7MS #739: Tales of Pentest Pwnage – Part 89
Show notes
Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have never seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I'm absolutely going to say it was intentional and that I totally meant to do that.
Here's what we cover:
- A client that's actually doing the things – year two or three of testing this environment, and they had buttoned up so much that I had to dig deep. Great for them, freaking frustrating for me.
- Why my Kerberoasting success rate has fallen off a cliff – Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now.
- Selective poisoning vs. poison-all-the-things – a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn't get nearly enough love in blogs and videos.
- The relay that fired… and did something completely different than I expected – I saw the ntlmrelayx log scroll by, thought "yes, I've got DA," and then had a "wait, wait, whoa, what?" moment. I was honestly a little panicked.
- An ancient Exchange vulnerability comes back to bite – CVE-2021-34470 (vulnerable Exchange schema) turned out to be the fallback that got me a foothold I had no business having.
- My favorite evil privesc trick, revisited – queuing up a scheduled task that runs under an interactively logged-in DA's context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying.
- A bonus thing to always look for – scheduled tasks running under saved DA creds that point at a script you can edit. Add one little line to fire an evil command of your choice, and you're in like a dirty shirt.
Check us out at 7MinSec.com for pentesting, training, controls assessments and security miscellany, 7MinSec.club for our Substack and weekly TuesdayTOOLSday videos, and 7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above).