Active Directory Hacking: MidGarden2 (Part 3) - Hack Smarter Labs

Active Directory Hacking: MidGarden2 (Part 3) - Hack Smarter Labs

Source: YouTube · Tyler Ramsbey - Hack Smarter · published Feb 26, 2026 · 21:03

Penetration Testing
No ratings yet Log in to rate
Transcript Available
Description

This video demonstrates part three of the "Midg Garden 2 Lab" walkthrough on Hacksmarter, focusing on escalating privileges via the Hoder user and introducing the Bad Successor vulnerability 0:04-0:06.

Key Takeaways:
• The creator promotes a web app pentesting course that teaches legal hacking methodologies and offers a 100% refund guarantee 0:30-0:41
• Using BloodHound and net rpc, the attacker exploits the Thor user’s "force change password" privilege to reset Hoder’s credentials 1:20-2:15
• Enumerating Hoder reveals membership in "Remote Management Users," enabling WinRM access to the domain controller and retrieval of the user flag 3:10-3:45
• The walkthrough concludes by identifying "Bad Successor" as the next attack vector, leveraging DMSA configurations to escalate to domain admin 4:30-5:00

The session highlights the critical importance of understanding Active Directory service accounts and concludes by challenging viewers to attempt the Bad Successor exploitation independently before part four.

Sources:

  • 0:04-0:06 Introduction to Midg Garden 2 Lab
  • 0:30-0:41 Course promotion and refund policy
  • 1:20-2:15 Password reset via net rpc and BloodHound
  • 3:10-3:45 WinRM access and user flag capture
  • 4:30-5:00 Bad Successor vulnerability explanation

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Penetration Testing. Commonly maps to: Security Assessment and Testing, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

What is up everyone? Welcome back to another video. This is part three of working through the Midg Garden 2 Lab on the Hacksmarter platform. You'll also notice as we go there is live chat on the screen somewhere. No, that way. It's really hard for me to point when I'm looking at the camera, but I make all of these while I'm live streaming and I live stream all the time. So, where are you? You should have been in the live studio audience. So, make sure you smash the subscribe button as the YouTubers say and hit the little bell notification so that you are notified the next time I am live. But hey, before we dive into all of the fun hacking for today's video, I have a short little one minute video to share with you about a course I just released. So, let me share this and then we will dive i…