While testing #20881 I found an interesting condition, cracked credentials aren't displaying correctly. I'm not sure where the issue lies as I don't know the database and credential linking.
Reproduce
git checkout upstream/pr/20881
./msfconsole -q
creds -d
creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
use auxiliary/analyze/crack_windows
rm ~/.msf4/john.pot
set action john
set verbose true
rexploit
creds
Output:
msf > creds -d
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
msf > creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
msf > creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
msf > use auxiliary/analyze/crack_windows
[*] Setting default action auto - view all 3 actions with the show actions command
msf auxiliary(analyze/crack_windows) > rm ~/.msf4/john.pot
[*] exec: rm ~/.msf4/john.pot
msf auxiliary(analyze/crack_windows) > set action john
action => john
msf auxiliary(analyze/crack_windows) > set verbose true
verbose => true
msf auxiliary(analyze/crack_windows) > rexploit
[*] Reloading module...
[+] john Version Detected: 1.9.0-jumbo-1+bleeding-aec1328d6c 2021-11-02 10:45:52 +0100 OMP
[*] No lm found to crack
[*] No nt found to crack
[*] No mscash found to crack
[*] No mscash2 found to crack
[*] No netntlm found to crack
[*] No netntlmv2 found to crack
[*] No krb5tgs-aes128 found to crack
[*] No krb5tgs-aes256 found to crack
[*] No timeroast found to crack
[*] Wordlist file written out to /tmp/jtrtmp20260311-3550674-ut0wf5
[*] Checking krb5tgs hashes already cracked...
[*] Cracking krb5tgs hashes in single mode...
[*] Cracking Command: /usr/sbin/john --session=DGCXMDBg --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5tgs --wordlist=/tmp/jtrtmp20260311-3550674-ut0wf5 --rules=single /tmp/hashes_krb5tgs_20260311-3550674-ajlg81
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
[*] hashcat (936)
1g 0:00:00:00 DONE (2026-03-11 10:07) 50.00g/s 256000p/s 256000c/s 256000C/s sandman..aardwolf
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"936", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"936", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core id: 938, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 441, private_id: 17, public_id: 15, realm_id: nil, workspace_id: 1, created_at: "2026-03-11 14:07:25.891293360 +0000", updated_at: "2026-03-11 14:07:25.891293360 +0000", logins_count: 0>
[+] Cracked Hashes
==============
DB ID Hash Type Username Cracked Password Method
----- --------- -------- ---------------- ------
936 krb5tgs hashcat Single
[*] Checking krb5asrep hashes already cracked...
[+] Cracked Hashes
==============
DB ID Hash Type Username Cracked Password Method
----- --------- -------- ---------------- ------
936 krb5tgs hashcat Single
936 krb5tgs hashcat Single
[*] Cracking krb5asrep hashes in single mode...
[*] Cracking Command: /usr/sbin/john --session=irg4Nll9 --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5asrep --wordlist=/tmp/jtrtmp20260311-3550674-ut0wf5 --rules=single /tmp/hashes_krb5asrep_20260311-3550674-2rffcj
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 AVX 4x])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
1g 0:00:00:00 DONE (2026-03-11 10:07) 50.00g/s 256000p/s 256000c/s 256000C/s twinkle..aardwolf
[*] hashcat (937)
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core workspace_id: 1, realm_id: nil, id: 938, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 441, private_id: 17, public_id: 15, created_at: "2026-03-11 14:07:25.891293000 +0000", updated_at: "2026-03-11 14:07:25.891293000 +0000", logins_count: 0>
[+] Cracked Hashes
==============
DB ID Hash Type Username Cracked Password Method
----- --------- -------- ---------------- ------
936 krb5tgs hashcat Single
936 krb5tgs hashcat Single
936 krb5tgs hashcat Single
937 krb5asrep hashcat Single
[*] Auxiliary module execution completed
msf auxiliary(analyze/crack_windows) > creds
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
936 krb5tgs $krb5tgs$23$*user$realm$test/spn*$63386d22d359fe42230300d56852c9eb$891ad31d0 (TRUNCATED) Nonreplayable hash krb5tgs hashcat
937 krb5asrep $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED) Nonreplayable hash krb5asrep
The Problem
We cracked the krb5asrep password, however the cred command doesn't show the password. Looking at the XXX debugging output above we can see 3 relevant lines:
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"937", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core workspace_id: 1, realm_id: nil, id: 938, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 441, private_id: 17, public_id: 15, created_at: "2026-03-11 14:07:25.891293000 +0000", updated_at: "2026-03-11 14:07:25.891293000 +0000", logins_count: 0>
- The first line shows we read in from the cracking command (john) that it was cracked correctly and read in. We have the core ID correct as well to link the password back to the correct cred
- same as above, just tracing the object's path
- create_cracked_credential returns back an object so we know it didn't fail with an error or silently return
nil
- Going back to the original output, looking at the final line we see the password as blank from the
creds command
More Inconsistency
