> For the complete documentation index, see [llms.txt](https://maurvan.gitbook.io/ctf-writeups/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://maurvan.gitbook.io/ctf-writeups/various-challenges/index/kerberos-authentication.md).

# Kerberos - Authentication

## Challenge

> You have been asked by Cat Corporation’s SOC team to retrieve a user’s password linked to a suspicious Kerberos connection.
>
> Flag format : `RM{user@DomainName:password}`

And the corresponding zip file:

{% file src="/files/A3VwRMlfLtGAFOYfVDJX" %}

## Solution

As we open the archive, we can see we're dealing with a pcapng file. This means we will be using Wireshark and looking at the information we received, we're going to search for a Kerberos connection.

After filtering we end up with 7 frames.

<figure><img src="https://1102212211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fa46Jmz9dIuFnWcXn3ooO%2Fuploads%2F1WH5AQ4VV7LrDmzbW2b0%2Fkerberos_filter.PNG?alt=media&amp;token=69b6669e-0bf4-4486-a263-018565f15111" alt=""><figcaption></figcaption></figure>

Looking at the first one, we already find something really interesting. Namely, a user: william.dupond and a domain name: CATCORP.LOCAL.

<figure><img src="https://1102212211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fa46Jmz9dIuFnWcXn3ooO%2Fuploads%2FWwnbbR32egDCPnKTlqzy%2Fkerberos_username.PNG?alt=media&amp;token=f127ecf7-c63a-4a64-90b4-5f902aabb408" alt=""><figcaption></figcaption></figure>

Now we only have the password left to find !

If you're not familiar with Kerberos and AR-REQ Roasting, I recommend reading some more about it. But basically if you use Kerberos, you will send an AS-REQ to the authentication service. This message includes sensitive data, with segments encrypted using the user's password hash.&#x20;

Knowing this, when we look at the AS-REQ frame, we can indeed find a very interesting hash.

<figure><img src="https://1102212211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fa46Jmz9dIuFnWcXn3ooO%2Fuploads%2F7uMHmgGrs8heB3ESVY1X%2Fkerberos_hashed.PNG?alt=media&amp;token=304aafcd-f7fc-427f-9a61-c13ebc717371" alt=""><figcaption></figcaption></figure>

Alternatively, we could also have used [NetworkMiner](https://www.netresec.com/?page=Blog\&month=2014-02\&post=HowTo-install-NetworkMiner-in-Ubuntu-Fedora-and-Arch-Linux) (a network forensics tool). You just open the pcap file with it, then check the "Credentials" tab and it's the first entry.

<figure><img src="https://1102212211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fa46Jmz9dIuFnWcXn3ooO%2Fuploads%2FOT1Uo0TK6m5ShSCjfI3D%2Fnetworkminer.PNG?alt=media&amp;token=c23f7c37-0534-4334-932c-e4502395de62" alt=""><figcaption></figcaption></figure>

We can now try to crack this hash using JohnTheRipper or HashCat.

Note: Kerberos uses a specific format so make sure your hash looks like this before attempting to crack it.

```
$krb5pa$18$william.dupond$CATCORP.LOCAL$fc8bbe22b2c967b222ed73dd7616ea71b2ae0c1b0c3688bfff7fecffdebd4054471350cb6e36d3b55ba3420be6c0210b2d978d3f51d1eb4f
```

<figure><img src="https://1102212211-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fa46Jmz9dIuFnWcXn3ooO%2Fuploads%2FB3qmDqxNWrm567msT6NN%2Fkerberos_cracked.PNG?alt=media&amp;token=e0070f8f-59ac-4d91-8eca-615cfaacb7ee" alt=""><figcaption></figcaption></figure>

So that means our flag is: RM{<william.dupond@CATCORP.LOCAL>:kittycat12}
