{"version":1,"type":"rich","provider_name":"Libsyn","provider_url":"https:\/\/www.libsyn.com","height":90,"width":600,"title":"7MS #739: Tales of Pentest Pwnage \u2013 Part 89","description":"Hey friends! Today is a tale of pentest pwnage episode, and this one features a path to escalation I have&amp;nbsp;never&amp;nbsp;seen before \u2013 one I could only find few references on the entire Internet. It happened completely by accident, but during the report readout I\u2019m absolutely going to say it was intentional and that I totally meant to do that. Here\u2019s what we cover:  A client that\u2019s actually doing the things&amp;nbsp;\u2013 year two or three of testing this environment, and they had buttoned up so much that I had to dig&amp;nbsp;deep. Great for them, freaking frustrating for me. Why my Kerberoasting success rate has fallen off a cliff&amp;nbsp;\u2013 Microsoft pushed an encryption change earlier this year, and cracking those hashes is a whole different ballgame now. Selective poisoning vs. poison-all-the-things&amp;nbsp;\u2013 a nod to Pretender, which I covered in a TuesdayTOOLSday video over at 7MinSec.club. It doesn\u2019t get nearly enough love in blogs and videos. The relay that fired\u2026 and did something completely different than I expected&amp;nbsp;\u2013 I saw the ntlmrelayx log scroll by, thought \u201cyes, I\u2019ve got DA,\u201d and then had a \u201cwait, wait,&amp;nbsp;whoa, what?\u201d moment. I was honestly a little panicked. An ancient Exchange vulnerability comes back to bite&amp;nbsp;\u2013&amp;nbsp;CVE-2021-34470 (vulnerable Exchange schema)&amp;nbsp;turned out to be the fallback that got me a foothold I had no business having. My favorite evil privesc trick, revisited&amp;nbsp;\u2013 queuing up a scheduled task that runs under an interactively logged-in DA\u2019s context without ever knowing their password. The MDR alerts that come out of this are equal parts hilarious and terrifying. A bonus thing to always look for&amp;nbsp;\u2013 scheduled tasks running under saved DA creds that point at a script&amp;nbsp;you&amp;nbsp;can edit. Add one little line to fire an evil command of your choice, and you\u2019re in like a dirty shirt.  Check us out at&amp;nbsp;7MinSec.com&amp;nbsp;for pentesting, training, controls assessments and security miscellany,&amp;nbsp;7MinSec.club&amp;nbsp;for our Substack and weekly TuesdayTOOLSday videos, and&amp;nbsp;7MinSec.wiki for tips, cheat sheets and scripts (including pages on the scheduled task shenanigans above). ","author_name":"7 Minute Security","author_url":"https:\/\/7MinSec.com","html":"<iframe title=\"Libsyn Player\" style=\"border: none\" src=\"\/\/html5-player.libsyn.com\/embed\/episode\/id\/42874295\/height\/90\/theme\/custom\/thumbnail\/yes\/direction\/forward\/render-playlist\/no\/custom-color\/88AA3C\/\" height=\"90\" width=\"600\" scrolling=\"no\"  allowfullscreen webkitallowfullscreen mozallowfullscreen oallowfullscreen msallowfullscreen><\/iframe>","thumbnail_url":"https:\/\/assets.libsyn.com\/secure\/item\/42874295"}