gentilkiwi / mimikatz

A little tool to play with Windows security
http://blog.gentilkiwi.com/mimikatz
19.49k stars 3.74k forks source link

Resolving #322 - fixing KERB_HASHPASSWORD structures #323

Open eyalk5 opened 3 years ago

eyalk5 commented 3 years ago

The KERB_HASHPASSWORD_GENERIC structure has turned out not to be generic in recent versions of windows. Therefore, a new structure that is compatible with version 2004 was added (KERB_HASHPASSWORD_GENERIC_2004). This is the same structure but packed.

Consequently, kerb helper was updated with the new 2004 version and in addition, two offsets were added in KERB_INFOS.
Additionally, the offset of the generic structure in _KERB_HASHPASSWORD_xxxx was also changed (in the 2004 version).