Category: Control and IT

I built it, I protected it, and I hacked it.

  • Naming Artworks with Help from Bots: From Celestial Arachnid to Ringscape Skyline

    Naming Artworks with Help from Bots: From Celestial Arachnid to Ringscape Skyline

    In the old days, my digital artworks were numbered:Reality and Imagination #0 to #12. Then I started Atoll of Diffraction and immediately christened each artwork, giving it a title like Peek through the Peaks. It added another interesting step to the creative process! So, I needed to make Reality and Imagination complete as well! After…

  • Found Poetry from nanoGPT’s Sampling of elkemental Text

    Found Poetry from nanoGPT’s Sampling of elkemental Text

    Will the internet end in the implosion of all that self-referential mess? Will AI generate text from AI-generated text from AI-generated text? Let me be part of that! I used to create Found Poetry from my own articles (and my own poems), but I better make myself redundant and let AI help me! I fed…

  • Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually

    Lord of the SID: How to Add the objectSID Attribute to a Certificate Manually

    In May 2022 Microsoft has fixed a vulnerability related to certificate logon to Active Directory. As a non-privileged user you could escalate privileges by impersonating a Domain Controller, as you can join machines to the domain and thus control the dnsHostName attribute. Microsoft fixed this in an indirect way: Since last May, Windows Certification Authority…

  • Defused That SAN Flag!

    Defused That SAN Flag!

    In May, Microsoft has fixed a bug that allowed normal users to impersonate Domain Controllers. This bug allowed non-privileged users to obtain a logon certificate issued to a domain controller, because users can write to the Active Directory attribute dnsHostName of a computer they have joined to the domain. If a machine can enroll for…

  • How to Add a Subject Alternative Name Safely

    How to Add a Subject Alternative Name Safely

    I am writing about that PKI stuff again. I am running out of ideas for catchy introductions. So, here is a new post with old code! In Active Directory a UPN is mapped to a user automatically if it matches a user’s LDAP attribute userPrincipalName (and a DNS SAN is mapped to dnsHostName).  A Windows…

  • Rogue Certificate Challenge: No Hardware Tokens, No Linux, Just a Web Server with Certificate Mapping.

    Rogue Certificate Challenge: No Hardware Tokens, No Linux, Just a Web Server with Certificate Mapping.

    I am back to my favorite security research: How to abuse certificates in a Windows / Active Directory environment! If an Active Directory integrated certification authority sign a certificate with a custom Subject Alternative Name of your choosing, you can impersonate any administrator in an AD forest. I’ve published two blog posts about how to…

  • Looking Back: Hacking and Defending Windows Public Key Infrastructure (ADCS)

    Looking Back: Hacking and Defending Windows Public Key Infrastructure (ADCS)

    I live at the fringes of the cybersecurity community. I have never attended infosec conferences. There will be a talk on PKI hacking at Blackhat 2021 soon: Top AD offensive security gurus are presenting comprehensive research on abusing ADCS (Active Directory Certificate Services). I only know about that, because I noticed backlinks from their article…

  • Secure Poetry: “I have been quite confident”

    Secure Poetry: “I have been quite confident”

    A poem from snippets of two postings on cybersecurity. Trying to carve words out of jargon. Details on the creative process at the bottom of the post. I have been quite confident I have been inspired In this simple way to find both options take note of an extra stealth factor I hardly ever visited…

  • Injecting an EFS Recovery Agent – and Let the Virus Scanner Help You!

    Injecting an EFS Recovery Agent – and Let the Virus Scanner Help You!

    How can you read files encrypted with Windows’s Encrypting File System if you neither have access to the owner’s encryption certificate and key and nor that of a legit data recovery agent (DRA) … but if you are a local administrator? This work is still inspired by the hackthebox machine Helpline. You were able to…

  • Parse Certificates Stored in the Windows Registry

    Parse Certificates Stored in the Windows Registry

    You can parse the binary blobs that represent certificates stored in the Windows registry with certutil correctly, even when the Windows Explorer / GUI tells you that this is not a certificate. certutil seems to be able to handle / ignore meta data better. Once upon a time I played with the machine Ethereal provided by…

  • Infinity

    Infinity

    New Year’s Eve 2019 seems infinitely far in the past. It was the first day news about this mysterious disease had been published in my country. Yet it seems infinitely far away at that time, somewhere in China. Today we see something glowing at the end of a weird long corridor. Despite horrible news, I…

  • The RSA Algorithm

    The RSA Algorithm

    You want this: Encrypt a message to somebody else – using information that is publicly available. Somebody else should then be able to decrypt the message, using only information they have; nobody else should be able to read this information. The public key cryptography algorithm RSA does achieve this. This article is my way of…

  • Impersonating a Windows Enterprise Admin with a Certificate: Kerberos PKINIT from Linux

    Impersonating a Windows Enterprise Admin with a Certificate: Kerberos PKINIT from Linux

    This is about a serious misconfiguration of a Windows Public Key Infrastructure integrated with Active Directory: If you can edit certificate templates, you can impersonate the Active Directory Forests’s Enterprise Administrator by logging on with a client certificate. You have a persistent credential that will also survive the reset of this admin’s password. In the…

  • Locating Domain Controllers and Spoofing Active Directory DNS Servers

    Locating Domain Controllers and Spoofing Active Directory DNS Servers

    Last year, hackthebox let me test something I have always found fascinating – and scary: You can impersonate any user in a Windows Active Directory Forest if you have control over the certificate templates of an AD-integrated Windows Public Key Infrastructure: Add extended key usages for smartcard logon to the template, enroll for the certificate,…

  • Helpline @ hackthebox: Injecting an EFS Recovery Agent to Read Encrypted Files

    Helpline @ hackthebox: Injecting an EFS Recovery Agent to Read Encrypted Files

    Another great machine has been retired on hackthebox.eu – Helpline by @egre55! Here is my ‘silly’ unintended way to root the box: You can get both the encrypted user and root flag via the cumbersome web RCE alone – if you wait for a legit user to just look at the file. This is unlikely…

  • Sizzle @ hackthebox – Unintended: Getting a Logon Smartcard for the Domain Admin!

    Sizzle @ hackthebox – Unintended: Getting a Logon Smartcard for the Domain Admin!

    My writeup – how to pwn my favorite box on hackthebox.eu, using a (supposedly) unintended path. Sizzle – created by @mrb3n813 and @lkys37en – was the first box on HTB that had my favorite Windows Server Role – the Windows Public Key Infrastructure / Certification Authority. This CA allows a low-privileged user – amanda –…

  • Simple Ping Sweep, Port Scan, and Getting Output from Blind Remote Command Execution

    Simple Ping Sweep, Port Scan, and Getting Output from Blind Remote Command Execution

    Just dumping some quick and dirty one-liners! These are commands I had used to explore locked-down Windows and Linux machines, using bash or powershell when no other binaries were available or could be transferred to the boxes easily. Trying to ping all hosts in a subnet Linux for i in $(seq 1 254); do host=192.168.0.$i;…

  • Echo Unreadable Hex Characters in Windows: forfiles

    Echo Unreadable Hex Characters in Windows: forfiles

    How to transfer small files to a locked-down Windows machine? When there is no option to copy, ftp, or http GET a file. When powershell is blocked so that you can only use Windows cmd commands? My first choice would be to use certutil: certutil is a built-in tool for certificate and PKI management. It…