Skip to content

Commit 8c9c7c8

Browse files
authored
Merge pull request PowerShellMafia#182 from monoxgas/dev
Service DACL false positive | Request-SPNTicket double hash
2 parents 5e2200b + 8e41548 commit 8c9c7c8

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

Privesc/PowerUp.ps1

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1404,7 +1404,7 @@ function Test-ServiceDaclPermission {
14041404
else {
14051405
ForEach($TargetPermission in $TargetPermissions) {
14061406
# check permissions || style
1407-
if (($ServiceDacl.AccessRights -band $AccessMask[$TargetPermission]) -eq $AccessMask[$TargetPermission]) {
1407+
if (($ServiceDacl.AceType -eq 'AccessAllowed') -and ($ServiceDacl.AccessRights -band $AccessMask[$TargetPermission]) -eq $AccessMask[$TargetPermission]) {
14081408
Write-Verbose "Current user has '$TargetPermission' for $IndividualService"
14091409
$TargetService
14101410
break

Recon/PowerView.ps1

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1382,6 +1382,7 @@ function Request-SPNTicket {
13821382
[System.Collections.ArrayList]$Parts = ($TicketHexStream -replace '^(.*?)04820...(.*)','$2') -Split "A48201"
13831383
$Parts.RemoveAt($Parts.Count - 1)
13841384
$Parts -join "A48201"
1385+
break
13851386
}
13861387
}
13871388
}

0 commit comments

Comments
 (0)