ADCS
4 posts
HTB Authority: Medium Walkthrough – Ansible Vault, LDAP Pass-Back, and ADCS ESC1
Anonymous SMB access to an Ansible playbook leaks a vault password, which cracks open a chain of credential pivots — an LDAP pass-back attack against a password manager — and ends in a full ADCS ESC1 compromise of the domain.
VulnCicada — ADCS ESC8 relay via PetitPotam coercion to Domain Admin
NFS share leaks a user password hidden in an image post-it note; NTLM is disabled forcing Kerberos-only auth; ESC8 web enrollment relay via PetitPotam coercion yields a DC certificate and full domain compromise.
TombWatcher — AD Privilege Chain to ESC15 (CVE-2024-49019) Domain Takeover
A five-hop BloodHound chain — WriteSPN → Kerberoast → gMSA dump → password resets → WinRM — leads to a deleted AD account holding ESC15 (CVE-2024-49019) rights on an ADCS template, ultimately yielding Domain Admin via PassTheCert over Schannel.
ESC1 à ESC8 — comprendre chaque vecteur d'attaque ADCS
Tour d'horizon complet des 8 vecteurs d'attaque ADCS : conditions requises, exploitation, et détection.