harvesting-tickets-from-linux.md (8179B)
1 --- 2 title: "Harvesting Tickets from Linux" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-kerberos-88/harvesting-tickets-from-linux.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Harvesting Tickets from Linux 14 15 ### Credential Storage in Linux 16 17 Linux Kerberos implementations support several credential-cache types, including **files**, **directories**, **kernel keyrings**, **KCM**, and **process memory**. The `default_ccache_name` setting in `/etc/krb5.conf` indicates the configured default; an implementation or distribution may choose a different default when the setting is absent.<sup>[[5]](#references)</sup> 18 19 MIT/Heimdal also support additional backends that you should look for during post-exploitation: 20 21 - `DIR:/run/user/%{uid}/krb5cc` for directory-backed multi-ticket caches (systemd-logind default on modern distros). 22 - `KEYRING:persistent:%{uid}` or `KEYRING:session` to stash ccaches inside the kernel keyring (`KEY_SPEC_SESSION_KEYRING`, `KEY_SPEC_USER_KEYRING`, etc.). 23 - `KCM:%{uid}` when SSSD’s Kerberos Cache Manager daemon (kcm) fronts ticket storage. 24 - `MEMORY:unique_id` for process-local caches created by libraries (`gssproxy`, `sshd`, etc.).<sup>[[2]](#references)[[5]](#references)</sup> 25 26 Whenever you pop a shell, dump `KRB5CCNAME` from `/proc/<pid>/environ` of interesting daemons (e.g. Apache, sshd, gssproxy) to know which cache backend is being used before you start copying files. 27 28 ### Enumerating Active Caches 29 30 Enumerate the caches before extraction to avoid missing high-value tickets: 31 32 ```bash 33 $ klist -l # list caches registered in the local keyring/KCM 34 $ klist -A # show all ticket-granting tickets in the current cache 35 $ sudo keyctl get_persistent @u 36 $ sudo keyctl show `keyctl get_persistent @u` 37 $ sudo ls -al /tmp/krb5cc_* /run/user/*/krb5cc* 38 $ sudo find /proc -maxdepth 2 -name environ -exec sh -c 'tr "\0" "\n" < {} | grep -H KRB5' \; 39 ``` 40 41 The combination of `klist`, `keyctl`, and `/proc` inspection quickly reveals whether credentials live in files, keyrings, or KCM so you can pick the right dumping technique.<sup>[[4]](#references)[[5]](#references)</sup> 42 43 ### Extracting Credentials 44 45 The 2017 paper, [**Kerberos Credential Thievery (GNU/Linux)**](https://web.archive.org/web/20210721113019/https://www.delaat.net/rp/2016-2017/p97/report.pdf), outlines methods for extracting credentials from keyrings and processes, emphasizing the Linux kernel's keyring mechanism for managing and storing keys.<sup>[[4]](#references)</sup> 46 47 #### Keyring Extraction Overview 48 49 The **keyctl system call**, introduced in kernel version 2.6.10, allows user space applications to interact with kernel keyrings. Credentials in keyrings are stored as components (default principal and credentials), distinct from file ccaches which also include a header. The **hercules.sh script** from the paper demonstrates extracting and reconstructing these components into a usable file ccache for credential theft.<sup>[[4]](#references)</sup> Remember that keyring-stored ccaches may live under `KEYRING:persistent:%{uid}` (permanent across logins), `KEYRING:session` (cleared on logout), or even `KEY_SPEC_THREAD_KEYRING` for services spawning helper threads—so always enumerate all keyring types for the compromised UID. 50 51 #### Manual KEYRING Workflow 52 53 You can manually harvest tickets without helper scripts whenever `default_ccache_name` is set to `KEYRING:`: 54 55 ```bash 56 $ KRING=$(keyctl get_persistent @u) 57 $ keyctl show $KRING # note the key serial of each ccache blob 58 $ keyctl pipe <serial> > /tmp/key_blob # extract one key payload 59 ``` 60 61 The extracted key payload is not necessarily a complete MIT ccache: KEYRING collections store a cache as several components. Reconstruct the components with a tool such as `tickey`/`hercules.sh`, validate the resulting cache with `klist`, and then convert it with `kerbtool` or Impacket's `ticketConverter.py` when `.kirbi` interoperability is required. Repeat the extraction for every relevant serial and principal.