Главная
Study mode:
on
1
Introduction
2
Why this talk?
3
Takeaways
4
What is "Active Directory"?
5
Core AD Technologies
6
Working with AD Protocols
7
Find Active Directory through DNS
8
Domain Meta-Data Through LDAP
9
MS-RPC Calls
10
Communicating with MS-RPC
11
Impacket Binaries
12
Impacket Static Binaries
13
Active Directory uses LDAP
14
What does LDAP in AD look like?
15
Idapsearch - Computers
16
Nested Lookups
17
Nested Domain Admins
18
Admin-Count
19
Why do it manually?
20
LDAP Summary
21
Kerberos Crash-Course
22
What does Kerberos look like?
23
Kerberos and Authorization
24
Kerberos from Linux
25
Setting up Kerberos
26
Using Kerberos with GSSAPI
27
Viewing Kerberos Tickets
28
Using Kerberos with Impacket
29
When NTLM Auth is disabled
30
Password Spraying with SMB / RPC
31
Other Password Guessing Techniques
32
Password Guessing with Kerberos
33
What about logs?
34
Kerberos Event Logging
35
Requesting TGS for SPN
36
Cracking TGS Resp
37
Over Pass the Hash - AES
38
Forging Kerberos Tickets
39
Golden Ticket Creation
40
Golden Ticket Usage
41
Silver Ticket Creation
42
Silver Ticket Usage
43
Shoulders of Giants
Description:
Explore the intricacies of attacking Active Directory from non-Windows machines in this comprehensive conference talk. Delve into the core technologies of Active Directory, including LDAP and Kerberos, and learn how to leverage these protocols for reconnaissance and exploitation. Discover techniques for finding Active Directory through DNS, extracting domain metadata, and performing nested lookups. Gain hands-on experience with tools like Impacket and ldapsearch while understanding the nuances of Kerberos authentication and authorization. Master advanced tactics such as password spraying, over-pass-the-hash attacks, and forging Kerberos tickets. Examine logging mechanisms and understand how to minimize detection. By the end of this talk, acquire valuable insights into attacking AD from non-Windows environments, equipping yourself with practical skills for penetration testing and security assessments.

Fun with LDAP and Kerberos - Attacking AD from Non-Windows Machines

WEareTROOPERS
Add to list
0:00 / 0:00