The Fall of a Domain
LOCAL ADMIN TO DOMAIN USER HASHES
Riyaz Walikar
Disclaimer
Please exercise caution!
The story so far
Visually. This.
Local Admin eh?
Think Sysinternals!
Dump connected user credentials
Windows (In)Security?
Now what?
http://gapingvoid.com/2008/06/13/now-what/
Remote CMD anyone?
Lets grab some hashes ☺
Lets grab some hashes ☺
Core files needed
NTDS.dit structure parse?
get framework + compile + make + run
get framework + compile + make + run
Yay!
(https://raw.github.com/inquisb/miscellaneous/master/ntdstopwdump.py)
Now what?
http://gapingvoid.com/2008/06/13/now-what/
Pass the hash / Password Cracking!
References
Thank you
riyazwalikar@gmail.com
http://www.riyazwalikar.com