Oh my gosh…I wasn’t sure we’d get there. But we did. On this week’s Tuesday TOOLSday we finally pwned Ninja Hacker Academy! The pwnage required:
Some sleuthing and comparison of users in ACADEMY.NINJA.LAN and NINJA.HACK
Abusing a WriteDacl permission between two AD objects
Adding ourselves to a group via excessive group permissions
ADCS attacks
Fun fun fun fun fun! ALSO, we did a deeper dive into NHA on YouTube this week as part of our Third Thursday livestream - check that out here.
Thanks for joining me on this journey and we’ll see you again on Tuesday!
Thanks,
Brian
Share this post