[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvJ1ASYYl0r9mWxoy9cFqLDj7aG7MfyvCK8ns9jniLWY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},305,"From a defensive perspective, why is it important to minimize users with 'Password Never Expires' and how can you monitor them?","Reducing the number of users with non-expiring passwords limits the attack surface for credential theft and persistence. Attackers often target such accounts because they remain valid indefinitely, making them ideal for lateral movement or [Domain Penetration - Using MachineAccount to Achieve DCSync](\u002Fnews\u002Fdomain-penetration-using-machineaccount-to-achieve-dcsync). Defenders should regularly enumerate users with this attribute using the same tools (PowerShell, PowerView) and set up monitoring alerts for any changes to `userAccountControl` values that add or remove the 65536 bit.","\u003Cp>Reducing the number of users with non-expiring passwords limits the attack surface for credential theft and persistence. Attackers often target such accounts because they remain valid indefinitely, making them ideal for lateral movement or [Domain Penetration - Using MachineAccount to Achieve DCSync](\u002Fnews\u002Fdomain-penetration-using-machineaccount-to-achieve-dcsync). Defenders should regularly enumerate users with this attribute using the same tools (PowerShell, PowerView) and set up monitoring alerts for any changes to `userAccountControl` values that add or remove the 65536 bit.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fpenetration-basics-the-password-never-expires-attribute-for-domain-users\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","from-a-defensive-perspective-why-is-it-important-to-minimize-users-with-password-1777484268546","defense, monitoring, credential persistence, userAccountControl monitoring, attack surface reduction",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},78,"Penetration Basics - The Password Never Expires Attribute for Domain Users","penetration-basics-the-password-never-expires-attribute-for-domain-users","Learn to enumerate, add, and remove the password never expires attribute for domain users using userAccountControl bitwise operations for security and management.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a domain environment, domain user credentials are crucial information. To enhance security, domain group policies set a maximum validity period for all domain user passwords, forcing users to change their passwords upon expiration.\u003C\u002Fp>\u003Cp>In practical environments, some domain users need to be configured with passwords that never expire, which can be achieved by adding the password never expires attribute.\u003C\u002Fp>\u003Cp>In domain penetration testing, we need to enumerate domain users with the password never expires attribute and also be able to set a specific domain user's password to never expire.\u003C\u002Fp>\u003Cp>Conversely, from a defensive perspective, we need to minimize the number of domain users with the password never expires attribute and be able to monitor this list of domain users in real time.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce various methods for enumerating, adding, and removing the password never expires attribute under different conditions, analyze the principles, and provide open-source code.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Enumerating Users with Passwords Set to Never Expire\u003C\u002Fli>\u003Cli>Methods for Adding the Password Never Expires Attribute to a Specified User\u003C\u002Fli>\u003Cli>Methods for Removing the Password Never Expires Attribute from a Specified User\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The password never expires attribute for a domain user is stored in the userAccountControl attribute of the domain user.\u003C\u002Fp>\u003Cp>The userAccountControl attribute is represented numerically, with the value being the sum of multiple specific attribute values.\u003C\u002Fp>\u003Cp>Each specific attribute corresponds to a different numerical value. For specific values, refer to: https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>The following example illustrates:\u003C\u002Fp>\u003Cp>If the userAccountControl attribute value for user test1 is 514, then the specific attributes for this user are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>ACCOUNTDISABLE, 2\u003C\u002Fli>\u003Cli>NORMAL_ACCOUNT, 512\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The calculation method is 2 + 512 = 514.\u003C\u002Fp>\u003Ch4>Method to add the password never expires attribute:\u003C\u002Fh4>\u003Cp>The value corresponding to the password never expires attribute is 65536 (DONT_EXPIRE_PASSWORD). Add 65536 to the userAccountControl attribute value 514, and set it to 66048.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In programming design, for reusability, the method used is to perform a bitwise OR operation (operator |) with 65536.\u003C\u002Fp>\u003Cp>Bitwise OR operation rule: For two numbers involved in the operation, perform an OR operation on each binary bit. If at least one corresponding binary bit is 1, the result bit is 1; otherwise, it is 0.