
AD 계정 설명을 가져와 그 안에서 비밀번호를 검색합니다.
이 도구의 목적은 Active Directory 계정의 설명(description)에 비밀번호가 평문으로 저장되어 있는지 확인하는 것입니다.
요구 사항은 다음과 같습니다.
Python이 없다면 이 저장소의 binary 폴더에 있는 스크립트의 .exe 버전을 사용할 수 있습니다.
조직의 Active Directory 계정 설명(description) 필드에 비밀번호가 저장되어 있는지 확인하려는 경우입니다.
포스트 익스플로잇: ntds.dit와 SYSTEM 하이브를 성공적으로 덤프했고, 해시를 크래킹하는 동안 Active Directory 계정의 설명 필드에서 일부 평문 비밀번호를 확인하고 싶은 경우입니다.
요구 사항을 설치합니다.
$ git clone https://github.com/AssuranceMaladieSec/AD-description-password-finder.git
$ pip3 install -r requirements.txt
> python check_description.py -h
usage: check_description.py [-h] [-system SYSTEM] [-ntds NTDS] [-ts] [-debug]
optional arguments:
-h, --help show this help message and exit
-system SYSTEM SYSTEM hive to parse. MANDATORY
-ntds NTDS NTDS.DIT file to parse. MANDATORY
-ts Adds timestamp to every logging output during hashes extraction
-debug Turn DEBUG output ON during hashes extraction
> python check_description.py -ntds ntds\ntds.dit -system ntds\SYSTEM
Extracting hash and descriptions in the ntds
Saving output to ntds/output.ntds
Creating hash file in './output/description_hashes.json' and plain text file in './output/description_plain.json'
Done!
Loading ./output/description_hashes.json
Loading ./output/description_plain.json
Loading ./ntds/output.ntds
We have 9 user's descriptions to analyze
Done!
We found 4 CONFIRMED password in the accounts description
2 accounts are SUSPECTED of exposing their passwords and need to be verified by a HUMAN
You can find the results in the file ./results/2022-07-21_17h8_results.txt
That's all folks!
CONFIRMED_LEAK - Disabled user - password for user adm-test-alice2 found in description: Achanger6Achanger6!
CONFIRMED_LEAK - Enabled (probably) user - password for user adm-test-alice found in description: Achanger1Achanger2!
SUSPECTED_LEAK - Enabled (probably) user - SUSPECTED password for user anakin in the description: here we go "pwd=test01!"
SUSPECTED_LEAK - Enabled (probably) user - SUSPECTED password for user ahsoka in the description: The new one for test (password=test054!)
CONFIRMED_LEAK - Enabled (probably) user - password for user mariatest02 found in description: test02!
CONFIRMED_LEAK - Enabled (probably) user - password for user blanqui found in description: woof01!
이 도구는 Impacket 라이브러리의 secretdump 코드를 수정한 버전을 사용합니다.
Impacket은 SECUREAUTH LABS에서 제공하는 도구입니다. Copyright (C) 2022 SecureAuth Corporation. All rights reserved.
GNU GENERAL PUBLIC LICENSE (GPL) Version 3