<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>MsDS-AllowedToDelegateTo on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/msds-allowedtodelegateto/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Fri, 22 Nov 2024 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/msds-allowedtodelegateto/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Redelegate</title><link>https://wearethebug.dev/posts/vl-redelegate/</link><pubDate>Fri, 22 Nov 2024 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-redelegate/</guid><description>Redelegate is a hard-difficultly Windows machine that starts with Anonymous FTP access, which allows the attacker to download sensitive Keepass Database files. The attacker then discovers that the credentials in the database are valid for MSSQL local login, which leads to enumerate SIDs and performs a password spray attack. Being a member of the HelpDesk group, the newly compromised user account Marie.Curie has a User-Force-Change-Password Access Control setup over the Helen.Frost user account; that user account has privileges to get a PS remoting session onto the Domain Controller. The Helen.Frost user account also has the SeEnableDelegationPrivilege assigned and has full control over the FS01$ machine account, essentially allowing the attacker account to modify the msDS-AllowedToDelegateTo LDAP attribute and change the password of a computer object and perform a Constrained Delegation attack.</description></item></channel></rss>