前言

配置文件

Untitled

解密流程

已知明文主密码

Untitled

已知主密码Hash

Untitled

Untitled

DPAPI_IMP BOOL CryptUnprotectData(
  DATA_BLOB                 *pDataIn,
  LPWSTR                    *ppszDataDescr,
  DATA_BLOB                 *pOptionalEntropy,
  PVOID                     pvReserved,
  CRYPTPROTECT_PROMPTSTRUCT *pPromptStruct,
  DWORD                     dwFlags,
  DATA_BLOB                 *pDataOut
);

Untitled

Untitled

Untitled

Untitled

使用演示

Untitled

Untitled

Untitled

参考

https://github.com/rapid7/metasploit-framework/pull/17009

Powered by Kali-Team