[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fPYxiSXYr44uD6qQvguaO2GweCSF5MhXj6sBKcHq_lNU":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":52,"createdAt":52,"_status":51},323,"How can a Password Filter DLL be applied on non-Windows Server systems that have password complexity disabled?","On non-server systems, password complexity is disabled by default. To use a Password Filter DLL, an attacker must first enable the policy by exporting the current security database with `secedit \u002Fexport \u002Fcfg gp.inf`, set `PasswordComplexity=1`, then import it with `secedit \u002Fconfigure` and refresh Group Policy with `gpupdate \u002Fforce`. After that, the standard installation steps (registry, DLL placement, reboot) apply, allowing password capture on workstations.","\u003Cp>On non-server systems, password complexity is disabled by default. To use a Password Filter DLL, an attacker must first enable the policy by exporting the current security database with `secedit \u002Fexport \u002Fcfg gp.inf`, set `PasswordComplexity=1`, then import it with `secedit \u002Fconfigure` and refresh Group Policy with `gpupdate \u002Fforce`. After that, the standard installation steps (registry, DLL placement, reboot) apply, allowing password capture on workstations.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fapplication-of-password-filter-dll-in-penetration-testing\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","how-can-a-password-filter-dll-be-applied-on-non-windows-server-systems-that-have-1777484136986","non-server systems, password complexity, secedit, gpupdate, workstation",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":48,"updatedAt":49,"createdAt":50,"_status":51},82,"Application of Password Filter DLL in Penetration Testing","application-of-password-filter-dll-in-penetration-testing","Learn how Password Filter DLLs can be exploited in penetration testing to capture plaintext passwords and implement backdoors on Windows systems.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration – Hook PasswordChangeNotify', we introduced the method of recording new passwords by injecting a DLL to hook PasswordChangeNotify, which essentially exploits the API PasswordChangeNotify.\u003C\u002Fp>\u003Cp>We know that API PasswordChangeNotify is a functional function of the Password Filter DLL. So, for the Password Filter DLL itself, can we directly develop a DLL that can be exploited?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Password Filter DLL\u003C\u002Fli>\u003Cli>Using Password Filter DLL to Record Plaintext Passwords\u003C\u002Fli>\u003Cli>Backdoor Implementation Using Password Filter DLL\u003C\u002Fli>\u003Cli>Application in Non-Windows Server Systems\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Password Filter DLL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In real-world use of Windows systems, to enhance security and prevent brute-force attacks on user passwords, system administrators often impose complexity requirements for user passwords, which can be enabled by configuring Group Policy.\u003C\u002Fp>\u003Cp>The location is as follows:\u003C\u002Fp>\u003Cp>gpedit.msc -&gt; Local Computer Policy -&gt; Computer Configuration -&gt; Windows Settings -&gt; Security Settings -&gt; Account Policies -&gt; Password Policy -&gt; Password must meet complexity requirements\u003C\u002Fp>\u003Cp>When enabled, passwords must meet the following minimum requirements:\u003C\u002Fp>\u003Cul>\u003Cli>Cannot contain the user's account name or more than two consecutive characters from the user's full name\u003C\u002Fli>\u003Cli>At least six characters long\u003C\u002Fli>\u003Cli>Contain characters from three of the following four categories:\u003C\u002Fli>\u003Cli>Uppercase English letters (A through Z)\u003C\u002Fli>\u003Cli>Lowercase English letters (a through z)\u003C\u002Fli>\u003Cli>Base 10 digits (0 through 9)\u003C\u002Fli>\u003Cli>Non-alphabetic characters (e.g., !, $, #, %)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Default:\u003C\u002Fp>\u003Cul>\u003Cli>Enabled on domain controllers\u003C\u002Fli>\u003Cli>Disabled on standalone servers\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If this policy still does not meet password complexity requirements, a