Trusted (Chain)
This is not a writeup, just my notes about the machine.
Machine information

Credentials
Username
Password
Method
Scope
Information Gathering
10.10.222.117
10.10.222.118
Service enumeration
10.10.90.117
SMB (enum4linux-ng)
DNS
10.10.90.118
SMB (enum4linux-ng)
DNS
HTTP

Initial Foothold
Discovering File Path Traversal

Poisoning the User-Agent header.

Verifying the Success of the attack

Exploiting to obtain a reverse shell.

Compromise parent domain
Automatic ExtraSids Attack
Manual ExtraSids Attack
Extracting krbtgt's NTLM
Extracting Current Domain SID
Extracting Enterprise Admins SID Group
Crafting Golden Ticket
Performing DCSync Attack against trusted.vl
trusted.vl Privilege escalation on labdc via DLL Hijacking

Last updated