Manual Stealing User Hashes Using NTP

Broker

Moderator
Staff member
Moderator
Exclusive
Infinity
Premium
Member
Joined
Apr 23, 2026
Messages
109
Reaction score
167
😈 Stealing User Hashes Using NTP

Timeroasting is a security attack technique that allows one to extract password hashes of computer accounts in an Active Directory (AD) domain.

The method involves exploiting the NTP protocol and the Kerberos response hashing mechanism to obtain hashes without the need for domain credentials.

These hashes can then be cracked offline using specialized tools, such as Hashcat.

Timeroasting has two weaknesses:
⏺ It can only be used to obtain computer hashes;
⏺ It requires mapping RIDs to usernames, so either anonymous access to the directory or valid credentials for any domain user is required.
 
2,516Threads
28,909Messages
4,609Members
moha404Latest member
Top Bottom