Active Directory Certificate Services (AD CS)
https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-certificate-services/#esc2-misconfigured-certificate-templates
If we have ports 3268, 3269 open, certificates should be checked!
Find Vulnerable Certificates
ESC1: Misconfigured Certificate Templates
ESC2: Misconfigured Certificate Templates
ESC3: Enrollment Agent Templates
ESC4: Vulnerable Certificate Template Access Control
First, overwrite the configuration to make it vulnerable to ESC1
ESC9
User 1 have GenericWrite to user2, we can get the user2 hash using shadow Crentials because of user's1 GenericWrite
We can also change the password of that user:
Last updated