Dec0ne / KrbRelayUp

KrbRelayUp - a universal no-fix local privilege escalation in windows domain environments where LDAP signing is not enforced (the default settings).
1.51k stars 202 forks source link

Notify User if Target For S4U Portion is Marked Sensitive #18

Open rpgmaster280 opened 2 years ago

rpgmaster280 commented 2 years ago

image

The default behavior of the tool is to target the Administrator account and when this fails as a result of an account being marked sensitive, the error is not human readable. It would be nice if the tool tested if the account can used for delegation prior to performing the attack.