ForceChangePassword
This abuse can be carried out when controlling an object that has a GenericAll
, AllExtendedRights
or User-Force-Change-Password
over the target user.
Alternative #1: using bloodyAD:
Alternative #2: using net, a tool for the administration of samba and cifs/smb clients. The pth-toolkit can also be used to run net commands with pass-the-hash.
Alternative #3: rpcclient can also be used on UNIX-like systems when the package samba-common-bin
is missing.
Last updated