Closed GoogleCodeExporter closed 9 years ago
Hey Renaud:
So you dare to get deeper into __tagToRecord.. hats off man! ;)
I have no problem changing the CODEPAGE_WESTERN but, do you have a repro step?
thanks!
beto
Original comment by bet...@gmail.com
on 26 Aug 2014 at 4:42
Yeah, on second thought, I'm probably a crazy one.... :)
Actually, it's pretty hard to reproduce. I pinpointed the issue during a
security audit while extracting hashes from a NTDS.dit and I can't send it to
you for some reasons :)).
However, this kind of record columns (encoded using cp1252) seems to appear in
pretty old active directory and seems to be a legacy stuff (but maybe I'm
wrong...)
Original comment by renaud.d...@synacktiv.com
on 26 Aug 2014 at 5:26
You definitely are :P..
Oh come on. cannot you give me those hashes?.. those ain't the passwords! :P
All right.. just committed the change in ese.py.. thanks man!..
I'm assuming you were using ese.py through secretsdump.py correct?... Hope it's
working well there..
BTW.. if you haven't ... check the wmiexec.py script.. might be useful for you
pentests.
Original comment by bet...@gmail.com
on 26 Aug 2014 at 5:39
Original issue reported on code.google.com by
renaud.d...@synacktiv.com
on 26 Aug 2014 at 4:32