ntds.dit --> new technology directory services.directory information tree
%Systemroot%\NTDS\Ntds.dit
this ntds.dit file is encrypted using system registry hive.
we will use ntdsutil.exe tool which is microsoft tool that will help us to copy the ntds.dit file to another location. because normally you cannot do this as this file is always used by the system.
The following command will copy ntds.dit, system registry hive and security hive to our said location. but we only require system hive registry file to decrypt ntds.dit file.
C:\>ntdsutil "ac i ntds" "ifm" "create full C:\ProgramData\backup" q q
now on this location C:\ProgramData\backup you will get ntds.dit, system and security registry hive file.
now as an attacker you can crack password offline.
https://www.youtube.com/watch?v=rioVumJB0Fo
Avi
Comments
Post a Comment