\u003C\u002Fp>\u003Ch4>Method to remove the password never expires attribute:\u003C\u002Fh4>\u003Cp>Subtract 65536 from the userAccountControl attribute value\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In programming design, for reusability, the method used is to perform a bitwise XOR operation (operator ^) with 65536\u003C\u002Fp>\u003Cp>Bitwise XOR operation rule: For two numbers involved in the operation, perform an \"XOR\" operation on each binary bit. If the corresponding bits are the same, the result is 0; otherwise, it is 1\u003C\u002Fp>\u003Ch4>Method to check the password never expires attribute:\u003C\u002Fh4>\u003Cp>The userAccountControl attribute value is the sum of various numerical values, making it impossible to determine whether it includes the addend 65536 through simple addition or subtraction\u003C\u002Fp>\u003Cp>This can be achieved using a bitwise AND operation (operator &amp;)\u003C\u002Fp>\u003Cp>Bitwise AND operation rule: For two numbers involved in the operation, perform an \"AND\" operation on each binary bit. The result is 1 only if both corresponding bits are 1; otherwise, it is 0\u003C\u002Fp>\u003Ch4>Calculation method to check the password never expires attribute:\u003C\u002Fh4>\u003Cp>Perform a bitwise AND operation between the userAccountControl attribute value and 65536. If the result is 65536, it indicates the password never expires attribute is set\u003C\u002Fp>\u003Ch2>0x03 Enumerate users with passwords set to never expire\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On the domain controller, by using Active Directory Users and Computers to view the Account properties of each domain user, we can see whether the user is set to have a password that never expires, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018741735_0_c2606647d0.jpeg\">\u003C\u002Fp>\u003Cp>The following introduces enumeration methods in different environments\u003C\u002Fp>\u003Ch3>1. Methods for enumeration from within the domain\u003C\u002Fh3>\u003Ch4>(1) Using the PowerShell ActiveDirectory module on Windows systems\u003C\u002Fh4>\u003Cp>Command examples:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module ActiveDirectory\u003Cbr>Search-ADAccount -PasswordNeverExpires | FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module ActiveDirectory\u003Cbr>Get-ADUser -filter * -properties Name, PasswordNeverExpires | where {$_.passwordNeverExpires -eq \"true\" }| FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using PowerView on Windows systems\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Command examples:\u003C\u002Fp>\u003Cp>Display attributes of a specified user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>Get-NetUser test1| select useraccountcontrol | ConvertFrom-UACValue\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018749148_1_cc98c5f3a0.jpeg\">\u003C\u002Fp>\u003Cp>Filter out all users that meet the conditions:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>ForEach($User in (Get-NetUser))\u003Cbr>{\u003Cbr>\tif(($User.useraccountcontrol -band 65536) -eq 65536)\u003Cbr>\t{\u003Cbr>\t\tWrite-Output $User.samaccountname\u003Cbr>\t}\t\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Implementing with C# in Windows systems\u003C\u002Fh4>\u003Cp>Using the namespace System.DirectoryServices, the detailed code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>If using the current user's credentials, replace the code DirectoryEntry de = new DirectoryEntry(\"LDAP:\u002F\u002F\" + args[0],args[1],args[2]); with DirectoryEntry de = new DirectoryEntry(\"LDAP:\u002F\u002F\" + args[0]);\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018759940_2_b65dcc6e5c.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Enumerating through ldapsearch on Kali system\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainPassword123! -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\" grep userAccountControl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018773739_3_c07314c8f8.jpeg\">\u003C\u002Fp>\u003Cp>After obtaining the userAccountControl attribute value, perform a bitwise AND operation with 65536 to get the final result\u003C\u002Fp>\u003Ch3>2. Methods for enumeration from outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using PowerShell ActiveDirectory module on Windows system\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>$uname=\"test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Search-ADAccount -Server 192.168.1.1 -Credential $cred -Verbose -PasswordNeverExpires | FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>$uname=\"test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Get-ADUser -Server 192.168.1.1 -Credential $cred -filter * -properties Name, PasswordNeverExpires | where {$_.passwordNeverExpires -eq \"true\" }| FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The ActiveDirectory module is installed by default on domain controllers. Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell Active Directory module, which I have extracted and uploaded to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>For systems without the Active Directory module installed, you can import the Active Directory module using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using PowerView on Windows systems\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>$uname=\"test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>$Users=Get-NetUser -Domain \"test.com\" -DomainController 192.168.1.1 -Credential $cred\u003Cbr>ForEach($User in $Users)\u003Cbr>{\u003Cbr>\tif(($User.useraccountcontrol -band 65536) -eq 65536)\u003Cbr>\t{\u003Cbr>\t\tWrite-Output $User.samaccountname\u003Cbr>\t}\t\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3)Windows system implementation using C#\u003C\u002Fh4>\u003Cp>Using the namespace System.DirectoryServices, detailed code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Method for adding password never expires attribute to specified user\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are