概要
TryHackMe「Active Directory Basics」のWalkthroughです。
Task2
Q1.In a Windows domain, credentials are stored in a centralised repository called...
A.Active Directory
Q2.The server in charge of running the Active Directory services is called...
A.Domain Controller
Task3
Q1.Which group normally administrates all computers and resources in a domain?
A.Domain Admins
Q2.What would be the name of the machine account associated with a machine named TOM-PC?
命名規則により最後に$
が付きます。
A.TOM-PC$
Q3.Suppose our company creates a new department for Quality Assurance. What type of containers should we use to group all Quality Assurance users so that policies can be applied consistently to them?
A.Organizational Units
Task4
Q1.What was the flag found on Sophie's desktop?
Active Directory Users and Computers
->View
->Advanced Features
にチェックを入れます。
Research and Development
->Properties
->Object
からProtect object from acciental deletion
のチェックを外します。
Research and Development
を削除します。
Sales
->Delegate Control
画面へ遷移します。
Add
ボタンをクリックし、phillip
ユーザーを追加します。
パスワードリセット権限にチェックを入れ設定します。
phillip
にRDPで接続します。
PowerShellからsophie
アカウントのパスワードをリセットします。
sophie
へRDPで接続し、デスクトップのファイルからフラグを入手できました。
A.THM{thanks_for_contacting_support}
Q2.The process of granting privileges to a user over some OU or other AD Object is called...
A.delegation
Task5
Q1.After organising the available computers, how many ended up in the Workstations OU?
thm.local
にOUを追加します。
Workstations
,Servers
というOUを2つ追加します。
Computers
のラップトップ,PCはWorkstations
にサーバーはServers
に移動させます。
Workstations
のコンピュータは7
個になりました。
A.7
Q2.Is it recommendable to create separate OUs for Servers and Workstations? (yay/nay)
A.yay
Task6
Q1.What is the name of the network share used to distribute GPOs to domain machines?
A.SYSVOL
Q2.Can a GPO be used to apply settings to users and computers? (yay/nay)
A.yay
Task7
Q1.Will a current version of Windows use NetNTLM as the preferred authentication protocol by default? (yay/nay)
A.nay
Q2.When referring to Kerberos, what type of ticket allows us to request further tickets known as TGS?
A.Ticket Granting Ticket
Q3.When using NetNTLM, is a user's password transmitted over the network at any point? (yay/nay)
A.nay
Task8
Q1.What is a group of Windows domains that share the same namespace called?
A.Tree
Q2.What should be configured between two domains for a user in Domain A to access a resource in Domain B?
A.****