ly4k / Certipy

Tool for Active Directory Certificate Services enumeration and abuse
MIT License
2.34k stars 318 forks source link

Update security.py #211

Open Blyth0He opened 4 months ago

Blyth0He commented 4 months ago

preventing false positive by checking ADS_RIGHT_DS_CONTROL_ACCESS bit flag, before this commit, there might false positve, when an ace has Enroll uuid without ADS_RIGHT_DS_CONTROL_ACCESS being set in Mask field, this happens when we unselect the checkbox which indicate the permission is allow or denied image before we uncheck the checkbox, we have CR(which means control access righ ) set on mask field, and the Enroll is also showed in the ace image if we uncheck the checkbox image we can find the CR flag is not set while the Enroll permission uuid still showed in the ace image when this happens, certipy still mark this cert template as "user can enroll", but actually it will be denied. image