Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
bifrost — ऑब्जेक्टिव-सी लाइब्रेरी और कंसोल macOS Kerberos के लिए Heimdal APIs के साथ इंटरैक्ट करने के लिए | Kitploit
उपकरण/GitHubGitHub/its-a-feature/bifrost
पासवर्ड हमलेशोषणपेनिट्रेशन टेस्टिंगप्रमाणीकरणरेड टीमिंग
GitHubits-a-feature/bifrost

bifrost

ऑब्जेक्टिव-सी लाइब्रेरी और कंसोल macOS Kerberos के लिए Heimdal APIs के साथ इंटरैक्ट करने के लिए

रिपॉजिटरी देखें
1581983 साल पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

Bifrost```


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (__/'()() () \___/'(____/_)

Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal

# Table of Contents
- [Overview](#overview)
- commands
    - [list](#list)
    - [dump](#dump)  
        - [tickets](#tickets)  
        - [keytab](#keytab)  
    - [askhash](#askhash)  
    - [asktgt](#asktgt)
        - [with plaintext](#with-plaintext-password)    
        - [with hash](#with-hash)
        - [with keytab entry](#with-keytab-entry)
    - [describe](#describe)
    - [asktgs](#asktgs)
        - [different domains](#different-domains)
        - [kerberoasting](#kerberoasting)
    - [s4u](#s4u)
    - [ptt](#ptt)
    - [remove](#remove)
        - [credential cache](#credential-cache)
        - [keytab entry](#keytab-entry)
        
## Overview
Bifrost एक Objective-C प्रोजेक्ट है जिसे macOS पर Heimdal krb5 APIs के साथ इंटरैक्ट करने के लिए डिज़ाइन किया गया है। Bifrost एक स्टैटिक लाइब्रेरी में कंपाइल होता है (लेकिन यदि आवश्यक हो तो आप इसे dylib में बदल सकते हैं), और bifrostconsole एक सरल कंसोल प्रोजेक्ट है जो Bifrost लाइब्रेरी का उपयोग करता है। इस प्रोजेक्ट का लक्ष्य macOS उपकरणों पर Kerberos के आसपास बेहतर सुरक्षा परीक्षण को सक्षम करना है, जो नेटिव APIs का उपयोग करके लक्ष्य पर किसी अन्य फ्रेमवर्क या पैकेज की आवश्यकता के बिना किया जाता है।

चूंकि इसे Mac पर कंपाइल करने की आवश्यकता है, और यह परीक्षण के उद्देश्यों के लिए सभी के लिए आसानी से उपलब्ध नहीं हो सकता है, मैंने कंसोल और लाइब्रेरी का एक कंपाइल किया हुआ संस्करण "compiled_binaries" फ़ोल्डर में शामिल किया है। चूंकि ये पूर्व-कंपाइल हैं, उम्मीद करें कि ये भारी रूप से सिग्नेचर किए गए हैं और केवल व्यक्तिगत परीक्षण उद्देश्यों के लिए उपयोगी हैं।
## list
`-action list` कमांड मेमोरी में सभी क्रेडेंशियल कैशे के माध्यम से लूप करेगा और प्रत्येक कैशे और उसके अंदर प्रत्येक प्रविष्टि के बारे में बुनियादी जानकारी देगा। यह `[*]` मार्कर के साथ डिफ़ॉल्ट कैशे और `[+]` मार्कर के साथ प्रत्येक अन्य कैशे की पहचान भी करेगा।```
spooky:~ lab_admin$ ./bifrost -action list
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 


[*] Principal: [email protected]
    Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
    Issued             Expires                Principal                    Flags
2019-11-13 18:00:20PST    2019-11-14 04:00:20PST    krbtgt/[email protected]    (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST    2019-12-13 18:00:21PST    krb5_ccache_conf_data/kcm-status@X-CACHECONF:    ()

dump

-action dump कमांड फ्लैग के आधार पर कीटैब या क्रेडेंशियल कैश के बारे में जानकारी निकाल सकता है।

tickets

विशेष रूप से टिकट डंप करने के लिए, -source tickets का उपयोग करें। डिफ़ॉल्ट रूप से, यह केवल डिफ़ॉल्ट क्रेडेंशियल कैश के माध्यम से पुनरावृति करेगा। डिफ़ॉल्ट क्रेडेंशियल कैश को -action list कमांड से और [*] मार्कर से पहचाने गए कैश को देखकर पहचाना जा सकता है। किसी विशिष्ट क्रेडेंशियल कैश को डंप करने के लिए, -name [name here] फ्लैग का उपयोग करें।

प्रत्येक टिकट का वर्णन किया जाएगा और उसे base64 Kirbi प्रारूप में डंप किया जाएगा, जिसका उपयोग अन्य कमांड या Windows पर अन्य टूल्स के साथ किया जा सकता है।``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (/'()() (_) `_/'(___/_)

Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=

Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA

### keytab
keytab कुंजियों को डंप करने के लिए, `-source keytab` पैरामीटर का उपयोग करें। डिफ़ॉल्ट रूप से, यह डिफ़ॉल्ट keytab (`/etc/krb5.keytab`) से जानकारी डंप करने का प्रयास करेगा, जो केवल root द्वारा पढ़ने योग्य है। एक अन्य keytab निर्दिष्ट करने के लिए, `-path /path/to/keytab` आर्गुमेंट का उपयोग करें।

प्रत्येक keytab प्रविष्टि का वर्णन किया जाएगा और कुंजी को base64 और hex में डंप किया जाएगा।```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__)
टूल डाउनलोड करें