Posts

  • RPC Encryption – An Exercise in Frustration

    Since of the release of Windows LAPS and the introduction of encrypted passwords I’ve been working towards a way of decrypting these payloads on non-Windows platforms. One of the key components of getting this working is to not only have a working RPC client but also support the RPC authentication level RPC_C_AUTHN_LEVEL_PKT_PRIVACY. I’ve worked with GSSAPI/SSPI before and thought this should be relatively simple, this is a tale of what is actually involved for others interested in the top. I won’t be going into too much details on the RPC process, I just wanted to focus on the authentication and subsequent message encryption details I found were not documented, or not very detailed.

  • Kerberos Delegation

    When authenticating against a server across the network a common problem that people encounter is the inability to access downstream servers like a file share. This is because the network session that is running the code does not have access to the account’s secret to regenerate the network tokens required to access that downstream server. This is commonly known as the double-hop problem in WinRM and is common enough to warrant its own docs to demonstrate the problem and mention workarounds. Some of those workarounds are:

  • Wacky WSMan on Linux

    A few years ago I jumped from doing all my dev work on Windows to Linux. This migration has had a few challenges but one of the things I struggled with initially was the lack of native tooling that can be used to easily and seamlessly interact with other Microsoft products. I’ve typically found some great open source products that fill in that gap quite nicely, but one area that has always felt a bit lacking was support for PSRemoting. There are some fantastic WSMan/WinRM client libraries out there which are pretty close to feature parity with WSMan on Windows but typically lack 2 main features, being interactive and directly integrated in PowerShell.

  • Windows mapped drives – what the hell is going on?

    Mapped drives have always been a curiosity for me, I’ve used them before in the past but usually come across an issue that forces me to abandon them. Alongside my curiosity, there has also been some demand in Ansible to be able to manage mapped drives and in my naivety I created a very basic module win_mapped_drive to do this. At the time it worked for what I needed to do and I had to use some hacks and workarounds to actually enumerate the existing mappings when running in WinRM. I should have read the warning signs then and given up but I pushed on ahead and the module was released with Ansible 2.4. We are now in the 2.8 development phase and there’s been a few issues crop up on GitHub saying the module doesn’t work as expected. I decided to take the time to look into the complex world of mapped drives and come up with a more satisfactory solution for managing them with Ansible.

  • Windows host through SSH bastion on Ansible

    A use case I’ve been asked about a few times is to be able to connect to a Windows host through another bastion host. In the context of this post, a bastion host is “a server that is placed on the boundary of an internal network and provides access to this network from another external network”.

  • PowerShell Remoting on Python

    One thing I am looking into everyday as part of my job is how to make the remote management of Windows servers easier. Currently the best way is through WinRM but as I’ve written about before, WinRM can be such a vague term. It can mean refer to different technologies and the answer to what is WinRM depends on who you ask and in what context. When talking about third party implementations, like Ansible/pywinrm; it refers to the raw Windows Remote Shell (WinRS) over the WSMan transport protocol. Whereas, a Windows admin, would probably be talking about the PowerShell remoting protocol through things like the Invoke-Command, Enter-PSSession PowerShell cmdlets.

  • Decrypting the secrets of Ansible Vault in PowerShell

    Ansible Vault is a pretty nifty tool that allows people to easily encrypt secrets for use in Ansible. It’s a builtin tool that can be use to encrypt secrets and make them easily usable for Ansible.

  • Introducing PsExec for Python

    Over the past few months I’ve been trying to find a way that gives people more options around running commands on a Windows host remotely. Currently you have a few options available to you that enable this;

  • Demystifying WinRM

    One of the most common problems I come across today when it comes to remotely managing Windows is dealing with WinRM and its inconsistencies. I wanted to create a blog post that will help people understand what goes on with WinRM a bit more so that they can better use this resource on Windows. This blog post will cover the following part of WinRM

  • Using Packer to create Windows images

  • Managing Windows Servers with Ansible

subscribe via RSS