Charlie Clark

1.3K posts

Charlie Clark banner
Charlie Clark

Charlie Clark

@exploitph

加入时间 Ocak 2010
1.1K 关注5.3K 粉丝
置顶推文
Charlie Clark
Charlie Clark@exploitph·
my latest post on abusing DES using Kerberos, I've not updated my RoastInTheMiddle tool yet but I'll be doing that shortly, enjoy: exploit.ph/des-is-useful.…
English
5
129
224
39.1K
Charlie Clark 已转推
Dirk-jan
Dirk-jan@_dirkjan·
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
English
140
902
3.2K
470.6K
UrfinJuice
UrfinJuice@UrfinJuice9·
@exploitph Could you please explain a bit, why do we need two pairs of s4u requests?
English
1
0
0
18
Charlie Clark 已转推
Andrew
Andrew@4ndr3w6S·
Happy to finally share a new blog with @exploitph on our work revisiting the Kerberos Diamond Ticket. ✅ /opsec for a more genuine flow ✅ /ldap to populate the PAC 🆕 Forge a diamond service ticket using an ST We finally gave it a proper cut 💎 huntress.com/blog/recutting…
English
0
62
145
40.6K
Alex Neff
Alex Neff@al3x_n3ff·
Did you know that you can kerberoast without any valid credentials? All you need is an account that is ASREProastable. This allows you to request service tickets for any account with a set SPN🔥 NetExec now has a native implementation of this technique, thanks to Azox
Alex Neff tweet media
English
7
116
470
30.8K
Charlie Clark 已转推
Jonny Johnson
Jonny Johnson@JonnyJohnson_·
Have you ever wondered if there was a way to deploy a "Remote EDR"? Today I'm excited to share research I've been working on for the past couple months. This dives into DCOM Interfaces that enable remote ETW trace sessions without dropping an agent to disk. Includes a detailed write-up: jonny-johnson.medium.com/no-agent-no-pr… And a new GitHub project "JonMon-Lite": github.com/jonny-jhnson/J…
English
15
127
377
53.2K
Charlie Clark
Charlie Clark@exploitph·
@_RastaMouse @_EthicalChaos_ @__invictus_ @4ndr3w6S I think the TDO holds both, as I said I think it's due to how the server lookup is coded, it was easier to have a trust account for requesting tickets rather than trying to code it differently or something, but I'd need to be familiar with the code to be sure
English
1
0
0
354
Rasta Mouse
Rasta Mouse@_RastaMouse·
One for the Kerberos experts: after a trust has been created, the ticket-granting service of each realm is registered as a principal with the other realm's KDC; but what is the account used for in the inter-realm referral process? /cc @exploitph @4ndr3w6S
English
3
5
44
7.4K
Charlie Clark
Charlie Clark@exploitph·
@_RastaMouse @4ndr3w6S idk why exactly, ig you'd have to ask MS, perhaps the way AD works under the hood it requires an actual account to create a ST
English
1
0
0
147
Rasta Mouse
Rasta Mouse@_RastaMouse·
@exploitph @4ndr3w6S Ok, that makes sense. But why a trust account specifically rather than storing the secret in the TDO like it is on the trusting domain side?
English
1
0
0
149
Charlie Clark
Charlie Clark@exploitph·
@_RastaMouse @4ndr3w6S so you request a referral to krbtgt/domain2, it uses the account cred for the DOMAIN2$ INTERDOMAIN_TRUST_ACCOUNT as the service key for the referral
English
1
0
1
111
Charlie Clark
Charlie Clark@exploitph·
@_RastaMouse @4ndr3w6S I assume you mean the INTERDOMAIN_TRUST_ACCOUNT, in which case it's used to request a referral to the foreign domain
English
2
0
1
858
Charlie Clark
Charlie Clark@exploitph·
@_abs0lute fwiw, I've not noticed a speed increase for AES encrypted tickets, only RC4
English
1
0
1
16
Ab Solute
Ab Solute@_abs0lute·
@exploitph Right on, makes sense. I'll have to try it out on an actual cracking rig.
English
1
0
0
21
Charlie Clark
Charlie Clark@exploitph·
fwiw, you can speed up cracking RC4 kerberoast tickets by requesting the ticket from the AS without a PAC
English
2
7
59
3.6K
Charlie Clark
Charlie Clark@exploitph·
@_abs0lute I'm not sure about with john and certainly the more resources you have, the larger increase you'll notice, but it seems to be due to the enc-part being around 1000 bytes smaller (at around 100-200 bytes without a PAC), it doesn't make a huge difference but it's definitely faster
English
1
0
0
109
Charlie Clark
Charlie Clark@exploitph·
@TheCovertCorvus no, you can request any non-krbtgt ticket from the AS without a PAC without any changes required
English
2
0
2
391