pcap-credential-extraction.md (11387B)
1 --- 2 title: "pcap-credential-extraction" 3 description: "ldap.simple or http.authorization or ftp.request.command == PASS or ntlmssp or kerberos" 4 category: tools 5 tags: ["tools", "kerberos", "ntlm", "sql-injection"] 6 tools: ["Hashcat", "John", "tshark"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Tools/pcap-credential-extraction-cheatsheet.md" 10 --- 11 # PCAP Credential Extraction Cheat Sheet 12 13 ## Quick Reference Table 14 15 | Protocol | Port | Tool | Filter/Command | 16 |----------|------|------|----------------| 17 | LDAP Simple Bind | 389 | tshark | `tshark -r file.pcap -Y "ldap.simple" -T fields -e ldap.name -e ldap.simple` | 18 | HTTP Basic Auth | 80/8080 | tshark | `tshark -r file.pcap -Y "http.authorization" -T fields -e http.authorization` | 19 | FTP | 21 | tshark | `tshark -r file.pcap -Y "ftp.request.command == USER or ftp.request.command == PASS" -T fields -e ftp.request.arg` | 20 | Telnet | 23 | tshark | `tshark -r file.pcap -Y "telnet" -T fields -e telnet.data` | 21 | SMTP Auth | 25/587 | tshark | `tshark -r file.pcap -Y "smtp.auth.password" -T fields -e smtp.auth.username -e smtp.auth.password` | 22 | POP3 | 110 | tshark | `tshark -r file.pcap -Y "pop.request.command == USER or pop.request.command == PASS" -T fields -e pop.request.parameter` | 23 | IMAP | 143 | tshark | `tshark -r file.pcap -Y "imap.request contains LOGIN" -T fields -e imap.request` | 24 | SNMP | 161 | tshark | `tshark -r file.pcap -Y "snmp" -T fields -e snmp.community` | 25 | MySQL | 3306 | tshark | `tshark -r file.pcap -Y "mysql.passwd" -T fields -e mysql.user -e mysql.passwd` | 26 | NTLMSSP | Various | tshark | `tshark -r file.pcap -Y "ntlmssp.auth.username" -T fields -e ntlmssp.auth.domain -e ntlmssp.auth.username` | 27 | Kerberos | 88 | tshark | `tshark -r file.pcap -Y "kerberos.CNameString" -T fields -e kerberos.CNameString -e kerberos.realm` | 28 | HTTP POST | 80/443 | tshark | `tshark -r file.pcap -Y "http.request.method == POST" -T fields -e http.file_data` | 29 30 --- 31 32 ## Wireshark Display Filters 33 34 ### Authentication Protocols 35 ```bash 36 # All authentication-related traffic 37 ldap.simple or http.authorization or ftp.request.command == PASS or ntlmssp or kerberos 38 39 # LDAP bind requests with credentials 40 ldap.bindRequest and ldap.simple 41 42 # LDAP simple bind only 43 ldap.protocolOp == 0 44 45 # HTTP Basic/Digest Authentication 46 http.authorization 47 48 # HTTP POST requests (login forms) 49 http.request.method == POST 50 51 # NTLM Authentication 52 ntlmssp.auth.username 53 54 # Kerberos traffic 55 kerberos.CNameString 56 57 # FTP credentials 58 ftp.request.command == USER or ftp.request.command == PASS 59 60 # SMB/CIFS authentication 61 smb.uid or smb2.session_id 62 ``` 63 64 ### By Service Port 65 ```bash 66 # LDAP 67 tcp.port == 389 or tcp.port == 636 68 69 # HTTP/HTTPS 70 tcp.port == 80 or tcp.port == 443 or tcp.port == 8080 71 72 # FTP 73 tcp.port == 21 74 75 # SSH (encrypted, but can identify users) 76 tcp.port == 22 77 78 # Telnet 79 tcp.port == 23 80 81 # SMTP 82 tcp.port == 25 or tcp.port == 587 83 84 # DNS (for recon) 85 udp.port == 53 86 87 # Kerberos 88 tcp.port == 88 or udp.port == 88 89 90 # SMB 91 tcp.port == 445 or tcp.port == 139 92 ``` 93 94 --- 95 96 ## tshark Commands 97 98 ### LDAP Credentials 99 ```bash 100 # Extract LDAP simple bind credentials 101 tshark -r capture.pcap -Y "ldap.simple" -T fields -e ldap.name -e ldap.simple 102 103 # LDAP with more context 104 tshark -r capture.pcap -Y "ldap.bindRequest" -T fields -e ip.src -e ip.dst -e ldap.name -e ldap.simple 105 106 # All LDAP operations 107 tshark -r capture.pcap -Y "ldap" -T fields -e frame.number -e ldap.protocolOp -e ldap.name -e ldap.simple 108 109 # To see whole packet and info 110 sudo tshark -r UserInfo.exe.pcap -Y "ldap.simple" -V 111 ``` 112 113 ### HTTP Credentials 114 ```bash 115 # HTTP Basic Auth (base64 encoded) 116 tshark -r capture.pcap -Y "http.authorization" -T fields -e ip.src -e http.host -e http.authorization 117 118 # Decode Base64 inline 119 tshark -r capture.pcap -Y "http.authorization" -T fields -e http.authorization | cut -d' ' -f2 | base64 -d 120 121 # HTTP POST data (form submissions) 122 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e http.host -e http.request.uri -e http.file_data 123 124 # Look for password fields in POST 125 tshark -r capture.pcap -Y "http.request.method == POST" -T fields -e http.file_data | grep -iE "(pass|pwd|password|passwd)" 126 127 # HTTP cookies (session tokens) 128 tshark -r capture.pcap -Y "http.cookie" -T fields -e http.host -e http.cookie 129 ``` 130 131 ### FTP Credentials 132 ```bash 133 # FTP username and password 134 tshark -r capture.pcap -Y "ftp.request.command == USER or ftp.request.command == PASS" -T fields -e ip.src -e ftp.request.command -e ftp.request.arg 135 136 # All FTP commands 137 tshark -r capture.pcap -Y "ftp.request" -T fields -e frame.time -e ip.src -e ftp.request.command -e ftp.request.arg 138 ``` 139 140 ### SMTP/Email Credentials 141 ```bash 142 # SMTP AUTH credentials 143 tshark -r capture.pcap -Y "smtp.auth.password" -T fields -e smtp.auth.username -e smtp.auth.password 144 145 # SMTP commands 146 tshark -r capture.pcap -Y "smtp.req.command" -T fields -e smtp.req.command -e smtp.req.parameter 147 ``` 148 149 ### SMB/Windows Authentication 150 ```bash 151 # NTLMSSP usernames 152 tshark -r capture.pcap -Y "ntlmssp.auth.username" -T fields -e ip.src -e ntlmssp.auth.domain -e ntlmssp.auth.username 153 154 # SMB2 session setup 155 tshark -r capture.pcap -Y "smb2.cmd == 1" -T fields -e ip.src -e ip.dst -e smb2.acct -e smb2.domain 156 157 # Extract NTLMv2 hashes (for cracking) 158 tshark -r capture.pcap -Y "ntlmssp.auth.ntresponse" -T fields -e ntlmssp.auth.username -e ntlmssp.auth.domain -e ntlmssp.auth.ntresponse 159 ``` 160 161 ### Kerberos 162 ```bash 163 # Kerberos principals 164 tshark -r capture.pcap -Y "kerberos.CNameString" -T fields -e ip.src -e kerberos.CNameString -e kerberos.realm 165 166 # AS-REQ (initial auth) 167 tshark -r capture.pcap -Y "kerberos.msg_type == 10" -T fields -e kerberos.CNameString -e kerberos.realm 168 ``` 169 170 ### SNMP Community Strings 171 ```bash 172 # SNMP community strings (like passwords) 173 tshark -r capture.pcap -Y "snmp.community" -T fields -e ip.src -e ip.dst -e