[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUpL5ikzE1qT41DEdlGdb0-rgPe-H1V2FiiXgsjtD2sQ":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":33,"aiModel":30,"aiConfidence":30,"updatedAt":56,"createdAt":56,"_status":55},1259,"What key parameters are extracted by the vCenter_ExtraCertFromMdb.py script and how are they used in SAML authentication?","The script extracts the domain, idp_cert, trusted_cert_1, and trusted_cert_2. These parameters are used to forge a SAML request for an administrator user: the domain and certificates are employed by the SAML login tool (vcenter_saml_login.py) to authenticate against the vCenter server and obtain an administrator JSESSIONID cookie.\n\n---\n**Related reading:**\n- [vSphere Development Guide 6 - vCenter SAML Certificates](\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates) — original article\n- [Covenant Utilization Analysis](\u002Fnews\u002Fcovenant-utilization-analysis)\n- [ADAudit Plus Exploitation Analysis — Data Encryption Analysis](\u002Fnews\u002Fadaudit-plus-exploitation-analysis-data-encryption-analysis)\n- [Domain Penetration - Executing Programs on Remote Systems Using DCOM](\u002Fnews\u002Fdomain-penetration-executing-programs-on-remote-systems-using-dcom)","\u003Cp>The script extracts the domain, idp_cert, trusted_cert_1, and trusted_cert_2. These parameters are used to forge a SAML request for an administrator user: the domain and certificates are employed by the SAML login tool (vcenter_saml_login.py) to authenticate against the vCenter server and obtain an administrator JSESSIONID cookie.\u003Cbr>\u003Cbr>---\u003Cbr>**Related reading:**\u003Cbr>- [vSphere Development Guide 6 - vCenter SAML Certificates](\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates) — original article\u003Cbr>- [Covenant Utilization Analysis](\u002Fnews\u002Fcovenant-utilization-analysis)\u003Cbr>- [ADAudit Plus Exploitation Analysis — Data Encryption Analysis](\u002Fnews\u002Fadaudit-plus-exploitation-analysis-data-encryption-analysis)\u003Cbr>- [Domain Penetration - Executing Programs on Remote Systems Using DCOM](\u002Fnews\u002Fdomain-penetration-executing-programs-on-remote-systems-using-dcom)\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fvsphere-development-guide-6-vcenter-saml-certificates\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-key-parameters-are-extracted-by-the-vcenter_extracertfrommdbpy-script-and-h-1777477594270","vCenter_ExtraCertFromMdb.py, domain, idp_cert, trusted_cert, SAML request",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":27,"cover":30,"author":31,"views":19,"readingTime":32,"status":33,"publishedAt":34,"seo":35,"tags":39,"qaPairs":40,"meta":52,"updatedAt":53,"createdAt":54,"_status":55},297,"vSphere Development Guide 6 - vCenter SAML Certificates","vsphere-development-guide-6-vcenter-saml-certificates","Learn how to exploit vCenter SAML certificates for admin access, optimize scripts for vSphere 6, and implement defense strategies to secure your VMware environment.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>A recent exploitation technique I learned: Using administrator privileges on vCenter to extract the IdP certificate from \u002Fstorage\u002Fdb\u002Fvmware-vmdir\u002Fdata.mdb, create a SAML request for an administrator user, and finally authenticate using the vCenter server to obtain a valid administrator cookie.\u003C\u002Fp>\u003Cp>Intuitive understanding: From local administrator privileges on vCenter to administrator access to the VCSA management panel.\u003C\u002Fp>\u003Cp>Learning materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fwww.horizon3.ai\u002Fcompromising-vcenter-via-saml-certificates\u002F\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhorizon3ai\u002Fvcenter_saml_login\u003C\u002Fp>\u003Cp>This article will improve the code based on the learning materials, enhance its versatility, and provide defense recommendations in conjunction with exploitation ideas.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Method reproduction\u003C\u002Fli>\u003Cli>Script optimization\u003C\u002Fli>\u003Cli>Exploitation ideas\u003C\u002Fli>\u003Cli>Defense Recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Method Reproduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Testing on Kali System\u003C\u002Fp>\u003Cp>Install Openssl:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>apt install python3-openssl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>1. Obtain Database File from vCenter\u003C\u002Fh3>\u003Cp>Path: \u002Fstorage\u002Fdb\u002Fvmware-vmdir\u002Fdata.mdb\u003C\u002Fp>\u003Cp>vCenter Administrator Privileges Required\u003C\u002Fp>\u003Ch3>2. Run the Script\u003C\u002Fh3>\u003Cp>Download URL:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Fhorizon3ai\u002Fvcenter_saml_login\u002Fblob\u002Fmain\u002Fvcenter_saml_login.py\u003C\u002Fp>\u003Cp>Command Parameter Example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>python3 .