← All posts
#

Active Directory

8 posts

HTB Authority: Medium Walkthrough – Ansible Vault, LDAP Pass-Back, and ADCS ESC1
HTB · Medium

HTB Authority: Medium Walkthrough – Ansible Vault, LDAP Pass-Back, and ADCS ESC1

Anonymous SMB access to an Ansible playbook leaks a vault password, which cracks open a chain of credential pivots — an LDAP pass-back attack against a password manager — and ends in a full ADCS ESC1 compromise of the domain.

Medium
HTB Administrator: Medium Walkthrough – ACL Abuse Chain to Targeted Kerberoasting and DCSync
HTB · Medium

HTB Administrator: Medium Walkthrough – ACL Abuse Chain to Targeted Kerberoasting and DCSync

A single set of low-privilege AD credentials unlocks a chain of ACL abuses — GenericAll, ForceChangePassword, and GenericWrite — that leads to a targeted Kerberoasting attack and finally a DCSync, dumping the Administrator hash straight out of the domain.

Medium
HTB Voleur: Medium Walkthrough – Kerberos-Only AD, Targeted Kerberoasting & Tombstone Revival to Domain Admin
HTB · Medium

HTB Voleur: Medium Walkthrough – Kerberos-Only AD, Targeted Kerberoasting & Tombstone Revival to Domain Admin

A Kerberos-only domain controller forces every tool into Kerberos mode. An encrypted spreadsheet leaks service account passwords, a WriteSPN ACL enables targeted Kerberoasting, and AD's rarely-abused deleted-object restore feature resurrects a leaver account whose leftover DPAPI secrets cascade all the way to a WSL root shell holding a full NTDS.dit backup.

Medium
StreamIO — SQL Injection to RFI, Firefox Creds, and LAPS Abuse on a Windows DC
HTB · Medium

StreamIO — SQL Injection to RFI, Firefox Creds, and LAPS Abuse on a Windows DC

MSSQL injection on a movie streaming site leaks password hashes, chained with LFI and a dangerous PHP eval() to land a shell — then Firefox saved passwords and BloodHound ACL abuse lead to reading LAPS and becoming Administrator.

Medium
TombWatcher — AD Privilege Chain to ESC15 (CVE-2024-49019) Domain Takeover
HTB · Medium

TombWatcher — AD Privilege Chain to ESC15 (CVE-2024-49019) Domain Takeover

A five-hop BloodHound chain — WriteSPN → Kerberoast → gMSA dump → password resets → WinRM — leads to a deleted AD account holding ESC15 (CVE-2024-49019) rights on an ADCS template, ultimately yielding Domain Admin via PassTheCert over Schannel.

Medium
Checkpoint — BadSuccessor CVE-2025-29810 + VM Memory Forensics
HTB · Medium Non-retired

Checkpoint — BadSuccessor CVE-2025-29810 + VM Memory Forensics

From a malicious VS Code extension to Domain Admin via a fresh 2025 AD privilege escalation — BadSuccessor (CVE-2025-29810) chained with VM memory forensics.

Medium
Forest — AS-REP Roasting et DCSync via Exchange permissions
HTB · Easy

Forest — AS-REP Roasting et DCSync via Exchange permissions

AS-REP Roasting sur un compte sans pré-auth Kerberos, puis abus des permissions Exchange WriteDACL pour obtenir DCSync et dumper les hashes NTDS.

Easy
ESC1 à ESC8 — comprendre chaque vecteur d'attaque ADCS
ADCS

ESC1 à ESC8 — comprendre chaque vecteur d'attaque ADCS

Tour d'horizon complet des 8 vecteurs d'attaque ADCS : conditions requises, exploitation, et détection.