Open cardosec

Case FDD1B2 · Identity & AD · L5 Expert

RBCD Attack Chain

Practise as: Explain it · Interview · Deep dive

Interview questionYou hold GenericWrite on a server computer object. Walk me through turning that into admin on the server.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Write msDS-AllowedToActOnBehalfOfOtherIdentity on the target so it trusts a principal you control that has an SPN
  2. Get that principal by adding a machine account (default ms-DS-MachineAccountQuota is 10) or using a compromised SPN account
  3. S4U2Self gets a ticket to yourself as a privileged user; S4U2Proxy turns it into a service ticket to the target
  4. Blocked for Protected Users and accounts marked sensitive and cannot be delegated; set MachineAccountQuota to 0
  5. Detect: 5136 on msDS-AllowedToActOnBehalfOfOtherIdentity, 4741 new computer accounts, unusual S4U 4769 requests

If the interviewer pushes back

  • Why does RBCD still work when the S4U2Self ticket is not forwardable, unlike classic constrained delegation?
  • How would you chain NTLM relay to LDAP with RBCD, and which control breaks that chain?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.