404 Commits
Author SHA1 Message Date
0xe7 74215f68ea Merge pull request #215 from LuemmelSec/master
Fixed issue with wrongly derived Salt e.g. for protected users
2025-11-14 08:08:01 +00:00
LuemmelSec 1ece993b58 Change target framework version to v4.0
Updated target framework version from v4.8 to v4.0.
2025-11-13 08:06:35 +01:00
LuemmelSec aef5d06e9f Fixed issue with wrongly derived Salt for protected users
This is a fix for the problem which already was described here:
https://github.com/GhostPack/Rubeus/issues/119

For AES preauth, the KDC expects a key derived with an exact, KDC-defined salt. Currently the salt is derived locally (DOMAIN + user), which can be wrong when the sAMAccountName’s exact casing or other rules differ. That led to a bad PA-ENC-TIMESTAMP and KDC_ERR_PREAUTH_FAILED.
The tool did not reliably consume the KDC’s salt hints. It only handled a single PA-ETYPE-INFO2 entry, didn’t support legacy PA-ETYPE-INFO, and didn’t probe unless asked.

Added a no-preauth “probe” (when using /opsec) before the real request.
Fully parse both PA-ETYPE-INFO2 and PA-ETYPE-INFO, supporting multiple entries and robust string extraction.
Defer password hashing until after the probe and use the exact salt returned by the KDC; fall back only if none is provided.
Kept behavior gated by /opsec so normal traffic still looks realistic.
2025-11-10 12:39:37 +01:00
lyntux e35a5e3a2c Update Helpers.cs (#208)
Fix Rubeus issue 205
2025-09-08 12:55:05 +01:00
Will Schroeder d7a2506d47 Merge pull request #200 from cnotin/patch-1
Fix minor typo "requset"
2025-07-23 14:15:51 -07:00
JoeandJoe Dibley f5a37e4563 PKINIT Authentication Minor Improvements (#198)
* Add option for multiple PADATAs in certificate requests

* Add agreement Q

* Make SignedAuthPack implicit for wireshark

* Check PaChecksum is actually hit

* Revert "Check PaChecksum is actually hit"

This reverts commit e8d6369b1f.

* Revert "Add agreement Q"

This reverts commit 17ca3bc7fd.

---------

Co-authored-by: Joe Dibley <joe.dibley@netwrix.com>
2025-04-17 11:11:56 +01:00
Ceri Coburn 146edb070e Fixed issue where s4u2self was broken by the credential guard feature. (#201) 2025-04-04 16:10:38 +01:00
Clément Notin d139d630c9 Fix minor typo "requset" 2025-04-03 02:13:37 +02:00
Clément Notin 48a0a7b418 Fix minor typo "requset" 2025-04-03 02:12:32 +02:00
0xe7 7401a2378f Merge pull request #199 from GhostPack/credguard
Add support for requesting TGS tickets via LSA to bypass Credential Guard
2025-04-01 11:47:31 +01:00
Ceri Coburn 73bbae3704 Further checks added for internal Rubeus version of asktgs vs LSA method 2025-03-28 17:02:41 +00:00
Ceri Coburn 5ca374f62a Add support for requesting services tickets via LSA. This is helpful on machines where credential guard is present 2025-02-25 09:30:10 +00:00
Joe afa32afc96 Support Delegated Managed Service Account Kerberos Processes (#194)
* Initial Implementation of DMSA Support. This includes KERB-DMSA-KEY-PACKAGE and KERB-SUPERSEDED-BY-USER structures and returning data.

* Remove a console output

* Help doc updates

* Ticket Display Updates so if previous keys are needed they can be added at a later date easily.

* Clean up, comments and support child domain fqdns

* Update versions

* Change output for DMSA Request to include DMSA User and the requesting user (Computer)
2025-02-01 12:32:55 +00:00
Steve Embling 6ce95440c7 (For review)Clearer messaging when working with Credential Guard blobs (#193)
* CredentialGuard blob handling
2024-09-12 08:13:42 +01:00
Ceri Coburn 351cb3bc04 Merge pull request #191 from SAERXCIT/fix-netbiosaddr-padding
Fix Netbios address padding: 16 bytes instead of 8
2024-06-13 08:23:03 +01:00
SAERXCIT b25c2e50b9 Netbios addresses are 16 bytes long instead of 8. cf RFC4120 7.1 2024-06-12 17:25:32 +02:00
Will b98d898217 Merge pull request #188 from theogobinet/master
Fixing GetLSAHandle as SYSTEM
2024-05-15 09:35:44 -07:00
Théo Gobinet e5072968c1 Fixing GetLSAHandle as SYSTEM 2024-05-15 11:00:23 +02:00
0xe7 04f81a41a5 Merge pull request #182 from GhostPack/fix_encoding
Check for console before setting encoding
2024-02-01 22:19:50 +00:00
Lee Christensen 129c49dc4c up version 2024-02-01 14:16:30 -08:00
Lee Christensen 0e1e63ebd8 check for console before setting encoding 2024-02-01 13:53:31 -08:00
Will b303d1c9d8 Removed call to LsaRegisterLogonProcess
-Removed call to `LsaRegisterLogonProcess` as it was ultimately unnecessary.

