7.3 - AS-REP Roasting
AS-REP Roasting
AS-REP Process
1) AS-REQ (Client -> KDC/AS)
- Timestamp 🔑 Encrypted with Client key (only if preauthentication is enabled)
2) AS-REP (KDC/AS -> Client)
- TGT 🔑 Encrypted with KDC key
- TGS Session Key 🔑 Encrypted with Client keyExample: Exploiting AS-REP Roasting
New-ADUser -Name "asrep" -SamAccountName "asrep" -UserPrincipalName "asrep@dev-angelist.lab" -AccountPassword (ConvertTo-SecureString -AsPlainText "Password123!" -Force) -Enabled $trueWin + R -> dsa.msc
User -> Properties -> Account -> Account Options -> Do not require Kerberos preauthentication



Other Resources
Labs
Last updated