daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

49-pentesting-tacacs.md (6603B)


      1 ---
      2 title: "49 - Pentesting TACACS+"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/49-pentesting-tacacs+.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/49-pentesting-tacacs%2B.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 49 - Pentesting TACACS+
     14 
     15 ## Basic Information
     16 
     17 The **Terminal Access Controller Access Control System (TACACS)** protocol is used to centrally validate users trying to access routers or Network Access Servers (NAS). Its upgraded version, **TACACS+**, separates the services into authentication, authorization, and accounting (AAA).
     18 
     19 ```text
     20 PORT   STATE  SERVICE
     21 49/tcp open   tacacs
     22 300/tcp open  tacacs-tls
     23 ```
     24 
     25 **Default ports:** 49/TCP (**legacy TACACS+**) and 300/TCP (**TACACS+ over TLS**).
     26 
     27 A useful offensive detail is that **legacy TACACS+ does not provide full transport encryption**. The **header stays in cleartext** (`version`, `type`, `seq_no`, `flags`, `session_id`, `length`) and the **body is only MD5-based obfuscation with the shared secret**.<sup>[[1]](#references)</sup> Therefore, if you can capture traffic, you can still carve sessions, identify auth/accounting flows, and prepare offline cracking attacks against the shared secret.
     28 
     29 > Newer deployments may implement **TACACS+ over TLS**. If you see **TCP/300** and an immediate TLS handshake, the classic capture-and-crack / packet-flipping attacks from this page usually only apply to the **legacy TCP/49** service. RFC 9887 also requires **TLS 1.3+** and disables the legacy TACACS+ body obfuscation inside the protected channel.<sup>[[3]](#references)</sup>
     30 
     31 ## Quick Enumeration
     32 
     33 ```bash
     34 nmap -sV -Pn -p 49,300 <IP>
     35 ```
     36 
     37 If you already have a packet capture, useful filters are:
     38 
     39 ```bash
     40 tcp.port == 49 || tcp.port == 300
     41 ```
     42 
     43 If the target uses legacy TACACS+, note the packet **type**, **sequence number**, and **session ID** from the cleartext header before attempting traffic manipulation or secret recovery. If the device uses **single-connection**, one long-lived TCP flow may contain multiple AAA exchanges, so a single capture can be much more valuable than it first appears.
     44 
     45 ## Capture Material for Shared-Secret Recovery
     46 
     47 The shared secret is **not transmitted** in a TACACS+ packet. A captured legacy exchange provides cleartext header fields and an obfuscated body that can be used to test shared-secret candidates offline when enough of the body plaintext is predictable. Cracking is not logged as repeated server authentication attempts, although the traffic interception itself may be detectable. Recovering the secret permits deobfuscation and, depending on device configuration, may support impersonation or manipulation; it does not automatically grant an interactive device login.<sup>[[1]](#references)</sup>
     48 
     49 ### Performing a MitM Attack
     50 
     51 An **ARP spoofing attack can be utilized to perform a Man-in-the-Middle (MitM) attack**. For routed environments, a TCP proxy/NAT setup can also be used to force TACACS+ traffic through the attacker.
     52 
     53 ### Brute-forcing the Key
     54 
     55 Loki is a historical tool for TACACS+ attacks, while a more practical modern workflow converts a captured exchange into a **Hashcat** input and cracks it offline.<sup>[[4]](#references)</sup>
     56 
     57 Using TacoTaco:<sup>[[2]](#references)</sup>
     58 
     59 ```bash
     60 python3 tac2cat.py -t 1 -m "Password: " \
     61   -p <hex_stream_from_wireshark> > tacacs.hash
     62 hashcat -m 16100 tacacs.hash <wordlist>
     63 ```
     64 
     65 The main gotcha is that `tac2cat.py` expects the **TACACS+ packet bytes** (for example, the second authentication packet exported from Wireshark as hex) plus the **prompt/banner string** shown by the device.
     66 
     67 If the secret is recovered, use it to deobfuscate the captured legacy TACACS+ bodies and assess whether the same secret enables unauthorized NAS/server interactions.
     68 
     69 ### Decrypting Traffic
     70 
     71 Once the key is successfully cracked, the next step is to **decrypt the TACACS-encrypted traffic**. Wireshark can handle **legacy** TACACS+ traffic if the shared secret is provided. By analyzing the decrypted traffic, information such as the **banner used**, the **username**, and sometimes **authorization/accounting AV pairs** can be obtained.
     72 
     73 ## Active Manipulation of Legacy TACACS+
     74 
     75 Legacy TACACS+ is also interesting from an **inline manipulation** perspective: because it lacks strong integrity protection, a MitM can sometimes **flip bits**, **replay packets**, or alter **authorization/accounting fields** without knowing the shared secret.<sup>[[1]](#references)</sup>
     76 
     77 The TacoTaco project includes `tacoflip.py`, built for **MitM authentication/authorization bypass** testing against legacy Cisco-style TACACS+ deployments:<sup>[[2]](#references)</sup>
     78 
     79 ```bash
     80 python3 tacoflip.py -t <TACACS_SERVER_IP>
     81 ```
     82 
     83 This is not a "remote unauthenticated RCE" primitive; it is a **traffic-position attack** that becomes viable when you can sit between the NAS and the TACACS+ server and the deployment is still using **plain TACACS+ over TCP/49**.
     84 
     85 ## Configuration Hunting
     86 
     87 If you already obtained device configurations through another path (for example via backups, TFTP, or [Cisco SNMP config-copy abuse](/hacktricks/network-services-pentesting/pentesting-snmp/cisco-snmp)), search them before spending time on live traffic attacks. TACACS+ client definitions often expose the target server addresses and sometimes directly expose the shared secret or its recoverable representation.
     88 
     89 ```bash
     90 rg -n "tacacs|aaa group server|tacacs-server| key " *.cfg
     91 ```
     92 
     93 On Cisco gear, look for legacy lines such as `tacacs-server host <ip> key <secret>` and newer `tacacs server <name>` blocks. Recovering the secret from configuration files is usually cleaner than trying to brute-force it from a short capture.
     94 
     95 By gaining access to the control panel of network equipment using the obtained credentials, the attacker can exert control over the network. It's important to note that these actions are strictly for educational purposes and should not be used without proper authorization.
     96 
     97 ## References
     98 
     99 - [1] [RFC 8907 - The TACACS+ Protocol](https://datatracker.ietf.org/doc/html/rfc8907)
    100 - [2] [TacoTaco - MitM traffic manipulation and offline cracking tools for TACACS+](https://github.com/GrrrDog/TacoTaco)
    101 - [3] [RFC 9887 - Using Transport Layer Security (TLS) to Secure TACACS+](https://datatracker.ietf.org/doc/html/rfc9887)
    102 - [4] [Loki source archive](https://c0decafe.de/svn/codename_loki/trunk/)