Certified: abusing AD CS (ESC9)
A write-up of the HackTheBox machine “Certified”. This box revolves around a vulnerable certificate template that we can abuse to achieve Domain Admin privileges. The target The host is a domain controller for certified.htb, and we are handed one working account, judith.mader. The objective is the built-in Administrator. In outline the path runs from that account, through ownership of a group, to a service account, and finally to the certificate authority, where a misconfigured template lets us issue ourselves a certificate in the Administrator’s name. ...