When EPA isn't EPA'ing: What Tools Like Certify, Certipy and checkMSSQLStatus.py miss
Recently on engagements I started experiencing two reoccurring patterns, the first being that certipy and certify would both show me that a endpoint is not vulnerable to the ESC8 attack even though it is. The same was in telling me that the endpoint is vulnerable during my retests even though I knew it was not! Secondly that clients even after following Microsoft’s advice in turning EPA on, still are vulnerable to the NTLM relay against the Web enrollment endpoint. A recent example can be shown below where I was told by certipy that ESC8 was not present(even though it was and I successfully exploited it): ...