Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

FeedsKontaktDatenschutz© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
bifrost — Objective-C-Bibliothek und Konsole zur Interaktion mit Heimdal-APIs für macOS Kerberos | Kitploit
Tools/GitHubGitHub/its-a-feature/bifrost
PasswortangriffeExploitationPenetrationstestsAuthentifizierungRed Teaming
GitHubits-a-feature/bifrost

bifrost

Objective-C-Bibliothek und Konsole zur Interaktion mit Heimdal-APIs für macOS Kerberos

Repository anzeigen
158199vor 3 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Bifrost```


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (__/'()() () \___/'(____/_)

Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal

# Inhaltsverzeichnis
- [Übersicht](#overview)
- Befehle
    - [list](#list)
    - [dump](#dump)  
        - [tickets](#tickets)  
        - [keytab](#keytab)  
    - [askhash](#askhash)  
    - [asktgt](#asktgt)
        - [mit Klartext](#with-plaintext-password)    
        - [mit Hash](#with-hash)
        - [mit Keytab-Eintrag](#with-keytab-entry)
    - [describe](#describe)
    - [asktgs](#asktgs)
        - [verschiedene Domänen](#different-domains)
        - [Kerberoasting](#kerberoasting)
    - [s4u](#s4u)
    - [ptt](#ptt)
    - [remove](#remove)
        - [Credential-Cache](#credential-cache)
        - [Keytab-Eintrag](#keytab-entry)
        
## Übersicht
Bifrost ist ein Objective-C-Projekt, das für die Interaktion mit den Heimdal krb5-APIs unter macOS entwickelt wurde. Bifrost wird als statische Bibliothek kompiliert (kann aber bei Bedarf in ein dylib geändert werden), und bifrostconsole ist ein einfaches Konsolenprojekt, das die Bifrost-Bibliothek verwendet. Ziel des Projekts ist es, bessere Sicherheitstests rund um Kerberos auf macOS-Geräten unter Verwendung nativer APIs zu ermöglichen, ohne dass andere Frameworks oder Pakete auf dem Zielsystem erforderlich sind.

Da dies auf einem Mac kompiliert werden muss und dies möglicherweise nicht für alle zu Testzwecken leicht verfügbar ist, habe ich eine kompilierte Version der Konsole und der Bibliothek im Ordner "compiled_binaries" beigefügt. Da diese vorkompiliert sind, erwarten Sie, dass sie stark signiert sind und nur für persönliche Testzwecke nutzbar sind.
## list
Der Befehl `-action list` durchläuft alle Credential Caches im Speicher und gibt grundlegende Informationen zu jedem Cache und jedem darin enthaltenen Eintrag aus. Er identifiziert außerdem den Standard-Cache mit dem Marker `[*]` und jeden anderen Cache mit dem Marker `[+]`.```
spooky:~ lab_admin$ ./bifrost -action list
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 


[*] Principal: [email protected]
    Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
    Issued             Expires                Principal                    Flags
2019-11-13 18:00:20PST    2019-11-14 04:00:20PST    krbtgt/[email protected]    (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST    2019-12-13 18:00:21PST    krb5_ccache_conf_data/kcm-status@X-CACHECONF:    ()

dump

Der Befehl -action dump kann je nach Flags Informationen über Keytabs oder Credential Caches extrahieren.

tickets

Um spezifisch Tickets zu dumpen, verwende -source tickets. Standardmäßig wird dabei nur der Standard-Credential-Cache durchlaufen. Der Standard-Credential-Cache kann mit dem Befehl -action list identifiziert werden, indem nach dem Cache mit einem [*]-Marker gesucht wird. Um einen bestimmten Credential-Cache zu dumpen, verwende das Flag -name [name here].

Jedes Ticket wird beschrieben und in ein Base64-Kirbi-Format gedumpt, das dann für andere Befehle oder mit anderen Tools unter Windows verwendet werden kann.``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (/'()() (_) `_/'(___/_)

Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=

Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA

### keytab
Um keytab-Schlüssel zu dumpen, verwenden Sie den Parameter `-source keytab`. Standardmäßig wird versucht, Informationen aus dem Standard-Keytab (`/etc/krb5.keytab`) zu dumpen, das nur von root gelesen werden kann. Um ein anderes Keytab anzugeben, verwenden Sie das Argument `-path /path/to/keytab`.

Jeder Keytab-Eintrag wird beschrieben und der Schlüssel wird in Base64 und Hex ausgegeben.```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__)
Tool herunterladen