Skip to content


Find DC IPs

Enumerate and confirm the Domain Controllers of the target domain by DNS via nslookup or dig

nslookup -type=srv _ldap._tcp.dc._msdcs.sevenkingdoms.local
nslookup -type=srv _ldap._tcp.dc._msdcs.buildcyber.north.sevenkingdoms.local
nslookup -type=srv _ldap._tcp.dc._msdcs.essos.local
nslookup to find domain controllers

Configure Kerberos on Linux

In order to use kerberos authentication and related tradecraft, we will have to do some configurations to our Linux machine. - First we need to setup DNS so that the machines will resolve correctly. We can accomplish this by editing our /etc/host file & by using the Linux kerberos client package.

Editing /etc/hosts file

sudo nano /etc/hosts

# add below to /etc/hosts file
# Red Seer Labs: GOADv2   sevenkingdoms.local kingslanding.sevenkingdoms.local kingslanding   winterfell.north.sevenkingdoms.local north.sevenkingdoms.local winterfell   essos.local meereen.essos.local meereen   castelblack.north.sevenkingdoms.local castelblack   braavos.essos.local braavos
editing /etc/host file

Setting up Kerberos Client

Next we need to install and set up the kerberos linux client.

sudo apt install krb5-user
# if you already have this installed and need to change its configuration run: 'sudo dpkg-reconfigure krb5-config'
If/when you get a prompt during the installation, you can answer the questions to help configuration along.

krb5-user configuration questions

krb5-user config questions

krb5-user config questions

After the package is installed we need to edit the /etc/krb5.conf settings to finish the setup.

sudo nano /etc/krb5.conf
/etc/krb5.conf contents:
        default_realm = essos.local

# The following krb5.conf variables are only for MIT Kerberos.
        kdc_timesync = 1
        ccache_type = 4
        forwardable = true
        proxiable = true
        rdns = false

# The following libdefaults parameters are only for Heimdal Kerberos.
        fcc-mit-ticketflags = true

        essos.local = {
                kdc = meereen.essos.local
                admin_server = meereen.essos.local
        sevenkingdoms.local = {
                kdc = kingslanding.sevenkingdoms.local
                admin_server = kingslanding.sevenkingdoms.local
        north.sevenkingdoms.local = {
                kdc = winterfell.north.sevenkingdoms.local
                admin_server = winterfell.north.sevenkingdoms.local

Now we can test that it is configured correctly by seeing if we can successfully obtain a TGT for a user....spoiler: we won't 🙁

impacket-getTGT essos.local/khal.drogo:horse

Thankfully, the error is nice enough to tell us the problem.

Alt text

Kerberos is very particular about clocks syncing up closely to the Domain Controllers, and our system clock isn't matching the essos.local domain controller's. Which kinda makes sense if you think about our targets operating out of a fictional universe.

We can use the -debug parameter of the same tool to figure out what the exact time the DC is looking for and then spoof ours to sync up using the faketime application.

Alt text Alt text So this tells us that our times are way different from our system's local time, AND that the target enterprise environment is using UTC as well and not EST in my case.

# we could also use 'ntpdate' to change our entire system clock if we wanted...however this will change our entire vms clock...which might not always be something you want or can do
# sudo ntpdate <dc we want to sync to IP>

sudo apt install faketime

Now we can utilize faketime to spoof whatever time, timezone and convention we wish, so we can match the KDC of our target's environment.

# faketime 'time we want to spoof and such` <command to execute with faked time>
faketime '2023-06-20 20:03:15 UTC' zsh

Finally, we can successfully obtain a valid kerberos TGT! 😺 spoofing system clock with faketime

Testing Kerberos Auth

Lets check to make certain everything is working correctly by using the TGT to try to connect to some network shares.

export KRB5CCNAME=./khal.drogo.ccache

impacket-smbclient -k @braavos.essos.local
# shares
# use C$
# ls
using the TGT with smbclient

Congratulations! We are all ready to start our pentest! Next: Attacking Part 1-Finding Users