Pre Windows 2000 Computers
TL;DR:
Identify
With creds
orWithout creds
Note
You can pass -n
to check blank passwords as well
Manual mode
Without using the tool, you can check by identifying pwdlastset: 12/31/1600 7:00:00PM
Note
The only error that indicates an auth failure is KDC_ERR_PREAUTH_FAILED
other errors do not mean you can't authenticate
Validate
Expected output:STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT
Exploit
Option 1: Change password
Note
this is semi-destructive, you're changing the machine password, may require the object be rejoined to the domain
Change the account password:
orOption 2: Use kerberos auth
No need to change the password if you use kerberos auth!
Grab the tgt for use with other tools.