<sup>[[1]](#references)[[3]](#references)[[4]](#references)[[6]](#references)</sup> 62 63 #### File/DIR Cache Theft Quick Wins 64 65 When credentials are stored as `FILE:` or `DIR:` caches, simple file operations are usually enough: 66 67 ```bash 68 $ sudo cp /tmp/krb5cc_1000 /tmp/websvc.ccache 69 $ sudo cp -r /run/user/1000/krb5cc /tmp/user1000_dircc 70 $ chmod 600 /tmp/*.ccache && chown attacker /tmp/*.ccache 71 ``` 72 73 Directory caches contain one file per service ticket, so compress and exfiltrate the whole directory to keep TGT + TGS pairs intact. You can also point your tooling at the directory directly: `KRB5CCNAME=DIR:/tmp/user1000_dircc impacket-psexec ...`. 74 75 #### Dumping KCM-Managed Caches 76 77 SSSD’s Kerberos Cache Manager (kcm) proxies credential storage through `/var/run/kcm/kcmsock` (or `/run/.heim_org.h5l.kcm-socket`) and persists encrypted blobs inside `/var/lib/sss/secrets/` together with `.secrets.mkey`.<sup>[[2]](#references)</sup> Attack flow: 78 79 1. Identify KCM usage via `/etc/krb5.conf` (`default_ccache_name = KCM:`) or `klist -l` outputs. 80 2. If you have UID 0 or are part of the `kcm` SELinux domain, enumerate caches via the management tool: 81 82 ```bash 83 $ sudo kcm_ctl list # lists UID + cache IDs handled by kcm 84 $ sudo kcm_ctl get 1000 0 > /tmp/1000.kcm.ccache 85 $ KRB5CCNAME=/tmp/1000.kcm.ccache klist 86 ``` 87 88 3. Offline approach: copy `/var/lib/sss/secrets/secrets.ldb` plus `/var/lib/sss/secrets/.secrets.mkey`, then run `SSSDKCMExtractor` (or similar PoCs) to decrypt and reassemble ccaches without touching the live socket. This is especially useful in forensics or when socket ACLs block you but disk access is possible. 89 90 Because the kcm daemon honors UID-based ACLs enforced by SSSD, privilege escalation to root (or compromising `sssd_kcm`) is usually required, but once achieved you can dump every user’s TGT in seconds. 91 92 ### Ticket Extraction Tooling 93 94 Automating the above steps reduces mistakes and gives you cross-platform ticket material you can replay from Windows tooling. 95 96 #### Tickey 97 98 Building on the principles of the **hercules.sh script**, the [**tickey**](https://github.com/TarlogicSecurity/tickey) tool is specifically designed for extracting tickets from keyrings, executed via `/tmp/tickey -i`. It enumerates kernel keyrings, reconstructs the serialized ccaches, and writes MIT-compatible cache files you can immediately feed to `klist`, `impacket-*`, or `kerberoast` tooling.<sup>[[1]](#references)</sup> 99 100 #### Kerbtool 101 102 [**kerbtool**](https://github.com/jfjallid/kerbtool) is a modern Go utility that runs natively on Linux and can parse, convert, and request Kerberos tickets. Two handy use cases when harvesting from Linux boxes:<sup>[[3]](#references)</sup> 103 104 ```bash 105 # Convert a stolen MIT ccache into a .kirbi usable by Windows tooling 106 $ ./kerbtool --convert --in /tmp/websvc.ccache --out websvc.kirbi 107 108 # Use an extracted cache to request additional TGS tickets without touching the victim again 109 $ KRB5CCNAME=/tmp/websvc.ccache ./kerbtool --ask --spn cifs/fileserver.lab.local 110 ``` 111 112 Having both tickey and kerbtool on your implant host lets you move seamlessly between Linux, Windows, and cross-platform Kerberos attack chains. 113 114 ## References 115 116 - [1] [Kerberos (II): How to attack Kerberos?](https://www.tarlogic.com/blog/how-to-attack-kerberos/) 117 - [2] [KCM server for SSSD](https://docs.pagure.org/sssd.sssd/design_pages/kcm.html) 118 - [3] [kerbtool](https://github.com/jfjallid/kerbtool) 119 - [4] [Kerberos Credential Thievery (GNU/Linux)](https://web.archive.org/web/20210721113019/https://www.delaat.net/rp/2016-2017/p97/report.pdf) 120 - [5] [MIT Kerberos - Credential cache types](https://web.mit.edu/kerberos/krb5-latest/doc/basic/ccache_def.html) 121 - [6] [Fortra Impacket - `ticketConverter.py`](https://github.com/fortra/impacket/blob/master/examples/ticketConverter.py)