You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
If an attacker has already compromised a computer with [Unconstrained Delegation](unconstrained-delegation.md), the attacker could **make the printer authenticate against this computer**. Due to the unconstrained delegation, the **TGT** of the **computer account of the printer** will be **saved in** the **memory** of the computer with unconstrained delegation. As the attacker has already compromised this host, he will be able to **retrieve this ticket** and abuse it ([Pass the Ticket](pass-the-ticket.md)).
55
55
56
-
## RCP Force authentication
57
-
58
-
59
-
{{#ref}}
60
-
https://github.com/p0dalirius/Coercer
61
-
{{#endref}}
56
+
## RPC Force authentication
57
+
58
+
[Coercer](https://github.com/p0dalirius/Coercer)
59
+
60
+
### RPC UNC-path coercion matrix (interfaces/opnums that trigger outbound auth)
Note: These methods accept parameters that can carry a UNC path (e.g., `\\attacker\share`). When processed, Windows will authenticate (machine/user context) to that UNC, enabling NetNTLM capture or relay.
92
+
93
+
### MS-EVEN: ElfrOpenBELW (opnum 9) coercion
94
+
- Interface: MS-EVEN over \\PIPE\\even (IF UUID 82273fdc-e32a-18c3-3f78-827929dc23ea)
- Effect: the target attempts to open the supplied backup log path and authenticates to the attacker-controlled UNC.
97
+
- Practical use: coerce Tier 0 assets (DC/RODC/Citrix/etc.) to emit NetNTLM, then relay to AD CS endpoints (ESC8/ESC11 scenarios) or other privileged services.
62
98
63
99
## PrivExchange
64
100
@@ -137,4 +173,13 @@ If you can perform a MitM attack to a computer and inject HTML in a page he will
137
173
If you can capture [NTLMv1 challenges read here how to crack them](../ntlm/index.html#ntlmv1-attack).\
138
174
_Remember that in order to crack NTLMv1 you need to set Responder challenge to "1122334455667788"_
0 commit comments