BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Certified Re-Pwned: escalating all the way up\n   Ta
 gs: DEF CON Official Talk | Demo ðŸ’» | Tool ðŸ› \n   When: Friday\, Aug 7
 \, 16:00 - 16:59 PDT\n   Where: LVCCW Level 1 Hall 3 906 (Main Track 3) an
 d DCTV-3 - [1]Map\n\n   Description:\n\n   Four years after KB5014754 and 
 one year after CVE-2024-49019\, every\n   hardening guide says Active Dire
 ctory Certificate Services is a closed\n   book. This talk reopens it.\n\n
    We present five new primitives â€” proposed as ESC18 through ESC22\,\n 
   extending the public ESC1â€“ESC17 numbering â€” each validated\n   end-t
 o-end on a fully-patched Windows Server 2025 Enterprise CA with\n   every 
 Microsoft-recommended mitigation applied. Every primitive starts\n   from 
 a Domain Users account with no ACL\, GPO\, or template edges\, and\n   end
 s at krbtgt extraction.\n\n   Each primitive targets a different component
  of the post-2022 defence:\n   the CA's CSR processor\, the CA's Security-
 Extension writer\, the KDC's\n   PKINIT binder\, the CA's Enroll-On-Behalf
 -Of path\, and the\n   registry-level enforcement layer everyone thinks is
  already hardened.\n   Together they argue that Microsoft's 2022 and 2024 
 fixes patched\n   specific instances of the underlying bug classes\, not t
 he classes\n   themselves â€” and that at least one control has an undocum
 ented\n   fallback path its own documentation does not mention.\n\n   A Ce
 rtipy research fork will be released at the time of the talk to\n   check 
 and exploit the new techniques.\n\n   https://posts.specterops.io/certifie
 d-pre-owned-d95910965cd2\n   https://specterops.io/wp-content/uploads/site
 s/3/2022/06/Certified_Pre-Owned.pdf\n   https://support.microsoft.com/en-u
 s/topic/kb5014754-certificate-based-authentication-changes-on-windows-doma
 in-controllers-ad2c23b0-15d8-4340-a468-4d4f3b188f16\n   https://msrc.micro
 soft.com/update-guide/vulnerability/CVE-2024-49019\n   https://posts.spect
 erops.io/adcs-esc13-abuse-technique-fda4272fbd53\n   https://github.com/ly
 4k/Certipy\n\n   Speakers:Daniel Monzon\,Eric Labrador\n\n   SpeakerBio:  
 Daniel Monzon\n\n   Daniel MonzÃ³n (stark0de) â€” Offensive Security Engin
 eer at Halborn\n   with 6+ years of offensive security experience across w
 eb pentesting\,\n   code review\, Active Directory (on-premise and hybrid)
 \, Android/iOS\n   mobile audits\, thick-client assessments and red teamin
 g. Holds\n   certifications such as: OSCP\, CRTP\, OSWP\, CREST CPSA\, eMA
 PT\, PACSP\,\n   and CARTP. Has been credited with multiple CVEs in open-s
 ource and\n   commercial products\, and currently focuses on Web3 and\n   
 financial-sector security. Prior speaker at hack0n\, RootedCON MÃ¡laga\,\n
    DragonJARCON\, and SecAdmin.\n\n   SpeakerBio:  Eric Labrador\n\n   Eri
 c Labrador is an offensive security researcher at Accenture with\n   over 
 6 years of experience breaking into networks\, applications\, and\n   buil
 dings for a living. His day-to-day work covers Red and Purple Team\n   exe
 rcises\, web and API audits\, Android and iOS mobile application\n   asses
 sments\, internal and external penetration testing\, physical\n   intrusio
 ns into corporate buildings\, and large-scale phishing\n   campaigns. He h
 olds the OSCP\, CRTE\, CRTO\, BSCP\, and eWPTXv2\n   certifications\, and 
 is the author of ImagePanick\, an open-source\n   exploit chain that achie
 ves arbitrary file write and remote code\n   execution by combining weak d
 efault policies in ImageMagick with SAFER\n   bypasses in Ghostscript\, al
 l triggered from a malicious SVG. Over the\n   years he has delivered end-
 to-end attack paths that chain phishing\,\n   external footholds\, lateral
  movement\, and physical entry into full\n   compromise across multiple in
 dustries\, helping clients understand what\n   a motivated attacker can ac
 tually do with the people\, processes\, and\n   technology already in plac
 e.\n\n   '\n\n   1. #LVCCW_Level1_Hall3\n\n\n
DTEND:20260807T235900Z
DTSTART:20260807T230000Z
LOCATION:DEF CON Talks - LVCCW Level 1 Hall 3 906 (Main Track 3) and DCTV-3
SUMMARY:Certified Re-Pwned: escalating all the way up
END:VEVENT
END:VCALENDAR
