
Active Directory ACL दुरुपयोग टूलकिट जो विशेषाधिकार वृद्धि, DCSync, ऑब्जेक्ट स्वामित्व संशोधन, और लॉगऑन स्क्रिप्ट हेरफेर तथा समूह सदस्यता परिवर्तनों के माध्यम से पार्श्व गति के लिए उपयोग होता है।
acltoolkit ACL दुरुपयोग के लिए एक बहुउपयोगी उपकरण है। यह कई ACL दुरुपयोगों को लागू करता है।
pip install acltoolkit-ad
या
git clone https://github.com/zblurx/acltoolkit.git
cd acltoolkit
make
usage: acltoolkit [-h] [-debug] [-hashes LMHASH:NTHASH] [-no-pass] [-k] [-dc-ip ip address] [-scheme ldap scheme]
target {get-objectacl,set-objectowner,give-genericall,give-dcsync,add-groupmember,set-logonscript} ...
ACL abuse swiss-army knife
positional arguments:
target [[domain/]username[:password]@]<target name or address>
{get-objectacl,set-objectowner,give-genericall,give-dcsync,add-groupmember,set-logonscript}
Action
get-objectacl Get Object ACL
set-objectowner Modify Object Owner
give-genericall Grant an object GENERIC ALL on a targeted object
give-dcsync Grant an object DCSync capabilities on the domain
add-groupmember Add Member to Group
set-logonscript Change Logon Sript of User
options:
-h, --help show this help message and exit
-debug Turn DEBUG output ON
-no-pass don't ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the
command line
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-scheme ldap scheme
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
$ acltoolkit get-objectacl -h
usage: acltoolkit target get-objectacl [-h] [-object object] [-all]
options:
-h, --help show this help message and exit
-object object Dump ACL for <object>. Parameter can be a sAMAccountName, a name, a DN or an objectSid
-all List every ACE of the object, even the less-interesting ones
get-objectacl इनपुट के रूप में -object के साथ एक sAMAccountName, एक नाम, एक DN या एक objectSid लेगा और उसके Sid, Name, DN, Class, adminCount, कॉन्फ़िगर किया गया LogonScript, प्राथमिक समूह, स्वामी और DACL को सूचीबद्ध करेगा। यदि कोई पैरामीटर प्रदान नहीं किया जाता है, तो प्रमाणीकरण के लिए उपयोग किए गए खाते के बारे में जानकारी सूचीबद्ध करेगा।
$ acltoolkit waza.local/jsmith:Password#[email protected] get-objectacl
Sid : S-1-5-21-267175082-2660600898-836655089-1103
Name : waza\John Smith
DN : CN=John Smith,CN=Users,DC=waza,DC=local
Class : top, person, organizationalPerson, user
adminCount : False
Logon Script
scriptPath : \\WAZZAAAAAA\OCD\test.bat
msTSInitialProgram: \\WAZZAAAAAA\OCD\test.bat
PrimaryGroup
Sid : S-1-5-21-267175082-2660600898-836655089-513
Name : waza\Domain Users
DN : CN=Domain Users,OU=Builtin Groups,DC=waza,DC=local
[...]
OwnerGroup
Sid : S-1-5-21-267175082-2660600898-836655089-512
Name : waza\Domain Admins
Dacl
ObjectSid : S-1-1-0
Name : Everyone
AceType : ACCESS_ALLOWED_OBJECT_ACE
AccessMask : 256
ADRights : EXTENDED_RIGHTS
IsInherited : False
ObjectAceType : User-Change-Password
[...]
ObjectSid : S-1-5-32-544
Name : BUILTIN\Administrator
AceType : ACCESS_ALLOWED_ACE
AccessMask : 983485
ADRights : WRITE_OWNER, WRITE_DACL, GENERIC_READ, DELETE, EXTENDED_RIGHTS, WRITE_PROPERTY, SELF, CREATE_CHILD
IsInherited : True
$ acltoolkit set-objectowner -h
usage: acltoolkit target set-objectowner [-h] -target-sid target_sid [-owner-sid owner_sid]
options:
-h, --help show this help message and exit
-target-sid target_sid
Object Sid targeted
-owner-sid owner_sid New Owner Sid
set-objectowner इनपुट के रूप में एक लक्ष्य Sid और एक स्वामी Sid लेगा, और लक्ष्य वस्तु के स्वामी को बदल देगा।
$ acltoolkit give-genericall -h
usage: acltoolkit target give-genericall [-h] -target-sid target_sid [-granted-sid owner_sid]
options:
-h, --help show this help message and exit
-target-sid target_sid
Object Sid targeted
-granted-sid owner_sid
Object Sid granted GENERIC_ALL
give-genericall इनपुट के रूप में एक लक्ष्य Sid और एक अनुदत्त Sid लेगा, और लक्ष्य वस्तु पर अनुदत्त SID को GENERIC_ALL DACL प्रदान करेगा।
$ acltoolkit give-dcsync -h
usage: acltoolkit target give-dcsync [-h] [-granted-sid owner_sid]
options:
-h, --help show this help message and exit
-granted-sid owner_sid
Object Sid granted DCSync capabilities
give-dcsync इनपुट के रूप में एक अनुदत्त Sid लेगा, और अनुदत्त SID को DCSync क्षमताएँ प्रदान करेगा।
$ acltoolkit add-groupmember -h
usage: acltoolkit target add-groupmember [-h] [-user user] -group group
options:
-h, --help show this help message and exit
-user user User added to a group
-group group Group where the user will be added
add-groupmember इनपुट के रूप में एक उपयोगकर्ता sAMAccountName और एक समूह sAMAccountName लेगा, और उपयोगकर्ता को समूह में जोड़ देगा।
$ acltoolkit set-logonscript -h
usage: acltoolkit target set-logonscript [-h] -target-sid target_sid -script-path script_path [-logonscript-type logonscript_type]
options:
-h, --help show this help message and exit
-target-sid target_sid
Object Sid of targeted user
-script-path script_path
Script path to set for the targeted user
-logonscript-type logonscript_type
Logon Script variable to change (default is scriptPath)
set-logonscript इनपुट के रूप में एक लक्ष्य Sid और एक स्क्रिप्ट पथ लेगा, और लक्ष्य उपयोगकर्ता के लॉगऑन स्क्रिप्ट पथ को निर्दिष्ट स्क्रिप्ट पथ पर सेट करेगा।