snmp.community 174 ``` 175 176 ### Database Credentials 177 ```bash 178 # MySQL login attempts 179 tshark -r capture.pcap -Y "mysql.user" -T fields -e ip.src -e mysql.user 180 181 # PostgreSQL 182 tshark -r capture.pcap -Y "pgsql.type == 'p'" -T fields -e pgsql.user -e pgsql.password 183 ``` 184 185 --- 186 187 ## Automated Tools 188 189 ### PCredz 190 ```bash 191 # Install 192 git clone https://github.com/lgandx/PCredz.git 193 194 # Run on pcap 195 python3 Pcredz -f capture.pcap 196 197 # Run on interface (live capture) 198 python3 Pcredz -i eth0 199 ``` 200 201 ### NetworkMiner (GUI) 202 ```bash 203 # Install on Linux 204 sudo apt install networkminer 205 206 # Or download from: https://www.netresec.com/?page=NetworkMiner 207 # Open pcap file -> Credentials tab shows extracted creds 208 ``` 209 210 ### Chaosreader 211 ```bash 212 # Extract all sessions and files 213 chaosreader capture.pcap 214 215 # Creates HTML report with extracted data 216 ``` 217 218 ### ngrep 219 ```bash 220 # Search for password patterns 221 ngrep -I capture.pcap -q "pass|pwd|password|passwd" 222 223 # Search for specific strings 224 ngrep -I capture.pcap -q "admin" 225 226 # Search in specific protocol 227 ngrep -I capture.pcap -q "PASS" port 21 228 ``` 229 230 ### dsniff 231 ```bash 232 # Extract passwords from pcap 233 dsniff -p capture.pcap 234 ``` 235 236 --- 237 238 ## Quick & Dirty Methods 239 240 ### strings + grep 241 ```bash 242 # Find all readable strings 243 strings capture.pcap | less 244 245 # Look for password patterns 246 strings capture.pcap | grep -iE "(password|passwd|pass|pwd).*[:=]" 247 248 # Look for usernames 249 strings capture.pcap | grep -iE "(user|username|login|uname).*[:=]" 250 251 # Find base64 strings (potential encoded creds) 252 strings capture.pcap | grep -E "^[A-Za-z0-9+/]{20,}={0,2}$" 253 254 # Find email addresses 255 strings capture.pcap | grep -oE "[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}" 256 257 # Find IP addresses 258 strings capture.pcap | grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" 259 260 # Find URLs 261 strings capture.pcap | grep -oE "https?://[^ ]+" 262 ``` 263 264 ### xxd / hexdump 265 ```bash 266 # View hex dump with ASCII 267 xxd capture.pcap | less 268 269 # Search for string in hex 270 xxd capture.pcap | grep -i "password" 271 272 # Hexdump with strings highlighted 273 hexdump -C capture.pcap | less 274 ``` 275 276 --- 277 278 ## Wireshark GUI Tips 279 280 ### Follow Streams 281 1. Right-click packet → Follow → TCP/UDP/HTTP Stream 282 2. Shows full conversation in readable format 283 3. Great for seeing complete authentication exchanges 284 285 ### Export Objects 286 1. File → Export Objects → HTTP/SMB/TFTP/etc. 287 2. Extracts files transferred over network 288 3. May contain config files with credentials 289 290 ### Useful Columns to Add 291 - `ldap.name` - LDAP bind DN 292 - `ldap.simple` - LDAP simple bind password 293 - `http.authorization` - HTTP auth headers 294 - `ftp.request.arg` - FTP command arguments 295 296 ### Protocol Hierarchy 297 1. Statistics → Protocol Hierarchy 298 2. Quick overview of what protocols are in capture 299 3. Helps identify what to look