CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A tester enumerates Active Directory user accounts and identifies several with the 'Do not require Kerberos preauthentication' flag enabled. The tester requests authentication service tickets for these accounts without supplying valid credentials, then extracts the encrypted timestamp portion for offline cracking. What attack is being performed?
- APass-the-hash
- BGolden Ticket attack
- CKerberoasting
- DAS-REP Roasting
Show answer & explanationAnswer & explanation
Correct answer: D. AS-REP Roasting
AS-REP Roasting targets accounts with Kerberos preauthentication disabled, allowing an attacker to request an AS-REP response without any credentials and crack the encrypted portion offline. Kerberoasting instead targets service accounts by requesting TGS tickets using a valid authenticated session, Golden Ticket abuses the krbtgt hash, and pass-the-hash reuses NTLM hashes for authentication.
Why the other options are wrong
- A. Pass-the-hash reuses captured NTLM hashes to authenticate, unrelated to Kerberos preauthentication.
- B. A Golden Ticket forges TGTs using the compromised krbtgt hash, a different post-compromise technique.
- C. Kerberoasting requires a valid domain session to request TGS tickets for SPN accounts, not AS-REP.
AS-REP Roasting
An Active Directory attack that targets accounts with Kerberos preauthentication disabled, allowing an attacker to request an AS-REP message without valid credentials and crack its encrypted portion offline.
- Requires the 'Do not require Kerberos preauthentication' UAC flag set
- No valid credentials needed to request the AS-REP
- Cracked offline with tools like hashcat (mode 18200)
Memory trick: AS-REP Roasting: 'Ask without asking permission first'