1 of 43

HEAD TO TAIL

Derbycon 9.0 - “Finish Line” Louisville, Kentucky 2019

2 of 43

AGENDA

SharpHound Review

Example Attack Path

Kerberoast

WriteOwner

Resource-Based Constrained Delegation

HasSession

MSSQL Execution

2

3 of 43

3

Andy Robbins

@_wald0

Rohan Vazarkar

@CptJesus

4 of 43

SharpHound

How does it work?

5 of 43

The Most Basic Level

  • Step 1 - Resolve User Options to Tasks
  • Step 2 - Query LDAP for necessary information
  • Step 3 - Feed each returned item into a pipeline
  • Step 4 - Run API calls or data processing for each item

5

6 of 43

Collection Methods

  • Invoked with the --CollectionMethod or -c flag
  • Allows you to specify WHAT is collected
  • Main Collection Methods: All, Default, DCOnly
  • Each individual collection method has an LDAP filter which are joined with each option you specify

6

7 of 43

Default Collection

  • SharpHound.exe
  • A bit outdated (this is basically BloodHound 1.0!)
  • Default Collection includes the following
    • Group Membership
    • Local Groups (RDP, DCOM, Local Admin)
    • Session Collection
    • Trusts
  • Touches
    • Domain Controllers for LDAP
    • Every computer for Local Group/Session collection

7

8 of 43

All Collection

  • SharpHound.exe -c All
  • All Collection collects EVERYTHING that SharpHound is capable of collecting
    • Excludes the LoggedOn collection method, which requires privilege
    • Excludes GPO Local Group collection as direct querying is more accurate
    • Add LoggedOn by doing -c All, LoggedOn (great for defensive runs!)
  • Touches
    • Domain Controller for LDAP
    • Every computer for sessions/local groups

8

9 of 43

DCOnly Collection

  • SharpHound.exe -c DCOnly
  • DCOnly Collection includes the following
    • Group Membership
    • ACL Collection
    • Container Collection
    • Object Properties
    • Trusts
    • GPO Local Group Collection
  • Touches
    • Domain Controllers for LDAP
    • Domain Controllers to read GPO Files

9

10 of 43

Stealth

  • SharpHound.exe -c All --Stealth
  • Activate by adding --Stealth
  • Is a modifier for other collection methods, NOT a seperate collection method
  • Sessions
    • Limits session collection to Domain Controllers and “File Servers”
    • File Servers are determined from homedirectory, scriptpath, profilepath
  • Local group collection from GPOs (Equivalent to GPOLocalGroup)

10

11 of 43

Lesser Known Options

  • ExcludeDC - Removes Domain Controllers from session collection. Bypasses ATA (that we know of)
  • LdapFilter - Appends an LDAP filter onto the query builder
  • PingTimeout - Defaults to 200ms. Up this on laggy environments for better data
  • Throttle/Jitter - Create variations in requests to fool IDS
  • NoSaveCache - Don’t drop the cache file to disk (opsec?)
  • RandomFileNames - Randomizes the JSON file names (opsec?)

11

12 of 43

Available Collection Methods

Hybrid

  • Default
  • All
  • DCOnly
  • ComputerOnly
  • LocalGroup

Individual

  • Group
  • GPOLocalGroup
  • RDP
  • DCOM
  • LocalAdmin

More

  • Session
  • LoggedOn
  • Container
  • ACL
  • Trusts
  • SPNTargets

12

13 of 43

Example Attack Path

14 of 43

14

15 of 43

Available Abusable Edges/Configs

Lateral movement:

  • AdminTo
  • ExecuteDCOM
  • CanRDP
  • SQLAdmin
  • AllowedToAct
  • AllowedToDelegate

ACL Edges:

  • GenericAll
  • AllExtendedRights
  • GenericWrite
  • WriteOwner
  • WriteDacl
  • Owns
  • ForceChangePassword
  • AddMember

ETC:

  • Kerberoast
  • AS-Rep Roast
  • HasSession
  • GpLink

15

16 of 43

Available Abusable Edges/Configs

Lateral movement:

  • AdminTo
  • ExecuteDCOM
  • CanRDP
  • SQLAdmin
  • AllowedToAct
  • AllowedToDelegate

ACL Edges:

  • GenericAll
  • AllExtendedRights
  • GenericWrite
  • WriteOwner
  • WriteDacl
  • Owns
  • ForceChangePassword
  • AddMember

ETC:

  • Kerberoast
  • AS-Rep Roast
  • HasSession
  • GpLink

16

17 of 43

ETC: Kerberoast

  • Original research by Tim Medin (@timmedin)
  • Offline password cracking…
    • By any domain authenticated principal
    • Against any user with a serviceprincipalname set*
  • One very big problem...