Password Filter DLL can be used to further enhance password complexity\u003C\u002Fp>\u003Ch3>Implementation approach:\u003C\u002Fh3>\u003Col>\u003Cli>Installing Password Filter DLL by modifying the registry\u003C\u002Fli>\u003Cli>Automatically loading Password Filter DLL and importing plaintext passwords when users change passwords\u003C\u002Fli>\u003Cli>Developers can define password complexity in the Password Filter DLL and compare it with the complexity of plaintext passwords; if the plaintext password does not meet the complexity requirements, a dialog box prompts the user and the password change fails\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For specific usage, refer to the official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms721766(v=vs.85).aspx\u003C\u002Fp>\u003Ch2>0x03 Development of Password Filter DLL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Supports the following three functions:\u003C\u002Fp>\u003Cul>\u003Cli>BOOLEAN InitializeChangeNotify(void);\u003C\u002Fli>\u003Cli>NTSTATUS PasswordChangeNotify(_In_ PUNICODE_STRING UserName,_In_ ULONG RelativeId,_In_ PUNICODE_STRING NewPassword);\u003C\u002Fli>\u003Cli>BOOLEAN PasswordFilter(_In_ PUNICODE_STRING AccountName,_In_ PUNICODE_STRING FullName,_In_ PUNICODE_STRING Password,_In_ BOOLEAN SetOperation);\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms721849(v=vs.85).aspx#password_filter_functions\u003C\u002Fp>\u003Cp>Notable points:\u003C\u002Fp>\u003Cul>\u003Cli>The input parameters for the APIs PasswordChangeNotify and PasswordFilter both include the user's plaintext password\u003C\u002Fli>\u003Cli>When the API PasswordFilter returns TRUE, it indicates the password meets requirements; returning FALSE means the password does not meet complexity requirements, and a dialog prompts the user to modify it.\u003C\u002Fli>\u003Cli>When writing a Password Filter DLL, it is necessary to declare export functions.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>A proof-of-concept (POC) for reference is provided at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>This project declares the export functions InitializeChangeNotify, PasswordChangeNotify, and PasswordFilter.\u003C\u002Fp>\u003Cp>Use PasswordChangeNotify and PasswordFilter respectively to record plaintext passwords, saved in c:\\logFile1 and c:\\logFile2.\u003C\u002Fp>\u003Cp>During compilation, it must correspond to the target system's platform.\u003C\u002Fp>\u003Cp>%wZ indicates outputting PUNICODE_STRING, a Unicode string pointer type.\u003C\u002Fp>\u003Ch2>0x04 Installation of Password Filter DLL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. In the registry at HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, under Notification Packages, add the name of the Password Filter DLL, excluding the .dll suffix.\u003C\u002Fp>\u003Cp>2. Save the Password Filter DLL in %windir%\\system32\\.\u003C\u002Fp>\u003Cp>3. Enable the group policy 'Password must meet complexity requirements'.\u003C\u002Fp>\u003Cp>4. Restart the system (logging off the current user will not take effect).\u003C\u002Fp>\u003Cp>5. Modify any user's password to load the Password Filter DLL.\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Test system: Windows Server 2008 R2 x64\u003C\u002Fp>\u003Cp>Compile the Password Filter DLL project to generate the 64-bit Win32Project3.dll\u003C\u002Fp>\u003Cp>1. Save Win32Project3.dll under %windir%\\system32\\\u003C\u002Fp>\u003Cp>2. Modify the Notification Packages registry key under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, add Win32Project3\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018746891_0_2a27d1331e.jpeg\">\u003C\u002Fp>\u003Cp>The method to achieve via command line is as follows:\u003C\u002Fp>\u003Cp>Read the key value:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the key value content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\u003Cbr>    Notification Packages    REG_MULTI_SZ    scecli\\0rassfm\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add Win32Project3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\" \u002Ft REG_MULTI_SZ \u002Fd \"scecli\\0rassfm\\0Win32Project3\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\\0 indicates a line break\u003C\u002Fp>\u003Cp>3. The group policy of Windows Server systems by default enforces that passwords must meet complexity requirements\u003C\u002Fp>\u003Cp>4. Restart the system\u003C\u002Fp>\u003Cp>5. Change user password\u003C\u002Fp>\u003Cp>6. Record plaintext password\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018755047_1_d6135a1c19.