\u002Fvcenter_saml_login.py -t 192.168.1.1 -p data.mdb\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Command Line Return Result:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>JSESSIONID=XX533CDFA344DE842517C943A1AC7611\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>3. Log in to the VCSA management panel\u003C\u002Fp>\u003Cp>Access https:\u002F\u002F192.168.1.1\u002Fui\u003C\u002Fp>\u003Cp>Set Cookie: JSESSIONID=XX533CDFA344DE842517C943A1AC7611\u003C\u002Fp>\u003Cp>Successfully logged into the management panel as administrator\u003C\u002Fp>\u003Ch2>0x03 Script Optimization\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Typically, the size of data.mdb is at least 20MB\u003C\u002Fp>\u003Cp>To reduce interaction traffic, choose to modify vcenter_saml_login.py to be usable directly under vCenter\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Python is installed by default on vCenter\u003C\u002Fp>\u003Cp>Specifically, the following issues need to be considered when modifying the script:\u003C\u002Fp>\u003Ch3>1. Remove the reference to the third-party package bitstring\u003C\u002Fh3>\u003Cp>The approach I adopted is to streamline the content of the third-party package bitstring and directly insert it into the Python script\u003C\u002Fp>\u003Ch3>2. Avoid using f-string formatting\u003C\u002Fh3>\u003Cp>Python 3.6 introduced a new f-string formatting feature\u003C\u002Fp>\u003Cp>vCenter 6.7 uses Python 3.5.6, which does not support the 'f' prefix for formatted string literals\u003C\u002Fp>\u003Cp>The approach I adopted was to use the format method for string formatting\u003C\u002Fp>\u003Cp>For example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cn = stream.read(f'bytes:{cn_len}').decode()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Replaced with:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cn = stream.read('bytes:{}'.format(cn_len)).decode()\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>vCenter_ExtraCertFromMdb.py can be uploaded to vCenter and executed directly. After execution, the following four important parameters will be obtained:\u003C\u002Fp>\u003Cul>\u003Cli>domain, displayed in the command line\u003C\u002Fli>\u003Cli>idp_cert, saved as idp_cert.txt\u003C\u002Fli>\u003Cli>trusted_cert_1, saved as trusted_cert_1.txt\u003C\u002Fli>\u003Cli>trusted_cert_2, saved as trusted_cert_2.txt\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Next, a SAML request can be created for the administrator user on any host, using the vCenter server for authentication to obtain a valid administrator cookie. The complete code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Parameter description is as follows:\u003C\u002Fp>\u003Cul>\u003Cli>target: URL of the VCSA management panel\u003C\u002Fli>\u003Cli>hostname: Corresponds to the CN in the certificate Subject attribute of the VCSA management panel\u003C\u002Fli>\u003Cli>domain: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>idp_cert path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>trusted_cert_1 path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003Cli>trusted_cert_2 path: Can be obtained from data.mdb using vCenter_ExtraCertFromMdb.py\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Exploitation Approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. From vCenter local administrator privileges to VCSA management panel administrator access\u003C\u002Fh3>\u003Cp>Prerequisite: Gained vCenter local administrator privileges through a vulnerability\u003C\u002Fp>\u003Cp>Exploitation effect:\u003C\u002Fp>\u003Cp>Obtain administrator access to the VCSA management panel, enabling interaction with virtual machines manageable by vCenter\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>At this point, administrator users can also be added via the LDAP database using the method described in 'vSphere Development Guide 5 - LDAP', enabling interaction with virtual machines manageable by vCenter.\u003C\u002Fp>\u003Ch3>2. Obtain data.mdb from vCenter backup files\u003C\u002Fh3>\u003Cp>Prerequisite: Need to obtain the correct data.mdb file\u003C\u002Fp>\u003Cp>Exploitation effect:\u003C\u002Fp>\u003Cp>Gain administrator access to the VCSA management panel, enabling interaction with virtual machines manageable by vCenter\u003C\u002Fp>\u003Ch2>0x05 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Apply patches to prevent attackers from obtaining vCenter local administrator privileges\u003C\u002Fp>\u003Cp>2. Avoid leakage of vCenter backup files in use\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces optimization ideas for vcenter_saml_login, enhances its generality, and provides defense recommendations based on exploitation approaches.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr",null,"Onedaysec",3,"published","2026-02-02T07:25:19.682Z",{"title":36,"description":14,"keywords":37,"ogImage":30,"canonicalUrl":30,"noIndex":38},"vSphere vCenter SAML Certificates Exploit & Defense Guide","vSphere, vCenter, SAML certificates, exploit, VCSA, administrator access, security, defense, VMware, penetration testing",false,[],{"docs":41,"hasNextPage":51},[42,43,44,45,4,46,47,48,49,50],1263,1262,1261,1260,1258,1257,1256,1255,1254,true,{"title":30,"description":30,"image":30},"2026-07-24T02:07:12.323Z","2026-07-23T16:02:42.134Z","draft","2026-07-23T16:17:43.924Z"]