Skip to content

Conversation

@ShutdownRepo
Copy link
Member

Original PR on fortra/impacket: fortra#1879

Adds the ability to enumerate ADCS templates using only HTTP with a relayed user. Useful in the event that LDAP signing is enforced and LDAP channel binding is set up properly, but ESC8 is still present. Previously, you would have needed another way to enumerate certificate names (or attempt to blindly hit Client or Machine templates with your fingers crossed).

Note that the HTTP endpoint doesn't give back verbose details like EnrolleeSuppliesSubject, etc. so its still only a way to get accessible/enabled certificate templates only.

  • Added --enum-templates for ADCS options

Default behavior

image

With debug

image
image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants