324 Commits
Author SHA1 Message Date
LuemmelSec 1ece993b58 Change target framework version to v4.0
Updated target framework version from v4.8 to v4.0.
2025-11-13 08:06:35 +01:00
LuemmelSec aef5d06e9f Fixed issue with wrongly derived Salt for protected users
This is a fix for the problem which already was described here:
https://github.com/GhostPack/Rubeus/issues/119

For AES preauth, the KDC expects a key derived with an exact, KDC-defined salt. Currently the salt is derived locally (DOMAIN + user), which can be wrong when the sAMAccountName’s exact casing or other rules differ. That led to a bad PA-ENC-TIMESTAMP and KDC_ERR_PREAUTH_FAILED.
The tool did not reliably consume the KDC’s salt hints. It only handled a single PA-ETYPE-INFO2 entry, didn’t support legacy PA-ETYPE-INFO, and didn’t probe unless asked.

Added a no-preauth “probe” (when using /opsec) before the real request.
Fully parse both PA-ETYPE-INFO2 and PA-ETYPE-INFO, supporting multiple entries and robust string extraction.
Defer password hashing until after the probe and use the exact salt returned by the KDC; fall back only if none is provided.
Kept behavior gated by /opsec so normal traffic still looks realistic.
2025-11-10 12:39:37 +01:00
lyntux e35a5e3a2c Update Helpers.cs (#208)
Fix Rubeus issue 205
2025-09-08 12:55:05 +01:00
Will Schroeder d7a2506d47 Merge pull request #200 from cnotin/patch-1
Fix minor typo "requset"
2025-07-23 14:15:51 -07:00
JoeandJoe Dibley f5a37e4563 PKINIT Authentication Minor Improvements (#198)
* Add option for multiple PADATAs in certificate requests

* Add agreement Q

* Make SignedAuthPack implicit for wireshark

* Check PaChecksum is actually hit

* Revert "Check PaChecksum is actually hit"

This reverts commit e8d6369b1f.

* Revert "Add agreement Q"

This reverts commit 17ca3bc7fd.

---------

Co-authored-by: Joe Dibley <joe.dibley@netwrix.com>
2025-04-17 11:11:56 +01:00
Ceri Coburn 146edb070e Fixed issue where s4u2self was broken by the credential guard feature. (#201) 2025-04-04 16:10:38 +01:00
Clément Notin 48a0a7b418 Fix minor typo "requset" 2025-04-03 02:12:32 +02:00
Ceri Coburn 73bbae3704 Further checks added for internal Rubeus version of asktgs vs LSA method 2025-03-28 17:02:41 +00:00
Ceri Coburn 5ca374f62a Add support for requesting services tickets via LSA. This is helpful on machines where credential guard is present 2025-02-25 09:30:10 +00:00
Joe afa32afc96 Support Delegated Managed Service Account Kerberos Processes (#194)
* Initial Implementation of DMSA Support. This includes KERB-DMSA-KEY-PACKAGE and KERB-SUPERSEDED-BY-USER structures and returning data.

* Remove a console output

* Help doc updates

* Ticket Display Updates so if previous keys are needed they can be added at a later date easily.

* Clean up, comments and support child domain fqdns

* Update versions

* Change output for DMSA Request to include DMSA User and the requesting user (Computer)
2025-02-01 12:32:55 +00:00
Steve Embling 6ce95440c7 (For review)Clearer messaging when working with Credential Guard blobs (#193)
* CredentialGuard blob handling
2024-09-12 08:13:42 +01:00
SAERXCIT b25c2e50b9 Netbios addresses are 16 bytes long instead of 8. cf RFC4120 7.1 2024-06-12 17:25:32 +02:00
Théo Gobinet e5072968c1 Fixing GetLSAHandle as SYSTEM 2024-05-15 11:00:23 +02:00
Lee Christensen 129c49dc4c up version 2024-02-01 14:16:30 -08:00
Lee Christensen 0e1e63ebd8 check for console before setting encoding 2024-02-01 13:53:31 -08:00
Will b303d1c9d8 Removed call to LsaRegisterLogonProcess
-Removed call to `LsaRegisterLogonProcess` as it was ultimately unnecessary.

