Attacking Kerberos in Windows Domain Environment

content-image

บทความชุดนี้ตั้งใจเขียนอธิบายเรื่อง Kerberos ใน Windows Domain Environment และวิธีการโจมตีเหมาะสำหรับนักทดสอบเจาะระบบ อาจเป็นประโยชน์กับผู้ดูแลระบบบ้างแต่ไม่ได้มากนักเพราะไม่ได้เน้นเนื้อหาส่วน detection และ prevention สักเท่าไรเมื่อเทียบกับการอธิบายที่มาที่ไปและวิธีการโจมตี

บทความชิ้นนี้เขียนไว้ตั้งแต่ปีที่แล้ว แต่ก็ยังเขียนไม่เสร็จสักทีเพราะตั้งใจเขียนเป็น miniseries และ publish ทีเดียวเลียนแบบ serires ดัง ๆ ใน Netflix แต่ตอนนี้คิดว่าควรจะเผยแพร่ season แรกออกไปก่อนไว้มีโอกาสจะทำ season ถัดไปเพื่อ update เนื้อหาในหัวข้อที่น่าสนใจเช่นเทคนิคใหม่ ๆ หรือแม้แต่การโจมตีไปยัง Cloud Assets

Attacking Kerberos in Windows Domain EnvironmentAttacking Kerberos in Windows Domain Environment

เนื้อหาของแต่ละตอนมีประมาณนี้

EP 1.

Related articleKerberos in Windows Domain EnvironmentKerberos ทำงานอย่างไรใน Windows Domain ตั้งแต่กลไก ticket ที่ใช้พิสูจน์ตัวตนระหว่างเครื่อง ไปจนถึงกรณีที่ระบบถอยไปใช้ NTLMv2 แทนincognitolab.com/blogs/kerberos-in-windows-domain-environment

ใครที่เคยได้ยินหรือรู้จัก Kerberos มาก่อน แต่อยากรู้จักให้ลึกและละเอียดขึ้น อยากให้อ่านบทนี้เป็นบทแรก เนื่องจากจะถูกอ้างอิงในภายหลังค่อนข้างบ่อยและมีความจำเป็นต่อการทำความเข้าใจถึงเทคนิคการโจมตี Kerberos ใน Windows Domain Environment

EP 2.

Related articleNTLMv2 AttackWindows ถอยจาก Kerberos ไปใช้ NTLMv2 ในเงื่อนไขไหน และเงื่อนไขนั้นเปิดช่องให้โจมตีอย่างไร ต่อจากบทความเรื่อง Kerberos ใน Windows Domainincognitolab.com/blogs/ntlmv2-attack

ใน Windows Domain Environment เมื่อเครื่องที่อยู่ใน domain ต้องการสื่อสารกันจะใช้ Kerberos เป็น Protocol หลักในการทำ Authentication หากไม่สามารถใช้ Kerberos ได้ NTLMv2 จะถูกใช้งานแทน นักเจาะระบบต้องรู้จักการโจมตีบน NTLMv2 ด้วย

EP 3.

Related articleASREPRoast AttackASREPRoast Attack เป็นวิธีการโจมตีโดยนำ message ที่ได้จาก step ของ TGT Reply หรือ AS_REP มาทำ offline attack เพื่อหา password ของ account ที่สนใจincognitolab.com/blogs/asreproast-attack

เป็น attack ที่เป็นไปได้แรก ๆ ใน Kerberos Authentication Flow ที่นักเจาะระบบต้องไม่ลืมตรวจสอบ และผู้ดูแลระบบต้องห้ามผิดพลาด

EP 4.

Related articleKerberoasting AttackKerberoasting คือการขอ TGS จาก KDC มา crack หารหัสผ่านของ service account แบบ offline โดยไม่ต้องแตะเครื่องเป้าหมาย บทความอธิบายกลไกและข้อดีในมุมผู้ทดสอบincognitolab.com/blogs/kerberoasting-attack

เทคนิคหนึ่งในการโจมตี Kerberos มีเป้าหมายเพื่อ crack หา Password ของ target service บน Windows Domain Environment แบบ offline โดยที่เราไม่จำเป็นต้องไปแตะหรือ interface กับ target service หรือเครื่องเป้าหมายเลย

EP 5.

Related articlePave the way to Domain Admins with BloodHoundก่อนมี BloodHound การไล่หาเส้นทางสู่ Domain Admins กินเวลามาก บทความแสดงว่าเครื่องมือนี้ย่นขั้นตอนให้ pentester ได้อย่างไรincognitolab.com/blogs/pave-the-way-to-domain-admins-with-bloodhound

1 ใน Game Changer ของ tool สำหรับการทำ Internal Network Penetration Test ที่นักเจาะระบบไม่รู้ไม่ได้ และหากต้องประเมิน security ของ Windows Domain Environment แล้วไม่ได้ใช้ การประเมินครั้งนั้นย่อมขาดข้อมูลสำคัญไปเช่นกัน

EP 6.

Related articleDomain Controller Post-exploitationยึด domain admin ได้แล้วทำอะไรต่อ ทางเลือกในการขยายผลบน Domain Controller ที่ทั้ง pentester และ attacker ใช้ เริ่มจากการเข้าถึง database ของ Active Directoryincognitolab.com/blogs/domain-controller-post-exploitation

รวบรวมเทคนิคหลัง compromise domain admin สำเร็จแล้ว เช่น Golden Ticket, การ dump NTDS.dit, DC Sync, Silver Ticket และเทคนิคอื่น ๆ ที่ควรจะเคยได้ยินบ้าง


บทความชุดนี้น่าจะตอบโจทย์ของคนที่อยากเข้าใจ Kerberos มากขึ้นและใช้เป็นแหล่งอ้างอิงสำหรับการทดสอบ Internal Network Penetration Test ได้เป็นอย่างดี

OUR SERVICES

PENETRATION TEST

With our high-ethical, professional certified team and methodology based on NIST SP800-115, we offer a full range of cost-effective services to identify your cyber risks in application, infrastructure, and mobile platforms to meet the requirements of your organisation.

logologo

INCOGNITO LAB CO., LTD.

38 Soi Petchakasem 30, Pak Khlong Phasi Charoen, Phasi Charoen, Bangkok 10160

©2026 Incognito Lab Co., Ltd. All rights reserved

Terms & ConditionsPrivacy Policy