Login attempt with wrong domain name with trusted domain can lead to account lockout
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 35/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- csharp
调研方向
Start with the SharpHound.exe command and trace how --Domain, --domaincontroller, --ldapusername, and --ldappassword are used when collecting data from trusted domains. Reproduce the two-domain setup described in the issue, then verify that repeated collection does not attempt authentication as the trusted-domain username or cause those accounts to lock out.
由索引模型根据 Issue 内容生成。
描述
Description:
I executed SharpHound.exe (Version 2.0.0) on a none-domain-joined machine and provided the target domain, domain controller and ldap credentials via arguments. I expected that all required login attempts to collect the data would use as account name <provided_domain>\<provided_username>. However, when data was collected for trusted domains, the logins were performed using <trusted_domain>\<provided_username>. Since the same user account name existed in the other trusted domains (but with different passwords), this increased the "incorrect login attempts" count. After several executions this lead to a lockout of the user account in all trusted domains.
I'm unsure if this behavior is intended and that I just called SharpHound the wrong way, but I was expecting that all logins would be performed with the ldap username with the provided domain name. Or do I need to also specify the domain with the ldap username argument?
Steps to Reproduce:
-
Create a network with two domains (DomainA.NET and DomainB.NET and create a trust relationship between them) with the same username in both domains but with different passwords.
In my case I tested it with a domain administrator account, e.g.: "DomainA.NET\DomainAdmin" with password "Password1" and "DomainB.NET\DomainAdmin" with password "Password2" -
Create a Windows Client (in my case it was Windows 10 system which was not domain joined) and execute the following command on the system:
SharpHound.exe --CollectionMethods All,GPOLocalGroup,SPNTargets,LoggedOn --collectallproperties --memcache --Domain DomainA.NET --domaincontroller DC01.DomainA.NET --ldapusername DomainAdmin --ldappassword Password1
- Execute the command multiple times until the configured account lockout treshhold is reached. => "DomainB.NET\DomainAdmin" will get locked because SharpHound will attempt to perform a login as LDAP user "DomainAdmin" also in DomainB because of the trust relationship, however, this user has as password "Password2" and not "Password1".
Expected Behavior:
I expected that all logins would be performed as "DomainA.NET\DomainAdmin" user, even when querying data from "DomainB.NET". Actually, I also assumed that no connections to DC01.DomainB.NET would be established and that no logins with accounts in DomainB would be attempted.
I expected that the "--Domain" and "--ldapusername" flags are combined to form the final username which is used to perform the login and not that a login as "DomainB.NET\DomainAdmin" is attempted at all.
Actual Behavior:
A login as "DomainB.NET\DomainAdmin" is attempted which can lead to an account lockout after multiple executions.
Environment Information:
BloodHound: -
Collector: 2.0.0
- 主要语言
- C#
- 星标
- 1.4k
- 派生
- 264
- 平均合并
- 10 分钟
- 30 天内合并 PR
- 3
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
SpecterOps/SharpHound 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 48/100
SpecterOps/SharpHound#203 · 2 条评论 · 3 个 reaction ·
-
难度 4/5 3-5 天 新手友好度 42/100
SpecterOps/SharpHound#194 ·
-
难度 4/5 3-5 天 新手友好度 42/100
SpecterOps/SharpHound#185 · 1 条评论 · 1 个 reaction ·
-
难度 4/5 3-5 天 新手友好度 35/100
SpecterOps/SharpHound#177 · 7 条评论 · 1 个 reaction ·
-
难度 5/5 一周以上 新手友好度 20/100
SpecterOps/SharpHound#169 · 1 条评论 · 3 个 reaction ·
查看 SpecterOps/SharpHound 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 66/100
MicrosoftLearning/PL-400_Microsoft-Power-Platform-Developer#231 ·
-
难度 2/5 1-3 小时 新手友好度 66/100
joinrpg/joinrpg-net#5313 ·
维护者通常 1 天内回复
-
[12.x] FixIncorrectOwnerIdRelationships can delete legitimate library roots when UserView shares the same path可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 74/100
-
难度 2/5 1-3 小时 新手友好度 79/100
维护者通常 1 天内回复