PetitPotam: recommended actions to neutralize this attack

PetitPotam: an NTLM relay attack

PetitPotam is an attack technique identified by security researcher Lionel GILLES.

This attack belongs to the NTLM relay family. NTLM (NT LAN Manager) is an authentication protocol widely used in Microsoft technologies. NTLM relies on a "challenge/response" technique. This method allows users to prove their identity without transmitting a password, using cryptographic hash calculations. The NTLM concept works as follows:

  • the user knows their username and password;
  • the target server also knows the user's username and password;
  • the user proves their identity by receiving a value, adding their password to it, and calculating a cryptographic hash;
  • the target server performs the same operation and calculates the same cryptographic hash;
  • the user then transmits the hash, and the target server compares it to the one it calculated, thereby verifying the legitimacy of the connection.

An "NTLM relay" attack involves forcing a targeted user to connect to a compromised system, then relaying the resulting requests to the service being attacked. This allows the attacker to solve the challenge-response process on behalf of another user, thereby achieving privilege escalation.

The PetitPotam attack forces a domain controller to send a request to an NTLM service controlled by the attacker, using the MS-EFSRPCAPI. If successful, the attacker gains full control over the domain controller.

PetitPotam will not be patched by Microsoft

Microsoft states in article KB5005413 that:

  • PetitPotam is a classic NTLM relay attack;
  • Numerous documented technical recommendations are available to neutralize these attacks.

Consequently, Microsoft has stated that PetitPotam will not receive security patches. It is up to each organization to implement the appropriate countermeasures on their domain controllers to prevent this attack.

Which systems are affected by PetitPotam?

ANSSI specifies in its bulletin CERTFR-2021-ACT-032 that PetitPotam targets "servers where Active Directory Certificate Services (AD CS) are not configured with protections against NTLM relay attacks. The mitigation measures described in KB5005413 instruct users on how to protect their AD CS servers against such attacks."

ANSSI also indicates that networks where NTLM authentication is enabled within a domain are potentially vulnerable if the following "Active Directory Certificate Services (AD CS)" are in use: Certificate Authority Web Enrollment and Certificate Enrollment Web Service.

Are there any attack kits or exploits available to use PetitPotam?

Lionel GILLES (topotam) has published an exploit on GitHub, which uses the LSARPC and EFSRPC named pipes via the c681d488-d850-11d0-8c52-00c04fd90f7e and df1941c5-fe89-4e79-bf10-463657acf44d interfaces.

How can PetitPotam be neutralized?

The simplest approach today, which generates the fewest side effects, is to add RPC filters. In this case, these filters are added at the network level, on the User Mode (UM) layer, to block requests on the interfaces used by PetitPotam.

Benjamin Delpy suggests the following procedure, which is also recommended by Bleeping Computer:

  1. On your desktop, create a file named " block_efsr.txt " containing the following lines:

rpc
filter
add rule layer=um actiontype=block
add condition field=if_uuid matchtype=equal data=c681d488-d850-11d0-8c52-00c04fd90f7e
add filter
add rule layer=um actiontype=block
add condition field=if_uuid matchtype=equal data=df1941c5-fe89-4e79-bf10-463657acf44d
add filter
quit

  1. Click "Start," search for "cmd," and launch "Command Prompt" as an Administrator.
  2. Next, in the Command Prompt, run:

netsh -f %userprofile%\desktop\block_efsr.txt

You can then verify that the procedure was successful using the command:

netsh rpc filter show filter

If we break down the block_efsr.txt file line by line, it consists of:

  • Adding a rule (add rule) to block (actiontype=block) at the user layer (layer=um for User Mode)
  • Set the rule activation condition to use a UUID (field=if_uuid) with a value equal (matchtype=equal) to one of the UUIDs used by PetitPotam (c681d488-d850-11d0-8c52-00c04fd90f7e for LSARPC and df1941c5-fe89-4e79-bf10-463657acf44d for EFSRPC)

To remove the rules configured in this way, simply run the following command:

netsh rpc filter show filter

Then note the filterKey values used by the 2 PetitPotam filters, and run:

netsh rpc filter delete filter filterkey=<filter_key_to_delete>

In addition to this relatively effective and low-impact approach, Microsoft also recommends enabling EPA (Extended Protection for Authentication) and disabling HTTP on servers using AD CS. Cyberwatch leaves it to the reader to decide whether to apply these measures in addition to or as a replacement for RPC filters.

Cyberwatch Compliance Manager offers a compliance rule to verify the presence of RPC filtering rules on your domain controller. Please feel free to request a demo via the dedicated form.

Thanks for submitting the form.