Catalog WADComs

WAD · Tool

Impacket-goldenPac

1 technique Linux · ActiveDirectory · WindowsWADComs GPL-3.0

Impacket-GoldenPac

NEW
Privilege EscalationExecutionLateral Movement LinuxActiveDirectoryWindows

Impacket goldenPac.py exploits MS14-068 (CVE-2014-6324): on an unpatched domain controller the PAC signature validation can be bypassed, letting an ordinary domain user forge a TGT claiming Domain Admin membership without the krbtgt key. The script builds the forged PAC, obtains a privileged ticket and then executes a command (PSEXEC-style) on the target DC. Only affects DCs missing the 2014 patch, but remains relevant against legacy lab and CTF environments. Command Reference: Domain: test.local Username: john Password: password123 Domain Controller host: dc.test.local

# Exploit MS14-068 to gain SYSTEM on an unpatched DC
goldenPac.py test.local/john:password123@dc.test.local
Native
PrivEsc, Exploitation, Lateral Movement
MITRE
T1558
Requires
Username, Password
Services
Kerberos, SMB