CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A penetration tester is evaluating an Active Directory environment. They have compromised a low-privilege user account and are attempting to escalate privileges. During their reconnaissance, they discover that the `svc_backup` service account has a Service Principal Name (SPN) registered for `MSSQLSvc/db.corp.local:1433`. The tester uses `setspn -query svc_backup` to confirm this. Which type of attack should the tester attempt next to potentially retrieve the service account's password hash?

  1. AKerberoasting
  2. BPass-the-Hash
  3. CGolden Ticket
  4. DAS-REP Roasting
Show answer & explanation

Correct answer: A. Kerberoasting

Kerberoasting exploits service accounts with SPNs by requesting a service ticket (TGS) for that SPN. The Key Distribution Center (KDC) encrypts this ticket with the service account's NTLM hash. An attacker can then capture this ticket and attempt to crack the hash offline to obtain the service account's password.

Why the other options are wrong

  • B. Pass-the-Hash requires obtaining the NTLM hash first, not an attack to retrieve it from an SPN.
  • C. Golden Ticket attacks require compromise of the krbtgt account hash, which is not the scenario described here.
  • D. AS-REP Roasting targets user accounts that do not require Kerberos preauthentication, which is a different vulnerability than SPN-related hashes.

Kerberoasting

An attack against Active Directory that targets service accounts with registered Service Principal Names (SPNs). Attackers request service tickets for these SPNs, which are encrypted with the service account's NTLM hash, allowing for offline hash cracking.

  • Targets service accounts with SPNs.
  • Requests Kerberos Service Tickets (TGS).
  • Tickets are encrypted with the service account's NTLM hash.
  • Hashes can be cracked offline.

Memory trick: AD hashes: Pass, Golden, Kerber, AS-REP – each a different key to the kingdom.

More Attacks and Exploits questions