
Libreria Objective-C e console per interagire con le API Heimdal per Kerberos su macOS
( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| () )| || | | | ( () )_, | |_
(__/'()() () \___/'(____/_)
Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal
# Indice dei contenuti
- [Panoramica](#overview)
- comandi
- [list](#list)
- [dump](#dump)
- [tickets](#tickets)
- [keytab](#keytab)
- [askhash](#askhash)
- [asktgt](#asktgt)
- [con password in chiaro](#with-plaintext-password)
- [con hash](#with-hash)
- [con voce keytab](#with-keytab-entry)
- [describe](#describe)
- [asktgs](#asktgs)
- [domini diversi](#different-domains)
- [kerberoasting](#kerberoasting)
- [s4u](#s4u)
- [ptt](#ptt)
- [remove](#remove)
- [cache delle credenziali](#credential-cache)
- [voce keytab](#keytab-entry)
## Panoramica
Bifrost è un progetto Objective-C progettato per interagire con le API Heimdal krb5 su macOS. Bifrost viene compilato in una libreria statica (ma puoi cambiarla in una dylib se necessario), e bifrostconsole è un semplice progetto console che utilizza la libreria Bifrost. L'obiettivo del progetto è consentire migliori test di sicurezza relativi a Kerberos sui dispositivi macOS utilizzando le API native, senza richiedere altri framework o pacchetti sul target.
Poiché questo deve essere compilato su un Mac, e potrebbe non essere facilmente disponibile a tutti per scopi di test, ho incluso una versione compilata della console e della libreria nella cartella "compiled_binaries". Poiché sono precompilate, aspettati che siano pesantemente firmate e utilizzabili solo per scopi di test personali.
## list
Il comando `-action list` scorrerà tutte le cache delle credenziali in memoria e fornirà informazioni di base su ogni cache e ogni voce al suo interno. Identificherà anche la cache predefinita con il marcatore `[*]` e ogni altra cache con il marcatore `[+]`.```
spooky:~ lab_admin$ ./bifrost -action list
___ ___ _
( _`\ _ /'___) ( )_
| (_) )(_)| (__ _ __ _ ___ | ,_)
| _ <'| || ,__)( '__)/'_`\ /',__)| |
| (_) )| || | | | ( (_) )\__, \| |_
(____/'(_)(_) (_) `\___/'(____/\__)
[*] Principal: [email protected]
Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
Issued Expires Principal Flags
2019-11-13 18:00:20PST 2019-11-14 04:00:20PST krbtgt/[email protected] (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST 2019-12-13 18:00:21PST krb5_ccache_conf_data/kcm-status@X-CACHECONF: ()
Il comando -action dump può estrarre informazioni su keytab o cache delle credenziali in base ai flag.
Per eseguire il dump dei ticket nello specifico, usa -source tickets. Per impostazione predefinita, questo itererà solo attraverso la cache delle credenziali predefinita. La cache delle credenziali predefinita può essere identificata con il comando -action list e cercando la cache identificata con un indicatore [*]. Per eseguire il dump di una cache delle credenziali specifica, usa il flag -name [nome qui].
Ogni ticket verrà descritto e salvato in un formato Kirbi base64 che può poi essere utilizzato per altri comandi o con altri strumenti su Windows.``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets
( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| () )| || | | | ( () )_, | |_
(/'()() (_) `_/'(___/_)
Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=
Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA
### keytab
Per estrarre le chiavi keytab, usa il parametro `-source keytab`. Per impostazione predefinita, tenterà di estrarre le informazioni dalla keytab predefinita (`/etc/krb5.keytab`) che è leggibile solo da root. Per specificare un'altra keytab, usa l'argomento `-path /path/to/keytab`.
Ogni voce della keytab verrà descritta e la chiave verrà estratta in base64 e hex.```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
___ ___ _
( _`\ _ /'___) ( )_
| (_) )(_)| (__ _ __ _ ___ | ,_)
| _ <'| || ,__)( '__)/'_`\ /',__)| |
| (_) )| || | | | ( (_) )\__, \| |_
(____/'(_)(_) (_) `\___/'(____/\__)