Pass the Ticket (PtT) - Linux
Check If Linux Machine is Domain Joined
realm
david@inlanefreight.htb@linux01:~$ realm list
inlanefreight.htb
type: kerberos
realm-name: INLANEFREIGHT.HTB
domain-name: inlanefreight.htb
configured: kerberos-member
server-software: active-directory
client-software: sssd
required-package: sssd-tools
required-package: sssd
required-package: libnss-sss
required-package: libpam-sss
required-package: adcli
required-package: samba-common-bin
login-formats: %U@inlanefreight.htb
login-policy: allow-permitted-logins
permitted-logins: david@inlanefreight.htb, julio@inlanefreight.htb
permitted-groups: Linux AdminsPS
Finding Kerberos Tickets in Linux
Using Find to Search for Files with Keytab in the Name
Identifying Keytab Files in Cronjobs
Finding ccache Files
Reviewing Environment Variables for ccache Files.
Searching for ccache Files in /tmp
Abusing KeyTab Files
Listing keytab File Information
Impersonating a User with a keytab
Connecting to SMB Share as another user
Keytab Extract
1. Extracting Keytab Hashes with KeyTabExtract
2. Log in as Carlos
Abusing Keytab ccache
Privilege Escalation to Root
Privilege EscalationLooking for ccache Files
Identifying Group Membership with the id Command
Use a ccache file
Using Linux Attack Tools with Kerberos
Pivot, Tunneling and Port ForwardingTransfer ccache file
Host File Modified
Proxychains Configuration File
Download Chisel to our Attack Host
Connect to MS01 with xfreerdp
Execute chisel from MS01
Setting the KRB5CCNAME Environment Variable
Impacket
Evil-WinRM
Evil-WinRMMiscellaneous
Impacket Ticket Converter
Importing Converted Ticket into Windows Session with Rubeus
Linikatz
V2
Last updated