So long User32LogonProcesss IOC, we hardly knew thee :)
2024-01-17 10:42:48 -08:00
0xe7 c06bfca781 missed some ToLower calls to change to ToLowerInvariant for unicode chars 2024-01-05 16:48:48 +00:00
0xe7 63a0604df2 upped minor version 2024-01-05 14:53:15 +00:00
0xe7 c5e53c7079 fix for unicode domains and s4u /opsec dates 2024-01-05 14:48:42 +00:00
0xe7 558c4ef75a fix unicode domain encoding 2023-11-28 17:38:38 +00:00
0xe7 2da1d303a6 added fix for TGS-REQ checksum and S4UUserID domain encoding 2023-11-28 16:58:17 +00:00
Will f5d1dca687 Update KrbCredInfo.cs 2023-11-03 14:48:21 -07:00
0xe7 945ffabd7d added newpac to silver command 2023-09-22 23:19:14 +01:00
0xe7 3596d62366 Merge pull request #168 from koztkozt/koztkozt-patch-2
Fix substring issue in S4U.cs
2023-09-11 11:45:36 +01:00
0xe7 4a2fc8a3d9 Merge branch 'master' into des 2023-09-01 12:06:38 +01:00
ztko f4c2b6e639 Update S4U.cs
Fix substring issue with /opsec flag
2023-08-15 10:14:53 +08:00
0xe7 679e992947 adding modifications to support DES attacks 2023-08-08 23:29:31 +01:00
Ceri Coburn 64114442ef Added support for requesting a TGT with a specific principal name type 2023-08-08 13:37:14 +01:00
0xe7 6e3736c3b4 remove unneeded assembly includes to asrep2kirbi 2023-05-17 12:26:36 +01:00
0xe7 9489a0c5a0 Merge pull request #156 from MWR-CyberSec/add-asreproast-aes-support
Added support for AS-REP Roasting with AES encryption types
2023-05-16 16:44:56 +01:00
0xe7 7293b2b3b5 Merge pull request #157 from eladshamir/asrep2kirbi
Add an asrep2kirbi action
2023-05-16 16:41:49 +01:00
Christo Erasmus 473933979d Added support for AS-REP Roasting with AES etypes
Added support for AS-REP Roasting with AES encryption types, through the
/aes flag for the asreproast module
2023-05-15 14:38:50 +02:00
0xe7 3cea8317bd small modify to tgssub 2023-04-20 21:00:01 +01:00
michael-dev c13534a1a1 Currently asktgt ignores /changepw when /certificate is used. Fix this by adding support for /changepw with /certificates. Can be used to change the ad user password of a user using smartcard / certificate authentication.
Tested with Windows 10 + Windows Server 2019.
2023-04-19 08:47:56 +02:00
Elad Shamir 9cf6c8d683 Add an asrep2kirbi action 2023-04-18 20:09:58 +00:00
0xe7 f6685f4b71 Merge pull request #147 from JoeDibley/Key-List-Attack
Kerberos Key-List-Request and Replies
2023-02-03 15:25:12 +00:00
0xe7 51f1863f5d Bump version number 2023-02-03 15:20:42 +00:00
JoeDibley 6b62732efa Update Help for KeyList Requests
Updated the Info.cs and README.md to include new KeyList Request options
2023-02-01 11:37:29 +00:00
0xe7 c286cc953c fix for parsing RODC EncryptedData kvno and display RODC number using describe 2023-01-28 00:11:46 +00:00
JoeDibley f2a89781f2 Update Rubeus.csproj 2022-12-12 16:35:49 +00:00
JoeDibley b0d9aa3487 Fix ticket display problems 2022-12-12 16:35:39 +00:00
JoeDibley 4f06820277 Implementing KeyList attack
Keylist attack involes personating a RODC and requesting a key (password hash) for a user.
2022-12-12 16:20:14 +00:00
0xe7 39a3b88d92 several changes but mainly to add support for the new FullPacChecksum signature 2022-11-19 01:08:30 +00:00
CCob 52faf3b4e6 Embed Requestor SID and Attributes PAC by default
During the October 2022 update Microsoft has switched to enforcement mode for the presence of the Requestor SID and Attributes PAC as part of CVE-2021-42287, therefore default golden tickets no longer work.  Switch the behavior so that this is now default which can then be excluded using /oldpac argument
2022-11-08 09:23:17 +00:00
0xe7 cd33efcaee bugfixes in error codes and describe 2022-10-11 22:40:41 +01:00
0xe7 c777771e55 added preauthscan command, various arguments to asktgt/kerberoast without preauth from the AS 2022-09-27 10:53:33 +01:00
4ndr3w6 82cca04a27 Version bump to 2.1.2 2022-08-09 16:15:05 -05:00
4ndr3w6 9c44f68ec7 Update to catch tgtdeleg error 2022-08-08 18:19:41 -05:00
0xe7 e2b77dcab1 Merge branch 'master' into master 2022-07-05 23:44:01 +01:00
4ndr3w6S b4718685e7 upload of initial 'diamond' command 2022-07-05 01:23:34 +00:00