CVE-2020-1472 又名 Zerologon 漏洞利用 POC

这是什么?
NetLogon (MS-NRPC) 可以建立域间控制易受攻击的安全通道。
攻击者可以将域控制器上机器账户的密码置空。
注意:
- 当密码被置空时,DC 会处于半失效状态,不过该程序结束后会将密码恢复
- 可能导致 DC 出现 DNS 问题(重启可解决)
- Kerberos 票证在过期前有 10 小时的生存期
- 需要来自 GitHub 的最新版 impacket,其中包含新增的 netlogon 结构
- 请注意,默认情况下该程序会更改域控制器系统账户的密码,然后再将其恢复。是的,这允许你进行 DCSync,但也会在短时间内中断与其他域控制器的通信,因此请务必小心!
研究资料:
所需依赖
- 需要来自 GitHub 的最新版 impacket,其中包含新增的 netlogon 结构。
检查是否存在漏洞:
- 脚本的默认行为是仅检查是否存在漏洞,不会更改任何内容!
zerologon.py 用法
- 请先阅读上面的博客/白皮书,确保你清楚自己在做什么
- 该脚本会检查域控制器是否存在 CVE-2020-1472 漏洞。
- 如果提供了 -exploit 选项,它将:
- 将域控制器系统密码置空
- 使用空密码调用 secretsdump 的 DRSUAPI 来获取 ntds 哈希
- 解析导出的数据,获取 rid 为 :500: 的域管理员账户,并再次调用 secretsdump 获取 lsa 机密信息
- 解析第二次导出的数据,获取 plain_password_hex 值
- 使用该十六进制值调用恢复脚本,将 DC 的系统密码恢复为原始值
python zerologon.py
usage: zerologon.py [-h] [-exploit] dc_name dc_ip
Tests whether a domain controller is vulnerable to the Zerologon attack. Resets the DC account password to an empty string
when vulnerable.
positional arguments:
dc_name The (NetBIOS) computer name of the domain controller.
dc_ip IP Address of the domain controller.
optional arguments:
-h, --help show this help message and exit
-exploit Zero out the computer's hash
检测方法:
- 事件 4661,特权请求为 SetPassword(不知道旧密码)(附截图)
- 事件 4723,尝试更改账户密码
- 事件 4738,用户账户的“密码上次设置”值被更改
修补方法:
受影响系统:
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2012
- Windows Server 2012 (Server Core installation)
- Windows Server 2012 R2
- Windows Server 2012 R2 (Server Core installation)
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server, version 1903 (Server Core installation)
- Windows Server, version 1909 (Server Core installation)
- Windows Server, version 2004 (Server Core installation)