Onus Posted March 17, 2017 Share Posted March 17, 2017 Hi all, im pretty new to responder and was wondering if someone could let me know how to read the output log. I ran quickcreds on a VM running windows 8 and got the following log file with creds. Batman::Batcav:1c93d2ae0a457f99:FCEE4E4C0642636DF8B4F25F2103A1E8:0101000000000000C7302F5C549FD201F68533B32AA2A4FC000000000200060053004D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C000300280073006500720076006500720032003000300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000FC102DA35E193C199E6CD31916EF9B8C9C6E67F99BD6F2612D9684B30145268C0A0010000000000000000000000000000000000009001A0048005400540050002F00700072006F00780079007300720076000000000000000000 Batman::Batcave:d2c085b3b7dfb090:9714D79FAD2EC23E3FB93935526EF6DE:01010000000000001DBA385C549FD201DCDAD414F7880853000000000200060053004D0042000100160053004D0042002D0054004F004F004C004B00490054000400120073006D0062002E006C006F00630061006C000300280073006500720076006500720032003000300033002E0073006D0062002E006C006F00630061006C000500120073006D0062002E006C006F00630061006C000800300030000000000000000100000000200000FC102DA35E193C199E6CD31916EF9B8C9C6E67F99BD6F2612D9684B30145268C0A0010000000000000000000000000000000000009001A0048005400540050002F00700072006F00780079007300720076000000000000000000 great! a few questions though.. they are both for the user batman on batcav machine, so why are they different? also there seems to be three hashes for each.. Is one an LMHASH and one an NTHASH? if so which is which.. im so confused.. need sleep. Quote Link to comment Share on other sites More sharing options...
diverg Posted March 31, 2017 Share Posted March 31, 2017 https://zone13.io/post/cracking-ntlmv2-responses-captured-using-responder/ Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.