Open cardosec

Case D86CD3 · Identity & AD · L2 Practitioner

AS-REP Roasting

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Targets accounts with "Do not require Kerberos preauthentication" set (UF_DONT_REQUIRE_PREAUTH)
  2. Attacker sends an AS-REQ without pre-auth; the AS-REP contains data encrypted with the user key, crackable offline
  3. No credentials needed if usernames are known; tools: Rubeus asreproast, Impacket GetNPUsers.py
  4. Detect: 4768 with Pre-Authentication Type 0 and RC4; find exposed accounts via LDAP userAccountControl filter
  5. Fix: re-enable pre-auth on every account and enforce strong passwords on any legacy exception

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.