Confusion regarding output from Get-ADReplAccount
#4
(06-02-2023, 10:02 AM)Snoopy Wrote: first mask the hash

second, it seems your are dumping an NT hash (like in hashcatnt), so the mode your are looking for is -m1000

third, delete sum.dude: in front of the hash or use option --username

I should have masked - but I did munge it, changing a few characters. Will mask next time, if needed.

I got it working by rebuilding the machine using ubuntu instead of The-Distribution-Which-Does-Not-Handle-OpenCL-Well (Kali), and using -m1000 and --username.

Also did a bit of searching and found how to get the username and password into a file.

One other question - I've searched a bit, but can't seem to find an explanation for output that shows a format of

$HEX[xxxxxxxxxx34303a29]

Would that be someone using upper ASCII/ALT-gray characters, or is it a glitch in the output, or something else?

Thanks for the help.

Kurt
Reply


Messages In This Thread
RE: Confusion regarding output from Get-ADReplAccount - by Kurt-MT - 06-05-2023, 06:57 PM