News: 1627331471

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

You, too, can be a Windows domain controller and do whatever you like, with this one weird WONTFIX trick

(2021/07/26)


Microsoft completed a vulnerability hat-trick this month as yet another security weakness was uncovered in its operating systems. And this one doesn't even need authentication to work its magic.

The security shortcoming can be exploited using the wonderfully named [1]PetitPotam technique. It involves abusing Redmond's [2]MS-EFSRPC (Encrypting File System Remote Protocol) to take over a corporate Windows network. It seems ideal for penetration testers, and miscreants who have gained a foothold in a Windows network.

Specifically, security researcher Gilles Lionel found it was possible to use MS-EFSRPC force a device, including Windows domain controllers, to authenticate with a remote attacker-controlled NTLM relay. The [3]end result is an authentication certificate that grants the attacker domain-controller-level access to services, allowing them to commandeer the entire domain.

[4]

"PetitPotam takes advantage of servers," [5]said Microsoft , "where the Active Directory Certificate Services (AD CS) is not configured with protections for NTLM Relay Attacks."

[6]

[7]

Lionel published a proof-of-concept exploit, available from the above link, and Microsoft responded by burying the bad news in an [8]advisory released on Friday. The Windows giant described PetitPotam as "a classic NTLM relay attack," and noted that such attacks have a [9]long, long history .

Which does make us wonder: why does the problem linger on?

[10]Microsoft has a workaround for 'HiveNightmare' flaw: Nuke your shadow copies from orbit

[11]Securing the cloud while Windows burns: Microsoft pops CloudKnox in trolley

[12]Make-me-admin holes found in Windows, Linux kernel

[13]You'll want to shut down the Windows Print Spooler service (yes, again): Another privilege escalation bug found

Microsoft's preferred [14]mitigation is for administrators to simply disable NTLM authentication, although doing so could break any number of services and applications that depend on it. A variety of alternatives are also on offer, "listed in order of more secure to less secure."

Great.

[15]

The advisory makes grim reading for sysadmins pondering how to plug this latest WONTFIX issue. PetitPotam makes use of the Certificate Authority Web Enrollment service or Certificate Enrollment Web Service (depending on system) and, according to Lionel's PoC, uses the MS-EFSRPC EfsRpcOpenFileRaw function "to coerce Windows hosts to authenticate to other machines."

CERT/CC analyst Will Dormann summarized the attack:

nth time is the charm! Not sure what was up the first times, but this is a DEFAULT install/config of the Certification Authority WEb Enrollment (ADCS-Web-Enrollment) on a machine other than the DC.

Lowly domain-joined user to golden ticket.

No credentials required, even. [16]pic.twitter.com/EHxq17oT4p — Will Dormann (@wdormann) [17]July 23, 2021

Windows Server 2008 and up are affected, according to Microsoft's advisory, and, other than suggesting customers take NTLM mitigations, a fix for MS-EFSRPC does not appear to be incoming. We asked Microsoft and will update if it tells us anything more than to look at the advisory again.

"Microsoft are no[t] fixing this," [18]tweeted IT security guru Kevin Beaumont, "so you have an out-of-the-box no-auth to Domain Admin path on default config Active Directory environments now, attackers."

We'll leave the final word to Mimikatz creator Benjamin Delpy and await Microsoft's move... ®

Hey [19]@msftsecurity ... focusing on NTLM Relay & AD CS default configuration is interesting, but could you fix [MS-EFSR] first?

You (maybe?) know PetitPotam is primary about abusing [MS-EFSR] remote calls *without authentication*

> [20]https://t.co/hTE2JgBmPi

> [21]https://t.co/doK77F9cz2 [22]https://t.co/gsoweKbsrd [23]pic.twitter.com/Y26TYEvJow — 🥝 Benjamin Delpy (@gentilkiwi) [24]July 26, 2021

Get our [25]Tech Resources



[1] https://github.com/topotam/PetitPotam

[2] https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-efsr/08796ba8-01c8-4872-9221-1000ec2eff31

[3] https://blog.truesec.com/2021/07/25/mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-adv210003-kb5005413-petitpotam/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YP8weTiGhmPLFCf@37SwrAAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[5] https://support.microsoft.com/en-us/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YP8weTiGhmPLFCf@37SwrAAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YP8weTiGhmPLFCf@37SwrAAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[8] https://msrc.microsoft.com/update-guide/en-US/vulnerability/ADV210003

[9] https://docs.microsoft.com/en-us/security-updates/SecurityAdvisories/2009/974926

[10] https://www.theregister.com/2021/07/22/microsoft_hivenightmare/

[11] https://www.theregister.com/2021/07/22/microsoft_cloudknox/

[12] https://www.theregister.com/2021/07/21/windows_linux_privilege_escalation/

[13] https://www.theregister.com/2021/07/16/spooler_service_local_privilege_escalation/

[14] https://support.microsoft.com/en-gb/topic/kb5005413-mitigating-ntlm-relay-attacks-on-active-directory-certificate-services-ad-cs-3612b773-4043-4aa9-b23d-b87910cd3429

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YP8weTiGhmPLFCf@37SwrAAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[16] https://t.co/EHxq17oT4p

[17] https://twitter.com/wdormann/status/1418576755389083662?ref_src=twsrc%5Etfw

[18] https://twitter.com/GossiTheDog/status/1418990195169497099

[19] https://twitter.com/msftsecurity?ref_src=twsrc%5Etfw

[20] https://t.co/hTE2JgBmPi

[21] https://t.co/doK77F9cz2

[22] https://t.co/gsoweKbsrd

[23] https://t.co/Y26TYEvJow

[24] https://twitter.com/gentilkiwi/status/1419585218227363856?ref_src=twsrc%5Etfw

[25] https://whitepapers.theregister.com/



"Microsoft are no[t] fixing this,"

Version 1.0

I'm sure that they will "fix" it but we have to accept that fixing a security issue that we've discovered doesn't mean that there are no other security holes in the system. Every time this happens we're told that "It's been fixed" but then a week or two later we discover another issue - so how many problems are there out there? We're told that "it's fixed" but does anyone ever check the entire environment? This quote isn't a criticism, it's just the way life is and an accurate statement by someone who worked in this world all his life:

"The trouble with programmers is that you can never tell what a programmer is doing until its too late." - Seymour Cray

Right to repair

elsergiovolador

This is where bodies like CMA and Trading Standards should be intervening.

If company does not want to fix the software, they should be required to give up the source code to the customer, so they can get someone or a software shop to fix it for them.

It's crazy that this isn't even talked about.

Re: Right to repair

Nunyabiznes

Upvote, but...

Would this spell an end to Intellectual Property? Would that be a bad thing?

I don't know the answer to either of those questions, but you are correct there should be a conversation.

In love, she who gives her portrait promises the original.
-- Bruton