two implementation methods:\u003C\u002Fp>\u003Cp>1. Perform bitwise OR operation (operator |) between userAccountControl attribute value and 65536\u003C\u002Fp>\u003Cp>2. Directly add 65536 to userAccountControl attribute value\u003C\u002Fp>\u003Cp>For reusability, the following methods all use the bitwise OR operation with 65536\u003C\u002Fp>\u003Ch3>1. Implement from within the domain\u003C\u002Fh3>\u003Ch4>(1) Using dsmod command\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmod user \"CN=testc,CN=Users,DC=test,DC=com\" -pwdneverexpires yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using Powershell ActiveDirectory module\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ADUser -Identity testc -PasswordNeverExpires $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Using PowerView\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ADObject -SamAccountName testc -PropertyName useraccountcontrol -PropertyXorValue 65536\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) C# Implementation\u003C\u002Fh4>\u003Cp>Using the System.DirectoryServices namespace, detailed code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Implementation from outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using the PowerShell ActiveDirectory module\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>$uname=\"administrator\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Set-ADUser -Server 192.168.1.1 -Credential $cred -Identity testc -PasswordNeverExpires $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using PowerView\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"administrator\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>$Users=Get-NetUser -Domain \"test.com\" -DomainController 192.168.1.1 -Credential $cred\u003Cbr>Set-ADObject -Domain \"test.com\" -DomainController 192.168.1.1 -Credential $cred -SamAccountName testc -PropertyName useraccountcontrol -PropertyXorValue 65536\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) C# Implementation\u003C\u002Fh4>\u003Cp>Using the namespace System.DirectoryServices, detailed code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Testing as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018786913_4_fa04964f00.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Method to Remove Password Never Expires Attribute for a Specified User\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are two implementation methods:\u003C\u002Fp>\u003Cp>1. Perform a bitwise XOR operation (operator ^) between the userAccountControl attribute value and 65536\u003C\u002Fp>\u003Cp>2. Directly subtract 65536 from the userAccountControl attribute value\u003C\u002Fp>\u003Cp>The specific method is similar to 0x04 and will not be repeated here\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the characteristics of domain users with the password never expires attribute, analyzes the principles of enumerating, adding, and removing this attribute, presents various implementation methods under different conditions, and provides open-source C# implementation code.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In a domain environment, domain user credentials are crucial information. To enhance security, domain group policies set a maximum validity period for all domain user passwords, forcing users to change their passwords upon expiration.\u003C\u002Fp>\u003Cp>In practical environments, some domain users need to be configured with passwords that never expire, which can be achieved by adding the password never expires attribute.\u003C\u002Fp>\u003Cp>In domain penetration testing, we need to enumerate domain users with the password never expires attribute and also be able to set a specific domain user's password to never expire.\u003C\u002Fp>\u003Cp>Conversely, from a defensive perspective, we need to minimize the number of domain users with the password never expires attribute and be able to monitor this list of domain users in real time.\u003C\u002Fp>\u003Cp>Therefore, this article will introduce various methods for enumerating, adding, and removing the password never expires attribute under different conditions, analyze the principles, and provide open-source code.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Implementation Principles\u003C\u002Fli>\u003Cli>Enumerating Users with Passwords Set to Never Expire\u003C\u002Fli>\u003Cli>Methods for Adding the Password Never Expires Attribute to a Specified User\u003C\u002Fli>\u003Cli>Methods for Removing the Password Never Expires Attribute from a Specified User\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Implementation Principle\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The password never expires attribute for a domain user is stored in the userAccountControl attribute of the domain user.\u003C\u002Fp>\u003Cp>The userAccountControl attribute is represented numerically, with the value being the sum of multiple specific attribute values.\u003C\u002Fp>\u003Cp>Each specific attribute corresponds to a different numerical value. For specific values, refer to: https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fhelp\u002F305144\u002Fhow-to-use-useraccountcontrol-to-manipulate-user-account-properties\u003C\u002Fp>\u003Cp>The following example illustrates:\u003C\u002Fp>\u003Cp>If the userAccountControl attribute value for user test1 is 514, then the specific attributes for this user are as follows:\u003C\u002Fp>\u003Cul>\u003Cli>ACCOUNTDISABLE, 2\u003C\u002Fli>\u003Cli>NORMAL_ACCOUNT, 512\u003C\u002Fli>\u003C\u002Ful>\u003Cp>The calculation method is 2 + 512 = 514.