Attack Chain Summary
The full chain was:
Anonymous SMB
-> support-tools share
-> UserInfo.exe.zip
-> LDAP credential extraction
-> LDAP enum as ldap
-> support user password in LDAP attribute
-> create controlled computer account
-> set RBCD on DC$
-> S4U Administrator impersonation
-> dump secrets / execute as admin
Full Writeup: https://medium.com/@chokrihammedi/support-htb-writeup-99482db016ac
Video Walkthrough: https://www.youtube.com/watch?v=4XTPhktYgyk
Top comments (0)