Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Test ntds.dit from a RODC #24

Open
MichaelGrafnetter opened this issue Aug 22, 2016 · 0 comments
Open

Test ntds.dit from a RODC #24

MichaelGrafnetter opened this issue Aug 22, 2016 · 0 comments
Assignees
Labels
Milestone

Comments

@MichaelGrafnetter
Copy link
Owner

Message from Eugen:

I have a question about RODC’s NTDS.dit file. It seems that it is been built differently as the NTDS on writable DC.

So, my purpose was to demonstrate to my collegues in lab, that it is impossible to stolen non-cached user passwords from the RODC. I tried to read pwd hashes from NTDS file extracted from a RODC. I’ve pre-populated my RODC by some user passwords, but $key = Get-BootKey -SystemHivePath ‘d:\SHARE\SYSTEM’
Get-ADDBAccount -all -DBPath ‘d:\share\ntds.dit’ -BootKey $key -Verbose

does not generate any output. The ADUC snap-in says some password are replicated to the RODC. I pushed the replication of those passwords from repadmin too. When I specify a NTDS file from writable DC in the same domain, it shows me NT hashes of all accounts.

Have tried 2012 R2 and 2016 domains. What may be a reason?

@MichaelGrafnetter MichaelGrafnetter modified the milestones: 2.17, 2.18, 2.19 Aug 22, 2016
@MichaelGrafnetter MichaelGrafnetter modified the milestones: 2.19, 2.20 Oct 21, 2016
@MichaelGrafnetter MichaelGrafnetter modified the milestones: 2.20, 2.21 Nov 14, 2016
@MichaelGrafnetter MichaelGrafnetter self-assigned this Jul 7, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant