#
DCSync
2 posts
HTB Administrator: Medium Walkthrough – ACL Abuse Chain to Targeted Kerberoasting and DCSync
A single set of low-privilege AD credentials unlocks a chain of ACL abuses — GenericAll, ForceChangePassword, and GenericWrite — that leads to a targeted Kerberoasting attack and finally a DCSync, dumping the Administrator hash straight out of the domain.
Forest — AS-REP Roasting et DCSync via Exchange permissions
AS-REP Roasting sur un compte sans pré-auth Kerberos, puis abus des permissions Exchange WriteDACL pour obtenir DCSync et dumper les hashes NTDS.