<?xml version="1.0" encoding="utf-8"?>
<oembed>
  <version>1</version>
  <type>rich</type>
  <provider_name>Libsyn</provider_name>
  <provider_url>https://www.libsyn.com</provider_url>
  <height>90</height>
  <width>600</width>
  <title>7MS #739: Tales of Pentest Pwnage – Part 89</title>
  <description>Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have&amp;amp;nbsp;never&amp;amp;nbsp;seen before – one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I’m absolutely going to say it was intentional and that I totally meant to do that. Here’s what we cover:  A client that’s actually doing the things&amp;amp;nbsp;– year two or three of testing this environment, and they had buttoned up so much that I had to dig&amp;amp;nbsp;deep. Great for them, freaking frustrating for me. Why my Kerberoasting success rate has fallen off a cliff&amp;amp;nbsp;– Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now. Selective poisoning vs. poison-all-the-things&amp;amp;nbsp;– a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn’t get nearly enough love in blogs and videos. The relay that fired… and did something completely different than I expected&amp;amp;nbsp;– I saw the ntlmrelayx log scroll by, thought “yes, I’ve got DA,” and then had a “wait, wait,&amp;amp;nbsp;whoa, what?” moment. I was honestly a little panicked. An ancient Exchange vulnerability comes back to bite&amp;amp;nbsp;–&amp;amp;nbsp;CVE-2021-34470 (vulnerable Exchange schema)&amp;amp;nbsp;turned out to be the fallback that got me a foothold I had no business having. My favorite evil privesc trick, revisited&amp;amp;nbsp;– queuing up a scheduled task that runs under an interactively logged-in DA’s context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying. A bonus thing to always look for&amp;amp;nbsp;– scheduled tasks running under saved DA creds that point at a script&amp;amp;nbsp;you&amp;amp;nbsp;can edit. Add one little line to fire an evil command of your choice, and you’re in like a dirty shirt.  Check us out at&amp;amp;nbsp;7MinSec.com&amp;amp;nbsp;for pentesting, training, controls assessments and security miscellany,&amp;amp;nbsp;7MinSec.club&amp;amp;nbsp;for our Substack and weekly TuesdayTOOLSday videos, and&amp;amp;nbsp;7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above). </description>
  <author_name>7 Minute Security</author_name>
  <author_url>https://7MinSec.com</author_url>
  <html>&lt;iframe title="Libsyn Player" style="border: none" src="//html5-player.libsyn.com/embed/episode/id/42874295/height/90/theme/custom/thumbnail/yes/direction/forward/render-playlist/no/custom-color/88AA3C/" height="90" width="600" scrolling="no"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen&gt;&lt;/iframe&gt;</html>
  <thumbnail_url>https://assets.libsyn.com/secure/item/42874295</thumbnail_url>
</oembed>