So long User32LogonProcesss IOC, we hardly knew thee :)
2024-01-17 10:42:48 -08:00
Ceri Coburn baf34c7dcf Merge pull request #180 from GhostPack/unicode-domain
Fix for unicode domains
2024-01-08 10:23:58 +00:00
0xe7 c06bfca781 missed some ToLower calls to change to ToLowerInvariant for unicode chars 2024-01-05 16:48:48 +00:00
0xe7 63a0604df2 upped minor version 2024-01-05 14:53:15 +00:00
0xe7 c5e53c7079 fix for unicode domains and s4u /opsec dates 2024-01-05 14:48:42 +00:00
0xe7 0e57072d27 Merge pull request #177 from GhostPack/fix-domain
fix unicode domain encoding
2023-11-28 17:39:15 +00:00
0xe7 558c4ef75a fix unicode domain encoding 2023-11-28 17:38:38 +00:00
0xe7 1353dff181 Merge pull request #176 from GhostPack/fix-opsec
added fix for TGS-REQ checksum and S4UUserID domain encoding
2023-11-28 17:00:12 +00:00
0xe7 2da1d303a6 added fix for TGS-REQ checksum and S4UUserID domain encoding 2023-11-28 16:58:17 +00:00
Will 51e2dc19ce Merge pull request #172 from GhostPack/HarmJ0y-patch-1
Update KrbCredInfo.cs
2023-11-03 14:48:34 -07:00
Will f5d1dca687 Update KrbCredInfo.cs 2023-11-03 14:48:21 -07:00
0xe7 5db3150243 Merge pull request #170 from GhostPack/newpac-silver
added newpac to silver command
2023-09-22 23:20:02 +01:00
0xe7 945ffabd7d added newpac to silver command 2023-09-22 23:19:14 +01:00
0xe7 3596d62366 Merge pull request #168 from koztkozt/koztkozt-patch-2
Fix substring issue in S4U.cs
2023-09-11 11:45:36 +01:00
0xe7 0dc51e1057 Merge pull request #166 from GhostPack/des
adding modifications to support DES attacks
2023-09-11 11:43:06 +01:00
0xe7 4a2fc8a3d9 Merge branch 'master' into des 2023-09-01 12:06:38 +01:00
ztko f4c2b6e639 Update S4U.cs
Fix substring issue with /opsec flag
2023-08-15 10:14:53 +08:00
0xe7 679e992947 adding modifications to support DES attacks 2023-08-08 23:29:31 +01:00
0xe7 92413123b3 Merge pull request #165 from GhostPack/principal_types
Added support for requesting a TGT with a specific principal name type
2023-08-08 13:51:42 +01:00
Ceri Coburn 64114442ef Added support for requesting a TGT with a specific principal name type 2023-08-08 13:37:14 +01:00
0xe7 659d98d858 Merge pull request #159 from GhostPack/dev
remove unneeded assembly includes to asrep2kirbi
2023-05-17 12:28:10 +01:00
0xe7 6e3736c3b4 remove unneeded assembly includes to asrep2kirbi 2023-05-17 12:26:36 +01:00
0xe7 9489a0c5a0 Merge pull request #156 from MWR-CyberSec/add-asreproast-aes-support
Added support for AS-REP Roasting with AES encryption types
2023-05-16 16:44:56 +01:00
0xe7 7293b2b3b5 Merge pull request #157 from eladshamir/asrep2kirbi
Add an asrep2kirbi action
2023-05-16 16:41:49 +01:00
Christo Erasmus 473933979d Added support for AS-REP Roasting with AES etypes
Added support for AS-REP Roasting with AES encryption types, through the
/aes flag for the asreproast module
2023-05-15 14:38:50 +02:00
0xe7 bec0e35ed3 Merge pull request #153 from GhostPack/tgssub-change
small modify to tgssub
2023-04-20 21:20:45 +01:00
0xe7 3cea8317bd small modify to tgssub 2023-04-20 21:00:01 +01:00
0xe7 8452430aab Merge pull request #152 from michael-dev/feature/changepw-from-certificate
asktgt /changepw support with /certificate
2023-04-20 20:45:21 +01:00
michael-dev c13534a1a1 Currently asktgt ignores /changepw when /certificate is used. Fix this by adding support for /changepw with /certificates. Can be used to change the ad user password of a user using smartcard / certificate authentication.
Tested with Windows 10 + Windows Server 2019.
2023-04-19 08:47:56 +02:00