How I Cracked a 128-bit Password
ID: c1f51b3b-3471-5175-b244-e64a338340de
STIX ID: report--c1f51b3b-3471-5175-b244-e64a338340de
Feed Name: Black Hills Infosec Blog
This blog post demonstrates that Active Directory accounts with the "store passwords using reversible encryption" setting result in RC4-encrypted credentials that can be trivially recovered to cleartext by extracting the SYSKEY and ntds.dit (e.g., via VSS snapshot, ntdsutil, and tools like Impacket's secretsdump). The author reproduced an instance where secretsdump produced a .CLEARTEXT file containing user passwords (including 128-character passwords and a domain admin) and provides PowerShell/LDAP queries to find and remediate such accounts, highlighting the high risk when backups or snapshots are accessible to lower-privileged users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
