Skip to content

Cracked Credentials not linking right #21098

Description

@h00die

While testing #20881 I found an interesting condition, cracked credentials aren't displaying correctly. I'm not sure where the issue lies as I don't know the database and credential linking.

Reproduce

git checkout upstream/pr/20881
./msfconsole -q
creds -d
creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
use auxiliary/analyze/crack_windows
rm ~/.msf4/john.pot
set action john
set verbose true
rexploit
creds

Output:

msf > creds -d
Credentials
===========

id  host  origin  service  public  private  realm  private_type  JtR Format  cracked_password
--  ----  ------  -------  ------  -------  -----  ------------  ----------  ----------------

msf > creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
msf > creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
msf > use auxiliary/analyze/crack_windows
[*] Setting default action auto - view all 3 actions with the show actions command
msf auxiliary(analyze/crack_windows) > rm ~/.msf4/john.pot
[*] exec: rm ~/.msf4/john.pot

msf auxiliary(analyze/crack_windows) > set action john
action => john
msf auxiliary(analyze/crack_windows) > set verbose true
verbose => true
msf auxiliary(analyze/crack_windows) > rexploit
[*] Reloading module...
[+] john Version Detected: 1.9.0-jumbo-1+bleeding-aec1328d6c 2021-11-02 10:45:52 +0100 OMP
[*] No lm found to crack
[*] No nt found to crack
[*] No mscash found to crack
[*] No mscash2 found to crack
[*] No netntlm found to crack
[*] No netntlmv2 found to crack
[*] No krb5tgs-aes128 found to crack
[*] No krb5tgs-aes256 found to crack
[*] No timeroast found to crack
[*] Wordlist file written out to /tmp/jtrtmp20260311-3550674-ut0wf5
[*] Checking krb5tgs hashes already cracked...
[*] Cracking krb5tgs hashes in single mode...
[*]    Cracking Command: /usr/sbin/john --session=DGCXMDBg --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5tgs --wordlist=/tmp/jtrtmp20260311-3550674-ut0wf5 --rules=single /tmp/hashes_krb5tgs_20260311-3550674-ajlg81
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
[*] hashcat          (936)     
1g 0:00:00:00 DONE (2026-03-11 10:07) 50.00g/s 256000p/s 256000c/s 256000C/s sandman..aardwolf
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"936", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"936", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core id: 938, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 441, private_id: 17, public_id: 15, realm_id: nil, workspace_id: 1, created_at: "2026-03-11 14:07:25.891293360 +0000", updated_at: "2026-03-11 14:07:25.891293360 +0000", logins_count: 0>
[+] Cracked Hashes
==============

 DB ID  Hash Type  Username  Cracked Password  Method
 -----  ---------  --------  ----------------  ------
 936    krb5tgs              hashcat           Single

[*] Checking krb5asrep hashes already cracked...
[+] Cracked Hashes
==============

 DB ID  Hash Type  Username  Cracked Password  Method
 -----  ---------  --------  ----------------  ------
 936    krb5tgs              hashcat           Single
 936    krb5tgs              hashcat           Single

[*] Cracking krb5asrep hashes in single mode...
[*]    Cracking Command: /usr/sbin/john --session=irg4Nll9 --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5asrep --wordlist=/tmp/jtrtmp20260311-3550674-ut0wf5 --rules=single /tmp/hashes_krb5asrep_20260311-3550674-2rffcj
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 AVX 4x])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
1g 0:00:00:00 DONE (2026-03-11 10:07) 50.00g/s 256000p/s 256000c/s 256000C/s twinkle..aardwolf
[*] hashcat          (937)     
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core workspace_id: 1, realm_id: nil, id: 938, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 441, private_id: 17, public_id: 15, created_at: "2026-03-11 14:07:25.891293000 +0000", updated_at: "2026-03-11 14:07:25.891293000 +0000", logins_count: 0>
[+] Cracked Hashes
==============

 DB ID  Hash Type  Username  Cracked Password  Method
 -----  ---------  --------  ----------------  ------
 936    krb5tgs              hashcat           Single
 936    krb5tgs              hashcat           Single
 936    krb5tgs              hashcat           Single
 937    krb5asrep            hashcat           Single

