Using Linux
Checking if Linux is Domain Joined
$ realm list$ ps -ef | grep -i "winbind\|sssd"Finding Kerberos Tickets
Finding Keytab Files
$ find / -name *keytab* -ls 2>/dev/nullIdentifying Keytab Files in cronjobs
$ crontab -l
# m h dom mon dow command
*5/ * * * * /home/carlos@inlanefreight.htb/.scripts/kerberos_script_test.sh
$ cat /home/carlos@inlanefreight.htb/.scripts/kerberos_script_test.sh
#!/bin/bash
kinit svc_workstations@INLANEFREIGHT.HTB -k -t /home/carlos@inlanefreight.htb/.scripts/svc_workstations.kt
smbclient //dc01.inlanefreight.htb/svc_workstations -c 'ls' -k -no-pass > /home/carlos@inlanefreight.htb/script-test-results.txtFinding ccache files
Searching Environment Variables
Searching /tmp
Exploitation
Abusing keytab files
Listing keytab file information
Impersonating a user
Connecting to SMB Share as carlos
Keytab Extract
Abusing Keytab ccache
Looking for ccache files
Identifying group membership
Importing ccache file to our current session
Using Linux Attack Tools with Kerberos
Proxy Chains Configuration File
Download Chisel to our attack host
Execute Chisel from our victim host
Download ccache
Using impacket with proxychains
Using Evil-Winrm
Miscellaneous
Linikatz
Last updated