Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Secretsdump errors with "Unknown DCE RPC fault status code: 00000057" when executed against a RODC #1668

Open
dkjajhqu2h3j opened this issue Dec 20, 2023 · 1 comment
Labels
in review This issue or pull request is being analyzed

Comments

@dkjajhqu2h3j
Copy link

dkjajhqu2h3j commented Dec 20, 2023

Configuration

impacket version: 0.11.0
Python version: 3.11.6
Target OS: Windows Server 2019 (10.0.17763 N/A Build 17763)

Issue

I am trying to dump the AES256 key of a RODC's Kerberos service account cached in LSA on a RODC using secretsdump. If I use the default DRSUAPI mode I get the error "Unknown DCE RPC fault status code: 00000057". If I use the VSS mode I can dump the NTLM hash of the service account but I get no AES256 key. Mimikatz can successfully dump the AES256 key but I would prefer to not use that.

Skärmbild 2023-12-20 102531

I am aware that it is not possible to DCSync a RODC but that is not what I do. I am dumping LSA.

Thanks!

@gabrielg5
Copy link
Collaborator

Linking with #1552 as, if not duplicates, they are related for sure

@gabrielg5 gabrielg5 added the in review This issue or pull request is being analyzed label Jan 4, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
in review This issue or pull request is being analyzed
Projects
None yet
Development

No branches or pull requests

2 participants