*Some caveats can apply, we will update this slide with a link to our colleague, Will Schroder’s, talk from earlier today

17

18 of 43

Finite Password Cracking Resources

  • Wasted effort on low privilege accounts
  • Limited keyspace explored per hash
  • This affects you whether you have…
    • 2 kerberoastable users
    • 200 kerberoastable users
    • 20,000 kerberoastable users
  • BloodHound lets us intelligently prioritize cracking effort

19 of 43

19

20 of 43

DON’T BE AFRAID TO ROLL UP YOUR SLEEVES

20

21 of 43

21

22 of 43

22

Count of kerberoastable users

MATCH (u:User {hasspn:true})

RETURN COUNT(u)

23 of 43

23

Count of kerberoastable users with a path to DA

MATCH (u:User {hasspn:true})

MATCH (g:Group {name:'DOMAIN ADMINS@CONTOSO.LOCAL'})

MATCH p = shortestPath(

(u)-[*1..]->(g)

)

RETURN u.name,LENGTH(p)

ORDER BY LENGTH(p) ASC

24 of 43

24

Most privileged kerberoastable users

MATCH (u:User {hasspn:true})

OPTIONAL MATCH (u)-[:AdminTo]->(c1:Computer)

OPTIONAL MATCH (u)-[:MemberOf*1..]->(:Group)-[:AdminTo]->(c2:Computer)

WITH u,COLLECT(c1) + COLLECT(c2) AS tempVar

UNWIND tempVar AS comps

RETURN u.name,COUNT(DISTINCT(comps))

ORDER BY COUNT(DISTINCT(comps)) DESC

25 of 43

Kerberoast JFRANK

25

26 of 43

26

27 of 43

27

The group IT00035 has the WriteOwner privilege against the user Bob.Accounting

The users added to IT00035 can edit the object owner attribute on the Bob.Accounting user object

Object owners can modify object DACLs (read: add/remove permissions against the object)

28 of 43

WriteOwner - Attack Plan

  1. Change the owner of BOB.ACCOUNTING to JFRANK
  2. Grant JFRANK the ForceChangePassword right against BOB.ACCOUNTING
  3. Change BOB.ACCOUNTING’s password (without knowing his current password)

28

29 of 43

29

30 of 43

30

31 of 43

Lateral Movement: AllowedToAct

  • Shorthand for “Allowed to Act on Behalf of Other Identity”
  • Abuse research by Elad Shamir (@elad_shamir)
  • Attribute on computer object called:
    • msDs-AllowedToActOnBehalfOfOtherIdentity

31

32 of 43

32

The user Bob.Accounting is Allowed To Act On Behalf Of Other Identities to the computer Accounting-001

The user Bob.Accounting is Allowed To Impersonate Other Identities to the computer Accounting-001

Accounting-001 trusts Bob.Accounting to Impersonate ANYONE ELSE against ANY SERVICE

IT’S KERBEROS DELEGATION!

33 of 43

AllowedToAct - Attack Plan

  • Determine which principal to impersonate
    1. Account cannot be marked as “sensitive”
    2. Account can’t belong to “Protected Users” group
    3. Account needs privilege on the target
  • Impersonate that principal
  • Execute privileged code on target computer

33

34 of 43

34

35 of 43

35

36 of 43

36

37 of 43

What Creates this Edge?

  • SPNTargets Collection Method (Included in All)
  • SharpHound will parse the serviceprincipalnames field of user accounts to find SQL SPNs
    • MSSQL/sqlbox01
  • Will do a port check on the targeted system to ensure the SQL port is open
  • Shout out to Scott Sutherland, Karl Fosaaen and Eric Gruber

37

38 of 43

Lateral Movement: SQLAdmin

  • To support kerberos authentication, the SQL user account must have an SPN
  • The user configured to start the service is very frequently a sysadmin for the SQL instance
  • MSSQL administration allows you to run commands on the host, often as a high privileged user/admin
  • Tons of MSSQL research and abuse in PowerUpSQL
  • Good old reliable xp_cmdshell
  • Tons of ways to exploit this!

38

39 of 43

SQLAdmin - Attack Plan

  • Confirm the MSSQL instance is accessible
  • Confirm your user is a SQL Sysadmin
  • Execute code on target computer

39

40 of 43

40

41 of 43

41

42 of 43

THANK YOU

  • @_wald0
  • @CptJesus
  • Specterops.io

BloodHound Slack:�https://bloodhoundgang.herokuapp.com

42

42

43 of 43

CREDITS

Special thanks to all the people who made and released these awesome resources for free:

  • Presentation template by SlidesCarnival

43