Priv Esc

Outbound object rights

Generic all

  • We are going to create a new machine account

  • When you create accounts in AD you can specify the password

  • Now that we know the password the machine account, we can use it so sign tickets

  • We can then grab the SID

  • We then add the ability for to act on the behalf of other identities to the new computer

  • This will allow the computer to sign Kerberos rickets for other users other than itself (S4U)

  • Now we can forge a ticket from the Administrator that comes this machine and machines in the domain will trust it

  • Use the ticket to get a pop a shell

Test permissions

10 machines can be created

Paste contents into ticket.kirbi.b64 and remove spaces

Last updated

Was this helpful?