7MS #668: Tales of Pentest Pwnage – Part 69

7MS #668: Tales of Pentest Pwnage – Part 69

Hola friends! Today’s tale of pentest pwnage talks about abusing Exchange and the Azure ADSync account! Links to the discussed things:

  • adconnectdump – for all your ADSync account dumping needs!
  • Adam Chester PowerShell script to dump MSOL service account
  • dacledit.py (part of Impacket) to give myself full write privileges on the MSOL sync account: dacledit.py -action ‘write’ -rights ‘FullControl’ -principal lowpriv -target MSOL-SYNC-ACCOUNT -dc-ip 1.2.3.4 domain.com/EXCHANGEBOX$ -k -no-pass
  • Looking to tighten up your Exchange permissions – check out this crazy detailed post

Episoder(690)

Populært innen Politikk og nyheter

giver-og-gjengen-vg
aftenpodden
bt-dokumentar-2
forklart
aftenpodden-usa
stopp-verden
popradet
hva-star-du-for
nokon-ma-ga
fotballpodden-2
dine-penger-pengeradet
det-store-bildet
aftenbla-bla
e24-podden
frokostshowet-pa-p5
rss-ness
rss-dannet-uten-piano
rss-penger-polser-og-politikk
unitedno
rss-borsmorgen-okonominyhetene