7MS #668: Tales of Pentest Pwnage – Part 69
MP3•Episode home
Manage episode 473976986 series 3603998
Content provided by Brian Johnson. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Brian Johnson or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Hola friends! Today’s tale of pentest pwnage talks about abusing Exchange and the Azure ADSync account! Links to the discussed things:
- adconnectdump – for all your ADSync account dumping needs!
- Adam Chester PowerShell script to dump MSOL service account
- dacledit.py (part of Impacket) to give myself full write privileges on the MSOL sync account: dacledit.py -action ‘write’ -rights ‘FullControl’ -principal lowpriv -target MSOL-SYNC-ACCOUNT -dc-ip 1.2.3.4 domain.com/EXCHANGEBOX$ -k -no-pass
- Looking to tighten up your Exchange permissions – check out this crazy detailed post
671 episodes