Impacket
Kerberos with Impacket
in order to perform ticket manipulation we need to install the kerberos linux client utilities on the kali box
If you screw up the install or need to change something
sudo dpkg-reconfigure krb5-config
all values to target domain
We’ll also have to copy the ccache file previously obtained to our local Kali box
Next we’ll have to update the environment variable on our local kali box
We’ll need to update the hosts file to map the hostnames to IP addresses
Also the source IP address will have to be correct so proxychains will need to be used
proxychains4.conf will need to comment out DNS
set up a socks server on the pivot host
now proxychains & impacket can be used to interact with the remote host
Gather a list of SPNs available
get a shell on the remote box
Renew
Convert ccache to kirbi
inject ticket on compromised windows box
Last updated
Was this helpful?