[Samba] Being able to read password hashes

Stuart Naylor stuartiannaylor at thursbygarden.org
Mon Jul 21 02:29:24 MDT 2014

ldbsearch -H /var/lib/samba/private/sam.ldb '(&(objectclass=person)(name=Administrator))' name unicodePwd

# record 1
dn: CN=Administrator,CN=Users,DC=office,DC=zentyal,DC=lan
name: Administrator
unicodePwd:: kXh1DQFudwnw+lnHhubyUw==

http://www.hashkiller.co.uk/ntlm-decrypter.aspx just took 242ms to return my password

Only zent1 as its just a VM running a test of Zentyal3.5

More information about the samba mailing list