#
Pass-the-Hash
2 posts
HTB Administrator: Medium Walkthrough – ACL Abuse Chain to Targeted Kerberoasting and DCSync
A single set of low-privilege AD credentials unlocks a chain of ACL abuses — GenericAll, ForceChangePassword, and GenericWrite — that leads to a targeted Kerberoasting attack and finally a DCSync, dumping the Administrator hash straight out of the domain.
HackTheBox - Jeeves Writeup | Windows Medium
Unauthenticated Jenkins Script Console leads to RCE, a KeePass database is cracked to obtain an NTLM hash, and Pass-the-Hash grants SYSTEM access before extracting the root flag from an NTFS Alternate Data Stream.