\u003C\u002Fp>\u003Ch4>Method to add the password never expires attribute:\u003C\u002Fh4>\u003Cp>The value corresponding to the password never expires attribute is 65536 (DONT_EXPIRE_PASSWORD). Add 65536 to the userAccountControl attribute value 514, and set it to 66048.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In programming design, for reusability, the method used is to perform a bitwise OR operation (operator |) with 65536.\u003C\u002Fp>\u003Cp>Bitwise OR operation rule: For two numbers involved in the operation, perform an OR operation on each binary bit. If at least one corresponding binary bit is 1, the result bit is 1; otherwise, it is 0.\u003C\u002Fp>\u003Ch4>Method to remove the password never expires attribute:\u003C\u002Fh4>\u003Cp>Subtract 65536 from the userAccountControl attribute value\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>In programming design, for reusability, the method used is to perform a bitwise XOR operation (operator ^) with 65536\u003C\u002Fp>\u003Cp>Bitwise XOR operation rule: For two numbers involved in the operation, perform an \"XOR\" operation on each binary bit. If the corresponding bits are the same, the result is 0; otherwise, it is 1\u003C\u002Fp>\u003Ch4>Method to check the password never expires attribute:\u003C\u002Fh4>\u003Cp>The userAccountControl attribute value is the sum of various numerical values, making it impossible to determine whether it includes the addend 65536 through simple addition or subtraction\u003C\u002Fp>\u003Cp>This can be achieved using a bitwise AND operation (operator &amp;)\u003C\u002Fp>\u003Cp>Bitwise AND operation rule: For two numbers involved in the operation, perform an \"AND\" operation on each binary bit. The result is 1 only if both corresponding bits are 1; otherwise, it is 0\u003C\u002Fp>\u003Ch4>Calculation method to check the password never expires attribute:\u003C\u002Fh4>\u003Cp>Perform a bitwise AND operation between the userAccountControl attribute value and 65536. If the result is 65536, it indicates the password never expires attribute is set\u003C\u002Fp>\u003Ch2>0x03 Enumerate users with passwords set to never expire\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>On the domain controller, by using Active Directory Users and Computers to view the Account properties of each domain user, we can see whether the user is set to have a password that never expires, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018741735_0_c2606647d0-1.jpeg\">\u003C\u002Fp>\u003Cp>The following introduces enumeration methods in different environments\u003C\u002Fp>\u003Ch3>1. Methods for enumeration from within the domain\u003C\u002Fh3>\u003Ch4>(1) Using the PowerShell ActiveDirectory module on Windows systems\u003C\u002Fh4>\u003Cp>Command examples:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module ActiveDirectory\u003Cbr>Search-ADAccount -PasswordNeverExpires | FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Import-Module ActiveDirectory\u003Cbr>Get-ADUser -filter * -properties Name, PasswordNeverExpires | where {$_.passwordNeverExpires -eq \"true\" }| FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using PowerView on Windows systems\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Command examples:\u003C\u002Fp>\u003Cp>Display attributes of a specified user:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>Get-NetUser test1| select useraccountcontrol | ConvertFrom-UACValue\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018749148_1_cc98c5f3a0-1.jpeg\">\u003C\u002Fp>\u003Cp>Filter out all users that meet the conditions:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>ForEach($User in (Get-NetUser))\u003Cbr>{\u003Cbr>\tif(($User.useraccountcontrol -band 65536) -eq 65536)\u003Cbr>\t{\u003Cbr>\t\tWrite-Output $User.samaccountname\u003Cbr>\t}\t\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Implementing with C# in Windows systems\u003C\u002Fh4>\u003Cp>Using the namespace System.DirectoryServices, the detailed code has been uploaded to GitHub, with the address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>If using the current user's credentials, replace the code DirectoryEntry de = new DirectoryEntry(\"LDAP:\u002F\u002F\" + args[0],args[1],args[2]); with DirectoryEntry de = new DirectoryEntry(\"LDAP:\u002F\u002F\" + args[0]);\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018759940_2_b65dcc6e5c-1.jpeg\">\u003C\u002Fp>\u003Ch4>(4) Enumerating through ldapsearch on Kali system\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>ldapsearch -x -H ldap:\u002F\u002F192.168.1.1:389 -D \"CN=testa,CN=Users,DC=test,DC=com\" -w DomainPassword123! -b \"DC=test,DC=com\" \"(&amp;(objectClass=user)(objectCategory=person))\" grep userAccountControl\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018773739_3_c07314c8f8-1.jpeg\">\u003C\u002Fp>\u003Cp>After obtaining the userAccountControl attribute value, perform a bitwise AND operation with 65536 to get the final result\u003C\u002Fp>\u003Ch3>2. Methods for enumeration from outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using PowerShell ActiveDirectory module on Windows system\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>$uname=\"test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Search-ADAccount -Server 192.168.1.1 -Credential $cred -Verbose -PasswordNeverExpires | FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Or:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>$uname=\"test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Get-ADUser -Server 192.168.1.1 -Credential $cred -filter * -properties Name, PasswordNeverExpires | where {$_.passwordNeverExpires -eq \"true\" }| FT Name\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The ActiveDirectory module is installed by default on domain controllers. Microsoft.ActiveDirectory.Management.dll is generated after installing the PowerShell Active Directory module, which I have extracted and uploaded to GitHub:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>For systems without the Active Directory module installed, you can import the Active Directory module using the following command:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using PowerView on Windows systems\u003C\u002Fh4>\u003Cp>https:\u002F\u002Fgithub.com\u002FPowerShellMafia\u002FPowerSploit\u002Fblob\u002Fmaster\u002FRecon\u002FPowerView.ps1\u003C\u002Fp>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\PowerView.ps1\u003Cbr>$uname=\"test1\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>$Users=Get-NetUser -Domain \"test.com\" -DomainController 192.168.1.1 -Credential $cred\u003Cbr>ForEach($User in $Users)\u003Cbr>{\u003Cbr>\tif(($User.useraccountcontrol -band 65536) -eq 65536)\u003Cbr>\t{\u003Cbr>\t\tWrite-Output $User.samaccountname\u003Cbr>\t}\t\t\u003Cbr>}\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3)Windows system implementation using C#\u003C\u002Fh4>\u003Cp>Using the namespace System.DirectoryServices, detailed code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch2>0x04 Method for adding password never expires attribute to specified user\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are two implementation methods:\u003C\u002Fp>\u003Cp>1. Perform bitwise OR operation (operator |) between userAccountControl attribute value and 65536\u003C\u002Fp>\u003Cp>2. Directly add 65536 to userAccountControl attribute value\u003C\u002Fp>\u003Cp>For reusability, the following methods all use the bitwise OR operation with 65536\u003C\u002Fp>\u003Ch3>1. Implement from within the domain\u003C\u002Fh3>\u003Ch4>(1) Using dsmod command\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>dsmod user \"CN=testc,CN=Users,DC=test,DC=com\" -pwdneverexpires yes\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using Powershell ActiveDirectory module\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ADUser -Identity testc -PasswordNeverExpires $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) Using PowerView\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>Set-ADObject -SamAccountName testc -PropertyName useraccountcontrol -PropertyXorValue 65536\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(4) C# Implementation\u003C\u002Fh4>\u003Cp>Using the System.DirectoryServices namespace, detailed code has been uploaded to GitHub at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Ch3>2. Implementation from outside the domain\u003C\u002Fh3>\u003Ch4>(1) Using the PowerShell ActiveDirectory module\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>import-module .\\Microsoft.ActiveDirectory.Management.dll\u003Cbr>$uname=\"administrator\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>Set-ADUser -Server 192.168.1.1 -Credential $cred -Identity testc -PasswordNeverExpires $true\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(2) Using PowerView\u003C\u002Fh4>\u003Cp>Command example:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>$uname=\"administrator\"\u003Cbr>$pwd=ConvertTo-SecureString \"DomainPassword123!\" -AsPlainText –Force\u003Cbr>$cred=New-Object System.Management.Automation.PSCredential($uname,$pwd)\u003Cbr>$Users=Get-NetUser -Domain \"test.com\" -DomainController 192.168.1.1 -Credential $cred\u003Cbr>Set-ADObject -Domain \"test.com\" -DomainController 192.168.1.1 -Credential $cred -SamAccountName testc -PropertyName useraccountcontrol -PropertyXorValue 65536\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch4>(3) C# Implementation\u003C\u002Fh4>\u003Cp>Using the namespace System.DirectoryServices, detailed code has been uploaded to GitHub, address as follows:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>Testing as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018786913_4_fa04964f00-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Method to Remove Password Never Expires Attribute for a Specified User\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>There are two implementation methods:\u003C\u002Fp>\u003Cp>1. Perform a bitwise XOR operation (operator ^) between the userAccountControl attribute value and 65536\u003C\u002Fp>\u003Cp>2. Directly subtract 65536 from the userAccountControl attribute value\u003C\u002Fp>\u003Cp>The specific method is similar to 0x04 and will not be repeated here\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the characteristics of domain users with the password never expires attribute, analyzes the principles of enumerating, adding, and removing this attribute, presents various implementation methods under different conditions, and provides open-source C# implementation code.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1392,"Onedaysec",6,"published","2026-02-02T08:06:59.472Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Domain User Password Never Expires: Enumeration & Management Guide","domain user password never expires, userAccountControl, Active Directory security, password policy, penetration testing, domain enumeration, password expiration, bitwise operations",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],306,304,303,302,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.271Z","2026-07-23T16:01:21.525Z","draft","2026-07-23T16:05:14.351Z"]