Exploiting Microsoft Windows Active Directory Certificate Service | CVE-2022-26923

  Рет қаралды 9,178

Motasem Hamdan | Cyber Security & Tech

Motasem Hamdan | Cyber Security & Tech

Күн бұрын

Пікірлер
@guitarware
@guitarware 2 жыл бұрын
Thank you for this vulnerability breakdown and for even going through how ADCS works, very helpful. Liked and subbed
@eslammohamed7877
@eslammohamed7877 2 жыл бұрын
great video as usual how can i know ADCS hostname if i fully black box or i can just use DC hostname
@ダレモコーン-q2l
@ダレモコーン-q2l 2 жыл бұрын
Great video! It gives me a better understanding of AD and vulnerabilities. I have one question. What software is used in the video when you explain with diagrams? I ask because I think it is a good software that can explain things clearly.
@MotasemHamdan
@MotasemHamdan 2 жыл бұрын
Thanks. Software name is OpenBoard.
@ダレモコーン-q2l
@ダレモコーン-q2l 2 жыл бұрын
@@MotasemHamdan Thank you👍
@baconblaster6422
@baconblaster6422 Жыл бұрын
Great breakdown ! Subbed
@steak2254
@steak2254 Жыл бұрын
Please tell me, will I be able to exploit the invulnerability of CVE-2022-26923 with Certify.exe instead of certipy?
@افلامكعليمزاجك
@افلامكعليمزاجك 2 жыл бұрын
Cool
@wolfrevokcats7890
@wolfrevokcats7890 6 ай бұрын
0:07 doesn't make sense? Why?
@diegocondori5673
@diegocondori5673 2 жыл бұрын
nice
@Yashovardhan777
@Yashovardhan777 2 жыл бұрын
will this CVE-2022-26923 is applicable for Azure AD or on-prem or both?
@MotasemHamdan
@MotasemHamdan 2 жыл бұрын
Both.
@Yashovardhan777
@Yashovardhan777 2 жыл бұрын
@@MotasemHamdan thanks
@solofonantenaina5975
@solofonantenaina5975 2 жыл бұрын
Hello, i have an issue when i tried to request a TGT. I have this error: Kerberos SessionError: KDC_ERR_PADATA_TYPE_NOSUPP. And Can you explain please, why you have a ssh connection into the domain controller? Thank you,
@solofonantenaina5975
@solofonantenaina5975 2 жыл бұрын
My bad i forgot to request a certificate for the KDC that's why i got this error. But other thant that, can you explain please why you have ssh connexion to the domain controller? I thought the thm user has a low privileges.
@siripongjintung6316
@siripongjintung6316 2 жыл бұрын
When i got NTLM hash for the machine account. Can i "pass the hash" on NTLM hash ?
@MotasemHamdan
@MotasemHamdan 2 жыл бұрын
You can try :)
@siripongjintung6316
@siripongjintung6316 2 жыл бұрын
@@MotasemHamdan I send my issue to your mail. Please review on it.
@CyberCelt.
@CyberCelt. 2 жыл бұрын
I struggled today to pass it. Did you get it working? I wasn't sure what user the hash was for either. I think lunadc$...
@mohamedali8605
@mohamedali8605 2 жыл бұрын
Hi my friend I have 2 questions first you logged on the Lunar machine using ssh thm@ip & using password:Password1@ ???? second I keep getting this error when using Certipy failed to resolve lundc.lunar.eruca , is there something I'm missing my friend & thanks for all your efforts.
@mohamedali8605
@mohamedali8605 2 жыл бұрын
problem solved I didn't configure the DNS in the script at /etc/hosts thanks anyway for your efforts :) ;)
Understanding PrintNightmare Vulnerability | (CVE-2021-1675) and (CVE-2021-34527) TryHackMe
30:16
Motasem Hamdan | Cyber Security & Tech
Рет қаралды 5 М.
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 89 МЛН
What type of pedestrian are you?😄 #tiktok #elsarca
00:28
Elsa Arca
Рет қаралды 36 МЛН
How Many Balloons To Make A Store Fly?
00:22
MrBeast
Рет қаралды 152 МЛН
One day.. 🙌
00:33
Celine Dept
Рет қаралды 46 МЛН
How To Theme Linux USB Boot Menu
7:58
Gary Newell
Рет қаралды 7
Exploiting Windows RPC - CVE-2022-26809 Explained | Patch Analysis
7:15
ReCertifying Active Directory Certificate Services
40:19
Black Hat
Рет қаралды 6 М.
Domain Admin: Bloodhound, Mimikatz, Pass-The-Hash & Golden ticket.
10:42
ZeroLogon Exploit - Abusing CVE-2020-1472
8:07
The Cyber Mentor
Рет қаралды 78 М.
Windows Pentest Tutorial (Active Directory Game Over!)
1:49:45
David Bombal
Рет қаралды 241 М.
NVIDIA’s New AI: Stunning Voice Generator!
6:21
Two Minute Papers
Рет қаралды 92 М.
Why is Python 150X slower than C?
10:45
Mehul - Codedamn
Рет қаралды 25 М.
Why no RONALDO?! 🤔⚽️
00:28
Celine Dept
Рет қаралды 89 МЛН