Unconstrained Delegation
Identify
Linux - remote
Windows - localADSearch.exe --search "(&(objectCategory=computer)(userAccountControl:1.2.840.113556.1.4.803:=524288))" --attributes samaccountname,dnshostname
Domain Controllers are always permitted for unconstrained delegation.
Exploit
Force DC to auth to our box and steal tgt
Monitor for tickets with Rubeus
Run https://github.com/cube0x0/SharpSystemTriggers to coerce authentication Where:- DC01 is the "target".
- WEB is the "listener". Rebeus should capture a ticket