Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
timmedin
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
timmedin
1y ago
The reason that the KDC doesn't decide if the user should get a ticket is that then the power requirements of the DC would be enormous. It should have to know if a user is supposed to have access to every single service in the environm
2.
▲
by
timmedin
1y ago
Just to add to this, the salt (domain [realm] and username) is only used to generate the AES keys, not the RC4. The RC4 key is simply the NT hash. And thanks for the shout out!
3.
▲
by
timmedin
1y ago
In Kerberos, the answer is effectively no. To generate the NT hash, the password is hashed using a single round of MD4. This is what is used to encrypt (and sign) tickets. The attack is, guess a password, hash it, and attempt to decrypt. Wi
4.
▲
by
timmedin
1y ago
> That is why service accounts have really long complex passwords. The sad thing is, they don't always have long complex passwords. They SHOULD, but they don't. Many orgs are scared of changing service account passwords due to