Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Missing check: GPP autologon #11

Closed
cnotin opened this issue Sep 17, 2019 · 5 comments
Closed

Missing check: GPP autologon #11

cnotin opened this issue Sep 17, 2019 · 5 comments

Comments

@cnotin
Copy link
Contributor

cnotin commented Sep 17, 2019

Hello,

PingCastle is able to detect the "GPP passwords" cases (encrypted "cpassword" field in some XML files of the sysvol).
But it doesn't seem to cover the "GPP autologon" cases. It's even easier since only "registry.xml" files are concerned and the login is in "DefaultUsername" and password in "DefaultPassword".

See this implementation example:
https://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Get-GPPAutologon.ps1

@vletoux
Copy link
Contributor

vletoux commented Sep 17, 2019

@cnotin
Copy link
Contributor Author

cnotin commented Sep 17, 2019

That's exactly this thing!

@cnotin
Copy link
Contributor Author

cnotin commented Sep 17, 2019

By the way, it's not a request but only a kind suggestion :)

@vletoux
Copy link
Contributor

vletoux commented Sep 17, 2019

Done for 2.8
image

@vletoux vletoux closed this as completed Sep 17, 2019
@cnotin
Copy link
Contributor Author

cnotin commented Sep 17, 2019

That was fast! Thank you :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants