專案資訊 #1075
進行中專案資訊 #1064: 2025-PenTest
ADCS Web Enrollment Enabled for high-privileged accounts
100%
概述
N bookmark20250529113929916258883991 "ADCS Web Enrollment Enabled for high-privileged accounts
" Enabling ADCS Web Enrollment for high-privileged accounts increases the risk of credential theft, as attackers could exploit web-based vulnerabilities (like MITM or phishing) to intercept or forge certificates. This could lead to privilege escalation and domain compromise if abused for unauthorized authentication. "The following approaches are recommended to mitigate this potential vulnerability.
Enable Extended Protection for Authentication (EPA) on the ADCS Server.
Disable NTLM on the ADCS Server
Enforce SMB and LDAP Signing
"
檔案
是由 益利 周 於 約 2 個月 前更新
- 檔案 clipboard-202511271729-zjpzs.png clipboard-202511271729-zjpzs.png 已新增
- 檔案 clipboard-202511271734-mjb7z.png clipboard-202511271734-mjb7z.png 已新增
- 檔案 clipboard-202511271745-7neha.png clipboard-202511271745-7neha.png 已新增
- 狀態 從 New-新增 變更為 Resolved-解决
- 完成百分比 從 0 變更為 100
1.在 AD CS 伺服器上啟用擴充保護以進行驗證 (EPA)
2.在 AD CS 伺服器上停用 NTLM
3.強制執行 SMB 和 LDAP 簽章 (Signing)