adhammer-kerberos 1.5.2

ADhammer Kerberos — AS-REP/Kerberoast, S4U/RBCD, Shadow Credentials PKINIT (picky-krb).
Documentation

What it is

Kerberos protocol verbs used across ADhammer's attack subcommands:

  • AS-REP roast — offline crackable AS-REP for accounts with DONT_REQ_PREAUTH.
  • Kerberoast — request a service ticket for every account with an SPN; the ticket-part is offline-crackable to recover the password.
  • PKINIT — certificate-based AS-exchange; returns the TGT AND optionally the plain NT hash extracted from PAC_CREDENTIAL_INFO (WS-UNPAC-PKINIT).
  • Shadow Credentials — write msDS-KeyCredentialLink on a target, then AS-exchange with the injected cert to obtain the target's TGT.
  • S4U / RBCD — constrained + resource-based constrained delegation chains, including the RBCD write-then-impersonate sequence.
  • Ticket forge — Golden / Silver / Diamond variants (Diamond inherits real KDC timestamps + validity to drop the 10-year IOC).
  • ccache round-trip — MIT ccache v4 codec via the sibling ccache-io crate.

Built on picky-krb for ASN.1 primitives and picky-asn1-x509 for the PKINIT chain.

1.4.10 hardening

  • Outer-bound length guards on picky-krb's AES-CTS-HMAC-SHA1 decrypt path (AES_MIN = 44, RC4_MIN = 40) — mitigates BUG-19 (fuzz-found panic in generic-array::from_slice) at the production callsite.
  • The fuzz build itself still crashes under -C panic=abort because catch_unwind cannot catch abort; the upstream fix (picky-krb 0.12+) ships in the 1.5.0 WS-DEPS-MAJORS workstream.

Install

[dependencies]

adhammer-kerberos = "1.5"

Related

License

MIT — see LICENSE.