Kerberos
#rubeus #kerbrute
Brute Force
We can brute force username and password based on the errors that we get from kerberos.
KDC_ERR_PREAUTH_FAILED
: Incorrect passwordKDC_ERR_C_PRINCIPAL_UNKNOWN
: Invalid usernameKDC_ERR_WRONG_REALM
: Invalid domainKDC_ERR_CLIENT_REVOKED
: Disabled/Blocked user
Rubeus
Kerbrute (go)
User Enumeration
Password brute-force
Kerbrute.py
Last updated