BadSuccessor dMSA
Bad Successor dMSA
Tools:
Prerequisites:
Explanation
Enumeration and Exploitation
Windows
Linux
1) Install tools
2) Check for any writeable attributes for our user
3) Do the badSuccessor attack
4) Save the ccache file generated to the KRB5CCNAME environmental variable
5) Request a new service ticket
6) Save the newly created ccache file
7) Do DCSync
8) Log in as domain admin
Last updated