Self Exploit
What is the Self Permission For?
How can this be abused?
Scenario:
Get SID of MSPDB Account
Get-NetUser -Identity mspdb -domain msp.local
logoncount : 144
badpasswordtime : 10/6/2020 5:03:46 AM
distinguishedname : CN=mspdb,CN=Users,DC=msp,DC=local
objectclass : {top, person, organizationalPerson, user}
displayname : msp db
lastlogontimestamp : 1/9/2021 9:27:09 PM
userprincipalname : mspdb
name : mspdb
objectsid : S-1-5-21-2998733414-582960673-4099777928-1107
samaccountname : mspdb
codepage : 0
samaccounttype : USER_OBJECT
accountexpires : NEVER
countrycode : 0
whenchanged : 1/10/2021 5:27:09 AM
instancetype : 4
usncreated : 63471
objectguid : 9158587d-8b16-4b38-a013-0bfd1f2a5aaf
sn : db
lastlogoff : 12/31/1600 4:00:00 PM
objectcategory : CN=Person,CN=Schema,CN=Configuration,DC=msp,DC=local
dscorepropagationdata : {5/30/2019 11:42:37 AM, 1/1/1601 12:00:00 AM}
serviceprincipalname : MSSQLSvc/msp-sqlreport.msp.local
givenname : msp
lastlogon : 1/10/2021 1:38:13 AM
badpwdcount : 0
cn : mspdb
useraccountcontrol : NORMAL_ACCOUNT, DONT_EXPIRE_PASSWORD
whencreated : 5/30/2019 11:42:36 AM
primarygroupid : 513
pwdlastset : 5/30/2019 4:42:37 AM
usnchanged : 1338942
Query for any ACL's that are affected by this user
Add MSPDB to the ForestManagers Group
Finding Local Admin Access.
Last updated