Open cardosec

Case BEE679 · Identity & AD · L2 Practitioner

How Kerberos Authentication Works

Practise as: Explain it · Interview

Interview questionWalk me through what happens on the wire when a domain user opens a file share.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. AS-REQ/AS-REP: user proves key (pre-auth timestamp) to KDC and gets a TGT encrypted with the krbtgt account key
  2. TGS-REQ/TGS-REP: user presents TGT, gets a service ticket encrypted with the target service account key
  3. AP-REQ: client sends the service ticket to the server, which decrypts it with its own key; the KDC is not contacted
  4. PAC inside tickets carries group SIDs used for authorization; time skew over 5 minutes breaks auth by default
  5. Events: 4768 (TGT requested), 4769 (service ticket requested), 4771 (pre-auth failed) on domain controllers

If the interviewer pushes back

  • Why does the service not validate the PAC with the KDC by default, and what attack does that enable?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.