The post discusses various tools and techniques used by attackers to enumerate and exploit Active Directory (AD) user passwords, including vulnerabilities in password attributes like UserPassword, UnixUserPassword, unicodePwd, and msSFU30Password. It covers key vulnerabilities such as CVE-2020-1472 (Zerologon) and CVE-2017-0144
Table of contents
Table of ContentsUnderstanding of Active Directory (AD) password attributes:PrerequisitesLab SetupExploitationMitigationSort: