GenericWrite on User (Hugo -> Ramon)
Last updated
Last updated
As we just set up Hugo.Chavez's password we will now exploit the GenericWrite from hugo.Chavez to Ramon.Maldonado
This could be abuse with 3 different ways :
shadowCredentials (windows server 2016 or +)
targetKerberoasting (password should be weak enough to be cracked)
logonScript (this need a user connection and to be honest it never worked or unless with a script already inside sysvol)
First let’s do a target Kerberoasting, the principle is simple. Add an SPN to the user, ask for a tgs, remove the SPN on the user.
And now we can crack the TGS just like a classic kerberoasting.
Shutdown have done a tool which do all the work for you : https://github.com/ShutdownRepo/targetedKerberoast