Files
LuemmelSec aef5d06e9f Fixed issue with wrongly derived Salt for protected users
This is a fix for the problem which already was described here:
https://github.com/GhostPack/Rubeus/issues/119

For AES preauth, the KDC expects a key derived with an exact, KDC-defined salt. Currently the salt is derived locally (DOMAIN + user), which can be wrong when the sAMAccountName’s exact casing or other rules differ. That led to a bad PA-ENC-TIMESTAMP and KDC_ERR_PREAUTH_FAILED.
The tool did not reliably consume the KDC’s salt hints. It only handled a single PA-ETYPE-INFO2 entry, didn’t support legacy PA-ETYPE-INFO, and didn’t probe unless asked.

Added a no-preauth “probe” (when using /opsec) before the real request.
Fully parse both PA-ETYPE-INFO2 and PA-ETYPE-INFO, supporting multiple entries and robust string extraction.
Defer password hashing until after the probe and use the exact salt returned by the KDC; fall back only if none is provided.
Kept behavior gated by /opsec so normal traffic still looks realistic.
2025-11-10 12:39:37 +01:00
..
2020-01-31 13:14:24 -08:00
2019-02-07 10:09:27 -08:00
2020-05-19 08:30:00 -05:00
2025-09-08 12:55:05 +01:00
2025-04-03 02:12:32 +02:00
2021-11-26 22:24:04 +00:00