Hackers could abuse legitimate Windows AD FS to steal data

The flaw in Microsoft authentication servers could enable threat actors to perform a Golden SAML attack

padlock in a tech setting

Security researchers have warned that hackers could easily abuse a Windows service to steal data from any organization using Active Directory in their network.

According to FireEye, the new attack could give hackers another way to take over Microsoft 365 accounts via a flaw in Active Directory Federated Services (AD FS). The attack echoes the recent SolarWinds attack.

AD FS is a feature for Windows Servers that enables federated identity and access management. Organizations often use it to provide single sign-on functionality to access enterprise applications such as Microsoft 365.

Hackers could spoof one AD FS server communicating to another AD FS to obtain its keys. The attack is not dissimilar to a Golden SAML attack that CyberArk coined in 2017. In that type of attack, hackers can access any application supporting SAML authentication with any privileges and be any user on the targeted application.

In the new attack, hackers could abuse the Policy Store Transfer Service to acquire the encrypted Token Signing Certificate over the network.

With previous techniques, hackers needed to execute remote code on an AD FS server to extract the data or at least an SMB connection to transfer the backing database files. The new attack requires only access to the AD FS server over the standard HTTP port. The default AD FS installation will create a Windows Firewall rule to allow HTTP traffic from any system.

“Additionally, a threat actor does not need the credentials for the AD FS service account and can instead use any account that is a local administrator on an AD FS server. Lastly, there is no Event Log message that is recorded when a replication event occurs on an AD FS server. Altogether, this makes the technique both much easier to execute and much harder to detect,” said Doug Bienstock, IR Manager at FireEye.

Bienstock said the authorization policy itself also presents an opportunity for abuse. Because the authorization policy is stored as XML text in the configuration database, a threat actor with enough access could modify it to be more permissive.

Related Resource

NETSCOUT threat intelligence report

Cyber crime: Exploiting a pandemic

Threat intelligence report - whitepaper from NETSCOUTDownload now

“A threat actor could modify the Authorization Policy to include a group SID such as domain users, S-1-5-21-X-513. Similarly, they could add an ACE to the DKM key container in Active Directory. This would allow the threat actor to easily obtain the Token Signing Certificate and decrypt it using any domain user credentials. This would give them persistent ability to perform a Golden SAML attack with only access to the network as a requirement,” Bienstock said.

While the attack has not yet been observed in the wild, writing a proof of concept would be trivial, according to Bienstock.

Researchers said the best mitigation against this technique is to use the Windows Firewall to restrict access to port 80 TCP to only the AD FS servers in the farm.

“If an organization has only a single AD FS server, then port 80 TCP can be blocked completely. This block can be put in place because all traffic to and from AD FS servers and proxies for user authentication is over port 443 TCP,” said Bienstock.

Featured Resources

The ultimate law enforcement agency guide to going mobile

Best practices for implementing a mobile device program

Free download

The business value of Red Hat OpenShift

Platform cost savings, ROI, and the challenges and opportunities of Red Hat OpenShift

Free download

Managing security and risk across the IT supply chain: A practical approach

Best practices for IT supply chain security

Free download

Digital remote monitoring and dispatch services’ impact on edge computing and data centres

Seven trends redefining remote monitoring and field service dispatch service requirements

Free download

Recommended

Microsoft shares more details about Android apps in Windows 11
Microsoft Windows

Microsoft shares more details about Android apps in Windows 11

20 Oct 2021
A quarter of all malicious JavaScript is obfuscated
hacking

A quarter of all malicious JavaScript is obfuscated

20 Oct 2021
Organizations warned of ransomware risk from smaller operators
ransomware

Organizations warned of ransomware risk from smaller operators

19 Oct 2021
WANdisco makes LiveData platform for Azure generally available
Microsoft Azure

WANdisco makes LiveData platform for Azure generally available

18 Oct 2021

Most Popular

Apple MacBook Pro 15in vs Dell XPS 15: Clash of the titans
Laptops

Apple MacBook Pro 15in vs Dell XPS 15: Clash of the titans

11 Oct 2021
Best Linux distros 2021
operating systems

Best Linux distros 2021

11 Oct 2021
HPE wins networking contract with Birmingham 2022 Commonwealth Games
Network & Internet

HPE wins networking contract with Birmingham 2022 Commonwealth Games

15 Oct 2021