7MS #663: Pentesting GOAD SCCM
MP3•Episode home
Manage episode 467808035 series 3603998
Content provided by Brian Johnson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Brian Johnson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Today we live-hack an SCCM server via GOAD SCCM using some attack guidance from Misconfiguration Manager! Attacks include:
- Unauthenticated PXE attack
- PXE (with password) attack
- Relaying the machine account of the MECM box over to the SQL server to get local admin
677 episodes