Certificate PrivEsc
Certificate-Based Privilege Escalation in Active Directory leverages misconfigurations in certificate infrastructure to elevate privileges. Attackers often exploit certificate-based authentication mechanisms, such as Kerberos delegation or certificate impersonation, to gain unauthorized access to sensitive resources. This section explores advanced techniques for exploiting certificate-based vulnerabilities in AD environments.
Kerberos Delegation and Certificate Impersonation¶
Kerberos delegation allows services to act on behalf of users, but misconfigured permissions can enable attackers to impersonate service accounts using certificates. For example, if a user has access to a certificate issued to a privileged service (e.g., krbtgt), they can use it to forge Kerberos tickets and escalate privileges.
Example: Requesting a Certificate via Certipy
certipy request -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS> -template <TEMPLATE_NAME>
<TEMPLATE_NAME> with a certificate template that grants elevated privileges (e.g., UserAccountControl-Admin).
Example: Using the Certificate for Impersonation
certipy dump -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS> -certificate <CERT_FILE>
kerberos or mimikatz to forge tickets.
Exploiting Certificate Revocation Lists (CRLs)¶
Certificate revocation lists (CRLs) are used to invalidate compromised certificates. Attackers may exploit CRL bypasses or incomplete revocation checks to reuse revoked certificates. For instance, if a certificate is revoked but not properly checked during authentication, it can be used for privilege escalation.
Example: Checking CRL Status
Example: Bypassing CRL Checks
Attackers may use tools like certutil to manually update the CRL cache or manipulate the CRLDistributionPoints extension in a certificate to point to a malicious server.
Certipy for Certificate-Based Attacks¶
Certipy is a powerful tool for interacting with AD CS and managing certificates. It can be used to request, dump, and exploit certificates for privilege escalation.
Example: Enumerating Certificate Templates
Example: Requesting a Certificate with Specific Permissions
certipy request -dc-ip <DC_IP> -target <DOMAIN> -username <USER> -password <PASS> -template "UserAccountControl-Admin"
Key takeaways¶
- Kerberos delegation can be exploited if a user has access to a privileged certificate.
- CRL bypasses allow attackers to reuse revoked certificates if revocation checks are incomplete.
- Certipy is essential for requesting, dumping, and exploiting certificates in AD environments.
- Always verify certificate templates and revocation policies to identify potential misconfigurations.