Kerberos to an IP Address, Part 4: Why It Is Contained, and Where Detection Falls Short
Part 3 showed that enabling the IP SPN client path changes coerced authentication from NTLM to Kerberos when the destination carries an IP SPN, for both memb...
Part 3 showed that enabling the IP SPN client path changes coerced authentication from NTLM to Kerberos when the destination carries an IP SPN, for both memb...
Parts 1 and 2 stayed on the mechanism: Kerberos to an IP works, gated on an SPN existing, and registering an arbitrary IP SPN requires unconstrained write ov...
Part 1 established that Kerberos to an IP address works, and that the single gate between a failed local resolution and a working ticket is whether an IP-bas...
For as long as most of us have worked with Active Directory, one rule held: Kerberos needs a name. Connect to a file share by hostname and you get a Kerberos...
This box is rated insane difficulty on HTB. It involves us enumerating passwords via LDAP injection on a web server, password spraying, finding a file disclo...
This post covers Impel, a Linux-native RPC coercion surface scanner we built as the final tool in our Windows authentication coercion research series. The pr...
Part one covered the mechanic and the lineage. This part is operational. We reproduce CVE-2026-24294 against a default Windows Server 2025 environment, docum...
Authentication reflection is a family of attacks that keeps getting declared dead and keeps coming back. It looks like a footnote to NTLM relay until you exa...
This box is rated hard difficulty on HTB. It involves us enumerating a pre-created machine account whose password is the same as its samAccountName value. Fr...
This box is rated hard difficulty on HTB. It involves us compromising a Linux web server running an outdated version of Icinga Web 2 through a File Disclosur...