mirror of
https://github.com/GhostPack/Rubeus
synced 2026-06-08 11:10:41 +00:00
This is a fix for the problem which already was described here: https://github.com/GhostPack/Rubeus/issues/119 For AES preauth, the KDC expects a key derived with an exact, KDC-defined salt. Currently the salt is derived locally (DOMAIN + user), which can be wrong when the sAMAccountName’s exact casing or other rules differ. That led to a bad PA-ENC-TIMESTAMP and KDC_ERR_PREAUTH_FAILED. The tool did not reliably consume the KDC’s salt hints. It only handled a single PA-ETYPE-INFO2 entry, didn’t support legacy PA-ETYPE-INFO, and didn’t probe unless asked. Added a no-preauth “probe” (when using /opsec) before the real request. Fully parse both PA-ETYPE-INFO2 and PA-ETYPE-INFO, supporting multiple entries and robust string extraction. Defer password hashing until after the probe and use the exact salt returned by the KDC; fall back only if none is provided. Kept behavior gated by /opsec so normal traffic still looks realistic.
4 lines
158 B
XML
4 lines
158 B
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<configuration>
|
|
<startup><supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8"/></startup></configuration>
|