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can record all users, including those not logged in\u003C\u002Fp>\u003Ch2>0x05 Applications in Domain Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Record plaintext password\u003C\u002Fh3>\u003Cp>For domain controller servers, domain controller server permissions are required. Place the Password Filter DLL under %windir%\\system32\\ and modify the registry key value\u003C\u002Fp>\u003Ch4>Advantages:\u003C\u002Fh4>\u003Cp>Domain controller servers have the group policy 'Password must meet complexity requirements' enabled by default\u003C\u002Fp>\u003Ch4>Drawback:\u003C\u002Fh4>\u003Cp>Requires a system reboot to take effect, which is rare for domain controllers\u003C\u002Fp>\u003Ch4>Extension:\u003C\u002Fh4>\u003Cp>Modify the payload to send plaintext passwords to a web server; refer to the code at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2013\u002F2013-09-11-stealing-passwords-every-time-they-change\u002F\u003C\u002Fp>\u003Ch3>2. Backdoor\u003C\u002Fh3>\u003Cp>Change the Password Filter DLL to launch a backdoor, such as returning a Meterpreter shell\u003C\u002Fp>\u003Cp>When any domain user changes their password, the Password Filter DLL loads and returns a high-privilege shell\u003C\u002Fp>\u003Ch2>0x06 Application on Non-Windows Server Systems\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Most current information suggests Password Filter DLLs are only applicable to Windows Server systems\u003C\u002Fp>\u003Cp>For non-Windows Server systems, they can also be used, but the group policy 'Password must meet complexity requirements' is disabled by default\u003C\u002Fp>\u003Cp>Therefore, note the following issues:\u003C\u002Fp>\u003Ch3>1. Check the current system's group policy configuration via command line\u003C\u002Fh3>\u003Cp>Group Policy configuration is stored in a database located at %windir%\\security\\database\\secedit.sdb\u003C\u002Fp>\u003Cp>The read command is as follows (administrator privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>secedit \u002Fexport \u002Fcfg gp.inf \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>The \u002Fdb parameter is not set, indicating the database uses the default %windir%\\security\\database\\secedit.sdb\u003C\u002Fli>\u003Cli>\u002Fquiet means no log is generated; otherwise, the generated log is saved by default at %windir%\\security\\logs\\scesrv.log\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After command execution, the file gp.inf is generated. Check the PasswordComplexity item in gp.inf; 1 indicates enabled, 0 indicates disabled\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The content in gp.inf is incomplete; to obtain the complete Group Policy configuration, the registry must also be read\u003C\u002Fp>\u003Ch3>2. Modify Group Policy configuration to enable the policy that passwords must meet complexity requirements\u003C\u002Fh3>\u003Cp>First, export the configuration file gp.inf, set the PasswordComplexity item to 1, and save\u003C\u002Fp>\u003Cp>Import into the database:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>secedit \u002Fconfigure \u002Fdb gp.sdb \u002Fcfg gp.inf \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Refresh Group Policy to take effect immediately (otherwise, it takes effect after restart):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>According to the exploitation methodology, the attacker first needs to obtain administrator privileges on the current system.\u003C\u002Fp>\u003Cp>The detection approach is as follows:\u003C\u002Fp>\u003Cp>1. Check for suspicious DLLs under %windir%\\system32\\\u003C\u002Fp>\u003Cp>2. Check the Notification Packages registry key value under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\u003C\u002Fp>\u003Cp>3. Check the DLLs loaded by the lsass.exe process\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770018767149_2_21a4b7bb16.jpeg\">\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Password Filter DLL is a legitimate function provided by the system. However, if system administrator privileges are obtained, this functionality can be exploited not only to record plaintext passwords but also to serve as a backdoor.