Перейти к содержимому

Kerberos Authentication | Tickets, Session Keys & Protocol Dissection via Wireshark

HackerForce

0:00 / 0:00

Kerberos Authentication | Tickets, Session Keys & Protocol Dissection via Wireshark

376 просмотров · 3 недели назад
HackerForce
1,12 тыс. подписчиков
376 просмотров · 3 недели назад
💬 Join the Community   / discord   💥 Red Cell Operator I https://hackerforce.io/courses/red-ce... 🖥️ Presentation https://tinyurl.com/kerberos-auth 📌 About Three heads. One job. Kerberos guards Active Directory the way legend says a dog once guarded the underworld, but its bite isn't what it used to be. 🤷🏼‍♂️ In HackerForce's latest video, sunflower gets stuck into: The anatomy of Kerberos, its history, core components (KDC, tickets, session keys, etc.), and how it squares up against NTLM The six-way handshake, pulled apart illustratively and decrypted in Wireshark Understand it before you attack it. Not a suggestion, the rest of the series depends on it. 📚 Resources Wireshark: https://www.wireshark.org/ Wireshark capture and keytab: https://github.com/0x73unflower/Hacke... 🔔 Stay Connected X/Twitter: https://x.com/hackerforcex ⏱️ Timestamps 00:00 Introduction 01:52 Kerberos anatomy (KDC, tickets, etc.) 03:52 Kerberos history (versions, symmetric encryption, etc.) 07:29 Kerberos vs. NT LAN Manager (NTLM) 09:21 Kerberos and authorisation 10:24 Service principal names (SPNs), their structure, classes, etc. 12:04 Enumerating SPNs 12:58 Ticket granting tickets (TGTs) 14:51 The KDC and service tickets (STs) 17:52 Decrypting traffic in Wireshark using keytabs 20:26 Example files (Wireshark capture and keytab) 20:46 AS-REQ (structure) 23:30 AS-REQ (through Wireshark) 26:13 AS-REP (structure) 27:58 AS-REP (through Wireshark) 30:59 Cached tickets and their enumeration 32:37 TGS-REQ (structure) 34:25 TGS-REQ (through Wireshark) 36:45 TGS-REP (structure) 38:15 TGS-REP (through Wireshark) 39:53 AP-REQ, AP-REP (structure) 41:23 AP-REQ, AP-REP (through Wireshark) 43:22 Upcoming 🔗 Tags #sliver #c2 #redteam #blueteam #hacker #hack #penetrationtesters #pentesting #mimikatz #metasploit #wireshark #kerberos #activedirectory