49-pentesting-tacacs.md (6603B)
1 --- 2 title: "49 - Pentesting TACACS+" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/49-pentesting-tacacs+.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/49-pentesting-tacacs%2B.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 49 - Pentesting TACACS+ 14 15 ## Basic Information 16 17 The **Terminal Access Controller Access Control System (TACACS)** protocol is used to centrally validate users trying to access routers or Network Access Servers (NAS). Its upgraded version, **TACACS+**, separates the services into authentication, authorization, and accounting (AAA). 18 19 ```text 20 PORT STATE SERVICE 21 49/tcp open tacacs 22 300/tcp open tacacs-tls 23 ``` 24 25 **Default ports:** 49/TCP (**legacy TACACS+**) and 300/TCP (**TACACS+ over TLS**). 26 27 A useful offensive detail is that **legacy TACACS+ does not provide full transport encryption**. The **header stays in cleartext** (`version`, `type`, `seq_no`, `flags`, `session_id`, `length`) and the **body is only MD5-based obfuscation with the shared secret**.<sup>[[1]](#references)</sup> Therefore, if you can capture traffic, you can still carve sessions, identify auth/accounting flows, and prepare offline cracking attacks against the shared secret. 28 29 > Newer deployments may implement **TACACS+ over TLS**. If you see **TCP/300** and an immediate TLS handshake, the classic capture-and-crack / packet-flipping attacks from this page usually only apply to the **legacy TCP/49** service. RFC 9887 also requires **TLS 1.3+** and disables the legacy TACACS+ body obfuscation inside the protected channel.<sup>[[3]](#references)</sup> 30 31 ## Quick Enumeration 32 33 ```bash 34 nmap -sV -Pn -p 49,300 <IP> 35 ``` 36 37 If you already have a packet capture, useful filters are: 38 39 ```bash 40 tcp.port == 49 || tcp.port == 300 41 ``` 42 43 If the target uses legacy TACACS+, note the packet **type**, **sequence number**, and **session ID** from the cleartext header before attempting traffic manipulation or secret recovery. If the device uses **single-connection**, one long-lived TCP flow may contain multiple AAA exchanges, so a single capture can be much more valuable than it first appears. 44 45 ## Capture Material for Shared-Secret Recovery 46 47 The shared secret is **not transmitted** in a TACACS+ packet. A captured legacy exchange provides cleartext header fields and an obfuscated body that can be used to test shared-secret candidates offline when enough of the body plaintext is predictable. Cracking is not logged as repeated server authentication attempts, although the traffic interception itself may be detectable. Recovering the secret permits deobfuscation and, depending on device configuration, may support impersonation or manipulation; it does not automatically grant an interactive device login.<sup>[[1]](#references)</sup> 48 49 ### Performing a MitM Attack 50 51 An **ARP spoofing attack can be utilized to perform a Man-in-the-Middle (MitM) attack**. For routed environments, a TCP proxy/NAT setup can also be used to force TACACS+ traffic through the attacker. 52 53 ### Brute-forcing the Key 54 55 Loki is a historical tool for TACACS+ attacks, while a more practical modern workflow converts a captured exchange into a **Hashcat** input and cracks it offline.<sup>[[4]](#references)</sup> 56 57 Using TacoTaco:<sup>[[2]](#references)</sup> 58 59 ```bash 60 python3 tac2cat.py -t 1 -m "Password: " \ 61 -p <hex_stream_from_wireshark> > tacacs.hash 62 hashcat -m 16100 tacacs.hash <wordlist> 63 ``` 64 65 The main gotcha is that `tac2cat.py` expects the **TACACS+ packet bytes** (for example, the second authentication packet exported from Wireshark as hex) plus the **prompt/banner string** shown by the device. 66 67 If the secret is recovered, use it to deobfuscate the captured legacy TACACS+ bodies and assess whether the same secret enables unauthorized NAS/server interactions. 68 69 ### Decrypting Traffic 70 71 Once the key is successfully cracked, the next step is to **decrypt the TACACS-encrypted traffic**. Wireshark can handle **legacy** TACACS+ traffic if the shared secret is provided. By analyzing the decrypted traffic, information such as the **banner used**, the **username**, and sometimes **authorization/accounting AV pairs** can be obtained. 72 73 ## Active Manipulation of Legacy TACACS+ 74 75 Legacy TACACS+ is also interesting from an **inline manipulation** perspective: because it lacks strong integrity protection, a MitM can sometimes **flip bits**, **replay packets**, or alter **authorization/accounting fields** without knowing the shared secret.<sup>[[1]](#references)</sup> 76 77 The TacoTaco project includes `tacoflip.py`, built for **MitM authentication/authorization bypass** testing against legacy Cisco-style TACACS+ deployments:<sup>[[2]](#references)</sup> 78 79 ```bash 80 python3 tacoflip.py -t <TACACS_SERVER_IP> 81 ``` 82 83 This is not a "remote unauthenticated RCE" primitive; it is a **traffic-position attack** that becomes viable when you can sit between the NAS and the TACACS+ server and the deployment is still using **plain TACACS+ over TCP/49**. 84 85 ## Configuration Hunting 86 87 If you already obtained device configurations through another path (for example via backups, TFTP, or [Cisco SNMP config-copy abuse](/hacktricks/network-services-pentesting/pentesting-snmp/cisco-snmp)), search them before spending time on live traffic attacks. TACACS+ client definitions often expose the target server addresses and sometimes directly expose the shared secret or its recoverable representation. 88 89 ```bash 90 rg -n "tacacs|aaa group server|tacacs-server| key " *.cfg 91 ``` 92 93 On Cisco gear, look for legacy lines such as `tacacs-server host <ip> key <secret>` and newer `tacacs server <name>` blocks. Recovering the secret from configuration files is usually cleaner than trying to brute-force it from a short capture. 94 95 By gaining access to the control panel of network equipment using the obtained credentials, the attacker can exert control over the network. It's important to note that these actions are strictly for educational purposes and should not be used without proper authorization. 96 97 ## References 98 99 - [1] [RFC 8907 - The TACACS+ Protocol](https://datatracker.ietf.org/doc/html/rfc8907) 100 - [2] [TacoTaco - MitM traffic manipulation and offline cracking tools for TACACS+](https://github.com/GrrrDog/TacoTaco) 101 - [3] [RFC 9887 - Using Transport Layer Security (TLS) to Secure TACACS+](https://datatracker.ietf.org/doc/html/rfc9887) 102 - [4] [Loki source archive](https://c0decafe.de/svn/codename_loki/trunk/)