\u003C\u002Fp>\u003Cp>This article, in conjunction with specific exploitation methodologies, introduces detection methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration – Hook PasswordChangeNotify', we introduced the method of recording new passwords by injecting a DLL to hook PasswordChangeNotify, which essentially exploits the API PasswordChangeNotify.\u003C\u002Fp>\u003Cp>We know that API PasswordChangeNotify is a functional function of the Password Filter DLL. So, for the Password Filter DLL itself, can we directly develop a DLL that can be exploited?\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to Password Filter DLL\u003C\u002Fli>\u003Cli>Using Password Filter DLL to Record Plaintext Passwords\u003C\u002Fli>\u003Cli>Backdoor Implementation Using Password Filter DLL\u003C\u002Fli>\u003Cli>Application in Non-Windows Server Systems\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to Password Filter DLL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In real-world use of Windows systems, to enhance security and prevent brute-force attacks on user passwords, system administrators often impose complexity requirements for user passwords, which can be enabled by configuring Group Policy.\u003C\u002Fp>\u003Cp>The location is as follows:\u003C\u002Fp>\u003Cp>gpedit.msc -&gt; Local Computer Policy -&gt; Computer Configuration -&gt; Windows Settings -&gt; Security Settings -&gt; Account Policies -&gt; Password Policy -&gt; Password must meet complexity requirements\u003C\u002Fp>\u003Cp>When enabled, passwords must meet the following minimum requirements:\u003C\u002Fp>\u003Cul>\u003Cli>Cannot contain the user's account name or more than two consecutive characters from the user's full name\u003C\u002Fli>\u003Cli>At least six characters long\u003C\u002Fli>\u003Cli>Contain characters from three of the following four categories:\u003C\u002Fli>\u003Cli>Uppercase English letters (A through Z)\u003C\u002Fli>\u003Cli>Lowercase English letters (a through z)\u003C\u002Fli>\u003Cli>Base 10 digits (0 through 9)\u003C\u002Fli>\u003Cli>Non-alphabetic characters (e.g., !, $, #, %)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Default:\u003C\u002Fp>\u003Cul>\u003Cli>Enabled on domain controllers\u003C\u002Fli>\u003Cli>Disabled on standalone servers\u003C\u002Fli>\u003C\u002Ful>\u003Cp>If this policy still does not meet password complexity requirements, a Password Filter DLL can be used to further enhance password complexity\u003C\u002Fp>\u003Ch3>Implementation approach:\u003C\u002Fh3>\u003Col>\u003Cli>Installing Password Filter DLL by modifying the registry\u003C\u002Fli>\u003Cli>Automatically loading Password Filter DLL and importing plaintext passwords when users change passwords\u003C\u002Fli>\u003Cli>Developers can define password complexity in the Password Filter DLL and compare it with the complexity of plaintext passwords; if the plaintext password does not meet the complexity requirements, a dialog box prompts the user and the password change fails\u003C\u002Fli>\u003C\u002Fol>\u003Cp>For specific usage, refer to the official documentation:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms721766(v=vs.85).aspx\u003C\u002Fp>\u003Ch2>0x03 Development of Password Filter DLL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Supports the following three functions:\u003C\u002Fp>\u003Cul>\u003Cli>BOOLEAN InitializeChangeNotify(void);\u003C\u002Fli>\u003Cli>NTSTATUS PasswordChangeNotify(_In_ PUNICODE_STRING UserName,_In_ ULONG RelativeId,_In_ PUNICODE_STRING NewPassword);\u003C\u002Fli>\u003Cli>BOOLEAN PasswordFilter(_In_ PUNICODE_STRING AccountName,_In_ PUNICODE_STRING FullName,_In_ PUNICODE_STRING Password,_In_ BOOLEAN SetOperation);\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fwindows\u002Fdesktop\u002Fms721849(v=vs.85).aspx#password_filter_functions\u003C\u002Fp>\u003Cp>Notable points:\u003C\u002Fp>\u003Cul>\u003Cli>The input parameters for the APIs PasswordChangeNotify and PasswordFilter both include the user's plaintext password\u003C\u002Fli>\u003Cli>When the API PasswordFilter returns TRUE, it indicates the password meets requirements; returning FALSE means the password does not meet complexity requirements, and a dialog prompts the user to modify it.