專案

一般

配置概況

動作

專案資訊 #1077

進行中

專案資訊 #1064: 2025-PenTest

Krbtgt Password Unchanged for over 1 year

是由 Joy Liao3 個月 前加入. 於 約 2 個月 前更新.

狀態:
Resolved-解决
優先權:
Normal
被分派者:
分類:
-
開始日期:
2025-08-01
完成日期:
2025-12-31 (逾期 25 天)
完成百分比:

100%

預估工時:

概述

N bookmark20250526231504779653815004 "Krbtgt Password Unchanged for over 1 year

" A stale krbtgt password enables Golden Ticket attacks, letting attackers forge Kerberos tickets to impersonate any user, including admins, and maintain persistent, undetected domain access. The longer it goes unchanged, the greater the risk of widespread compromise. "To renew the Kerberos keys used to encrypt TGTs, it is necessary to manually change the krbtgt account password annually . It is recommended to perform this change using the script provided by Microsoft .  

The password change must be performed twice to be effective.

It is noteworthy that any operation to change the password of the krbtgt account must be performed only in an Active Directory environment where replication between domain controllers is nominal. Therefore, it is essential to wait a period before the second password change.

It is also possible to manually reset the krbtgt account password , in the same way as for a regular account. If the provided script is not used, it is recommended to leave at least 24 hours between the two changes and to ensure effective replication between domain controllers. A strategy could be to perform a single password change every 6 months, in order to guarantee an effective annual change.

"


檔案

是由 Joy Liao3 個月 前更新

  • 完成日期 設定為 2025-12-31
  • 被分派者 設定為 益利 周
  • 開始日期2025-11-10 變更為 2025-08-01

是由 益利 周約 2 個月 前更新

Krbtgt 帳號 已進行多次密碼變更 最後一次變更是在 2025/11/24 下午 08:01:04

動作

匯出至 Atom PDF