Guest User

Untitled

a guest
May 17th, 2018
158
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.93 KB | None | 0 0
  1.  
  2. root@w00den-pickle:/home/bperry/tmo/hives/ntreg-ruby# ruby ntreg.rb '\Select' ../SYSTEM
  3. Hive name: "SYSTEM"
  4. Found root key: CMI-CreateHive{F10156BE-0E87-4EFB-969E-5DA29D131144}
  5. The values and data of \CMI-CreateHive{F10156BE-0E87-4EFB-969E-5DA29D131144}\Select are:
  6. "Current: \x01\x00\x00\x00"
  7. "Default: \x01\x00\x00\x00"
  8. "Failed: \x00\x00\x00\x00"
  9. "LastKnownGood: \x02\x00\x00\x00"
  10. root@w00den-pickle:/home/bperry/tmo/hives/ntreg-ruby# ruby ntreg.rb '\ControlSet001\Control\Lsa' ../SYSTEM
  11. Hive name: "SYSTEM"
  12. Found root key: CMI-CreateHive{F10156BE-0E87-4EFB-969E-5DA29D131144}
  13. The children of \CMI-CreateHive{F10156BE-0E87-4EFB-969E-5DA29D131144}\ControlSet001\Control\Lsa are:
  14. "AccessProviders"
  15. "Audit"
  16. "Credssp"
  17. "Data"
  18. "FipsAlgorithmPolicy"
  19. "GBG"
  20. "JD"
  21. "Kerberos"
  22. "MSV1_0"
  23. "Skew1"
  24. "SSO"
  25. "SspiCache"
  26. The values and data of \CMI-CreateHive{F10156BE-0E87-4EFB-969E-5DA29D131144}\ControlSet001\Control\Lsa are:
  27. "auditbaseobjects: \x00\x00\x00\x00"
  28. "auditbasedirectories: \x00\x00\x00\x00"
  29. "crashonauditfail: \x00\x00\x00\x00"
  30. "fullprivilegeauditing: \x00\x00\x00\x00"
  31. "Bounds: \x000\x00\x00\x00 \x00\x00"
  32. "LimitBlankPasswordUse: \x01\x00\x00\x00"
  33. "NoLmHash: \x01\x00\x00\x00"
  34. "Notification Packages: s\x00c\x00e\x00c\x00l\x00i\x00\x00\x00\x00\x00"
  35. "Security Packages: k\x00e\x00r\x00b\x00e\x00r\x00o\x00s\x00\x00\x00m\x00s\x00v\x001\x00_\x000\x00\x00\x00s\x00c\x00h\x00a\x00n\x00n\x00e\x00l\x00\x00\x00w\x00d\x00i\x00g\x00e\x00s\x00t\x00\x00\x00t\x00s\x00p\x00k\x00g\x00\x00\x00p\x00k\x00u\x002\x00u\x00\x00\x00\x00\x00"
  36. "Authentication Packages: m\x00s\x00v\x001\x00_\x000\x00\x00\x00\x00\x00"
  37. "LsaPid: \xEC\x01\x00\x00"
  38. "SecureBoot: \x01\x00\x00\x00"
  39. "ProductType: \x02\x00\x00\x00"
  40. "disabledomaincreds: \x00\x00\x00\x00"
  41. "everyoneincludesanonymous: \x00\x00\x00\x00"
  42. "forceguest: \x00\x00\x00\x00"
  43. "restrictanonymous: \x00\x00\x00\x00"
  44. "restrictanonymoussam: \x01\x00\x00\x00"
  45. root@w00den-pickle:/home/bperry/tmo/hives/ntreg-ruby#
Add Comment
Please, Sign In to add comment