Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 55 guests and 2 members online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow New tool for finding domain admins for token theft
EH-Net
May 22, 2013, 02:42:19 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: New tool for finding domain admins for token theft  (Read 1842 times)
0 Members and 1 Guest are viewing this topic.
ajohnson
Recruiters
Hero Member
*
Offline Offline

Posts: 1057


aka dynamik


View Profile WWW
« on: November 08, 2012, 09:33:05 PM »

Hey everyone, I'm going to copy/paste what I sent to a SANS mailing list because I'm too tired to come up with something original. Please check out the blog article and give me some feedback.

When widespread local admin password reuse is detected on an engagement, finding privileged tokens to steal with incognito is a common next-step. There are already a few ways to automate finding privileged processes, but my solution seems to be faster and more flexible than most I've seen (granted, I could have totally missed something obvious). The only downside I've noticed thus far is that it fails on systems with UAC enabled.

I wrapped the Foofus winexe (which is patched to also accept hashes), threaded it, and basically used Tim Tome's technique of reviewing the output of tasklist on each system in an IP list. The script requires the credentials (password or hash) of the local admin account that's been reused, the target domain name, list of domain admins (or whatever list of users you're targeting), and SMB IPs. You can optionally specify the number of threads and timeout for winexe calls.

The tests I've done allowed me to analyze 120 systems in 104 seconds using 10 threads/30 second timeout, and 22 seconds using 80 threads/15 second timeout (diminishing returns). Also, this was over a WAN connection; that's just how the cookie crumbled on this engagement (the account names and IPs have obviously been changed to project the victims).

I have the script and a full write-up here: https://www.infosiege.net/2012/11/introducing-find-token-py/ This is the first "tool" I've published and am interested in feedback and constructive criticism. It worked well during this past engagement, so I figured I'd share it in case anyone else might find it useful.
Logged

WIP: GCFA | www.infosiege.net | @infosiege

The day you stop learning is the day you start becoming obsolete.
hayabusa
Hero Member
*****
Offline Offline

Posts: 1632



View Profile
« Reply #1 on: November 09, 2012, 05:50:09 AM »

Thanks!  I'll definitely give it a look.
Logged

~ hayabusa ~ 

"All men can see these tactics whereby I conquer, but what none can see is the strategy out of which victory is evolved." - Sun Tzu, 'The Art of War'


OSCE, OSCP , GPEN, C|EH
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #2 on: November 09, 2012, 07:26:55 AM »

Sweet, can think of plenty of times where this would have been helpful. Will test it out next opportunity I get.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.104 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.