Exploiting CVE-2022-26923 by Abusing AD CS | TryHackMe

preview_player
Показать описание
YOU CAN SUPPORT MY WORK BY BUYING A COFFEE
---------------------------------------------------

Learn how to Exploit CVE-2022-26923 by abusing AD CS (Active Directory Certificate Services). TryHackMe was quick enough to publish vulnerable lab, making it easier than ever to practice the exploit procedure. Certificates are complex and we barely touched the surface of the iceberg. Still I hope it was fun for you, if so:

❤️ Help the channel grow with a Like, Comment, & Subscribe!

JOIN MY DISCORD TO SHARE KNOWLEDGE AND EXPERIENCE
---------------------------------------------------

LINKS
---------------------------------------------------

Certifried: Active Directory Domain Privilege Escalation (CVE-2022–26923):

FOLLOW ME
---------------------------------------------------

TIMESTAMPS
--------------------------------------------------
00:00 - Intro
00:47 - Source Learning Materials Overview
01:34 - Explaining Certificate Granting Chain
04:07 - Some Terminology
05:50 - Explaining the Vulnerability
10:24 - TryHackMe Lab 1 (Abusing Certificate Templates with Certify and Rubeus)
28:15 - TryHackMe Lab 2 (CVE-2022-26923)
39:22 - Outro

Hope you learned something new.
Рекомендации по теме
Комментарии
Автор

Excellent video, this walkthrough was extremely helpful. Thanks!

TheBoomer
Автор

Great video! Really helped me out a lot.

ALinWrX
Автор

Thanks for posting -- excellent walk-through and explanation !

jjjww
Автор

Excellent thank you. I tried passing the hash today and struggled to login but never thought of secrets dump. Not sure what user it would be logging in as. Will try your way.

CyberCelt.