Attacks on Active Directory - Kerberos Delegation: *Exploitation of Active Directory using Kerberos Constrained Delegation
Jean Rosemond Dora, Ladislav Hluchý · 2024
Active Directory (AD) is generally designed for large-scale deployment. It is a core component that handles multiple authentication types, mainly in a large organization. Its complexity to configure and deploy can easily result in severe consequences. Several interesting attack vectors can be explored for attacking an active directory. For example, the Kerberos Delegation (KD) and the Object Security Permissions (OSP), play a great role in an analysis phase. When a weak or insecure configuration is detected, it can lead to a complete compromise of that company. Since AD is a large topic, we will embrace only the safer version of the KD, known as “Constrained Delegation (CD)”. More details about all the components of the KD and the OSP will be provided in our future work. This paper will mainly focus on the abuse of AD through the constrained delegation of the KD version. We will determine if any such possibility exists by priorly enumerating the domain users and the trusted authentication from inside the environment.