GetNPUsers & Kerberos Pre-Auth Explained

VbScrub
21 Feb 202021:05

Summary

TLDRThis video delves into the 'GetNPUsers' script, a tool used to exploit user accounts with disabled Kerberos pre-authentication. The script's functionality is demonstrated, revealing how it uncovers vulnerable accounts and extracts encrypted password hashes. The presenter explains the script's mechanics, the significance of Kerberos pre-authentication, and the process of cracking the hashes using tools like hashcat. The video also includes a Wireshark packet capture analysis and an exploration of LDAP queries, aiming to clarify the script's operation and the security implications of disabling pre-authentication.

The video is abnormal, and we are working hard to fix it.
Please replace the link and try again.
The video is abnormal, and we are working hard to fix it.
Please replace the link and try again.

Outlines

plate

This section is available to paid users only. Please upgrade to access this part.

Upgrade Now

Mindmap

plate

This section is available to paid users only. Please upgrade to access this part.

Upgrade Now

Keywords

plate

This section is available to paid users only. Please upgrade to access this part.

Upgrade Now

Highlights

plate

This section is available to paid users only. Please upgrade to access this part.

Upgrade Now

Transcripts

plate

This section is available to paid users only. Please upgrade to access this part.

Upgrade Now