daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (6478B)


      1 ---
      2 title: "88tcp/udp - Pentesting Kerberos"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-kerberos-88/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-kerberos-88/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 88tcp/udp - Pentesting Kerberos
     14 
     15 ## Basic Information
     16 
     17 **Kerberos** is a network authentication protocol: it establishes identities and session keys, while each application service makes its own authorization decision about the authenticated principal.<sup>[[5]](#references)</sup>
     18 
     19 In environments like **Active Directory**, **Kerberos** is instrumental in establishing the identity of users by validating their secret passwords. This process ensures that each user's identity is confirmed before they interact with network resources. However, **Kerberos** does not extend its functionality to evaluate or enforce the permissions a user has over specific resources or services. Instead, it provides a secure way of authenticating users, which is a critical first step in the security process.
     20 
     21 After Kerberos authentication, the target service evaluates the user's rights and permissions using its local policy and any authorization data carried in the ticket. This separates authentication from application-specific access control.<sup>[[5]](#references)</sup>
     22 
     23 **Default Port:** 88/tcp/udp
     24 
     25 ```text
     26 PORT   STATE SERVICE
     27 88/tcp open  kerberos-sec
     28 ```
     29 
     30 ### **To learn how to abuse Kerberos you should read the post about** [**Active Directory**](../../windows-hardening/active-directory-methodology/index.html)**.**
     31 
     32 ## Kerberos-only environments: client prep and troubleshooting
     33 
     34 When NTLM is disabled on domain services (SMB/WinRM/etc.), you must authenticate with Kerberos. Common pitfalls and a working workflow:<sup>[[4]](#references)</sup>
     35 
     36 - Time synchronization is mandatory. If your host clock is skewed by more than a few minutes you will see `KRB_AP_ERR_SKEW` and all Kerberos auth will fail. Sync against the DC:
     37 
     38 ```bash
     39 # quick one-shot sync (requires sudo)
     40 sudo ntpdate <dc.fqdn> || sudo chronyd -q 'server <dc.fqdn> iburst'
     41 ```
     42 
     43 - Generate a valid krb5.conf for the target realm/domain. `netexec` (CME fork) can output one for you while testing SMB:<sup>[[1]](#references)</sup>
     44 
     45 ```bash
     46 # Generate krb5.conf and install it
     47 netexec smb <dc.fqdn> -u <user> -p '<pass>' -k --generate-krb5-file krb5.conf
     48 sudo cp krb5.conf /etc/krb5.conf
     49 ```
     50 
     51 - Obtain a TGT and verify the ccache:<sup>[[3]](#references)</sup>
     52 
     53 ```bash
     54 kinit <user>
     55 klist
     56 ```
     57 
     58 - Use Kerberos with SMB tooling (no passwords sent, uses your ccache):
     59 
     60 ```bash
     61 # netexec / CME
     62 netexec smb <dc.fqdn> -k            # lists shares, runs modules using Kerberos
     63 # impacket examples also support -k / --no-pass to use the ccache
     64 smbclient --kerberos //<dc.fqdn>/IPC$
     65 ```
     66 
     67 - GSSAPI SSH single sign-on (OpenSSH to Windows OpenSSH server):<sup>[[2]](#references)</sup>
     68 
     69 ```bash
     70 # Ensure krb5.conf is correct and you have a TGT (kinit)
     71 # Use the FQDN that matches the host SPN. Wrong names cause: "Server not found in Kerberos database"
     72 ssh -o GSSAPIAuthentication=yes <user>@<host.fqdn>
     73 ```
     74 
     75 Tips:
     76 - Ensure your `/etc/hosts` resolves the exact FQDN you will SSH/SMB to, and that it comes before any bare domain entries if you are overriding DNS. SPN mismatches break GSSAPI.
     77 - If NTLM is disabled on SMB you may see `STATUS_NOT_SUPPORTED` with NTLM attempts; add `-k` to force Kerberos.
     78 
     79 ## More
     80 
     81 ### Shodan
     82 
     83 - `port:88 kerberos`
     84 
     85 ### MS14-068
     86 
     87 MS14-068 allowed a domain user to forge authorization data in a Kerberos ticket and have a vulnerable Domain Controller accept elevated group membership, potentially yielding Domain Admin privileges.<sup>[[6]](#references)</sup>
     88 
     89 The `pykek` exploit is archived in the SecWiki Windows kernel exploits collection.<sup>[[7]](#references)</sup>
     90 
     91 ## HackTricks Automatic Commands
     92 
     93 ```text
     94 Protocol_Name: Kerberos    #Protocol Abbreviation if there is one.
     95 Port_Number:  88   #Comma separated if there is more than one.
     96 Protocol_Description: AD Domain Authentication         #Protocol Abbreviation Spelled out
     97 
     98 Entry_1:
     99   Name: Notes
    100   Description: Notes for Kerberos
    101   Note: |
    102     Kerberos operates on a principle where it authenticates users without directly managing their access to resources. This is an important distinction because it underlines the protocol's role in security frameworks.
    103     In environments like **Active Directory**, Kerberos is instrumental in establishing the identity of users by validating their secret passwords. This process ensures that each user's identity is confirmed before they interact with network resources. However, Kerberos does not extend its functionality to evaluate or enforce the permissions a user has over specific resources or services. Instead, it provides a secure way of authenticating users, which is a critical first step in the security process.
    104 
    105     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-kerberos-88/index.html
    106 
    107 Entry_2:
    108   Name: Pre-Creds
    109   Description: Brute Force to get Usernames
    110   Command: nmap -p 88 --script=krb5-enum-users --script-args krb5-enum-users.realm="{Domain_Name}",userdb={Big_Userlist} {IP}
    111 
    112 Entry_3:
    113   Name: With Usernames
    114   Description: Brute Force with Usernames and Passwords
    115   Note: consider git clone https://github.com/ropnop/kerbrute.git ./kerbrute -h
    116 
    117 Entry_4:
    118   Name: With Creds
    119   Description: Attempt to get a list of user service principal names
    120   Command: GetUserSPNs.py -request -dc-ip {IP} active.htb/svc_tgs
    121 ```
    122 
    123 ## References
    124 
    125 - [1] [NetExec (CME) wiki – Kerberos and krb5.conf generation](https://www.netexec.wiki/)
    126 - [2] [OpenSSH GSSAPIAuthentication](https://man.openbsd.org/ssh_config#GSSAPIAuthentication)
    127 - [3] [MIT Kerberos Documentation – For users (ticket management: kinit/klist)](https://web.mit.edu/kerberos/krb5-1.22/doc/user/index.html)
    128 - [4] [0xdf – HTB: TheFrizz](https://0xdf.gitlab.io/2025/08/23/htb-thefrizz.html)
    129 - [5] [MIT Kerberos - Host configuration and login authorization](https://web.mit.edu/kerberos/krb5-latest/doc/admin/host_config.html)
    130 - [6] [ADSecurity - MS14-068 Kerberos vulnerability](https://adsecurity.org/?p=541)
    131 - [7] [SecWiki - MS14-068 `pykek`](https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek)