mpgn Profile picture
Feb 20 7 tweets 3 min read
It's 2023, CrackMapExec can now dump DPAPI credentials as a core feature !🚀

This is possible thanks to the work of @_zblurx and his library dploot ! He also added a module to dump firefox passwords 🔥

Pushed on @porchetta_ind v5.4.5 Bruce Wayne 🪂

No excuse, DA everytime, 🔽
But wait, yet yet another dpapi dumping tool ?
Well @_zblurx has fully embraced the concept of CME and taken leverage of cmedb !

Everytime you found a valid credential, CME will add this cred in his own DB, CMEDB 🧙‍♂️

Now why this is important in the case of dpapi credentials ?🔽
When using the option --dpapi (you need to be local adm), CrackMapExec will feed dploot lib with every credentials you already found during your internal pentest ! 🔥

Let me explain with a simple example 🔽
If you had previously compromised an account, let's say Ron and now you are dumping the dpapi as a local admin on a server and Ron is also using this server (Ron is not local adm), you will be able to dump the DPAPI credentials of Ron (if any) !

But wait, there is more 🔽
If you are Domain Admin, dploot will get the DPAPI Backup Key and you will be able to pretty much dump everything that use DPAPI on the domain !

But wait, there is more 🔽
Imagine credentials isn't enough or maybe they are not saved in the browser, why not just dump cookies ⁉️ 🍪

So yeah.. like DonPAPI 💕🇫🇷 but integrated to CrackMapExec ✌️🐙
Thanks for coming to my TED talk, more cool things are coming on the sponsors version 💪🪂

🇫🇷🥐dploot github.com/zblurx/dploot

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with mpgn

mpgn Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(