Latest

PenTest – Password – AD User Comment

There are 3-4 fields that seem to be common in most Active Directory schemas: UserPassword, UnixUserPassword, unicodePwd and msSFU30Password. Password in User Description crackmapexec ldap domain.lab -u 'username' -p 'password' -M user-desc crackmapexec
Read More

PenTest – Kerberos – Tickets

Tickets are used to grant access to network resources. A ticket is a data structure that contains information about the user’s identity, the network service or resource being
Read More

PenTest- Kerberos – Bronze Bit

CVE-2020-17049 An attacker can impersonate users which are not allowed to be delegated. This includes members of the Protected Users group and any other users explicitly configured as sensitive and cannot
Read More

PenTest – Internal – Shares

READ Permission Some shares can be accessible without authentication, explore them to find some juicy files ShawnDEvans/smbmap – a handy SMB enumeration tool smbmap -H 10.10.10.10 # null
Read More

Internal – PXE Boot Image

PXE allows a workstation to boot from the network by retrieving an operating system image from a server using TFTP (Trivial FTP) protocol. This boot over the network
Read More