<?xml version="1.0" encoding="utf-8"?>
<oembed>
  <version>1</version>
  <type>rich</type>
  <provider_name>Libsyn</provider_name>
  <provider_url>https://www.libsyn.com</provider_url>
  <height>90</height>
  <width>600</width>
  <title>7MS #693: Pwning Ninja Hacker Academy – Part 3</title>
  <description>This week your pal and mine Joe “The Machine” Skeen kept picking away at pwning&amp;amp;nbsp;Ninja Hacker Academy.&amp;amp;nbsp; To review where we’ve been in parts 1 and 2:  We found a SQL injection on a box called&amp;amp;nbsp;SQL,&amp;amp;nbsp;got a privileged Sliver beacon on it, and dumped mimikatz info From that dump, we used the&amp;amp;nbsp;SQL&amp;amp;nbsp;box hash to do a BloodHound run, which revealed that we had excessive permissions over the&amp;amp;nbsp;Computers&amp;amp;nbsp;OU We useddacledit.py&amp;amp;nbsp;to give ourselves too much permission on the&amp;amp;nbsp;Computers&amp;amp;nbsp;OU  Today we:  Did an RBCD attack against the&amp;amp;nbsp;WEB&amp;amp;nbsp;box Requested a service ticket to give us local admin superpowers on&amp;amp;nbsp;WEB Performed a secretsdump against&amp;amp;nbsp;WEB Struggled to do a mimikatz dump at the end of the episode (after we ended the stream I realized I could’ve just done the mimikatz dump because I had local admin access!&amp;amp;nbsp; Oh well, we’ll pick things up again during part 4 next month!)  </description>
  <author_name>7 Minute Security</author_name>
  <author_url>https://7MinSec.com</author_url>
  <html>&lt;iframe title="Libsyn Player" style="border: none" src="//html5-player.libsyn.com/embed/episode/id/38278300/height/90/theme/custom/thumbnail/yes/direction/forward/render-playlist/no/custom-color/88AA3C/" height="90" width="600" scrolling="no"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen&gt;&lt;/iframe&gt;</html>
  <thumbnail_url>https://assets.libsyn.com/secure/item/38278300</thumbnail_url>
</oembed>
