Certificate Authority (CA)
Enumerate CA for vulnerabilities
Some certificate templates can be vulnerable to injection.
Exploiting misconfigured templates
Request a certificate from a vulnerable template:
PKI admins group
If you are in the PKI admins group, you are able to create a vulnerable template and impersonate Administrator.
First create a new template by using the powershell module https://github.com/GoateePFE/ADCSTemplate
Next we request the template as Administrator:
Now we can use the PFX output file to retrieve the NT:NTLM hash of administrator by using:
Convert PEM to PFX
Request ticket
Pass the ticket
Last updated