
Objective-C-Bibliothek und Konsole zur Interaktion mit Heimdal-APIs für macOS Kerberos
( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| () )| || | | | ( () )_, | |_
(__/'()() () \___/'(____/_)
Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal
# Inhaltsverzeichnis
- [Übersicht](#overview)
- Befehle
- [list](#list)
- [dump](#dump)
- [tickets](#tickets)
- [keytab](#keytab)
- [askhash](#askhash)
- [asktgt](#asktgt)
- [mit Klartext](#with-plaintext-password)
- [mit Hash](#with-hash)
- [mit Keytab-Eintrag](#with-keytab-entry)
- [describe](#describe)
- [asktgs](#asktgs)
- [verschiedene Domänen](#different-domains)
- [Kerberoasting](#kerberoasting)
- [s4u](#s4u)
- [ptt](#ptt)
- [remove](#remove)
- [Credential-Cache](#credential-cache)
- [Keytab-Eintrag](#keytab-entry)
## Übersicht
Bifrost ist ein Objective-C-Projekt, das für die Interaktion mit den Heimdal krb5-APIs unter macOS entwickelt wurde. Bifrost wird als statische Bibliothek kompiliert (kann aber bei Bedarf in ein dylib geändert werden), und bifrostconsole ist ein einfaches Konsolenprojekt, das die Bifrost-Bibliothek verwendet. Ziel des Projekts ist es, bessere Sicherheitstests rund um Kerberos auf macOS-Geräten unter Verwendung nativer APIs zu ermöglichen, ohne dass andere Frameworks oder Pakete auf dem Zielsystem erforderlich sind.
Da dies auf einem Mac kompiliert werden muss und dies möglicherweise nicht für alle zu Testzwecken leicht verfügbar ist, habe ich eine kompilierte Version der Konsole und der Bibliothek im Ordner "compiled_binaries" beigefügt. Da diese vorkompiliert sind, erwarten Sie, dass sie stark signiert sind und nur für persönliche Testzwecke nutzbar sind.
## list
Der Befehl `-action list` durchläuft alle Credential Caches im Speicher und gibt grundlegende Informationen zu jedem Cache und jedem darin enthaltenen Eintrag aus. Er identifiziert außerdem den Standard-Cache mit dem Marker `[*]` und jeden anderen Cache mit dem Marker `[+]`.```
spooky:~ lab_admin$ ./bifrost -action list
___ ___ _
( _`\ _ /'___) ( )_
| (_) )(_)| (__ _ __ _ ___ | ,_)
| _ <'| || ,__)( '__)/'_`\ /',__)| |
| (_) )| || | | | ( (_) )\__, \| |_
(____/'(_)(_) (_) `\___/'(____/\__)
[*] Principal: [email protected]
Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
Issued Expires Principal Flags
2019-11-13 18:00:20PST 2019-11-14 04:00:20PST krbtgt/[email protected] (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST 2019-12-13 18:00:21PST krb5_ccache_conf_data/kcm-status@X-CACHECONF: ()
Der Befehl -action dump kann je nach Flags Informationen über Keytabs oder Credential Caches extrahieren.
Um spezifisch Tickets zu dumpen, verwende -source tickets. Standardmäßig wird dabei nur der Standard-Credential-Cache durchlaufen. Der Standard-Credential-Cache kann mit dem Befehl -action list identifiziert werden, indem nach dem Cache mit einem [*]-Marker gesucht wird. Um einen bestimmten Credential-Cache zu dumpen, verwende das Flag -name [name here].
Jedes Ticket wird beschrieben und in ein Base64-Kirbi-Format gedumpt, das dann für andere Befehle oder mit anderen Tools unter Windows verwendet werden kann.``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets
( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| () )| || | | | ( () )_, | |_
(/'()() (_) `_/'(___/_)
Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=
Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA
### keytab
Um keytab-Schlüssel zu dumpen, verwenden Sie den Parameter `-source keytab`. Standardmäßig wird versucht, Informationen aus dem Standard-Keytab (`/etc/krb5.keytab`) zu dumpen, das nur von root gelesen werden kann. Um ein anderes Keytab anzugeben, verwenden Sie das Argument `-path /path/to/keytab`.
Jeder Keytab-Eintrag wird beschrieben und der Schlüssel wird in Base64 und Hex ausgegeben.```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
___ ___ _
( _`\ _ /'___) ( )_
| (_) )(_)| (__ _ __ _ ___ | ,_)
| _ <'| || ,__)( '__)/'_`\ /',__)| |
| (_) )| || | | | ( (_) )\__, \| |_
(____/'(_)(_) (_) `\___/'(____/\__)