Attacking FreeIPA — Part III: Finding A Path
ID: 31c8c73d-aa28-5394-80dc-553bdfb51223
STIX ID: report--31c8c73d-aa28-5394-80dc-553bdfb51223
Feed Name: SpecterOps Blog
This post details an offensive workflow in a FreeIPA lab where an attacker, starting with access as the nginxadmin user on a compromised web server, leverages Kerberos ccache tickets, HBAC and sudo rules, and Kerberos-enabled SSH/SCP to laterally move to mysql.westeros.local, escalate by reusing/administering tickets and sudo to obtain admin/root contexts, and pivot to vault.westeros.local—demonstrating practical TTPs for credential reuse, privilege escalation, and domain-wide access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
