{"id":53879,"date":"2019-12-12T00:00:00","date_gmt":"2019-12-11T21:00:00","guid":{"rendered":"https:\/\/prohoster.info\/blog\/blog_prohoster\/problema-konfidentsialnosti-dannyh-v-active-directory"},"modified":"2020-02-18T14:01:49","modified_gmt":"2020-02-18T11:01:49","slug":"problema-konfidentsialnosti-dannyh-v-active-directory","status":"publish","type":"post","link":"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory","title":{"rendered":"Problem prywatno\u015bci danych w Active Directory","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Problem prywatno\u015bci danych w Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/75c9e3a02efe7a37321c3faba3c836e0.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nZajmowa\u0142em si\u0119 testowaniem penetracyjnym przy u\u017cyciu <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/powerview-for-penetration-testing\/\">PowerView<\/a><\/noindex> i u\u017cywa\u0142em go do pozyskiwania informacji o u\u017cytkownikach z Active Directory (zwanej dalej AD). W tym czasie koncentrowa\u0142em si\u0119 na gromadzeniu informacji o cz\u0142onkostwie w grupach zabezpiecze\u0144, a nast\u0119pnie wykorzysta\u0142em te dane do poruszania si\u0119 po sieci. W ka\u017cdym razie AD zawiera poufne dane o pracownikach, z kt\u00f3rych niekt\u00f3re rzeczywi\u015bcie nie powinny by\u0107 dost\u0119pne dla wszystkich w organizacji. W rzeczywisto\u015bci w systemach plik\u00f3w Windows istnieje ekwiwalentna <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/3-deadly-file-permissions-mistakes\/\">problem \u201eEveryone\u201d<\/a><\/noindex>, kt\u00f3ra r\u00f3wnie\u017c mo\u017ce by\u0107 wykorzystywana przez wewn\u0119trznych i zewn\u0119trznych przest\u0119pc\u00f3w.<\/p>\n<p>Ale zanim om\u00f3wimy problemy z poufno\u015bci\u0105 i sposoby ich rozwi\u0105zania, przyjrzyjmy si\u0119 danym przechowywanym w AD.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Active Directory to korporacyjny Facebook <\/h2>\n<p>\nAle w tym przypadku ju\u017c zaprzyja\u017ani\u0142e\u015b si\u0119 ze wszystkimi! Mo\u017ce nie wiesz o ulubionych filmach, ksi\u0105\u017ckach i restauracjach swoich koleg\u00f3w, ale AD zawiera wra\u017cliwe dane kontaktowe<br \/>\ni inne pola, kt\u00f3re mog\u0105 by\u0107 wykorzystywane przez haker\u00f3w, a nawet osoby wewn\u0119trzne bez specjalnych umiej\u0119tno\u015bci technicznych.<\/p>\n<p>Administratorzy system\u00f3w z pewno\u015bci\u0105 znaj\u0105 zrzut ekranu poni\u017cej. To interfejs Active Directory Users and Computers (ADUC), w kt\u00f3rym ustalaj\u0105 i edytuj\u0105 informacje o u\u017cytkownikach oraz przypisuj\u0105 u\u017cytkownik\u00f3w do odpowiednich grup.<\/p>\n<p><img decoding=\"async\" alt=\"Problem prywatno\u015bci danych w Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/f64d75191b3c3b5f2ec0e300f8ee0b7f.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nAD zawiera pola z imieniem i nazwiskiem pracownika, adresem oraz numerem telefonu, dlatego przypomina ksi\u0105\u017ck\u0119 telefoniczn\u0105. Ale to nie wszystko! Na innych zak\u0142adkach znajduj\u0105 si\u0119 r\u00f3wnie\u017c adres e-mail i adres strony internetowej, bezpo\u015bredni prze\u0142o\u017cony oraz uwagi.<\/p>\n<p>Czy wszyscy w organizacji powinni widzie\u0107 te informacje, szczeg\u00f3lnie w epoce <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/we-know-about-your-companys-data-osint-lessons-for-c-levels\/\">OSINT<\/a><\/noindex>, kiedy ka\u017cdy nowy szczeg\u00f3\u0142 u\u0142atwia poszukiwanie dodatkowych informacji?<\/p>\n<p>Oczywi\u015bcie, \u017ce nie! Problem si\u0119 zaostrza, gdy dane wy\u017cszego kierownictwa firmy s\u0105 dost\u0119pne dla wszystkich pracownik\u00f3w.<\/p>\n<h2>PowerView dla wszystkich<\/h2>\n<p>\nTutaj do gry wchodzi PowerView. Oferuje bardzo wygodny interfejs PowerShell dla (i zawi\u0142ych) funkcji Win32, kt\u00f3re odnosz\u0105 si\u0119 do AD. Kr\u00f3tko m\u00f3wi\u0105c:<br \/>\nsprawia, \u017ce pozyskiwanie p\u00f3l z AD jest tak proste, jak wpisanie bardzo kr\u00f3tkiego polecenia.