Exploit acl with external trust golden ticket

  • Ok now imagine we want to exploit this acl from Maryland:

By now i didn’t found a nice way to do this from linux, but from windows it is pretty easy

  • Connect as administrator on baltimore, disable the antivrius to be able to use mimikatz and powerview

  • Create the golden ticket with mimikatz matching the group CentralPark(RID 1130)

  • And now use powerview to change diego.Montenegro password

  • And it work !

  • And if we look at the created tickets with klist:

    • Server: krbtgt/maryland.local @ maryland.local (golden ticket)

    • Server: krbtgt/NEWYORK.LOCAL @ MARYLAND.LOCAL (kdc: baltimore) (tgt inter realm)

    • Server: ldap/nyc.newyork.local @ NEWYORK.LOCAL (kdc: NYC)

    • Server: ldap/nyc.newyork.local/newyork.local @ NEWYORK.LOCAL (kdc: nyc)

Last updated