Type Password Dump

From truxwiki.com
Jump to navigation Jump to search
<< Details >>
Defined Constant Type_Password_Dump
File Type Value 714
Parent Type ASCII Text
Carve Yes
Format Details No
MIME Type text/plain
Filename Extension pwdump

Password Dump

Description

A dump of password hashes.

Details

When this file is generated by Truxton, it will have the following format:

Administrator:500:aad3b435b51404eeaad3b435b51404ee:becedb42ec3c5c7f965255338be4453c:S-1-5-21-1220945662-884357618-682003330-500:1719dda9-ac1b-96e3-db89-08a4a479d567:5fb4f68b-d162-94ce-993a-3bc40000048a/letmein
Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0::1719dda9-ac1b-96e3-db89-08a4a479d567:5fb4f68b-d162-94ce-993a-3bc40000048a
HelpAssistant:1000:9b7062e6af8a93b90ab8d717cd9a3283:e711f50ca2355d5b8542fac99a523f27:S-1-5-21-1220945662-884357618-682003330-1000:1719dda9-ac1b-96e3-db89-08a4a479d567:5fb4f68b-d162-94ce-993a-3bc40000048a
SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:dc223b056c2db7e6410d439a29fff1dc:S-1-5-21-1220945662-884357618-682003330-1002:1719dda9-ac1b-96e3-db89-08a4a479d567:5fb4f68b-d162-94ce-993a-3bc40000048a
Owner:1003:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:S-1-5-21-1220945662-884357618-682003330-1003:1719dda9-ac1b-96e3-db89-08a4a479d567:5fb4f68b-d162-94ce-993a-3bc400001db3
Caster Troy:1004:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:S-1-5-21-1220945662-884357618-682003330-1004:1719dda9-ac1b-96e3-db89-08a4a479d567:5fb4f68b-d162-94ce-993a-3bc40000048a

This differs from the pwdump (aka passwd) file you normally see in that Truxton fills in the last three fields. Most other tools leave them blank.

The fields Truxton produces are:

Account:RID:LM:NTLM:SID:Media ID:Parent File ID/password

Account

The logon account name. This is what the user types into the logon window.

RID

Relative ID of the account.

LM

The Lan Manager hash value for cracking. The value for an empty password is aad3b435b51404eeaad3b435b51404ee

NTLM

The NT Lan Manager hash value for cracking. The value for an empty password id 31d6cfe0d16ae931b73c59d7e0c089c0

SID

The full security identifier of the account. This is required to decrypt DPAPI blobs.

Media ID

The identifier of the media this dump came from.

Parent File ID and Optional Password

The identifier of the file this data was derived from. Normally, it will be the folder that contained all of the registry files needed to produce the dump. If the plaintext password was cracked during exploitation, it will be included in this field separated by a slash.

Cracking

You can sometimes crack these hashes on line: