NetExec change-password Module
Reset a user's password when they are flagged STATUS_PASSWORD_MUST_CHANGE — typical after a freshly-spawned account or post-coercion. Works without needing existing valid auth, since the must-change pre-auth is its own state. Added in NetExec v1.5.0.
- Tool
- nxc
- Category
- Credential Attacks / Password Manipulation
- Platform
- linux
- Requires
- password
- Protocols
- SMB
Syntax
Angle-bracket tokens are placeholders — replace them with your target's values, or open this command in the app to fill them in and copy the result.
nxc smb <target> -u '<user>' -p '<old-password>' -M change-password -o NEWPASS='<new-password>'
Examples
nxc smb dc.corp.local -u newuser -p 'TempPass1!' -M change-password -o NEWPASS='AttackerPass1!'
Tags
References
Related commands
- bloodyAD add uac Toggle UserAccountControl flags on a target account. Setting DONT_REQ_PREAUTH on a user…
- BloodyAD Force Password Change Force password change using BloodyAD
- bloodyAD Set Password Reset another user's password if you have ForceChangePassword…
- Impacket changepasswd Change an AD user's password via RPC (requires appropriate ACL rights)
- Impacket Get-GPPPassword Decrypt Group Policy Preference (GPP) passwords from XML files
- Net RPC Password Change Force password change via Net RPC
- NetExec SMB GPP AutoLogin Search Group Policy Preferences for AutoLogon credentials stored in SYSVOL
- NetExec SMB GPP Password Search SYSVOL for Group Policy Preference XML files containing encrypted passwords