Exploit acl with external trust golden ticket
PreviousTrust ticket with external forest ( maryland.local-> newyork.local)NextExploiting IIS & Privilege escalation
Last updated
Last updated
Ok now imagine we want to exploit this acl from Maryland:
By now i didn’t found a nice way to do this from linux, but from windows it is pretty easy
Connect as administrator on baltimore, disable the antivrius to be able to use mimikatz and powerview
Create the golden ticket with mimikatz matching the group CentralPark(RID 1130)
And now use powerview to change diego.Montenegro password
And it work !
And if we look at the created tickets with klist:
Server: krbtgt/maryland.local @ maryland.local (golden ticket)
Server: krbtgt/NEWYORK.LOCAL @ MARYLAND.LOCAL (kdc: baltimore) (tgt inter realm)
Server: ldap/nyc.newyork.local @ NEWYORK.LOCAL (kdc: NYC)
Server: ldap/nyc.newyork.local/newyork.local @ NEWYORK.LOCAL (kdc: nyc)