密码 - AD 用户注释 (AD User Comment)
在大多数 Active Directory 架构中,似乎有 3-4 个常见的字段:UserPassword、UnixUserPassword、unicodePwd 和 msSFU30Password。
-
Windows/Linux 命令
-
用户描述中的密码 (Password in User Description)
netexec ldap domain.lab -u 'username' -p 'password' -M user-desc netexec ldap 10.0.2.11 -u 'username' -p 'password' --kdcHost 10.0.2.11 -M get-desc-users GET-DESC... 10.0.2.11 389 dc01 [+] Found following users: GET-DESC... 10.0.2.11 389 dc01 User: Guest description: Built-in account for guest access to the computer/domain GET-DESC... 10.0.2.11 389 dc01 User: krbtgt description: Key Distribution Center Service Account -
从 LDAP 中的所有用户获取
unixUserPassword属性 (GetunixUserPasswordattribute from all users in ldap) -
原生 Powershell 命令 (Native Powershell command)
-
导出 Active Directory 并使用
grep搜索内容 (Dump the Active Directory andgrepthe content)