
إطار عمل لرش كلمات المرور يعتمد على Kerberos لـ Active Directory مع منع القفل المدمج، وتكامل تعداد المستخدمين، ورش كلمات المرور المتكرر، وقدرات استئناف الحملة.
أداة لتعداد ورش كلمات مرور حسابات Active Directory الصالحة عبر التحقق المسبق من Kerberos.
على الرغم من وجود العديد من أدوات رش كلمات مرور Kerberos حاليًا في السوق، وجدت صعوبة في العثور على أدوات تحتوي على الوظائف المدمجة التالية:
يحل Tritium جميع المشكلات المذكورة أعلاه وأكثر. لن يهدر تعداد المستخدمين محاولة تسجيل دخول لأنه يستخدم ناتج الرش الأول لإنشاء ملف بالمستخدمين الصالحين. كما يمنح Tritium المستخدم القدرة على تمرير ملف كلمات مرور لرش كلمات المرور بشكل متكرر. وأخيرًا، يحتوي Tritium على وظيفة مدمجة للكشف عن قفل المجال بسبب رش كلمات المرور عن طريق حفظ الحالة والخروج من رش كلمات المرور إذا تم قفل 3 حسابات متتالية.
./Tritium -h
___________ .__ __ .__
\__ ___/______|__|/ |_|__|__ __ _____
| | \_ __ \ \ __\ | | \/ \
| | | | \/ || | | | | / Y Y \
|____| |__| |__||__| |__|____/|__|_|__/ v 0.4
Author: S4R1N, alfarom256
Required Params:
-d The full domain to use (-domain targetdomain.local)
-dc Domain controller to authenticate against (-dc washingtondc.targetdomain.local)
-dcf File of domain controllers to authenticate against
-u Select single user to authenticate as (-user jsmith)
-uf User file to use for password spraying (-userfile ~/home/users.txt)
-p Password to use for spraying (-password Welcome1)
Optional:
-help Print this help menu
-o Tritium Output file (default spray.json)
-w Wait time between authentication attempts [Default 1] (-w 0)
-jitter % Jitter between authentication attempts
-rs Enable recursive spraying
-ws Wait time between sprays [Default 3600] (-ws 1800)
-pwf Password file to use for recursive
-res Continue a password spraying campaign
-rf Tritium Json file
فيما يلي بعض الميزات قيد التطوير: