7MS #663: Pentesting GOAD SCCM


Episode Artwork
1.0x
0% played 00:00 00:00
Feb 21 2025 29 mins   35

Today we live-hack an SCCM server via GOAD SCCM using some attack guidance from Misconfiguration Manager! Attacks include:

  • Unauthenticated PXE attack
  • PXE (with password) attack
  • Relaying the machine account of the MECM box over to the SQL server to get local admin