> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/active-directory/kerberos/as-rep-roasting.md).

# AS-REP Roasting

### 原理

**AS-REP 烤票** 是一种针对配置了以下选项的 Active Directory 帐户的技术：

```bash
不要求 Kerberos 预身份验证
```

响应包含使用从用户密码派生的密钥加密的数据。

然后可以使用 John the Ripper 或 Hashcat 之类的工具对这些数据进行离线攻击。

### 简化示意图

{% code overflow="wrap" %}

```bash
攻击者
   │
   ├── 向 KDC 发送 AS-REQ
   │
   └── 使用从用户密码派生的密钥加密的 AS-REP
                    │
                    └── 离线破解
```

{% endcode %}

### 为什么它很危险

这种攻击很危险，因为：

* 它不一定需要有效凭据；
* 它可以远程针对 KDC 执行；
* 破解是在离线状态下进行的；
* 它在很大程度上取决于用户密码的强度。


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/active-directory/kerberos/as-rep-roasting.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
