byt3bl33d3r / CrackMapExec

A swiss army knife for pentesting networks
BSD 2-Clause "Simplified" License
8.37k stars 1.64k forks source link

Feature request: Don't show supplied credentials in the cme output #523

Closed edermi closed 2 years ago

edermi commented 2 years ago

Steps to reproduce

Use CrackMapExec to perform any authenticated action.

Command string used

Not relevant.

CME verbose output (using the --verbose flag)

Not relevant

CME Version (cme --version)

5.2.2dev

OS

Kali latest

Target OS

Windows

Detailed issue explanation

The log line printed on each authentication attempt contains full credentials of the user. This is cumbersome to censor for inclusion in reports. It would be nice, if the output of CrackMapExec would not show sensitive information that has been provided in the command line.

mpgn commented 2 years ago

Good idea ! I will do it :)