• 7MS #668: Tales of Pentest Pwnage – Part 69

  • 2025/03/28
  • 再生時間: 30 分
  • ポッドキャスト

7MS #668: Tales of Pentest Pwnage – Part 69

  • サマリー

  • Hola friends! Today’s tale of pentest pwnage talks about abusing Exchange and the Azure ADSync account! Links to the discussed things:

    • adconnectdump – for all your ADSync account dumping needs!
    • Adam Chester PowerShell script to dump MSOL service account
    • dacledit.py (part of Impacket) to give myself full write privileges on the MSOL sync account: dacledit.py -action ‘write’ -rights ‘FullControl’ -principal lowpriv -target MSOL-SYNC-ACCOUNT -dc-ip 1.2.3.4 domain.com/EXCHANGEBOX$ -k -no-pass
    • Looking to tighten up your Exchange permissions – check out this crazy detailed post
    続きを読む 一部表示

あらすじ・解説

Hola friends! Today’s tale of pentest pwnage talks about abusing Exchange and the Azure ADSync account! Links to the discussed things:

  • adconnectdump – for all your ADSync account dumping needs!
  • Adam Chester PowerShell script to dump MSOL service account
  • dacledit.py (part of Impacket) to give myself full write privileges on the MSOL sync account: dacledit.py -action ‘write’ -rights ‘FullControl’ -principal lowpriv -target MSOL-SYNC-ACCOUNT -dc-ip 1.2.3.4 domain.com/EXCHANGEBOX$ -k -no-pass
  • Looking to tighten up your Exchange permissions – check out this crazy detailed post

7MS #668: Tales of Pentest Pwnage – Part 69に寄せられたリスナーの声

カスタマーレビュー:以下のタブを選択することで、他のサイトのレビューをご覧になれます。