https://tryhackme.com/room/exploitingad

Task 1 - Introduction

Connecting to the Network

Configure DNS by adding THMDC's IP to the DNS Network Manager > Advanced Network Configuration > Your Connection > IPv4 Settings

Untitled

Then restart the resolved service

sudo systemctl restart NetworkManager

Requesting Your Credentials

For SSH access - Getting credentials from http://distributor.za.tryhackme.loc/creds

ssh za.tryhackme.loc\\\\<AD Username>@thmwrk1.za.tryhackme.loc

Task 2 - Exploiting Permission Delegation

20220614162804BloodHound.zip

A significant amount of ACEs can be misconfigured, and the exploits for each vary.

The Bloodhound documentation assists in explaining enumerated ACEs and how they can be exploited. However, we will look at a couple of notable ones here: