#GoldenTicket

StacesCases2 🇨🇦 📎stacescases2.bsky.social@bsky.brid.gy
2025-05-18

Trumps #GoldenTicket hard at work for the #American people.

WIRED - The Latest in Technology, Science, Culture and Businesswired.com@web.brid.gy
2025-05-12

A VIP Seat at Donald Trump’s Crypto Dinner Cost at Least $2 Million

fed.brid.gy/r/https://www.wire

WIRED - The Latest in Technology, Science, Culture and Businesswired.com@web.brid.gy
2025-05-07

A ‘Trump Card Visa’ Is Already Showing Up in Immigration Forms

fed.brid.gy/r/https://www.wire

Patrick Loftus 🖖:us_d:pwloftus@pwl.farted.net
2025-04-05

Now that citizenship costs $5m can we sell our legacy citizenship on a secondary market or would that reveal the true free market price?

#trump #usa #goldenticket

tomwsmftomwsmf
2025-03-02

While I whiffed on getting the of a fully assembled yesterday, I scored a kit of the NG Linotte v2. Ive been watching build videos and going thru the build docs till it arrives. I am so not ready, but if not now when?

I also purchased a separated wheel and crank set because.... . I am going to take what I learn building the Linotte and what I am learning building s ....and throw in my ready fire aim methodology. What could go wrong?

2025-01-26

Totally didn't notice the date when I wrote all this up. Happy #goldenticket day.

2025-01-24

Blahblahblah later, runout etch confirmed and #goldenticket secured. 2 tickets. any show! for life! So now we join the #bastards on their grand adventures whenever we can, sometimes bringing others along for the ride

2025-01-24

in lieu of a proper #introduction, let's tell a story. About those #primus bastards and how i got pulled into their glorious madness #goldenticket

Charlie holding a golden ticket
2024-11-05

The worst case has happened: Hackers have managed to breach your network and elevate their privileges to their ultimate goal: Domain Admin.

Today, we will take a look at one of the attacks that this absolute nightmare scenario makes possible for attackers: Golden Tickets (MITRE T1558.001)

But let’s start at the beginning: Kerberos authentication. When a user logs in, a Ticket Granting Ticket (TGT) is issued to the user. Put very simply, the ticket contains, among other things, the username to identify the user. To prevent users from simply modifying a ticket and impersonating other users, the ticket is encrypted.

The encryption key that secures the ticket is essentially the password hash of a user called krbtgt. This makes the krbtgt user one of the most sensitive, if not the most sensitive, user in an Active Directory domain. If this user's password is weak or the password (hash) is compromised, the entire domain is compromised.

This is because attackers can use this password hash to forge their own tickets and impersonate any user they want. They simply create a ticket with the username they want and encrypt it with the password hash. They now have an authentication ticket that, if done correctly, is virtually indistinguishable from a real ticket.

And that's what’s called a “Golden Ticket”. And there are many tools available to attackers, the most prominent of which are: Mimikatz, Rubeus and Impacket.

The fact that it abuses legitimate functionality, makes it difficult to detect a Golden Ticket attack. However, there are a few things that you can look out for:

* Are there TGS requests (Event 4769) without the original TGT being issued by the KDC (Event 4768)?
* Is RC4 encryption being used?
* Strange TGT parameters (e.g. very long lifetimes)?
* Are there logins from sensitive accounts that aren’t normally used (e.g. the default domain administrator account)?

Additionally, you can also look for signs of Pass the Ticket attacks (MITRE T1550.003).

To mitigate this attack, the krbtgt password should be changed whenever a highly privileged user leaves the organization and additionally on a fixed schedule (and, of course, if you suspect a compromise). Make sure that the password is very, very strong.

But changing the password once is not enough. It has to be changed twice because of the password history. However, be careful not to do this in quick succession. The change must be replicated to other domain controllers first. Otherwise, you risk severe authentication problems.

#itsecurity #GoldenTicket #ttp #mitre #redteam #redteaming #TechTuesday

A boy holding a golden ticket
2024-10-04

Golden Ticket premia con entrada doble a todos los eventos del 2025 presentados por BAC

San José, 04 oct (elmundo.cr) – Por segundo año consecutivo, BAC presenta Golden Ticket con American Express®, la promoción que brinda la oportunidad a cuatro ganadores de vivir experiencias únicas con entradas dobles a todos los conciertos presentados por el banco. Esta iniciativa permitirá a los ganadores seleccionar los concie [...]

#AmericanExpress #BAC #GoldenTicket #Tendencias

elmundo.cr/tendencias/golden-t

2024-08-18

Раскуриваем Golden Ticket и смотрим артефакты

🔥 Атака Golden Ticket позволяет злоумышленнику выпустить золотой билет Kerberos (TGT) с помощью секретного ключа (хэш) сервисной учетной записи KRBTGT. Данная техника позволяет максимально скрыть следы своего присутствия, поскольку для инфраструктуры злоумышленник будет казаться легитимным пользователем, но без фактической аутентификации и с желаемыми правами. В данной статье разберем атаку на практике и научимся ее детектить по артефактам...

habr.com/ru/articles/836818/

#golden_ticket #goldenticket #ad #activedirectory #rubeus #impacket

2024-06-24

Mastodon Biography: Julio Foolio
Source: linktr.ee/CelebrityBiopic

🤝 Foolio's collaboration with 🎹 Zaytoven was his 🎟️ ticket to the big time. But success in the 🎶 music industry often comes at a 💰 price…

2024-03-30
Lance (Ranger Bob) Taylorlancetay@universeodon.com
2024-01-28

Watching the Wonka movie while flashing back about 40 years in time and space. #AllThingsArePossible #iMemberBerry #Atari #MyArcade Saving a few of these for later to open. #GoldenTicket #RetroGaming

#SpecialEvent 15, 16, 17 December 2023 (Possibly longer) ~ #WØNKA

“…We will be in Browns Creek State Trail, Park K- 9386 to get more exposure and to give the POTA folks points. ~ After dark we will operate from the Chocolate Factory.

Get your very own #GoldenTicket like in the movie! Special tickets made for this event... and ONLY this event... but nothing else.

I am asking for you to cover the printing cost.” #SpecialEventStation #HamRadio #AmateurRadio #POTA

qrz.com/db/W0NKA

A picture of the “W0NKA’S Golden Ticket” QSL card that will be provided for QSO’s and shortwave reception of this special event.

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst