Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

WIN7 Failed #8

Closed
TryA9ain opened this issue Dec 2, 2021 · 5 comments
Closed

WIN7 Failed #8

TryA9ain opened this issue Dec 2, 2021 · 5 comments

Comments

@TryA9ain
Copy link

TryA9ain commented Dec 2, 2021

Target iInformation

Windows 7 Ultimate (x64)

I use the .exe version to run nanodump

image

then I downloaded the minidump and Recover invalid signatures

image

I use Kali pypykatz, But it failed

image

I also try to use Cobalt Strike, then use Kali pypykatz, it failed too

Declare in advance that my Kali pypykatz is OK

@S4ntiagoP
Copy link
Collaborator

Hey there,
I will get a Win7 VM and try it myself.
In the mean time, why don't you try with the latest version of pypykatz which is "0.5.2" (clone the repo and compile it locally).

@S4ntiagoP
Copy link
Collaborator

yep, this is a legitimate issue, thanks for reporting it!
I will investigate and try o find what's wrong

@S4ntiagoP
Copy link
Collaborator

I found the issue, it is fixed in this commit.
The thing is that I was setting the field TimeDateStamp to 0 on every DLL that was dumped. Aparently this field is important in Windows7 but not in Windows 10.
Thank you very much for finding and reporting this!

@hastalamuerte
Copy link

hastalamuerte commented Apr 5, 2024

image
image
@S4ntiagoP Hello , facing a bit same errors when trying to get secrets from nanodumps output

nanodumps was runned on machine with ASCII or UTF8 language pack . And en in second lang
I made a nanodump -w (via havok) and then try use commands provided . mimikatz - both version x64, x86 , pypykatz - no luck

@hastalamuerte
Copy link

hastalamuerte commented Apr 5, 2024

redumping with -v gave results! possible transport corrupt dump file a bit .

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants