GWS - Workspace Sync Attacks (GCPW, GCDS, GPS, Directory Sync with AD & EntraID)
Last updated
Last updated
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
Hii ni njia ya kuingia moja kwa moja ambayo Google Workspaces inatoa ili watumiaji waweze kuingia kwenye kompyuta zao za Windows wakitumia vithibitisho vyao vya Workspace. Aidha, hii itahifadhi tokens za kufikia Google Workspace katika maeneo kadhaa kwenye PC: Disk, kumbukumbu & rejista... hata inawezekana kupata nenosiri la wazi.
Note that Winpeas is capable to detect GCPW, get information about the configuration and even tokens.
Find more information about this in:
Hii ni zana ambayo inaweza kutumika kusawazisha watumiaji na vikundi vya active directory kwenye Workspace yako (na si kinyume chake wakati wa kuandika hii).
Ni ya kuvutia kwa sababu ni zana ambayo itahitaji vithibitisho vya mtumiaji mkuu wa Workspace na mtumiaji mwenye mamlaka ya AD. Hivyo, inaweza kuwa inawezekana kuipata ndani ya seva ya kikoa ambayo itakuwa ikisawazisha watumiaji mara kwa mara.
Note that Winpeas is capable to detect GCDS, get information about the configuration and even the passwords and encrypted credentials.
Find more information about this in:
Hii ni binary na huduma ambayo Google inatoa ili kuweka nenosiri za watumiaji zikiwa sawa kati ya AD na Workspace. Kila wakati mtumiaji anapobadilisha nenosiri lake katika AD, linawekwa kwa Google.
Inasakinishwa katika C:\Program Files\Google\Password Sync
ambapo unaweza kupata binary PasswordSync.exe
ili kuikamilisha na password_sync_service.exe
(huduma ambayo itaendelea kufanya kazi).
Note that Winpeas is capable to detect GPS, get information about the configuration and even the passwords and encrypted credentials.
Find more information about this in:
Tofauti kuu kati ya njia hii ya kusawazisha watumiaji na GCDS ni kwamba GCDS inafanywa kwa mikono na binaries ambazo unahitaji kupakua na kuendesha wakati Admin Directory Sync haina seva inayoendeshwa na Google katika https://admin.google.com/ac/sync/externaldirectories.
Find more information about this in:
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)