cube0x0 / KrbRelay

Framework for Kerberos relaying

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Error "the service cannot be started"

amjcyber opened this issue · comments

Hi there!
I'm always getting this error:

[*] Using CLSID: 90f18417-f0f1-484e-9d3c-59dceee5dbd8
System.Runtime.InteropServices.COMException (0x80070422): The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. (Exception from HRESULT: 0x80070422)
   at KrbRelay.Ole32.CoGetInstanceFromIStorage(COSERVERINFO pServerInfo, Guid& pclsid, Object pUnkOuter, CLSCTX dwClsCtx, IStorage pstg, UInt32 cmq, MULTI_QI[] rgmqResults)
   at KrbRelay.Program.Main(String[] args)

Which service might not be active?
I'm running the attack in a lab environment in AWS, DC+Server under domain, for research and detection.

go with different clsid
if cross-session works then you know the issue

LDAP_INSUFFICIENT_ACCESS . Maybe it's a matter of my environment, I'll try rebuilding it. Thanks

...
[*] ldap_get_option: LDAP_SASL_BIND_IN_PROGRESS
[*] apRep1: 6f8187308184a003020105a10302010fa2783076a003020112a26f046d9bc9f2dcf4a0ccdbd6829cbab86b17a3cdfdad564c59e04c9f2805793682fb207d599997ede47ba6b34fc146cb77d9cc87ec094ae7ec822c2a8706fe19ce3b1c281ba76cf31925905d91e22303cef2137af2206fecfbdab95fe13e0eb4208397354a852e0a52f1b3d74825b83d
[*] AcceptSecurityContext: SEC_I_CONTINUE_NEEDED
[*] fContextReq: Delegate, MutualAuth, UseDceStyle, Connection
[*] apRep2: 6f5b3059a003020105a10302010fa24d304ba003020112a2440442c1059a947840b811f054a7dded98c7d9c51007c7468fcae956cd17d28c14b8a76bb176a451b5f3eac63bfc361af23663068c0e7a26bcef799700dd098f2a13bebe93
[*] bind: 0
[*] ldap_get_option: LDAP_SUCCESS
[+] LDAP session established
[*] ldap_modify: LDAP_INSUFFICIENT_ACCESS