When a computer is configured as Trusted for , every user who connects to it sends it a copy of their . The TGT is stored in memory (LSASS) — and anyone who gains local privileges on the server can steal it and impersonate the user across the entire domain.
התוקף הוא Local Admin על שרת שמסומן TRUSTED_FOR_DELEGATION. שלב 1: הפעלת Printer Bug כדי לאלץ את ה־Domain Controller להתחבר לשרת. שלב 2: ה־DC מתחבר חזרה ומשאיר את ה־TGT של חשבון המחשב DC$ בזיכרון LSASS. שלב 3: התוקף גונב את הכרטיס ומבצע Pass-the-Ticket. שלב 4: DCSync ושליטה מלאה בדומיין. הגנה: Protected Users, סימון חשבון כרגיש, וביטול ההאצלה.
A typical attack path
- The attacker locates a server with (the TRUSTED_FOR_DELEGATION flag).
- They obtain Local Admin privileges on that server.
- They force a to connect to the server (for example using the Printer Bug / MS-RPRN).
- The of the DC's computer account is stored in memory and stolen.
- With the DC's , can be performed and the domain taken over.
Defense
- Disable wherever possible and move to or .
- Mark sensitive accounts as Account is sensitive and cannot be delegated.
- Add administrator accounts to the Protected Users group.
- Monitor Event ID 4769 and unusual ticket requests from delegated servers.