3 ms·
It sounds like the initial compromise is easier than it should be, though (I can't believe that after 20 years of known issues of accepting a password hash as p
by sillystuff 3y ago
It sounds like the initial compromise is easier than it should be, though (I can't believe that after 20 years of known issues of accepting a password hash as password equivalent in MS Windows, that MS is still making this mistake?!!
> The example below uses a few techniques: LDAP reconnaissance to discover AD FS, DCSync to export the service account’s hashes, and then Pass the Hash (PtH) to gain a session on the AD FS Server as the service account.