The User-Force-Change-Password extended right (and GenericAll, which includes it) lets you set a new password on a target account without supplying the old one, the same operation a helpdesk uses. It is the most direct way to turn a write over a user into control of it: reset the password, then log in as them. The cost is that it is destructive, so it is a deliberate choice rather than the default.
Resetting from Linux#
# bloodyAD
bloodyAD --host <dc> -d example.local -u user -p pass set password 'victim' 'Newpass123!'
# Samba net (SAMR), works with password or -k for Kerberos
net rpc password 'victim' 'Newpass123!' -U 'example.local/user%pass' -S <dc>
# Impacket (reset via SAMR without knowing the current password)
changepasswd.py example.local/victim@<dc> -reset -altuser example.local/user -altpass 'pass' -newpass 'Newpass123!'
From Windows, PowerView does the same:
Set-DomainUserPassword -Identity victim -AccountPassword (ConvertTo-SecureString 'Newpass123!' -AsPlainText -Force)
When to use it, and when not to#
A reset is loud: the legitimate user can no longer log in, which is noticed quickly and generates account-management events. So:
- Prefer a non-destructive edge first. The same
GenericWrite/GenericAllusually also allows shadow credentials (authenticate as the user without touching the password) or targeted Kerberoasting. Use those when the account is in use. - Reset is a good fit for stale or service accounts no one logs into, computer accounts (though resetting a computer password can break the host's domain membership), or when PKINIT is unavailable so shadow credentials are not an option.
- Restore where possible: if you captured the old NT hash first, you can set the password back by hash afterwards to reduce disruption.
Exploitation notes#
ForceChangePasswordis a reset (set new, no old needed), distinct from a change (needs the current password); BloodHound'sForceChangePasswordedge is exactly this right.- Over a computer account, prefer a key-credential or RBCD edge: resetting
MACHINE$desynchronises the host's secret and is both noisy and disruptive. - After reset you hold the plaintext, so it feeds straight into authenticated movement and, if the account is privileged, further DACL edges.
Tools#
- bloodyAD (
set password): single-command reset from Linux. - Samba
net rpc password/ Impacketchangepasswd.py -reset: SAMR-based reset. - PowerView (
Set-DomainUserPassword): on-host reset.
References#
- The Hacker Recipes: ForceChangePassword
- SpecterOps: BloodHound ForceChangePassword edge