-
Notifications
You must be signed in to change notification settings - Fork 53
Open
Description
The ACL Processor collects GenericAll, WriteDACL and WriteOwner ACLs on all object types.
For GenericWrite and WriteProperty, it collects the ACLs only for User, Group and Computer (and to some extent GPOs):
I just stumbled upon a case where an Everyone has GenericWrite on an OU, this can be exploited as shown in the following articles:
- https://labs.withsecure.com/blog/ou-having-a-laugh/
- https://markgamache.blogspot.com/2020/07/exploiting-ad-gplink-for-good-or-evil.html
I think this edge should also be collected on OUs. What do you think?
Thanks a lot for your great work!
Metadata
Metadata
Assignees
Labels
No labels