for 300 301 --- 302 303 ## Hash Extraction for Cracking 304 305 ### NTLMv2 Hashes 306 ```bash 307 # Extract for hashcat/john 308 tshark -r capture.pcap -Y "ntlmssp.auth" -T fields \ 309 -e ntlmssp.auth.username \ 310 -e ntlmssp.auth.domain \ 311 -e ntlmssp.ntlmserverchallenge \ 312 -e ntlmssp.auth.ntresponse \ 313 -e ntlmssp.auth.lmresponse 314 315 # Format for hashcat (mode 5600): 316 # username::domain:ServerChallenge:NTProofStr:NTLMv2Response 317 ``` 318 319 ### Kerberos Tickets (AS-REP Roasting) 320 ```bash 321 # Extract AS-REP for users without pre-auth 322 tshark -r capture.pcap -Y "kerberos.msg_type == 11" -T fields -e kerberos.cipher 323 ``` 324 325 ### HTTP Digest Auth 326 ```bash 327 # Extract digest for cracking 328 tshark -r capture.pcap -Y "http.authbasic" -T fields -e http.authorization 329 ``` 330 331 --- 332 333 ## One-Liners 334 335 ```bash 336 # Quick credential dump - tries multiple protocols 337 tshark -r capture.pcap -Y "ldap.simple or http.authorization or ftp.request.command == PASS or smtp.auth.password" -T fields -e frame.number -e ip.src -e ip.dst -e _ws.col.Protocol -e _ws.col.Info 2>/dev/null 338 339 # Find all cleartext passwords (broad search) 340 strings capture.pcap | grep -iE "^.{0,30}(password|passwd|pass|pwd)[^a-z].{0,50}$" | sort -u 341 342 # Extract and decode all HTTP Basic Auth 343 tshark -r capture.pcap -Y "http.authorization contains Basic" -T fields -e http.authorization | while read line; do echo "$line" | cut -d' ' -f2 | base64 -d; echo; done 344 345 # List all unique source IPs with auth attempts 346 tshark -r capture.pcap -Y "ldap.simple or http.authorization or ftp.request.command == PASS" -T fields -e ip.src | sort -u 347 348 # Count auth attempts by protocol 349 tshark -r capture.pcap -Y "ldap.simple or http.authorization or ftp.request.command == PASS" -T fields -e _ws.col.Protocol | sort | uniq -c 350 ``` 351 352 --- 353 354 ## Common Credential Locations by Protocol 355 356 | Protocol | Where to Look | 357 |----------|---------------| 358 | LDAP | `ldap.simple` field in bindRequest | 359 | HTTP Basic | `Authorization: Basic <base64>` header | 360 | HTTP Form | POST body, look for password/passwd/pass fields | 361 | FTP | USER and PASS commands in cleartext | 362 | Telnet | Full session in cleartext | 363 | SMTP | AUTH LOGIN/PLAIN commands (base64) | 364 | POP3 | USER and PASS commands | 365 | IMAP | LOGIN command arguments | 366 | SNMP | Community string (like a password) | 367 | VNC | Challenge-response (hashcat mode 7900) | 368 | RDP | NLA uses CredSSP/NTLMv2 | 369 | MySQL | mysql.passwd field | 370 | PostgreSQL | Startup message or password message | 371 372 --- 373 374 ## Tips 375 376 1. **Always check for TLS/SSL** - If traffic is encrypted, you need the private key or to perform MITM 377 2. **Time-based correlation** - Failed logins often followed by successful ones reveal valid creds 378 3. **Check both directions** - Server responses may echo back usernames 379 4. **Look at DNS** - Reveals internal hostnames and structure 380 5. **Export HTTP objects** - Config files often contain hardcoded creds 381 6. **Check for password reuse** - Same creds may work elsewhere