<\/p>\n<p>We will take the example of gathering information about the employee Cruella Deville, who is one of the executives of the company. For this, we will use the PowerView cmdlet get-NetUser:<\/p>\n<p><img decoding=\"async\" alt=\"Problem prywatno\u015bci danych w Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/1fe5f1772d4042d476f0a8d173932739.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nInstalling PowerView is not a serious issue \u2013 see for yourself on the page <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/PowerShellMafia\/PowerSploit\/tree\/master\/Recon\">github<\/a><\/noindex>. More importantly, you do not need elevated privileges to execute many PowerView commands, such as get-NetUser. Thus, a motivated but not very technically savvy employee can begin probing in AD with little effort.<\/p>\n<p>From the screenshot above, it can be seen that an insider can quickly learn a lot of new information about Cruella. Did you also notice that the 'info' field reveals details about personal habits and the user's password?<\/p>\n<p>This is not a theoretical possibility. From <noindex><a rel=\"nofollow\" href=\"https:\/\/info.varonis.com\/recorded-webinar\/basic-pen-testing-techniques-en\">conversations with other pentesters<\/a><\/noindex> I learned that they scan AD for passwords in unencrypted form, and unfortunately, these attempts are often successful. They know that companies are careless with information in AD and generally are unaware of the next topic \u2013 permissions in AD.<\/p>\n<h2>Active Directory has its own ACLs<\/h2>\n<p>\nThe AD Users and Computers interface allows you to set permissions for AD objects. There are ACLs in AD, and administrators can grant or deny access through them. You need to click 'Advanced' in the ADUC View menu, and then when you open a user, you will see the 'Security' tab where you set the ACL. <\/p>\n<p>In my scenario with Cruella, I did not want all authenticated users to see her personal information, so I denied them read access:<\/p>\n<p><img decoding=\"async\" alt=\"Problem prywatno\u015bci danych w Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/d23fdce2d51fca00abc4af8e292936d6.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nNow a regular user will see this if they try Get-NetUser in PowerView:<\/p>\n<p><img decoding=\"async\" alt=\"Problem prywatno\u015bci danych w Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/f27c39df9915865816b060b3111f4dcf.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nI was able to hide sensitive information from prying eyes. To maintain access for relevant users, I created another ACL to allow members of the VIP group (Cruella and her other high-ranking colleagues) to access this confidential data. In other words, I implemented AD permissions based on a role model, making sensitive data inaccessible to most employees, including insiders.<\/p>\n<p>However, you can make group membership invisible to users by appropriately setting the ACL for the group object in AD. This will help in terms of privacy and security.<\/p>\n<p>In my <noindex><a rel=\"nofollow\" href=\"https:\/\/www.varonis.com\/blog\/powerview-for-penetration-testing\/\">serie epickich pentest\u00f3w<\/a><\/noindex> Pokaza\u0142em, jak mo\u017cna porusza\u0107 si\u0119 po systemie, badaj\u0105c cz\u0142onkostwo w grupach za pomoc\u0105 PowerViews Get-NetGroupMember. W moim scenariuszu ograniczy\u0142em dost\u0119p do cz\u0142onkostwa w konkretnej grupie do odczytu. Widzisz wynik polecenia przed i po zmianach:<\/p>\n<p><img decoding=\"async\" alt=\"Problem prywatno\u015bci danych w Active Directory\" src=\"\/wp-content\/uploads\/2019\/12\/4b0393315480c6dad9b57cf6289a3f00.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nUda\u0142o mi si\u0119 ukry\u0107 cz\u0142onkostwo Cruelli i Montiego Burnsa w grupie VIP, co utrudni\u0142o hakerom i informatorom rozpoznawanie infrastruktury.