\u003C\u002Fli>\u003Cli>When writing a Password Filter DLL, it is necessary to declare export functions.\u003C\u002Fli>\u003C\u002Ful>\u003Cp>A proof-of-concept (POC) for reference is provided at the following address:\u003C\u002Fp>\u003Cp>An open-source project\u003C\u002Fp>\u003Cp>This project declares the export functions InitializeChangeNotify, PasswordChangeNotify, and PasswordFilter.\u003C\u002Fp>\u003Cp>Use PasswordChangeNotify and PasswordFilter respectively to record plaintext passwords, saved in c:\\logFile1 and c:\\logFile2.\u003C\u002Fp>\u003Cp>During compilation, it must correspond to the target system's platform.\u003C\u002Fp>\u003Cp>%wZ indicates outputting PUNICODE_STRING, a Unicode string pointer type.\u003C\u002Fp>\u003Ch2>0x04 Installation of Password Filter DLL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>1. In the registry at HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, under Notification Packages, add the name of the Password Filter DLL, excluding the .dll suffix.\u003C\u002Fp>\u003Cp>2. Save the Password Filter DLL in %windir%\\system32\\.\u003C\u002Fp>\u003Cp>3. Enable the group policy 'Password must meet complexity requirements'.\u003C\u002Fp>\u003Cp>4. Restart the system (logging off the current user will not take effect).\u003C\u002Fp>\u003Cp>5. Modify any user's password to load the Password Filter DLL.\u003C\u002Fp>\u003Ch3>Actual test:\u003C\u002Fh3>\u003Cp>Test system: Windows Server 2008 R2 x64\u003C\u002Fp>\u003Cp>Compile the Password Filter DLL project to generate the 64-bit Win32Project3.dll\u003C\u002Fp>\u003Cp>1. Save Win32Project3.dll under %windir%\\system32\\\u003C\u002Fp>\u003Cp>2. Modify the Notification Packages registry key under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa, add Win32Project3\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018746891_0_2a27d1331e-1.jpeg\">\u003C\u002Fp>\u003Cp>The method to achieve via command line is as follows:\u003C\u002Fp>\u003Cp>Read the key value:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG QUERY \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Obtain the key value content:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\u003Cbr>    Notification Packages    REG_MULTI_SZ    scecli\\0rassfm\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Add Win32Project3:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>REG ADD \"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\" \u002Fv \"Notification Packages\" \u002Ft REG_MULTI_SZ \u002Fd \"scecli\\0rassfm\\0Win32Project3\" \u002Ff\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>\\0 indicates a line break\u003C\u002Fp>\u003Cp>3. The group policy of Windows Server systems by default enforces that passwords must meet complexity requirements\u003C\u002Fp>\u003Cp>4. Restart the system\u003C\u002Fp>\u003Cp>5. Change user password\u003C\u002Fp>\u003Cp>6. Record plaintext password\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018755047_1_d6135a1c19-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Can record all users, including those not logged in\u003C\u002Fp>\u003Ch2>0x05 Applications in Domain Environment\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Record plaintext password\u003C\u002Fh3>\u003Cp>For domain controller servers, domain controller server permissions are required. Place the Password Filter DLL under %windir%\\system32\\ and modify the registry key value\u003C\u002Fp>\u003Ch4>Advantages:\u003C\u002Fh4>\u003Cp>Domain controller servers have the group policy 'Password must meet complexity requirements' enabled by default\u003C\u002Fp>\u003Ch4>Drawback:\u003C\u002Fh4>\u003Cp>Requires a system reboot to take effect, which is rare for domain controllers\u003C\u002Fp>\u003Ch4>Extension:\u003C\u002Fh4>\u003Cp>Modify the payload to send plaintext passwords to a web server; refer to the code at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmalicious.link\u002Fpost\u002F2013\u002F2013-09-11-stealing-passwords-every-time-they-change\u002F\u003C\u002Fp>\u003Ch3>2. Backdoor\u003C\u002Fh3>\u003Cp>Change