Skip to content

Conversation

@NeffIsBack
Copy link
Contributor

@NeffIsBack NeffIsBack commented Oct 21, 2025

With the hack.lu CTF this year and therefore a swedish AD environment it was reported that Kerberos authentication does not work with special chars (e.g. öäü) that are present in some localized environments: Pennyw0rth/NetExec#963

The problem is that kerberos uses utf-8 encoding for Kerberos Strings. However, as of now both minikerberos as well as impacket use latin1 as its encoding, resulting in failed authentication with users that contain special chars.
See:

Before and after:
image

Fixed and used in NetExec:
image

@NeffIsBack
Copy link
Contributor Author

@anadrianmanrique any chance you could press the "i believe" button on this one? Especially in domains where you have non-ascii chars in entities like the DA by default, it must be painful not be able to use kerberos.

@anadrianmanrique
Copy link
Collaborator

anadrianmanrique commented Nov 27, 2025

I'm calling it the day right now, and be off the next 2 weeks. Summoning @gabrielg5 to take care of this one. Thanks

@NeffIsBack
Copy link
Contributor Author

If you need any info/help @gabrielg5 let me know.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Unexpected problem or unintended behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants