<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Delegation on Ethical Hacking | Pentest e Sicurezza Informatica | Hackita</title><link>https://hackita.it/tags/delegation/</link><description>Recent content in Delegation on Ethical Hacking | Pentest e Sicurezza Informatica | Hackita</description><generator>Hugo</generator><language>it</language><lastBuildDate>Sat, 18 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://hackita.it/tags/delegation/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB Redelegate Walkthrough: SeEnableDelegationPrivilege</title><link>https://hackita.it/articoli/htb-redelegate-walkthrough/</link><pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate><guid>https://hackita.it/articoli/htb-redelegate-walkthrough/</guid><description>&lt;h1
 id="htb-redelegate-walkthrough-da-ftp-anonimo-a-domain-admin-con-constrained-delegation" class="group/anchor-heading"&gt;
 HTB Redelegate Walkthrough: da FTP anonimo a Domain Admin con Constrained Delegation
 &lt;a href="#htb-redelegate-walkthrough-da-ftp-anonimo-a-domain-admin-con-constrained-delegation" class="text-inherit opacity-0 group-hover/anchor-heading:opacity-100 decoration-transparent"&gt;#&lt;/a&gt;
&lt;/h1&gt;&lt;p&gt;Redelegate è una macchina Windows di difficoltà &amp;ldquo;Hard&amp;rdquo; su Hack The Box (rilasciata e ritirata il 17 luglio 2025, creata da Geiseric), incentrata su enumerazione MSSQL, password spraying e abuso della delega Kerberos vincolata tramite &lt;a href="https://hackita.it/articoli/seenabledelegationprivilege/"&gt;SeEnableDelegationPrivilege&lt;/a&gt;. Se non hai ancora chiaro cosa significhi quel privilegio e come funzionano S4U2Self/S4U2Proxy, ti conviene leggere prima quell&amp;rsquo;articolo — qui diamo per scontato che tu sappia già la teoria e ci concentriamo sul percorso pratico sulla macchina.&lt;/p&gt;</description></item><item><title>SeEnableDelegationPrivilege: privesc AD, S4U e delega</title><link>https://hackita.it/articoli/seenabledelegationprivilege/</link><pubDate>Sat, 18 Jul 2026 00:00:00 +0000</pubDate><guid>https://hackita.it/articoli/seenabledelegationprivilege/</guid><description>&lt;h1
 id="seenabledelegationprivilege-in-active-directory-guida-completa-a-delega-kerberos-s4u-e-privesc" class="group/anchor-heading"&gt;
 SeEnableDelegationPrivilege in Active Directory: guida completa a delega Kerberos, S4U e privesc
 &lt;a href="#seenabledelegationprivilege-in-active-directory-guida-completa-a-delega-kerberos-s4u-e-privesc" class="text-inherit opacity-0 group-hover/anchor-heading:opacity-100 decoration-transparent"&gt;#&lt;/a&gt;
&lt;/h1&gt;&lt;p&gt;Se stai facendo un lab di &lt;a href="https://hackita.it/articoli/active-directory/"&gt;Active Directory&lt;/a&gt; (Hack The Box, VulnLab, o un ambiente autorizzato) e BloodHound ti mostra che il tuo utente ha il privilegio &lt;strong&gt;SeEnableDelegationPrivilege&lt;/strong&gt;, ti starai chiedendo cos&amp;rsquo;è esattamente e se è sfruttabile. In breve: è un diritto di Windows che decide chi, nel dominio, può far &amp;ldquo;impersonare&amp;rdquo; un utente da un altro account verso un servizio — un meccanismo chiamato delega Kerberos, pensato per usi legittimi ma che diventa un bersaglio di privesc molto potente in mani sbagliate.&lt;/p&gt;</description></item></channel></rss>