Cross Forest Attacks
General
Same attack flow as with cross-domain attacks
But: trust between forest must be established manually
No implicit trust
Cannot abuse SID because of SID filtering
We only get the privileges the user we are impersonating has in the target forest
Exploitation
Mitigation
SID Filtering
Avoid attacks which abuse SID history attribute across forest trust
Enabled by default on all inter forest trusts. Intra forest trusts are assumed secured by default (MS considers forest and not the domain to be a security boundary)
But, since SID filtering has potential to break applications and user access, it is often disabled
Selective Authentication
If configured in an inter-forest trust, users between trusts will not be automatically authenticated
Invididual access to domains and servers in the trusting domain/forest should be given
Last updated