DSInternals icon indicating copy to clipboard operation
DSInternals copied to clipboard

PWDump custom view issue when run under SYSTEM account

Open DiPersiaTech opened this issue 3 years ago • 4 comments

When running

Get-ADDBAccount -All -DBPath "$Path\Active Directory\ntds.dit" -BootKey $key | Format-Custom -View PWDump

under the system account context (Which our automation system does), the output is broken into multiple lines. For example -

User:2677:NO LM-HASH**********************:1111111111111111111111111:::

Where output should show as a single line - User2677:NO LM-HASH**********************:1111111111111111111111111::::

Can replicate this by starting Powershell using PSEXEC as the system.

DiPersiaTech avatar Feb 22 '22 21:02 DiPersiaTech

Hello @DiPersiaTech , line wrapping depends solely on the configuration of your terminal window, which is profile-specific. You should be able to bypass it by piping the output to the Out-File cmdlet.

MichaelGrafnetter avatar Feb 24 '22 14:02 MichaelGrafnetter

@MichaelGrafnetter thanks for the response. Same behavior actually, regardless of screen or file. I assumed the custom view had something to do with it and running under system. This is with the out-file

Get-ADDBAccount -All -DBPath "$Path\Active Directory\ntds.dit" -BootKey $key | Format-Custom -View PWDump | Out-File $Path\dump.txt -Force -Encoding ascii

DiPersiaTech avatar Feb 24 '22 16:02 DiPersiaTech

Interesting. Looking into the source file, there is only a space.

MichaelGrafnetter avatar Feb 24 '22 16:02 MichaelGrafnetter

I concur. That is weird. If/when you get time, can you try to replicate with psexec just so I can see if it's me or. . .?

DiPersiaTech avatar Feb 24 '22 18:02 DiPersiaTech