bb00 / zer0dump

Abuse CVE-2020-1472 (Zerologon) to take over a domain and then repair the local stored machine account password.
176 stars 44 forks source link

Update zer0dump.py #2

Closed 3v4Si0N closed 4 years ago

3v4Si0N commented 4 years ago

If the domain admin user was not administrator the reset of the DC password did not work

bb00 commented 4 years ago

You do understand that a domain admin user by definition has to be an administrator, right?

Or is there something I’m misunderstanding about your issue; please provide a bit of context.

bb00 commented 4 years ago

Oh, read your changes. I made a simple mistake. Allow me to fix that within the next few minutes.

bb00 commented 4 years ago

Fixed. Thank you for your feedback.

3v4Si0N commented 4 years ago

Yes, of course. But, if you choose another user to dump the NTLM hash, the reset doesn't work because the hash you use to reset is the one that has been dump.