daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

harvesting-tickets-from-linux.md (8179B)


      1 ---
      2 title: "Harvesting Tickets from Linux"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Harvesting Tickets from Linux
     14 
     15 ### Credential Storage in Linux
     16 
     17 Linux Kerberos implementations support several credential-cache types, including **files**, **directories**, **kernel keyrings**, **KCM**, and **process memory**. The `default_ccache_name` setting in `/etc/krb5.conf` indicates the configured default; an implementation or distribution may choose a different default when the setting is absent.<sup>[[5]](#references)</sup>
     18 
     19 MIT/Heimdal also support additional backends that you should look for during post-exploitation:
     20 
     21 - `DIR:/run/user/%{uid}/krb5cc` for directory-backed multi-ticket caches (systemd-logind default on modern distros).
     22 - `KEYRING:persistent:%{uid}` or `KEYRING:session` to stash ccaches inside the kernel keyring (`KEY_SPEC_SESSION_KEYRING`, `KEY_SPEC_USER_KEYRING`, etc.).
     23 - `KCM:%{uid}` when SSSD’s Kerberos Cache Manager daemon (kcm) fronts ticket storage.
     24 - `MEMORY:unique_id` for process-local caches created by libraries (`gssproxy`, `sshd`, etc.).<sup>[[2]](#references)[[5]](#references)</sup>
     25 
     26 Whenever you pop a shell, dump `KRB5CCNAME` from `/proc/<pid>/environ` of interesting daemons (e.g. Apache, sshd, gssproxy) to know which cache backend is being used before you start copying files.
     27 
     28 ### Enumerating Active Caches
     29 
     30 Enumerate the caches before extraction to avoid missing high-value tickets:
     31 
     32 ```bash
     33 $ klist -l            # list caches registered in the local keyring/KCM
     34 $ klist -A            # show all ticket-granting tickets in the current cache
     35 $ sudo keyctl get_persistent @u
     36 $ sudo keyctl show `keyctl get_persistent @u`
     37 $ sudo ls -al /tmp/krb5cc_* /run/user/*/krb5cc*
     38 $ sudo find /proc -maxdepth 2 -name environ -exec sh -c 'tr "\0" "\n" < {} | grep -H KRB5' \;
     39 ```
     40 
     41 The combination of `klist`, `keyctl`, and `/proc` inspection quickly reveals whether credentials live in files, keyrings, or KCM so you can pick the right dumping technique.<sup>[[4]](#references)[[5]](#references)</sup>
     42 
     43 ### Extracting Credentials
     44 
     45 The 2017 paper, [**Kerberos Credential Thievery (GNU/Linux)**](https://web.archive.org/web/20210721113019/https://www.delaat.net/rp/2016-2017/p97/report.pdf), outlines methods for extracting credentials from keyrings and processes, emphasizing the Linux kernel's keyring mechanism for managing and storing keys.<sup>[[4]](#references)</sup>
     46 
     47 #### Keyring Extraction Overview
     48 
     49 The **keyctl system call**, introduced in kernel version 2.6.10, allows user space applications to interact with kernel keyrings. Credentials in keyrings are stored as components (default principal and credentials), distinct from file ccaches which also include a header. The **hercules.sh script** from the paper demonstrates extracting and reconstructing these components into a usable file ccache for credential theft.<sup>[[4]](#references)</sup> Remember that keyring-stored ccaches may live under `KEYRING:persistent:%{uid}` (permanent across logins), `KEYRING:session` (cleared on logout), or even `KEY_SPEC_THREAD_KEYRING` for services spawning helper threads—so always enumerate all keyring types for the compromised UID.
     50 
     51 #### Manual KEYRING Workflow
     52 
     53 You can manually harvest tickets without helper scripts whenever `default_ccache_name` is set to `KEYRING:`:
     54 
     55 ```bash
     56 $ KRING=$(keyctl get_persistent @u)
     57 $ keyctl show $KRING                       # note the key serial of each ccache blob
     58 $ keyctl pipe <serial> > /tmp/key_blob     # extract one key payload
     59 ```
     60 
     61 The extracted key payload is not necessarily a complete MIT ccache: KEYRING collections store a cache as several components. Reconstruct the components with a tool such as `tickey`/`hercules.sh`, validate the resulting cache with `klist`, and then convert it with `kerbtool` or Impacket's `ticketConverter.py` when `.kirbi` interoperability is required. Repeat the extraction for every relevant serial and principal.<sup>[[1]](#references)[[3]](#references)[[4]](#references)[[6]](#references)</sup>
     62 
     63 #### File/DIR Cache Theft Quick Wins
     64 
     65 When credentials are stored as `FILE:` or `DIR:` caches, simple file operations are usually enough:
     66 
     67 ```bash
     68 $ sudo cp /tmp/krb5cc_1000 /tmp/websvc.ccache
     69 $ sudo cp -r /run/user/1000/krb5cc /tmp/user1000_dircc
     70 $ chmod 600 /tmp/*.ccache && chown attacker /tmp/*.ccache
     71 ```
     72 
     73 Directory caches contain one file per service ticket, so compress and exfiltrate the whole directory to keep TGT + TGS pairs intact. You can also point your tooling at the directory directly: `KRB5CCNAME=DIR:/tmp/user1000_dircc impacket-psexec ...`.