[*] Auxiliary module execution completed
msf auxiliary(analyze/crack_windows) > creds
Credentials
===========

id   host  origin  service  public     private                                                                                   realm  private_type        JtR Format  cracked_password
--   ----  ------  -------  ------     -------                                                                                   -----  ------------        ----------  ----------------
936                         krb5tgs    $krb5tgs$23$*user$realm$test/spn*$63386d22d359fe42230300d56852c9eb$891ad31d0 (TRUNCATED)         Nonreplayable hash  krb5tgs     hashcat
937                         krb5asrep  $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED)         Nonreplayable hash  krb5asrep

The Problem

We cracked the krb5asrep password, however the cred command doesn't show the password. Looking at the XXX debugging output above we can see 3 relevant lines:

XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core workspace_id: 1, realm_id: nil, id: 938, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 441, private_id: 17, public_id: 15, created_at: "2026-03-11 14:07:25.891293000 +0000", updated_at: "2026-03-11 14:07:25.891293000 +0000", logins_count: 0>
  1. The first line shows we read in from the cracking command (john) that it was cracked correctly and read in. We have the core ID correct as well to link the password back to the correct cred
  2. same as above, just tracing the object's path
  3. create_cracked_credential returns back an object so we know it didn't fail with an error or silently return nil
  4. Going back to the original output, looking at the final line we see the password as blank from the creds command

More Inconsistency

Keeping the same sessions as previously run, lets clear out and just do the krb5asrep password because maybe that code branch has a bug in it:

creds -d
creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
use auxiliary/analyze/crack_windows
rm ~/.msf4/john.pot
set action john
set verbose true
rexploit
creds

krb5asrep Output:

msf auxiliary(analyze/crack_windows) > creds -d
Credentials
===========

id   host  origin  service  public     private                                                                                   realm  private_type        JtR Format  cracked_password
--   ----  ------  -------  ------     -------                                                                                   -----  ------------        ----------  ----------------
936                         krb5tgs    $krb5tgs$23$*user$realm$test/spn*$63386d22d359fe42230300d56852c9eb$891ad31d0 (TRUNCATED)         Nonreplayable hash  krb5tgs     hashcat
937                         krb5asrep  $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED)         Nonreplayable hash  krb5asrep

[*] Deleted 3 creds
msf auxiliary(analyze/crack_windows) > creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
msf auxiliary(analyze/crack_windows) > use auxiliary/analyze/crack_windows
[*] Setting default action john - view all 3 actions with the show actions command
msf auxiliary(analyze/crack_windows) > rm ~/.msf4/john.pot
[*] exec: rm ~/.msf4/john.pot

msf auxiliary(analyze/crack_windows) > set action john
action => john
msf auxiliary(analyze/crack_windows) > set verbose true
verbose => true
msf auxiliary(analyze/crack_windows) > rexploit
[*] Reloading module...
[+] john Version Detected: 1.9.0-jumbo-1+bleeding-aec1328d6c 2021-11-02 10:45:52 +0100 OMP
[*] No lm found to crack
[*] No nt found to crack
[*] No mscash found to crack
[*] No mscash2 found to crack
[*] No netntlm found to crack
[*] No netntlmv2 found to crack
[*] No krb5tgs found to crack
[*] No krb5tgs-aes128 found to crack
[*] No krb5tgs-aes256 found to crack
[*] No timeroast found to crack

[*] Wordlist file written out to /tmp/jtrtmp20260311-3550674-6sl8va
[*] Checking krb5asrep hashes already cracked...
[*] Cracking krb5asrep hashes in single mode...
[*]    Cracking Command: /usr/sbin/john --session=cSeYPYdX --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5asrep --wordlist=/tmp/jtrtmp20260311-3550674-6sl8va --rules=single /tmp/hashes_krb5asrep_20260311-3550674-etsbi3
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 AVX 4x])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
1g 0:00:00:00 DONE (2026-03-11 10:08) 50.00g/s 256000p/s 256000c/s 256000C/s twinkle..aardwolf
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
[*] hashcat          (939)     
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"939", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"939", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core id: 940, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 443, private_id: 17, public_id: 15, realm_id: nil, workspace_id: 1, created_at: "2026-03-11 14:08:59.250333277 +0000", updated_at: "2026-03-11 14:08:59.250333277 +0000", logins_count: 0>
[+] Cracked Hashes
==============

