Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

··Flux·Contact·Confidentialité·© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
bifrost — Bibliothèque Objective-C et console pour interagir avec les API Heimdal pour Kerberos sous macOS | Kitploit
Outils/GitHubGitHub/its-a-feature/bifrost
Attaques de Mots de PasseExploitationTests d'IntrusionAuthentificationRed Teaming
GitHubits-a-feature/bifrost

bifrost

Bibliothèque Objective-C et console pour interagir avec les API Heimdal pour Kerberos sous macOS

Voir le dépôt
158197il y a 3 ansVérifié par Kitploit

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager

Bifrost```


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (__/'()() () \___/'(____/_)

Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal

# Table des matières
- [Aperçu](#overview)
- commandes
    - [list](#list)
    - [dump](#dump)  
        - [tickets](#tickets)  
        - [keytab](#keytab)  
    - [askhash](#askhash)  
    - [asktgt](#asktgt)
        - [avec mot de passe en clair](#with-plaintext-password)    
        - [avec hash](#with-hash)
        - [avec entrée keytab](#with-keytab-entry)
    - [describe](#describe)
    - [asktgs](#asktgs)
        - [différents domaines](#different-domains)
        - [kerberoasting](#kerberoasting)
    - [s4u](#s4u)
    - [ptt](#ptt)
    - [remove](#remove)
        - [cache d'identifiants](#credential-cache)
        - [entrée keytab](#keytab-entry)
        
## Aperçu
Bifrost est un projet Objective‑C conçu pour interagir avec les API Heimdal krb5 sur macOS. Bifrost se compile en une bibliothèque statique (mais vous pouvez la transformer en dylib si nécessaire), et bifrostconsole est un simple projet console qui utilise la bibliothèque Bifrost. L’objectif du projet est de permettre de meilleurs tests de sécurité autour de Kerberos sur les appareils macOS en utilisant les API natives, sans nécessiter d’autre framework ou paquet sur la cible.

Comme cette compilation doit être effectuée sur un Mac, et que cela peut ne pas être accessible à tout le monde à des fins de test, j’ai inclus une version compilée de la console et de la bibliothèque dans le dossier « compiled_binaries ». Comme il s’agit de versions pré‑compilées, attendez‑vous à ce qu’elles soient fortement signées et qu’elles ne soient utilisables qu’à des fins de tests personnels.
## list
La commande `-action list` parcourt tous les caches d’identifiants en mémoire et donne des informations de base sur chaque cache et chaque entrée qu’il contient. Elle identifie également le cache par défaut avec le marqueur `[*]` et chaque autre cache avec le marqueur `[+]`.```
spooky:~ lab_admin$ ./bifrost -action list
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 


[*] Principal: [email protected]
    Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
    Issued             Expires                Principal                    Flags
2019-11-13 18:00:20PST    2019-11-14 04:00:20PST    krbtgt/[email protected]    (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST    2019-12-13 18:00:21PST    krb5_ccache_conf_data/kcm-status@X-CACHECONF:    ()

dump

La commande -action dump peut extraire des informations sur les keytabs ou les caches d'identifiants en fonction des indicateurs.

tickets

Pour vider spécifiquement les tickets, utilisez -source tickets. Par défaut, cela ne parcourra que le cache d'identifiants par défaut. Le cache d'identifiants par défaut peut être identifié avec la commande -action list en cherchant le cache marqué par un [*]. Pour vider un cache d'identifiants spécifique, utilisez l'indicateur -name [name here].

Chaque ticket sera décrit et vidé dans un format Kirbi base64 qui pourra ensuite être utilisé pour d'autres commandes ou avec d'autres outils sur Windows.``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (/'()() (_) `_/'(___/_)

Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=

Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA

### keytab
Pour vider les clés keytab, utilisez le paramètre `-source keytab`. Par défaut, cela tentera de vider les informations du keytab par défaut (`/etc/krb5.keytab`), qui n'est lisible que par root. Pour spécifier un autre keytab, utilisez l'argument `-path /path/to/keytab`.

Chaque entrée du keytab sera décrite et la clé sera vidée en base64 et hexadécimal.```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__)
Télécharger l’outil