{"id":53879,"date":"2019-12-12T00:00:00","date_gmt":"2019-12-11T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/problema-konfidentsialnosti-dannyh-v-active-directory"},"modified":"2020-02-18T14:01:49","modified_gmt":"2020-02-18T11:01:49","slug":"problema-konfidentsialnosti-dannyh-v-active-directory","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory","title":{"rendered":"The Data Privacy Issue in Active Directory","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"The Data Privacy Issue in Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/75c9e3a02efe7a37321c3faba3c836e0.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nI conducted penetration testing using <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/powerview-for-penetration-testing\/\">PowerView<\/a><\/noindex> and used it to extract user information from Active Directory (hereafter \u2013 AD). At that time, I focused on gathering information related to security group memberships, and then used this information to move laterally within the network. In any case, AD contains confidential information about employees, some of which really should not be accessible to everyone in the organization. In fact, there is an equivalent problem in Windows file systems, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/3-deadly-file-permissions-mistakes\/\">the \u2018Everyone\u2019 issue<\/a><\/noindex>, which can also be exploited by both internal and external attackers.<\/p>\n<p>But before we discuss privacy issues and how to address them, let\u2019s take a look at the data stored in AD.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Active Directory is like a corporate Facebook <\/h2>\n<p>\nBut in this case, you\u2019re already friends with everyone! You may not learn about your colleagues\u2019 favorite movies, books, and restaurants, but AD contains sensitive contact<br \/>\ninformation and other fields that can be exploited by hackers and even insiders with little technical skill.<\/p>\n<p>System administrators are certainly familiar with the screenshot below. This is the Active Directory Users and Computers (ADUC) interface, where they set and edit user information and assign users to appropriate groups.<\/p>\n<p><img decoding=\"async\" alt=\"The Data Privacy Issue in Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/f64d75191b3c3b5f2ec0e300f8ee0b7f.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAD contains fields with employee names, addresses, and phone numbers, making it similar to a phone book. But there\u2019s a lot more! Other tabs also include email addresses and web addresses, direct supervisors, and notes.<\/p>\n<p>Should everyone in the organization be able to see this information, especially in the age of <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/we-know-about-your-companys-data-osint-lessons-for-c-levels\/\">OSINT<\/a><\/noindex>, where every new detail makes the search for additional information even easier?<\/p>\n<p>Certainly not! The problem is compounded when the data of upper management is accessible to all employees.<\/p>\n<h2>PowerView for Everyone<\/h2>\n<p>\nThis is where PowerView comes into play. It provides a very user-friendly PowerShell interface for the underlying (and tangled) Win32 functions that interact with AD. In short:<br \/>\nit makes retrieving AD fields as easy as typing a very short cmdlet.<\/p>\n<p>Let's take the example of gathering information about employee Cruella Deville, who is one of the executives of the company. For this, we will use the PowerView cmdlet get-NetUser:<\/p>\n<p><img decoding=\"async\" alt=\"The Data Privacy Issue in Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/1fe5f1772d4042d476f0a8d173932739.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nInstalling PowerView is not a serious issue \u2013 see for yourself on the page <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/PowerShellMafia\/PowerSploit\/tree\/master\/Recon\">github<\/a><\/noindex>. More importantly, you do not need elevated privileges to execute many PowerView commands, such as get-NetUser. Thus, a motivated but not very technically savvy employee can start poking around in AD without much effort.<\/p>\n<p>From the screenshot above, it\u2019s clear that an insider can quickly learn a lot about Cruella. Did you also notice that in the 'info' field, personal habits and the user's password are revealed?<\/p>\n<p>This is not a theoretical possibility. From <noindex><a rel=\"nofollow\" href=\"https:\/\/info.varonis.com\/recorded-webinar\/basic-pen-testing-techniques-en\">conversations with other pentesters<\/a><\/noindex> I found out that they scan AD for passwords in unencrypted form, and often these attempts, unfortunately, succeed. They know that companies are careless with information in AD, and generally do not know about the next subject \u2013 permissions in AD.<\/p>\n<h2>Active Directory has its own ACLs<\/h2>\n<p>\nThe AD Users and Computers interface allows setting permissions for AD objects. AD has ACLs, and administrators can grant or deny access through them. You need to click 'Advanced' in the ADUC View menu, and then when you open a user, you will see the 'Security' tab where you set the ACL. <\/p>\n<p>In my scenario with Cruella, I did not want all authenticated users to see her personal information, so I denied them read access:<\/p>\n<p><img decoding=\"async\" alt=\"The Data Privacy Issue in Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/d23fdce2d51fca00abc4af8e292936d6.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAnd now a normal user will see this if they try Get-NetUser in PowerView:<\/p>\n<p><img decoding=\"async\" alt=\"The Data Privacy Issue in Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/f27c39df9915865816b060b3111f4dcf.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nI managed to hide potentially useful information from prying eyes. To maintain access for relevant users, I created another ACL to allow members of the VIP group (Cruella and her other high-ranking colleagues) to access this confidential data. In other words, I implemented AD permissions based on a role model, which made sensitive data unavailable to most employees, including insiders.<\/p>\n<p>However, you can make group membership invisible to users by appropriately setting the ACL for the group object in AD. This helps in terms of privacy and security.<\/p>\n<p>In my <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/powerview-for-penetration-testing\/\">series of epic pentests<\/a><\/noindex> I demonstrated how to navigate the system by exploring group membership using PowerViews Get-NetGroupMember. In my scenario, I restricted read access to the membership of a specific group. You can see the command output results before and after the changes:<\/p>\n<p><img decoding=\"async\" alt=\"The Data Privacy Issue in Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/4b0393315480c6dad9b57cf6289a3f00.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nI was able to hide the membership of Cruella and Monty Burns in the VIP group, making it more difficult for hackers and insiders to probe the infrastructure.<\/p>\n<p>This post was intended to motivate you to take a closer look at the fields<br \/>\nAD and the associated permissions. AD is a great resource, but think about how you<br \/>\nwould like to share sensitive information and personal data, especially,<br \/>\nwhen it comes to the executives in your organization. \u00a0<br \/>\n<br \/>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/varonis\/blog\/479814\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430 \u043f\u0440\u043e\u043d\u0438\u043a\u043d\u043e\u0432\u0435\u043d\u0438\u0435 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c PowerView \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b \u0435\u0433\u043e \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u0445 \u0438\u0437 Active Directory (\u0434\u0430\u043b\u0435\u0435 \u2013 AD). \u0412 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u044f \u0434\u0435\u043b\u0430\u043b \u0430\u043a\u0446\u0435\u043d\u0442 \u043d\u0430 \u0441\u0431\u043e\u0440\u0435 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e \u0447\u043b\u0435\u043d\u0441\u0442\u0432\u0435 \u0432 \u0433\u0440\u0443\u043f\u043f\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0430 \u0437\u0430\u0442\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b \u044d\u0442\u0443 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u043c\u0435\u0449\u0430\u0442\u044c\u0441\u044f \u043f\u043e \u0441\u0435\u0442\u0438. \u0412 \u043b\u044e\u0431\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435, AD \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043e \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u0445, \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-53879","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 Active Directory | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-11T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47The issue of data privacy in Active Directory | ProHoster","description":"I was engaged in testing.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 Active Directory | ProHoster","og:description":"\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-11T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53879","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 09:08:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:16:27","updated":"2026-01-24 09:08:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/53879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=53879"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/53879\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=53879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=53879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=53879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}