 DB ID  Hash Type  Username  Cracked Password  Method
 -----  ---------  --------  ----------------  ------
 939    krb5asrep            hashcat           Single

[*] Auxiliary module execution completed
msf auxiliary(analyze/crack_windows) > creds
Credentials
===========

id   host  origin  service  public     private                                                                                   realm  private_type        JtR Format  cracked_password
--   ----  ------  -------  ------     -------                                                                                   -----  ------------        ----------  ----------------
939                         krb5asrep  $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED)         Nonreplayable hash  krb5asrep   hashcat

msf auxiliary(analyze/crack_windows) > 

So that works correctly. Lets try it with just the krb5tgs cred to make sure that is working:

creds -d
creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
use auxiliary/analyze/crack_windows
rm ~/.msf4/john.pot
set action john
set verbose true
rexploit
creds

krb5tgs Output:

msf auxiliary(analyze/crack_windows) > creds -d
Credentials
===========

id   host  origin  service  public     private                                                                                   realm  private_type        JtR Format  cracked_password
--   ----  ------  -------  ------     -------                                                                                   -----  ------------        ----------  ----------------
939                         krb5asrep  $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED)         Nonreplayable hash  krb5asrep   hashcat

[*] Deleted 2 creds
msf auxiliary(analyze/crack_windows) > creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
msf auxiliary(analyze/crack_windows) > use auxiliary/analyze/crack_windows
[*] Setting default action john - view all 3 actions with the show actions command
msf auxiliary(analyze/crack_windows) > rm ~/.msf4/john.pot
[*] exec: rm ~/.msf4/john.pot

msf auxiliary(analyze/crack_windows) > set action john
action => john
msf auxiliary(analyze/crack_windows) > set verbose true
verbose => true
msf auxiliary(analyze/crack_windows) > rexploit
[*] Reloading module...
[+] john Version Detected: 1.9.0-jumbo-1+bleeding-aec1328d6c 2021-11-02 10:45:52 +0100 OMP
[*] No lm found to crack
[*] No nt found to crack
[*] No mscash found to crack
[*] No mscash2 found to crack
[*] No netntlm found to crack
[*] No netntlmv2 found to crack
[*] No krb5tgs-aes128 found to crack
[*] No krb5tgs-aes256 found to crack
[*] No krb5asrep found to crack
[*] No timeroast found to crack
[*] Wordlist file written out to /tmp/jtrtmp20260311-3550674-fy5gk8
[*] Checking krb5tgs hashes already cracked...
[*] Cracking krb5tgs hashes in single mode...
[*]    Cracking Command: /usr/sbin/john --session=2tljThil --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5tgs --wordlist=/tmp/jtrtmp20260311-3550674-fy5gk8 --rules=single /tmp/hashes_krb5tgs_20260311-3550674-aop1xi
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
1g 0:00:00:00 DONE (2026-03-11 10:17) 100.0g/s 512000p/s 512000c/s 512000C/s sandman..aardwolf
[*] hashcat          (941)     
Use the "--show" option to display all of the cracked passwords reliably
Session completed. 
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"941", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"941", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core id: 942, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 444, private_id: 17, public_id: 15, realm_id: nil, workspace_id: 1, created_at: "2026-03-11 14:17:47.725655739 +0000", updated_at: "2026-03-11 14:17:47.725655739 +0000", logins_count: 0>
[+] Cracked Hashes
==============

 DB ID  Hash Type  Username  Cracked Password  Method
 -----  ---------  --------  ----------------  ------
 941    krb5tgs              hashcat           Single

[*] Auxiliary module execution completed
msf auxiliary(analyze/crack_windows) > creds
Credentials
===========

id   host  origin  service  public   private                                                                                   realm  private_type        JtR Format  cracked_password
--   ----  ------  -------  ------   -------                                                                                   -----  ------------        ----------  ----------------
941                         krb5tgs  $krb5tgs$23$*user$realm$test/spn*$63386d22d359fe42230300d56852c9eb$891ad31d0 (TRUNCATED)         Nonreplayable hash  krb5tgs     hashcat

msf auxiliary(analyze/crack_windows) > 

So the problem only shows when its got both krb5tgs and krb5asrep creds, thus unlikely (but still possible) to be something in the password cracking modules, and more likely in the database/create_cracked_credential command from best I can determine.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

Status
Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions