This is a fix for the problem which already was described here:
https://github.com/GhostPack/Rubeus/issues/119
For AES preauth, the KDC expects a key derived with an exact, KDC-defined salt. Currently the salt is derived locally (DOMAIN + user), which can be wrong when the sAMAccountName’s exact casing or other rules differ. That led to a bad PA-ENC-TIMESTAMP and KDC_ERR_PREAUTH_FAILED.
The tool did not reliably consume the KDC’s salt hints. It only handled a single PA-ETYPE-INFO2 entry, didn’t support legacy PA-ETYPE-INFO, and didn’t probe unless asked.
Added a no-preauth “probe” (when using /opsec) before the real request.
Fully parse both PA-ETYPE-INFO2 and PA-ETYPE-INFO, supporting multiple entries and robust string extraction.
Defer password hashing until after the probe and use the exact salt returned by the KDC; fall back only if none is provided.
Kept behavior gated by /opsec so normal traffic still looks realistic.
* Add option for multiple PADATAs in certificate requests
* Add agreement Q
* Make SignedAuthPack implicit for wireshark
* Check PaChecksum is actually hit
* Revert "Check PaChecksum is actually hit"
This reverts commit e8d6369b1f.
* Revert "Add agreement Q"
This reverts commit 17ca3bc7fd.
---------
Co-authored-by: Joe Dibley <joe.dibley@netwrix.com>
* Initial Implementation of DMSA Support. This includes KERB-DMSA-KEY-PACKAGE and KERB-SUPERSEDED-BY-USER structures and returning data.
* Remove a console output
* Help doc updates
* Ticket Display Updates so if previous keys are needed they can be added at a later date easily.
* Clean up, comments and support child domain fqdns
* Update versions
* Change output for DMSA Request to include DMSA User and the requesting user (Computer)
During the October 2022 update Microsoft has switched to enforcement mode for the presence of the Requestor SID and Attributes PAC as part of CVE-2021-42287, therefore default golden tickets no longer work. Switch the behavior so that this is now default which can then be excluded using /oldpac argument