module

VMware vCenter Secrets Dump

Disclosed
Apr 15, 2022
Created
Nov 2, 2022

Description

Grab secrets and keys from the vCenter server and add them to
loot. This module is tested against the vCenter appliance only;
it will not work on Windows vCenter instances. It is intended to
be run after successfully acquiring root access on a vCenter
appliance and is useful for penetrating further into the
environment following a vCenter exploit that results in a root
shell.

Secrets include the dcAccountDN and dcAccountPassword for
the vCenter machine which can be used for maniuplating the SSO
domain via standard LDAP interface; good for plugging into the
vmware_vcenter_vmdir_ldap module or for adding new SSO admin
users. The MACHINE_SSL, VMCA_ROOT and SSO IdP certificates with
associated private keys are also plundered and can be used to
sign forged SAML assertions for the /ui admin interface.

Authors

npm npm@cesium137.io
Erik Wynter
h00die

Platform

Linux,Unix

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use post/linux/gather/vcenter_secrets_dump
msf post(vcenter_secrets_dump) > show actions
...actions...
msf post(vcenter_secrets_dump) > set ACTION < action-name >
msf post(vcenter_secrets_dump) > show options
...show and set options...
msf post(vcenter_secrets_dump) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.