0xe7
74215f68ea
Merge pull request #215 from LuemmelSec/master
...
Fixed issue with wrongly derived Salt e.g. for protected users
2025-11-14 08:08:01 +00:00
LuemmelSec
1ece993b58
Change target framework version to v4.0
...
Updated target framework version from v4.8 to v4.0.
2025-11-13 08:06:35 +01:00
LuemmelSec
aef5d06e9f
Fixed issue with wrongly derived Salt for protected users
...
This is a fix for the problem which already was described here:
https://github.com/GhostPack/Rubeus/issues/119
For AES preauth, the KDC expects a key derived with an exact, KDC-defined salt. Currently the salt is derived locally (DOMAIN + user), which can be wrong when the sAMAccountName’s exact casing or other rules differ. That led to a bad PA-ENC-TIMESTAMP and KDC_ERR_PREAUTH_FAILED.
The tool did not reliably consume the KDC’s salt hints. It only handled a single PA-ETYPE-INFO2 entry, didn’t support legacy PA-ETYPE-INFO, and didn’t probe unless asked.
Added a no-preauth “probe” (when using /opsec) before the real request.
Fully parse both PA-ETYPE-INFO2 and PA-ETYPE-INFO, supporting multiple entries and robust string extraction.
Defer password hashing until after the probe and use the exact salt returned by the KDC; fall back only if none is provided.
Kept behavior gated by /opsec so normal traffic still looks realistic.
2025-11-10 12:39:37 +01:00
lyntux
e35a5e3a2c
Update Helpers.cs ( #208 )
...
Fix Rubeus issue 205
2025-09-08 12:55:05 +01:00
Will Schroeder
d7a2506d47
Merge pull request #200 from cnotin/patch-1
...
Fix minor typo "requset"
2025-07-23 14:15:51 -07:00
Joe and Joe Dibley
f5a37e4563
PKINIT Authentication Minor Improvements ( #198 )
...
* Add option for multiple PADATAs in certificate requests
* Add agreement Q
* Make SignedAuthPack implicit for wireshark
* Check PaChecksum is actually hit
* Revert "Check PaChecksum is actually hit"
This reverts commit e8d6369b1f .
* Revert "Add agreement Q"
This reverts commit 17ca3bc7fd .
---------
Co-authored-by: Joe Dibley <joe.dibley@netwrix.com >
2025-04-17 11:11:56 +01:00
Ceri Coburn
146edb070e
Fixed issue where s4u2self was broken by the credential guard feature. ( #201 )
2025-04-04 16:10:38 +01:00
Clément Notin
d139d630c9
Fix minor typo "requset"
2025-04-03 02:13:37 +02:00
Clément Notin
48a0a7b418
Fix minor typo "requset"
2025-04-03 02:12:32 +02:00
0xe7
7401a2378f
Merge pull request #199 from GhostPack/credguard
...
Add support for requesting TGS tickets via LSA to bypass Credential Guard
2025-04-01 11:47:31 +01:00
Ceri Coburn
73bbae3704
Further checks added for internal Rubeus version of asktgs vs LSA method
2025-03-28 17:02:41 +00:00
Ceri Coburn
5ca374f62a
Add support for requesting services tickets via LSA. This is helpful on machines where credential guard is present
2025-02-25 09:30:10 +00:00
Joe
afa32afc96
Support Delegated Managed Service Account Kerberos Processes ( #194 )
...
* Initial Implementation of DMSA Support. This includes KERB-DMSA-KEY-PACKAGE and KERB-SUPERSEDED-BY-USER structures and returning data.
* Remove a console output
* Help doc updates
* Ticket Display Updates so if previous keys are needed they can be added at a later date easily.
* Clean up, comments and support child domain fqdns
* Update versions
* Change output for DMSA Request to include DMSA User and the requesting user (Computer)
2025-02-01 12:32:55 +00:00
Steve Embling
6ce95440c7
(For review)Clearer messaging when working with Credential Guard blobs ( #193 )
...
* CredentialGuard blob handling
2024-09-12 08:13:42 +01:00
Ceri Coburn
351cb3bc04
Merge pull request #191 from SAERXCIT/fix-netbiosaddr-padding
...
Fix Netbios address padding: 16 bytes instead of 8
2024-06-13 08:23:03 +01:00
SAERXCIT
b25c2e50b9
Netbios addresses are 16 bytes long instead of 8. cf RFC4120 7.1
2024-06-12 17:25:32 +02:00
Will
b98d898217
Merge pull request #188 from theogobinet/master
...
Fixing GetLSAHandle as SYSTEM
2024-05-15 09:35:44 -07:00
Théo Gobinet
e5072968c1
Fixing GetLSAHandle as SYSTEM
2024-05-15 11:00:23 +02:00
0xe7
04f81a41a5
Merge pull request #182 from GhostPack/fix_encoding
...
