Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
AD-description-password-finder — AD 계정 설명을 가져와 그 안에서 비밀번호를 검색합니다. | Kitploit
도구/GitHubGitHub/assurancemaladiesec/ad-description-password-finder
Defensive ToolsPassword CrackingPassword AttacksInformation GatheringPost-ExploitationPenetration TestingAuthenticationMisconfiguration

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHub
assurancemaladiesec/ad-description-password-finder

AD-description-password-finder

AD 계정 설명을 가져와 그 안에서 비밀번호를 검색합니다.

저장소 보기
8111194년 전Kitploit 검토 완료

AD 설명 비밀번호 찾기

이 도구의 목적은 Active Directory 계정의 설명(description)에 비밀번호가 평문으로 저장되어 있는지 확인하는 것입니다.

요구 사항은 다음과 같습니다.

  • ntds.dit와 SYSTEM 하이브의 사본을 보유해야 합니다.

Python이 없다면 이 저장소의 binary 폴더에 있는 스크립트의 .exe 버전을 사용할 수 있습니다.

블루팀 사용 사례

조직의 Active Directory 계정 설명(description) 필드에 비밀번호가 저장되어 있는지 확인하려는 경우입니다.

내부 침투 테스트/레드팀

포스트 익스플로잇: ntds.dit와 SYSTEM 하이브를 성공적으로 덤프했고, 해시를 크래킹하는 동안 Active Directory 계정의 설명 필드에서 일부 평문 비밀번호를 확인하고 싶은 경우입니다.

요구 사항

  • Python 3
  • six
  • pycryptodomex

설치

요구 사항을 설치합니다.

$ git clone https://github.com/AssuranceMaladieSec/AD-description-password-finder.git
$ pip3 install -r requirements.txt

사용법

check_description.py

> python check_description.py -h
usage: check_description.py [-h] [-system SYSTEM] [-ntds NTDS] [-ts] [-debug]

optional arguments:
  -h, --help      show this help message and exit
  -system SYSTEM  SYSTEM hive to parse. MANDATORY
  -ntds NTDS      NTDS.DIT file to parse. MANDATORY
  -ts             Adds timestamp to every logging output during hashes extraction
  -debug          Turn DEBUG output ON during hashes extraction



> python check_description.py -ntds ntds\ntds.dit -system ntds\SYSTEM

Extracting hash and descriptions in the ntds

Saving output to ntds/output.ntds

Creating hash file in './output/description_hashes.json' and plain text file in './output/description_plain.json'

Done!

Loading ./output/description_hashes.json

Loading ./output/description_plain.json

Loading ./ntds/output.ntds

We have 9 user's descriptions to analyze

Done!

We found 4 CONFIRMED password in the accounts description

2 accounts are SUSPECTED of exposing their passwords and need to be verified by a HUMAN

You can find the results in the file ./results/2022-07-21_17h8_results.txt

That's all folks!

결과 파일 예시

CONFIRMED_LEAK - Disabled user - password for user adm-test-alice2 found in description: Achanger6Achanger6!
CONFIRMED_LEAK - Enabled (probably) user - password for user adm-test-alice found in description: Achanger1Achanger2!
SUSPECTED_LEAK - Enabled (probably) user - SUSPECTED password for user anakin in the description: here we go "pwd=test01!"
SUSPECTED_LEAK - Enabled (probably) user - SUSPECTED password for user ahsoka in the description: The new one for test (password=test054!)
CONFIRMED_LEAK - Enabled (probably) user - password for user mariatest02 found in description: test02!
CONFIRMED_LEAK - Enabled (probably) user - password for user blanqui found in description: woof01!

impacket 사용

이 도구는 Impacket 라이브러리의 secretdump 코드를 수정한 버전을 사용합니다.

Impacket은 SECUREAUTH LABS에서 제공하는 도구입니다. Copyright (C) 2022 SecureAuth Corporation. All rights reserved.

작성자

  • Alice Climent-Pommeret ([email protected])

라이선스

GNU GENERAL PUBLIC LICENSE (GPL) Version 3

도구 다운로드