     74 
     75 #### Dumping KCM-Managed Caches
     76 
     77 SSSD’s Kerberos Cache Manager (kcm) proxies credential storage through `/var/run/kcm/kcmsock` (or `/run/.heim_org.h5l.kcm-socket`) and persists encrypted blobs inside `/var/lib/sss/secrets/` together with `.secrets.mkey`.<sup>[[2]](#references)</sup> Attack flow:
     78 
     79 1. Identify KCM usage via `/etc/krb5.conf` (`default_ccache_name = KCM:`) or `klist -l` outputs.
     80 2. If you have UID 0 or are part of the `kcm` SELinux domain, enumerate caches via the management tool:
     81 
     82 ```bash
     83 $ sudo kcm_ctl list                 # lists UID + cache IDs handled by kcm
     84 $ sudo kcm_ctl get 1000 0 > /tmp/1000.kcm.ccache
     85 $ KRB5CCNAME=/tmp/1000.kcm.ccache klist
     86 ```
     87 
     88 3. Offline approach: copy `/var/lib/sss/secrets/secrets.ldb` plus `/var/lib/sss/secrets/.secrets.mkey`, then run `SSSDKCMExtractor` (or similar PoCs) to decrypt and reassemble ccaches without touching the live socket. This is especially useful in forensics or when socket ACLs block you but disk access is possible.
     89 
     90 Because the kcm daemon honors UID-based ACLs enforced by SSSD, privilege escalation to root (or compromising `sssd_kcm`) is usually required, but once achieved you can dump every user’s TGT in seconds.
     91 
     92 ### Ticket Extraction Tooling
     93 
     94 Automating the above steps reduces mistakes and gives you cross-platform ticket material you can replay from Windows tooling.
     95 
     96 #### Tickey
     97 
     98 Building on the principles of the **hercules.sh script**, the [**tickey**](https://github.com/TarlogicSecurity/tickey) tool is specifically designed for extracting tickets from keyrings, executed via `/tmp/tickey -i`. It enumerates kernel keyrings, reconstructs the serialized ccaches, and writes MIT-compatible cache files you can immediately feed to `klist`, `impacket-*`, or `kerberoast` tooling.<sup>[[1]](#references)</sup>
     99 
    100 #### Kerbtool
    101 
    102 [**kerbtool**](https://github.com/jfjallid/kerbtool) is a modern Go utility that runs natively on Linux and can parse, convert, and request Kerberos tickets. Two handy use cases when harvesting from Linux boxes:<sup>[[3]](#references)</sup>
    103 
    104 ```bash
    105 # Convert a stolen MIT ccache into a .kirbi usable by Windows tooling
    106 $ ./kerbtool --convert --in /tmp/websvc.ccache --out websvc.kirbi
    107 
    108 # Use an extracted cache to request additional TGS tickets without touching the victim again
    109 $ KRB5CCNAME=/tmp/websvc.ccache ./kerbtool --ask --spn cifs/fileserver.lab.local
    110 ```
    111 
    112 Having both tickey and kerbtool on your implant host lets you move seamlessly between Linux, Windows, and cross-platform Kerberos attack chains.
    113 
    114 ## References
    115 
    116 - [1] [Kerberos (II): How to attack Kerberos?](https://www.tarlogic.com/blog/how-to-attack-kerberos/)
    117 - [2] [KCM server for SSSD](https://docs.pagure.org/sssd.sssd/design_pages/kcm.html)
    118 - [3] [kerbtool](https://github.com/jfjallid/kerbtool)
    119 - [4] [Kerberos Credential Thievery (GNU/Linux)](https://web.archive.org/web/20210721113019/https://www.delaat.net/rp/2016-2017/p97/report.pdf)
    120 - [5] [MIT Kerberos - Credential cache types](https://web.mit.edu/kerberos/krb5-latest/doc/basic/ccache_def.html)
    121 - [6] [Fortra Impacket - `ticketConverter.py`](https://github.com/fortra/impacket/blob/master/examples/ticketConverter.py)