Explaining Domain Trust

1)Client —> Ask the Domain Controller a Ticket Granting Ticket

Untitled

  1. Domain Controller —> Reply with Ticket Granting Ticket

Untitled

  1. Client —> Request a Ticket Granting Service from Domain Controller

Untitled

  1. Domain Controller —> Reply with Inter-Realm Ticket Granting Ticket encrypted with (Trust Key)

Untitled

  1. Client —> Request Ticket Granting Service from Forest Root Domain Controller and the Forest Root Only Check if it can decrypt the ticket or not (No Validation On the Service Or The User Or Anything)

Untitled

  1. Forest Root Domain Controller —> Reply with Ticket Granting Service

Untitled

  1. Client —> Provide the Ticket Granting Service for Access

Untitled

  1. Application Server —> Verify and authenticate the user

Untitled

Now let’s Start Dumping Trust Keys