Hacker News
- Abusing Exchange: One API call away from Domain Admin https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/ 5 comments
- PrivExchange - Abusing Exchange: One API call away from Domain Admin https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/ 5 comments netsec
- Abusing Exchange: One API call away from Domain Admin https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/ 23 comments netsec
Linking pages
- AD-Attack-Defense/README.md at master · infosecn1nja/AD-Attack-Defense · GitHub https://github.com/infosecn1nja/ad-attack-defense/blob/master/readme.md#discovery 19 comments
- A different way of abusing Zerologon (CVE-2020-1472) - dirkjanm.io https://dirkjanm.io/a-different-way-of-abusing-zerologon/ 10 comments
- The worst of both worlds: Combining NTLM Relaying and Kerberos delegation - dirkjanm.io https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/ 0 comments
- Exploiting CVE-2019-1040 - Combining relay vulnerabilities for RCE and Domain Admin - dirkjanm.io https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin/ 0 comments
- A New Attack Surface on MS Exchange Part 1 - ProxyLogon! | DEVCORE https://devco.re/blog/2021/08/06/a-new-attack-surface-on-MS-exchange-part-1-ProxyLogon/ 0 comments
Linked pages
- KB4034879: Use the LdapEnforceChannelBinding registry entry to make LDAP authentication over SSL/TLS more secure - Microsoft Support https://support.microsoft.com/en-us/help/4034879/how-to-add-the-ldapenforcechannelbinding-registry-entry 11 comments
- GitHub - fortra/impacket: Impacket is a collection of Python classes for working with network protocols. https://github.com/SecureAuthCorp/impacket 11 comments
- Escalating privileges with ACLs in Active Directory – Fox-IT International blog https://blog.fox-it.com/2018/04/26/escalating-privileges-with-acls-in-active-directory/ 3 comments
- Zero Day Initiative — An Insincere Form of Flattery: Impersonating Users on Microsoft Exchange https://www.thezdi.com/blog/2018/12/19/an-insincere-form-of-flattery-impersonating-users-on-microsoft-exchange 3 comments
- Relaying credentials everywhere with ntlmrelayx – Fox-IT International blog https://blog.fox-it.com/2017/05/09/relaying-credentials-everywhere-with-ntlmrelayx/ 0 comments
Related searches:
Search whole site: site:dirkjanm.io
Search title: Abusing Exchange: One API call away from Domain Admin - dirkjanm.io
See how to search.