8000 Password _TBAL_? · Issue #166 · gentilkiwi/mimikatz · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Password _TBAL_? #166

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
TheNaterz opened this issue Ju 8000 l 27, 2018 · 5 comments
Closed

Password _TBAL_? #166

TheNaterz opened this issue Jul 27, 2018 · 5 comments

Comments

@TheNaterz
Copy link
TheNaterz commented Jul 27, 2018

Hi Benjamin,

Looks like Microsoft pushed a patch out either yesterday or today. Previously, cleartext passwords could be seen under tspkg, but are now replaced by some sort of table reference?

image

The NTLM and SHA1 are still good, just wondering if you had any insight!

Release: 2.1.1-20180616
Windows 10 - Version 1803

@gentilkiwi
Copy link
Owner

Never seen a one like this :)
On my 1803, no reference at all to this.

image

Seems to be related to account in the cloud, there is a lots of chance the password is DPAPI protected somewhere or in registry as a "secret".

@TheNaterz
Copy link
Author

Weird, came back today and couldn't even replicate. If I see it again, I'll keep an eye out for any secrets. Thanks!

@jagotu
Copy link
jagotu commented Aug 7, 2018

@TheNaterz I did some research into TBAL and published my results here: https://vztekoverflow.com/tbal

@jagotu
Copy link
jagotu commented Aug 7, 2018

@gentilkiwi Sample registry hives to test parsing msv1_0 tbal secret:

https://vztekoverflow.com/files/tbal/1709.zip
https://vztekoverflow.com/files/tbal/1803.zip

@AeroSixNine
Copy link

Can you please tell me how do I exactly resolve this issue? (I am a noob)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3199
4 participants
0