Protecting the keys to the castle! - Restricted Admin Credential Exposure

14
Protecting the keys to the castle Restricted Admin Credential Exposure Marcus Murray & Hasain Alshakarti Truesec Security Team, MVP-Enterprise Security x2

description

More info on http://techdays.be.

Transcript of Protecting the keys to the castle! - Restricted Admin Credential Exposure

Page 1: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Protecting the keys to the castle – Restricted Admin Credential Exposure

Marcus Murray & Hasain AlshakartiTruesec Security Team, MVP-Enterprise Security x2

Page 2: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Marcus Murray Hasain Alshakarti

Page 3: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Who doesn’t want to be domain admin?

Page 4: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Passing the dutchie

Web Srv Mail Srv

File SrvDC

Client

UserAdmin

Client

Attacker

Page 5: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Mitigating Passing the dutchie

• SMB Signing! On domain controllers!

Page 6: Protecting the keys to the castle! - Restricted Admin Credential Exposure

mimikatz• privilege::debug • inject::process lsass.exe sekurlsa.dll • @getLogonPasswords

• Passwords in CLEAR TEXT!!!

Page 7: Protecting the keys to the castle! - Restricted Admin Credential Exposure

The ”Mandiant report”

Page 8: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Local account depencencies

Web Srv Mail Srv

File SrvDC Mail Srv

Client

CliAdmCliAdm

Client

Attacker

SrvAdm SrvAdm

Page 9: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Logged on account depencencies

Web Srv Mail Srv

File SrvDC Mail Srv

Client

Marcus_DAMarcus_DA

Client

Attacker

Marcus_DA Marcus_DA

Page 10: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Complete mission

Web Srv Mail Srv

File SrvDC Mail Srv

Client

UserAdmin

Client

Attacker

Attacker

Page 11: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Microsoft PtH Mitigations

Page 12: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Protecting!• Local firewalls• Non-admin• Cutting dependencies• Managed service accounts• AMA

Page 13: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Marcus Murray Hasain Alshakarti

Page 14: Protecting the keys to the castle! - Restricted Admin Credential Exposure

Thank you for listening!