Skip to content

Hacking Articles

Raj Chandel's Blog

  • Courses We Offer
  • CTF Challenges
  • Penetration Testing
  • Web Penetration Testing
  • Red Teaming
  • Donate us
Active Directory Certificate Attack

ADCS ESC15 – Exploiting Template Schema v1

July 12, 2025 by raj5 Min Reading

The ESC15 vulnerability (EKUwu), affects Active Directory Certificate Services (AD CS), allowing attackers to inject unauthorized EKUs (e.g., Client Authentication) into Schema Version 1 templates.

Red Teaming

Kerberoasting Attack in Active Directory

July 11, 2025 by raj6 Min Reading

This article explores Kerberoasting, a stealthy attack in Active Directory that exploits Service Principal Names (SPNs) to extract and crack TGS ticket hashes, revealing service

Active Directory Certificate Attack

ADCS ESC14 – Write access on altSecurityIdentities

July 3, 2025 by raj7 Min Reading

ESC14 targets weak certificate mapping in Active Directory, exploiting the altSecurityIdentities attribute to allow attackers to spoof Subject CN or Issuer DN fields. This enables

Active Directory Certificate Attack

ADCS ESC11 – Relaying NTLM to ICPR

June 29, 2025 by raj7 Min Reading

ESC11 (Enterprise Security Control 11) represents a sophisticated attack path targeting Active Directory Certificate Services (AD CS), exploiting a dangerous combination of vulnerabilities. This advanced

Red Teaming

Active Directory Penetration Testing Using Impacket

June 23, 2025 by raj12 Min Reading

Impacket is a powerful Python toolkit for working with network protocols, particularly useful in Active Directory (AD) penetration testing. It provides various scripts to exploit

Cloud Security

AWS: Penetration Testing Lab Setup

June 20, 2025 by raj7 Min Reading

This guide will walk you through setting up a web server with a simulated SSRF vulnerability and a Kali Linux instance on Amazon Web Services

Active Directory Certificate Attack

ADCS ESC10 – Weak Certificate Mapping

June 16, 2025 by raj9 Min Reading

ESC10 is a powerful post-exploitation technique in Active Directory Certificate Services (ADCS) that lets attackers authenticate as any user even Domain Admins without knowing their

Active Directory Certificate Attack

ADCS ESC9 – No Security Extension

June 15, 2025 by raj10 Min Reading

Misconfigured certificate templates, particularly those affected by ESC9, pose a critical threat to Active Directory environments. By disabling the szOID_NTDS_CA_SECURITY_EXT security extension through the CT_FLAG_NO_SECURITY_EXTENSION

Container Security, Docker Pentest, Pentest Lab Setup, Website Hacking

Web Application Pentest Lab setup Using Docker

June 13, 2025 by raj11 Min Reading

In the world of cybersecurity, penetration testing and vulnerability assessment are crucial steps in identifying and mitigating potential security threats. With the increasing number of

Posts pagination

Previous 1 … 5 6 7 … 156 Next

Categories

Join Our Training Program

Join Our Telegram Channel

Join Our Discord Channel

Cyber Security Mindmap

Follow us on Twitter

Follow us on Linkedin

© All Rights Reserved 2021 Theme: Prefer by Template Sell.