the Password Filter DLL to launch a backdoor, such as returning a Meterpreter shell\u003C\u002Fp>\u003Cp>When any domain user changes their password, the Password Filter DLL loads and returns a high-privilege shell\u003C\u002Fp>\u003Ch2>0x06 Application on Non-Windows Server Systems\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Most current information suggests Password Filter DLLs are only applicable to Windows Server systems\u003C\u002Fp>\u003Cp>For non-Windows Server systems, they can also be used, but the group policy 'Password must meet complexity requirements' is disabled by default\u003C\u002Fp>\u003Cp>Therefore, note the following issues:\u003C\u002Fp>\u003Ch3>1. Check the current system's group policy configuration via command line\u003C\u002Fh3>\u003Cp>Group Policy configuration is stored in a database located at %windir%\\security\\database\\secedit.sdb\u003C\u002Fp>\u003Cp>The read command is as follows (administrator privileges):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>secedit \u002Fexport \u002Fcfg gp.inf \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Parameter description:\u003C\u002Fp>\u003Cul>\u003Cli>The \u002Fdb parameter is not set, indicating the database uses the default %windir%\\security\\database\\secedit.sdb\u003C\u002Fli>\u003Cli>\u002Fquiet means no log is generated; otherwise, the generated log is saved by default at %windir%\\security\\logs\\scesrv.log\u003C\u002Fli>\u003C\u002Ful>\u003Cp>After command execution, the file gp.inf is generated. Check the PasswordComplexity item in gp.inf; 1 indicates enabled, 0 indicates disabled\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The content in gp.inf is incomplete; to obtain the complete Group Policy configuration, the registry must also be read\u003C\u002Fp>\u003Ch3>2. Modify Group Policy configuration to enable the policy that passwords must meet complexity requirements\u003C\u002Fh3>\u003Cp>First, export the configuration file gp.inf, set the PasswordComplexity item to 1, and save\u003C\u002Fp>\u003Cp>Import into the database:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>secedit \u002Fconfigure \u002Fdb gp.sdb \u002Fcfg gp.inf \u002Fquiet\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Refresh Group Policy to take effect immediately (otherwise, it takes effect after restart):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>gpupdate \u002Fforce\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Ch2>0x07 Defense Detection\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>According to the exploitation methodology, the attacker first needs to obtain administrator privileges on the current system.\u003C\u002Fp>\u003Cp>The detection approach is as follows:\u003C\u002Fp>\u003Cp>1. Check for suspicious DLLs under %windir%\\system32\\\u003C\u002Fp>\u003Cp>2. Check the Notification Packages registry key value under HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentControlSet\\Control\\Lsa\u003C\u002Fp>\u003Cp>3. Check the DLLs loaded by the lsass.exe process\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770018767149_2_21a4b7bb16-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x08 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Password Filter DLL is a legitimate function provided by the system. However, if system administrator privileges are obtained, this functionality can be exploited not only to record plaintext passwords but also to serve as a backdoor.\u003C\u002Fp>\u003Cp>This article, in conjunction with specific exploitation methodologies, introduces detection methods.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",1370,"Onedaysec",6,"published","2026-02-02T08:06:59.415Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Password Filter DLL Penetration Testing: Backdoor & Password Capture","Password Filter DLL, penetration testing, password capture, backdoor, Windows security, PasswordChangeNotify, PasswordFilter, plaintext passwords, registry exploit, DLL injection",null,false,[],{"docs":43,"hasNextPage":40},[44,4,45,46,47],324,322,321,320,{"title":39,"description":39,"image":39},"2026-07-24T15:37:14.159Z","2026-07-23T16:01:22.792Z","draft","2026-07-23T16:05:21.565Z"]