Check for console before setting encoding
2024-02-01 22:19:50 +00:00
Lee Christensen
129c49dc4c
up version
2024-02-01 14:16:30 -08:00
Lee Christensen
0e1e63ebd8
check for console before setting encoding
2024-02-01 13:53:31 -08:00
Will
b303d1c9d8
Removed call to LsaRegisterLogonProcess
...
-Removed call to `LsaRegisterLogonProcess` as it was ultimately unnecessary.
So long User32LogonProcesss IOC, we hardly knew thee :)
2024-01-17 10:42:48 -08:00
Ceri Coburn
baf34c7dcf
Merge pull request #180 from GhostPack/unicode-domain
...
Fix for unicode domains
2024-01-08 10:23:58 +00:00
0xe7
c06bfca781
missed some ToLower calls to change to ToLowerInvariant for unicode chars
2024-01-05 16:48:48 +00:00
0xe7
63a0604df2
upped minor version
2024-01-05 14:53:15 +00:00
0xe7
c5e53c7079
fix for unicode domains and s4u /opsec dates
2024-01-05 14:48:42 +00:00
0xe7
0e57072d27
Merge pull request #177 from GhostPack/fix-domain
...
fix unicode domain encoding
2023-11-28 17:39:15 +00:00
0xe7
558c4ef75a
fix unicode domain encoding
2023-11-28 17:38:38 +00:00
0xe7
1353dff181
Merge pull request #176 from GhostPack/fix-opsec
...
added fix for TGS-REQ checksum and S4UUserID domain encoding
2023-11-28 17:00:12 +00:00
0xe7
2da1d303a6
added fix for TGS-REQ checksum and S4UUserID domain encoding
2023-11-28 16:58:17 +00:00
Will
51e2dc19ce
Merge pull request #172 from GhostPack/HarmJ0y-patch-1
...
Update KrbCredInfo.cs
2023-11-03 14:48:34 -07:00
Will
f5d1dca687
Update KrbCredInfo.cs
2023-11-03 14:48:21 -07:00
0xe7
5db3150243
Merge pull request #170 from GhostPack/newpac-silver
...
added newpac to silver command
2023-09-22 23:20:02 +01:00
0xe7
945ffabd7d
added newpac to silver command
2023-09-22 23:19:14 +01:00
0xe7
3596d62366
Merge pull request #168 from koztkozt/koztkozt-patch-2
...
Fix substring issue in S4U.cs
2023-09-11 11:45:36 +01:00
0xe7
0dc51e1057
Merge pull request #166 from GhostPack/des
...
adding modifications to support DES attacks
2023-09-11 11:43:06 +01:00
0xe7
4a2fc8a3d9
Merge branch 'master' into des
2023-09-01 12:06:38 +01:00
ztko
f4c2b6e639
Update S4U.cs
...
Fix substring issue with /opsec flag
2023-08-15 10:14:53 +08:00
0xe7
679e992947
adding modifications to support DES attacks
2023-08-08 23:29:31 +01:00
0xe7
92413123b3
Merge pull request #165 from GhostPack/principal_types
...
Added support for requesting a TGT with a specific principal name type
2023-08-08 13:51:42 +01:00
Ceri Coburn
64114442ef
Added support for requesting a TGT with a specific principal name type
2023-08-08 13:37:14 +01:00
0xe7
659d98d858
Merge pull request #159 from GhostPack/dev
...
remove unneeded assembly includes to asrep2kirbi
2023-05-17 12:28:10 +01:00
0xe7
6e3736c3b4
remove unneeded assembly includes to asrep2kirbi
2023-05-17 12:26:36 +01:00
0xe7
9489a0c5a0
Merge pull request #156 from MWR-CyberSec/add-asreproast-aes-support
...
Added support for AS-REP Roasting with AES encryption types
2023-05-16 16:44:56 +01:00
0xe7
7293b2b3b5
Merge pull request #157 from eladshamir/asrep2kirbi
...
Add an asrep2kirbi action
2023-05-16 16:41:49 +01:00
Christo Erasmus
473933979d
Added support for AS-REP Roasting with AES etypes
...
Added support for AS-REP Roasting with AES encryption types, through the
/aes flag for the asreproast module
2023-05-15 14:38:50 +02:00
0xe7
bec0e35ed3
Merge pull request #153 from GhostPack/tgssub-change
...
small modify to tgssub
2023-04-20 21:20:45 +01:00
0xe7
3cea8317bd
small modify to tgssub
2023-04-20 21:00:01 +01:00
0xe7
8452430aab
Merge pull request #152 from michael-dev/feature/changepw-from-certificate
...
asktgt /changepw support with /certificate
2023-04-20 20:45:21 +01:00
michael-dev
c13534a1a1
Currently asktgt ignores /changepw when /certificate is used. Fix this by adding support for /changepw with /certificates. Can be used to change the ad user password of a user using smartcard / certificate authentication.
...
Tested with Windows 10 + Windows Server 2019.
2023-04-19 08:47:56 +02:00