Case FDD1B2 · Identity & AD · L5 Expert
RBCD Attack Chain
Practise as: Explain it · Interview · Deep dive
Interview questionYou hold GenericWrite on a server computer object. Walk me through turning that into admin on the server.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Write msDS-AllowedToActOnBehalfOfOtherIdentity on the target so it trusts a principal you control that has an SPN
- Get that principal by adding a machine account (default ms-DS-MachineAccountQuota is 10) or using a compromised SPN account
- S4U2Self gets a ticket to yourself as a privileged user; S4U2Proxy turns it into a service ticket to the target
- Blocked for Protected Users and accounts marked sensitive and cannot be delegated; set MachineAccountQuota to 0
- Detect: 5136 on msDS-AllowedToActOnBehalfOfOtherIdentity, 4741 new computer accounts, unusual S4U 4769 requests
If the interviewer pushes back
- Why does RBCD still work when the S4U2Self ticket is not forwardable, unlike classic constrained delegation?
- How would you chain NTLM relay to LDAP with RBCD, and which control breaks that chain?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.