{"id":2232,"date":"2009-10-29T07:16:52","date_gmt":"2009-10-29T07:16:52","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=2232"},"modified":"2015-09-09T19:37:51","modified_gmt":"2015-09-09T11:37:51","slug":"krbguess-guessenumerate-kerberos-user-accounts","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2009\/10\/krbguess-guessenumerate-kerberos-user-accounts\/","title":{"rendered":"KrbGuess – Guess\/Enumerate Kerberos User Accounts"},"content":{"rendered":"

KrbGuess is a small and simple tool which can be used during security testing to guess valid usernames against a Kerberos environment. It allows you to do this by studying the response from a TGT request to the KDC server. The tool works against both Microsoft Active Directory, MIT and Heimdal Kerberos implementations. In addition it will detect if an account lacks pre-authentication.<\/p>\n

The tool is supplied with a file containing a list of usernames and requests a TGT for each user and then waits for the response. If the KDC responds with a valid TGT or with an error message stating that pre-authentication is required, a valid username has been discovered. Several guesses can be run in parallel (currently only against a single KDC) in order to improve performance.<\/p>\n