{"id":634,"date":"2021-03-10T13:44:38","date_gmt":"2021-03-10T13:44:38","guid":{"rendered":"https:\/\/cas.cybercop-training.ch\/?page_id=634"},"modified":"2021-03-11T13:11:44","modified_gmt":"2021-03-11T13:11:44","slug":"kerberoasting","status":"publish","type":"page","link":"https:\/\/cas.cybercop-training.ch\/index.php\/kerberoasting\/","title":{"rendered":"Kerberoasting"},"content":{"rendered":"<h1>Lab: Lateral Movement<\/h1>\n<h2>Windows Attack Lab &#8211; Kerberoasting<\/h2>\n<p><strong>Teamwork &#8211; Team DaMa<\/strong><\/p>\n<h2>Description<\/h2>\n<h2>Questions to Answer<\/h2>\n<p><strong><em>Q1:<\/em><\/strong><br \/>\nWhat is the goal of a Kerberoasting attack?<\/p>\n<p><strong><em>A1:<\/em><\/strong><br \/>\n<em>Short form:<\/em><br \/>\nCollect the TGS of a user to get access to a SPN.<\/p>\n<p><em>Long form:<\/em><br \/>\nKerberoasting abuses traits of the Kerberos protocol to harvest password hashes for Active Directory user accounts with servicePrincipalName (SPN) values (i.e. service accounts). A user is allowed to request a ticket-granting service (TGS) ticket for any SPN, and parts of the TGS may be encrypted with the with RC4 using the password hash of the service account assigned the requested SPN as the key.<\/p>\n<p>An adversary who is able to extract the TGS tickets from memory, or captures them by sniffing network traffic, can extract the service account\u2019s password hash and attempt an offline brute force attack to obtain the plaintext password.<\/p>\n<p>Reference:<\/p>\n<ul>\n<li><a href=\"https:\/\/attack.stealthbits.com\/cracking-kerberos-tgs-tickets-using-kerberoasting\">https:\/\/attack.stealthbits.com\/cracking-kerberos-tgs-tickets-using-kerberoasting<\/a><\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q2:<\/em><\/strong><br \/>\nWhat is the vulnerability we are actually exploiting?<\/p>\n<p><strong><em>A2:<\/em><\/strong><br \/>\nBy default the TGS are hashed with <code>RC4<\/code> which is treated weak and can be brute-forced with some tools. Disable <code>RC4<\/code> at the domain controller level might cause lots of things to break in a Windows environment.<\/p>\n<p>Reference:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.harmj0y.net\/blog\/redteaming\/kerberoasting-revisited\/\">https:\/\/www.harmj0y.net\/blog\/redteaming\/kerberoasting-revisited\/<\/a><\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q3:<\/em><\/strong><br \/>\nDo you need admin privileges to perform this attack and if so, why?<\/p>\n<p><strong><em>A3:<\/em><\/strong><br \/>\nIt&#8217;s not necessary to have <code>admin privileges<\/code> to perform this attach. A normal <code>domain user<\/code> can perform such an attack without and specific privileges.<\/p>\n<p><em>Rubeus specific:<\/em><\/p>\n<ul>\n<li>It makes raw AS-REQs aka TGT requests with either RC4 (NTLM hash) or aes128\/256_hmac<br \/>\nencryption keys and applies the returned tickets using existing LSA APIs<\/li>\n<li>Because this does not patch LSASS directly, it lets you PTH without needing admin access<\/li>\n<\/ul>\n<hr \/>\n<p><strong><em>Q4:<\/em><\/strong><br \/>\nWhich encryption type was used to encrypt the TGS?<\/p>\n<p><strong><em>A4:<\/em><\/strong><br \/>\nIn the Kerberoast example the encryption type was <code>RC4-HMAC<\/code>. <\/p>\n<p><img decoding=\"async\" src=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/kerberoast-1.png\" alt=\"\" \/><\/p>\n<p>PDF Report<br \/>\n<a href=\"https:\/\/cas.cybercop-training.ch\/wp-content\/uploads\/2021\/03\/Readme-StepX.pdf\" class=\"mtli_attachment mtli_pdf\" title=\"Readme-StepX\">Readme-StepX<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lab: Lateral Movement Windows Attack Lab &#8211; Kerberoasting Teamwork &#8211; Team DaMa Description Questions to Answer Q1: What is the goal of a Kerberoasting attack? A1: Short form: Collect the TGS of a user to get access to a SPN. Long form: Kerberoasting abuses traits of the Kerberos protocol to harvest password hashes for Active [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-634","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/comments?post=634"}],"version-history":[{"count":3,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/634\/revisions"}],"predecessor-version":[{"id":758,"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/pages\/634\/revisions\/758"}],"wp:attachment":[{"href":"https:\/\/cas.cybercop-training.ch\/index.php\/wp-json\/wp\/v2\/media?parent=634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}