Extracting SSH Private Keys From Windows 10 SSH-agent (2018)
blog.ropnop.com
blog.ropnop.com
I'd love to know (I don't have a suitable machine available at the moment) if they can pull this off as a regular user, my feeling is probably not.
It seems as if the Linux approach is more honest. "You're root? Okay, you can have access to your SSH-keys. Be careful."
It's about how well you secure your machines, regulate behaviour and ensure good platform hygiene, the OS you're running is irrelevant.
I speak as a platform agnostic shared hoster guy who managed fleets of Windows and Linux environments, all public facing, and inherited an unholy security mess many years ago, both Windows and Linux, and had to unfuck it all. I could go into detail for the curious.
Actually even root will get plenty of permission denied errors on a Linux system configured for security.
1. You need admin access to reach the data.
2. The user has to have entered their password to allow DPAPI to unencrypt the data.
3. The data is stored in a binary form because that was the most convenient.
The DPAPI stuff wasn't just obfuscation, if that's what you're thinking. The steps you need are going to look roughly the same if you want to access someone's encrypted files on linux. It doesn't transparently decrypt the data, but that's because the encryption isn't built into the registry, not because it's trying to keep it away from you.
So in a sense we know its possible but unless someone abuses these things to demonstrate it, organizations won't care or be able to detect compromises and lateral movement. Real world adversaries do these things, most notably was when Google was throughly compromised by a foreign nation state for instance.
Also, it gets even more interesting for malware if its running on a bastion host because then malware has access to all the forwarded keys!
Maybe it's the deep cynic in me that tends to read these articles as another "oh look Windows bad" write up, rather than analyse what can happen if a stealthy attacker gains access to your machine and covers their footprints. These write ups get passed around in a sensationalised manner with very little thought about or understanding that the OS was functioning correctly given their user privileges.
This is why enabling ssh agent forwarding is something that should be evaluated on a per connection basis. You don't want to forward the agent holding your home keys to your work machine where someone else has root access.
But then again, the author didn't claim to do anything special, it was just a little demonstration.
I’m not sure the author knows this. He points out that this is useful for post-exploitation data gathering. That is, you’ve already compromised a machine/account and are looking to gather as much potentially useful information as possible. But he puts “securely” in scare quotes, which is not honest because this is secure storage: if you’re not authenticated, the key can’t be read. The encryption key is derived from the user password, so it can’t be defeated by offline reading either.
Unless they are on smartcards, there's always a way to compromise keys like this.
Admin accounts have access to everything, whether that's the registry, or a subdir in your user profile dir. That's the whole point of admin rights. Whether your private key is in a file in an .ssh dir or stored in the registry, admins can always get to them.
Yup. It's like saying you're able to read the private key out of ~/.ssh/id_rsa because you're logged in as the user, though with more steps because you need to deserialize the key from the internal representation. If you want this to not be possible even when logged in as the user, then use a hardware token like a smart card or smart-card-capable security key.
Could still be useful for post-exploitation as the OP mentions.
This quote actually summarizes it:
> I wasn’t very familiar with DPAPI
Well, neither do I, but at least know the basics!https://en.wikipedia.org/wiki/Data_Protection_API