Keeping the same sessions as previously run, lets clear out and just do the krb5asrep password because maybe that code branch has a bug in it:
creds -d
creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
use auxiliary/analyze/crack_windows
rm ~/.msf4/john.pot
set action john
set verbose true
rexploit
creds
krb5asrep Output:
msf auxiliary(analyze/crack_windows) > creds -d
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
936 krb5tgs $krb5tgs$23$*user$realm$test/spn*$63386d22d359fe42230300d56852c9eb$891ad31d0 (TRUNCATED) Nonreplayable hash krb5tgs hashcat
937 krb5asrep $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED) Nonreplayable hash krb5asrep
[*] Deleted 3 creds
msf auxiliary(analyze/crack_windows) > creds add user:krb5asrep hash:\$krb5asrep\$23\$user@domain.com:3e156ada591263b8aab0965f5aebd837\$007497cb51b6c8116d6407a782ea0e1c5402b17db7afa6b05a6d30ed164a9933c754d720e279c6c573679bd27128fe77e5fea1f72334c1193c8ff0b370fadc6368bf2d49bbfdba4c5dccab95e8c8ebfdc75f438a0797dbfb2f8a1a5f4c423f9bfc1fea483342a11bd56a216f4d5158ccc4b224b52894fadfba3957dfe4b6b8f5f9f9fe422811a314768673e0c924340b8ccb84775ce9defaa3baa0910b676ad0036d13032b0dd94e3b13903cc738a7b6d00b0b3c210d1f972a6c7cae9bd3c959acf7565be528fc179118f28c679f6deeee1456f0781eb8154e18e49cb27b64bf74cd7112a0ebae2102ac jtr:krb5asrep
msf auxiliary(analyze/crack_windows) > use auxiliary/analyze/crack_windows
[*] Setting default action john - view all 3 actions with the show actions command
msf auxiliary(analyze/crack_windows) > rm ~/.msf4/john.pot
[*] exec: rm ~/.msf4/john.pot
msf auxiliary(analyze/crack_windows) > set action john
action => john
msf auxiliary(analyze/crack_windows) > set verbose true
verbose => true
msf auxiliary(analyze/crack_windows) > rexploit
[*] Reloading module...
[+] john Version Detected: 1.9.0-jumbo-1+bleeding-aec1328d6c 2021-11-02 10:45:52 +0100 OMP
[*] No lm found to crack
[*] No nt found to crack
[*] No mscash found to crack
[*] No mscash2 found to crack
[*] No netntlm found to crack
[*] No netntlmv2 found to crack
[*] No krb5tgs found to crack
[*] No krb5tgs-aes128 found to crack
[*] No krb5tgs-aes256 found to crack
[*] No timeroast found to crack
[*] Wordlist file written out to /tmp/jtrtmp20260311-3550674-6sl8va
[*] Checking krb5asrep hashes already cracked...
[*] Cracking krb5asrep hashes in single mode...
[*] Cracking Command: /usr/sbin/john --session=cSeYPYdX --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5asrep --wordlist=/tmp/jtrtmp20260311-3550674-6sl8va --rules=single /tmp/hashes_krb5asrep_20260311-3550674-etsbi3
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5asrep, Kerberos 5 AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 128/128 AVX 4x])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
1g 0:00:00:00 DONE (2026-03-11 10:08) 50.00g/s 256000p/s 256000c/s 256000C/s twinkle..aardwolf
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
[*] hashcat (939)
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"939", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5asrep", "method"=>"Single", "core_id"=>"939", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core id: 940, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 443, private_id: 17, public_id: 15, realm_id: nil, workspace_id: 1, created_at: "2026-03-11 14:08:59.250333277 +0000", updated_at: "2026-03-11 14:08:59.250333277 +0000", logins_count: 0>
[+] Cracked Hashes
==============
DB ID Hash Type Username Cracked Password Method
----- --------- -------- ---------------- ------
939 krb5asrep hashcat Single
[*] Auxiliary module execution completed
msf auxiliary(analyze/crack_windows) > creds
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
939 krb5asrep $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED) Nonreplayable hash krb5asrep hashcat
msf auxiliary(analyze/crack_windows) >
So that works correctly. Lets try it with just the krb5tgs cred to make sure that is working:
creds -d
creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
use auxiliary/analyze/crack_windows
rm ~/.msf4/john.pot
set action john
set verbose true
rexploit
creds
krb5tgs Output:
msf auxiliary(analyze/crack_windows) > creds -d
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
939 krb5asrep $krb5asrep$23$user@domain.com:3e156ada591263b8aab0965f5aebd837$007497cb51b6c (TRUNCATED) Nonreplayable hash krb5asrep hashcat
[*] Deleted 2 creds
msf auxiliary(analyze/crack_windows) > creds add user:krb5tgs hash:\$krb5tgs\$23\$*user\$realm$test/spn*\$63386d22d359fe42230300d56852c9eb\$891ad31d09ab89c6b3b8c5e5de6c06a7f49fd559d7a9a3c32576c8fedf705376cea582ab5938f7fc8bc741acf05c5990741b36ef4311fe3562a41b70a4ec6ecba849905f2385bb3799d92499909658c7287c49160276bca0006c350b0db4fd387adc27c01e9e9ad0c20ed53a7e6356dee2452e35eca2a6a1d1432796fc5c19d068978df74d3d0baf35c77de12456bf1144b6a750d11f55805f5a16ece2975246e2d026dce997fba34ac8757312e9e4e6272de35e20d52fb668c5ed jtr:krb5tgs
msf auxiliary(analyze/crack_windows) > use auxiliary/analyze/crack_windows
[*] Setting default action john - view all 3 actions with the show actions command
msf auxiliary(analyze/crack_windows) > rm ~/.msf4/john.pot
[*] exec: rm ~/.msf4/john.pot
msf auxiliary(analyze/crack_windows) > set action john
action => john
msf auxiliary(analyze/crack_windows) > set verbose true
verbose => true
msf auxiliary(analyze/crack_windows) > rexploit
[*] Reloading module...
