GenericAll
Last updated
Was this helpful?
Last updated
Was this helpful?
Full control over the target account.
When a group/user has GenericAll
rights over another account, a fake SPN can be assigned to the target account.
Once the SPN is assigned to the target account, we should be able to it.
We can disable pre-authentication for the target account and then it.
An example of the above method can be found .
Check .
This can be done using , the , or PowerView.
If a group has GenericAll
rights over an OU, then the group members can be assigned GenericAll
rights over the OU as well, which results in them having FullControl
over the OU members. This gives the ability to .