writeups.xyz writeups.xyz / Kerberos

Title Vulnerabilities Programs Authors
Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust
Anonymised Penetration Test Report
Protected Users: you thought you were safe uh?
From CVE-2022-33679 to Unauthenticated Kerberoasting
From Zero to Hero Part 2: From SQL Injection to RCE on Intel DCM (CVE-2022-21225)
From Zero to Hero Part 1: Bypassing Intel DCM’s Authentication by Spoofing Kerberos and LDAP Responses (CVE-2022-33942)
RC4 Is Still Considered Harmful
New Attack Paths? AS Requested Service Tickets