Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issues related to cross-forest (inter-realm) attacks #126

Open
jsdhasfedssad opened this issue Feb 17, 2023 · 0 comments
Open

Issues related to cross-forest (inter-realm) attacks #126

jsdhasfedssad opened this issue Feb 17, 2023 · 0 comments

Comments

@jsdhasfedssad
Copy link

jsdhasfedssad commented Feb 17, 2023

Hi,

I am trying out Certipy in a cross-forest (inter-realm) attack scenario. I have a bidirectional trust between the forests adlab.local and adlab2.local. ADCS is installed in the adlab.local forest and has IP 10.0.0.200. IP 10.0.0.203 belongs to the DC in the adlab2.local forest.

  • Issue 1: The domain group domain [email protected] has been given enrollment rights on the certificate template ESC1. Still, the find command does not output this. See the top at the below screenshot. Below that you can see that the ESC1 attack actually works for accounts from the adlab2.local forest.

  • Issue 2: Despite that abusing ESC1 using accounts from the adlab2.local forest works, one cannot use accounts from the same forest for authentication when using the find command. No matter which DC you target. See the bottom half of the screenshot.

certipy1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant