AS-REP Roasting
Active Directory (AD) environments that rely on Kerberos for authentication are vulnerable to AS-REP roasting, a technique that leverages the NTLM authentication protocol to exfiltrate user hashes. This attack is enabled when user accounts are configured to accept NTLM authentication (e.g., for non-domain-joined clients or legacy systems), allowing attackers to request AS-REP responses that include NTLM hashes. These hashes can then be cracked to recover plaintext passwords, exposing sensitive credentials. Understanding how password policies influence the feasibility of this attack is critical for defensive strategies.
Reliance on NTLM Authentication¶
AS-REP roasting exploits the NTLM authentication protocol, which predates Kerberos and is often used in hybrid or legacy environments. When a user account is configured to accept NTLM authentication (via the Do not require Kerberos preauthentication flag), attackers can use tools like Mimikatz to request AS-REP responses. These responses contain the user’s NTLM hash, which is stored in the AD database and can be extracted via LDAP queries.
Example: Mimikatz AS-REP Roasting¶
# Using Mimikatz to request AS-REP responses
mimikatz.exe "privilege::debug" "lsa::tdt" "kerberos::list /export" "exit"
Impact of Password Policies on Attack Feasibility¶
Password policies directly influence the success of AS-REP roasting. Strong policies increase the difficulty of cracking hashes, while weak policies may enable faster credential recovery. Key factors include:
- Password Complexity Requirements:
- Strong policies (e.g., minimum length, special characters) generate hashes resistant to brute-force or dictionary attacks.
-
Weak policies (e.g., short, simple passwords) result in hashes that are easier to crack.
-
Password Expiration and History:
- Frequent password changes reduce the window for attackers to exploit stolen hashes.
-
Password history enforcement prevents reuse of previous credentials, limiting the value of stolen hashes.
-
Account Lockout Policies:
-
Lockout thresholds can deter automated credential enumeration attempts, though attackers may bypass them using pass-the-hash techniques.
-
User Account Configuration:
- Accounts with the
Do not require Kerberos preauthenticationflag are prime targets. Disabling this flag (where possible) mitigates the risk.
Mitigation Strategies¶
To defend against AS-REP roasting, organizations should:
1. Disable NTLM Authentication:
- Remove the Do not require Kerberos preauthentication flag from user accounts.
- Enforce Kerberos-only authentication for all domain-joined systems.
- Enforce Strong Password Policies:
- Implement complexity rules, minimum length, and regular expiration.
-
Use password history to prevent reuse of old credentials.
-
Monitor and Audit:
- Regularly check for accounts configured to accept NTLM.
-
Use tools like PowerView or ADSI Edit to audit account properties.
-
Deploy Advanced Detection:
- Monitor for unusual AS-REP request patterns or LDAP queries targeting user hashes.
- Leverage SIEM tools to correlate events with potential credential theft.
Key takeaways¶
- AS-REP roasting exploits NTLM authentication to extract hashes from AD.
- Password complexity and expiration policies directly impact the feasibility of cracking stolen hashes.
- Disabling NTLM and enforcing Kerberos-only authentication is critical for mitigation.
- Regular audits and monitoring are essential to detect and remediate vulnerable accounts.
- Strong password policies and account configuration reduce the attack surface for credential theft.