-
Notifications
You must be signed in to change notification settings - Fork 104
Dump|Crack remote SAM|SYSTEM Files
pedro ubuntu edited this page Mar 2, 2020
·
16 revisions
This Module allows attackers to Dump Remote-Host 'SAM|SYSTEM
' registry entrys to a text file ($env:tmp\sam | $env:tmp\system) to be then manualy downloaded (using meterpeter download module) and Cracked using 'samdump2
' and 'John the Ripper
' kali native applications.
[url] Credential Dumping - Mitre ATT&CK T1044
Remark
- The Module Used in this article requires the Client to be executed with Administrator Privs
- Instructions how to Install 'meterpeter' under new windows terminal can be review
<here>
Article Quick Jump List
- meterpeter - Dump SAM|SYSTEM reg Files
- meterpeter - Download SAM|SYSTEM backup files
- meterpeter - Crack hashes using samdump2 and John the Ripper
1º - Sellect meterpeter 'PostExploit
' Module
2º - Sellect meterpeter 'DumpSAM
' Module
This Module will Retrieve target machine regedit 'sam' and 'system' keys into '$env:tmp
' dir.
1º - Use meterpeter 'Download
' module to download 'sam' file to meterpeter working dir.