KrbGuess – Guess/Enumerate Kerberos User Accounts
来源:互联网 发布:一入淘宝深似海 编辑:程序博客网 时间:2024/06/04 18:16
KrbGuess is a small and simple tool which can be used during security testing to guess valid usernames against a Kerberos environment. It allows you to do this by studying the response from a TGT request to the KDC server. The tool works against both Microsoft Active Directory, MIT and Heimdal Kerberos implementations. In addition it will detect if an account lacks pre-authentication.
The tool is supplied with a file containing a list of usernames and requests a TGT for each user and then waits for the response. If the KDC responds with a valid TGT or with an error message stating that pre-authentication is required, a valid username has been discovered. Several guesses can be run in parallel (currently only against a single KDC) in order to improve performance.
Be careful not to run with to many threads and low timeouts as it will bring the KDC to its knees during the time of the test. The default values have been tuned against a virtual machine, and currently eat somewhere around 80% CPU which gives me roughly 700 guesses per second. In most cases the network throughput won’t be the performance bottleneck. So far I’m seeing that 2-3MBit of queries is generating a sustained 100% CPU load against both Heimdal on Ubuntu and Windows 2003.
The tool is written in Java and does not rely on any Kerberos libraries to perform the guessing. In order to successfully run the tool against a system it needs at least the realm, dictionary and a server parameters to be set. eg.
java -jar krbguess.jar -s 192.168.56.11 -r HEMMA / -o report.txt -d ./dic.txt
You can download KrbGuess here:
krbguess-0.21-bin.tar.gz
Or read more here.
- KrbGuess – Guess/Enumerate Kerberos User Accounts
- Types of user accounts
- SQL Server - User Accounts
- Windows User and computer accounts
- Creating AD user accounts in PowerShell
- oracle官方文档之Predefined User Accounts
- Security Tutorials系列文章第五章:Creating User Accounts
- mezzanine用户扩展/PUBLIC USER ACCOUNTS(一)
- enumerate
- enumerate
- enumerate
- enumerate
- enumerate()
- Kerberos
- Kerberos
- Kerberos
- Kerberos
- Kerberos
- 生产者-消费者 C的简单模拟
- 體對高煥堂於2009 QCon 北京大會演講評語
- Comet 基于AJAX的HTTP长连接
- 关于热插拔usb hotplug /proc/sys/kernel mdev udev busybox
- 获得当前数据库对象依赖关系的实用算法
- KrbGuess – Guess/Enumerate Kerberos User Accounts
- 深入理解Linux的系统调用
- C语言实例程序
- Unix/Linux下的Curses库开发指南——第二章 curses库I/O处理
- java与C++区别
- Javascript对url进行编码转换
- 找零时刻
- 设置jTable不能重新调整列宽 设置jTable不能重新排序各列
- C#开发ActiveX控件