB server. Only useful in forwarded mode
#smb_ip=192.168.126.206

# The username and password of a user having write access to the share on the SMB dummy domain controller. Only useful in forwarded mode
#smb_username=smbadm
#smb_password=Password1!

# The machine account name and password on the target domain that will be used to fake the SMB server delivering the GPT. Only useful in forwarded mode
#smb_machine_name=OUNED2$
#smb_machine_password=some_very_long_random_password

Uso de OUned

El único argumento obligatorio al ejecutar OUned es la opción --config, que indica la ruta al archivo de configuración.

Las opciones --just-coerce y coerce-to se utilizan para el modo de coerción de autenticación SMB, en el que OUned fuerza la autenticación SMB de los objetos secundarios de la OU hacia el destino especificado. Para más detalles, consulte el artículo enlazado en la introducción.

En cuanto a la opción --just-clean, consulte la siguiente sección.

root@kitploit:~
python3 OUned.py --help
                                                                                                                                                                                    
 Usage: OUned.py [OPTIONS]                                                                                                                                                          
                                                                                                                                                                                    
╭─ Options ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ *  --config               TEXT  The configuration file for OUned [default: None] [required]                                                                                      │
│    --skip-checks                Do not perform the various checks related to the exploitation setup                                                                              │
│    --just-coerce                Only coerce SMB NTLM authentication of OU child objects to the destination specified in the --coerce-to flag, or, if no destination is           │
│                                 specified, to a local SMB server that will print their NetNTLMv2 hashes                                                                          │
│    --coerce-to            TEXT  Coerce child objects SMB NTLM authentication to a specific destination - this argument should be an IP address [default: None]                   │
│    --just-clean                 This flag indicates that OUned should only perform cleaning actions from specified cleaning-file                                                 │
│    --cleaning-file        TEXT  The path to the cleaning file in case the --just-clean flag is used [default: None]                                                              │
│    --verbose                    Enable verbose output                                                                                                                            │
│    --help                       Show this message and exit.                                                                                                                      │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯

Acerca de la limpieza

De forma predeterminada y como se explica en el artículo, OUned realiza acciones de limpieza y, entre otras, restaura el valor original de gPLink en el dominio de destino. En caso de que el exploit no pueda finalizar correctamente, OUned crea un archivo de limpieza cada vez que se ejecuta el exploit, que puede utilizarse posteriormente para restaurar los valores legítimos mediante la opción --just-clean; por ejemplo:

root@kitploit:~
$ python3 OUned.py --config config.example.ini --just-clean --cleaning-file cleaning/FINANCE/2024_04_14-05_02_46.txt
Descargar herramienta