<\/p>\n<p>Ten post mia\u0142 na celu zmotywowanie ci\u0119 do dok\u0142adniejszego zapoznania si\u0119 z polami<br \/>\nAD i zwi\u0105zanymi z nimi uprawnieniami. AD to doskona\u0142e \u017ar\u00f3d\u0142o, ale pomy\u015bl, jak chcia\u0142by\u015b<br \/>\ndzieli\u0107 si\u0119 poufnymi informacjami i danymi osobowymi, szczeg\u00f3lnie<br \/>\ngdy mowa o pierwszych osobach w twojej organizacji. \u00a0<br \/>\n<br \/>\u0179r\u00f3d\u0142o: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/varonis\/blog\/479814\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430 \u043f\u0440\u043e\u043d\u0438\u043a\u043d\u043e\u0432\u0435\u043d\u0438\u0435 \u0441 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043d\u0438\u0435\u043c PowerView \u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b \u0435\u0433\u043e \u0434\u043b\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f\u0445 \u0438\u0437 Active Directory (\u0434\u0430\u043b\u0435\u0435 \u2013 AD). \u0412 \u0442\u043e \u0432\u0440\u0435\u043c\u044f \u044f \u0434\u0435\u043b\u0430\u043b \u0430\u043a\u0446\u0435\u043d\u0442 \u043d\u0430 \u0441\u0431\u043e\u0440\u0435 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043e \u0447\u043b\u0435\u043d\u0441\u0442\u0432\u0435 \u0432 \u0433\u0440\u0443\u043f\u043f\u0430\u0445 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u0438, \u0430 \u0437\u0430\u0442\u0435\u043c \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b \u044d\u0442\u0443 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e, \u0447\u0442\u043e\u0431\u044b \u043f\u0435\u0440\u0435\u043c\u0435\u0449\u0430\u0442\u044c\u0441\u044f \u043f\u043e \u0441\u0435\u0442\u0438. \u0412 \u043b\u044e\u0431\u043e\u043c \u0441\u043b\u0443\u0447\u0430\u0435, AD \u0441\u043e\u0434\u0435\u0440\u0436\u0438\u0442 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043e \u0441\u043e\u0442\u0440\u0443\u0434\u043d\u0438\u043a\u0430\u0445, \u043d\u0435\u043a\u043e\u0442\u043e\u0440\u044b\u0435 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-53879","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"pl_PL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 Active Directory | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-12-11T21:00:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-02-18T11:01:49+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Problem prywatno\u015bci danych w Active Directory | ProHoster","description":"Zajmowa\u0142em si\u0119 testowaniem na.","canonical_url":"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"pl_PL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043a\u043e\u043d\u0444\u0438\u0434\u0435\u043d\u0446\u0438\u0430\u043b\u044c\u043d\u043e\u0441\u0442\u0438 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 Active Directory | ProHoster","og:description":"\u042f \u0437\u0430\u043d\u0438\u043c\u0430\u043b\u0441\u044f \u0442\u0435\u0441\u0442\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f\u043c\u0438 \u043d\u0430.","og:url":"https:\/\/prohoster.info\/pl\/blog\/administrirovanie\/problema-konfidentsialnosti-dannyh-v-active-directory","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-12-11T21:00:00+00:00","article:modified_time":"2020-02-18T11:01:49+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"53879","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-24 09:08:21","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 20:16:27","updated":"2026-01-24 09:08:21","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/53879","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/comments?post=53879"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/posts\/53879\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/media?parent=53879"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/categories?post=53879"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/pl\/wp-json\/wp\/v2\/tags?post=53879"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}