Unconstrained Delegation
Active Directory (AD) unconstrained delegation is a critical misconfiguration that enables attackers to exploit Kerberos protocol weaknesses for credential theft and lateral movement. When a service account is configured with unconstrained delegation, it can request a Ticket Granting Service (TGS) ticket for any service on behalf of any user. This creates a pathway for Kerberos reflection attacks, where an attacker impersonates a user by leveraging the service account’s ability to forge tickets. Below, we explore how this exploitation unfolds.
Kerberos Reflection Attack Mechanics¶
-
Service Account Exploitation
A service account with unconstrained delegation can request a TGS ticket for itself using thekerberos::ticketcommand in tools like Mimikatz. Since the service account does not require the user’s password to request the ticket, the attacker can forge a ticket that appears to be issued to the user.
-
Ticket Forgery and Impersonation
The forged TGS ticket is then used to impersonate the user. For example, an attacker can use the ticket to access resources (e.g., file shares, databases) that the user has access to. The ticket’s validity is tied to the service account’s credentials, not the user’s, making this a stealthy attack vector. -
Credential Theft via DCSync
If the service account also has DCSync permissions, the attacker can exfiltrate Kerberos keys and other secrets from domain controllers. This allows them to decrypt tickets or request new ones, further enabling privilege escalation.
Tools and Techniques¶
-
Mimikatz:
-
CrackMapExec:
Automates Kerberos reflection attacks by leveraging service accounts with unconstrained delegation:
-
PowerShell:
Attackers can use PowerShell scripts to request TGS tickets and exfiltrate credentials:
Mitigation and Defense¶
-
Disable Unconstrained Delegation:
Ensure service accounts use constrained delegation instead, limiting their ability to request TGS tickets to specific services. -
Monitor for Anomalies:
Use SIEM tools to detect unusual Kerberos ticket requests or DCSync activity. -
Secure Service Accounts:
Avoid storing service account credentials in plaintext and enforce strong password policies.
Key takeaways¶
- Unconstrained delegation allows attackers to forge Kerberos tickets for any user, enabling impersonation and credential theft.
- Kerberos reflection attacks exploit this by leveraging service accounts to request TGS tickets without user passwords.
- Tools like Mimikatz and CrackMapExec automate the extraction and exploitation of Kerberos credentials.
- Proper configuration (e.g., constrained delegation) and monitoring are critical to mitigating these risks.