[+] john Version Detected: 1.9.0-jumbo-1+bleeding-aec1328d6c 2021-11-02 10:45:52 +0100 OMP
[*] No lm found to crack
[*] No nt found to crack
[*] No mscash found to crack
[*] No mscash2 found to crack
[*] No netntlm found to crack
[*] No netntlmv2 found to crack
[*] No krb5tgs-aes128 found to crack
[*] No krb5tgs-aes256 found to crack
[*] No krb5asrep found to crack
[*] No timeroast found to crack
[*] Wordlist file written out to /tmp/jtrtmp20260311-3550674-fy5gk8
[*] Checking krb5tgs hashes already cracked...
[*] Cracking krb5tgs hashes in single mode...
[*] Cracking Command: /usr/sbin/john --session=2tljThil --no-log --config=/root/metasploit-framework/data/jtr/john.conf --pot=/root/.msf4/john.pot --format=krb5tgs --wordlist=/tmp/jtrtmp20260311-3550674-fy5gk8 --rules=single /tmp/hashes_krb5tgs_20260311-3550674-aop1xi
Using default input encoding: UTF-8
[*] Loaded 1 password hash (krb5tgs, Kerberos 5 TGS etype 23 [MD4 HMAC-MD5 RC4])
Will run 4 OpenMP threads
Press Ctrl-C to abort, or send SIGUSR1 to john process for status
1g 0:00:00:00 DONE (2026-03-11 10:17) 100.0g/s 512000p/s 512000c/s 512000C/s sandman..aardwolf
[*] hashcat (941)
Use the "--show" option to display all of the cracked passwords reliably
Session completed.
XXX check_results function prior to process_crack_results: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"941", "password"=>"hashcat"}
XXX process_cracker_results cred prior to create_cracked_credential: {"hash_type"=>"krb5tgs", "method"=>"Single", "core_id"=>"941", "password"=>"hashcat"}
XXX create_cracked_credential returned: #<Metasploit::Credential::Core id: 942, origin_type: "Metasploit::Credential::Origin::CrackedPassword", origin_id: 444, private_id: 17, public_id: 15, realm_id: nil, workspace_id: 1, created_at: "2026-03-11 14:17:47.725655739 +0000", updated_at: "2026-03-11 14:17:47.725655739 +0000", logins_count: 0>
[+] Cracked Hashes
==============
DB ID Hash Type Username Cracked Password Method
----- --------- -------- ---------------- ------
941 krb5tgs hashcat Single
[*] Auxiliary module execution completed
msf auxiliary(analyze/crack_windows) > creds
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
941 krb5tgs $krb5tgs$23$*user$realm$test/spn*$63386d22d359fe42230300d56852c9eb$891ad31d0 (TRUNCATED) Nonreplayable hash krb5tgs hashcat
msf auxiliary(analyze/crack_windows) >
So the problem only shows when its got both krb5tgs and krb5asrep creds, thus unlikely (but still possible) to be something in the password cracking modules, and more likely in the database/create_cracked_credential command from best I can determine.
While testing #20881 I found an interesting condition, cracked credentials aren't displaying correctly. I'm not sure where the issue lies as I don't know the database and credential linking.
Reproduce
Output:
The Problem
We cracked the
krb5asreppassword, however thecredcommand doesn't show the password. Looking at theXXXdebugging output above we can see 3 relevant lines:nilcredscommandMore Inconsistency
Keeping the same sessions as previously run, lets clear out and just do the
krb5asreppassword because maybe that code branch has a bug in it:krb5asrep Output:
So that works correctly. Lets try it with just the
krb5tgscred to make sure that is working:krb5tgs Output:
So the problem only shows when its got both
krb5tgsandkrb5asrepcreds, thus unlikely (but still possible) to be something in the password cracking modules, and more likely in the database/create_cracked_credential command from best I can determine.