Select your language

WCE: Windows Credential Editor

Windows Credential Editor (WCE) v1.0 is a tool developed by Hernan Ochoa (Amplia Security) that has recently been published as an evolution of the Pass-the-Hash Toolkit, one of the best tools so far to perform Pass-the-Hash attacks, which we discussed earlier both in the blog and in the FIST Conferences.

If we download the tool and test it, we find a single binary, which when called with the -h option shows us the help. This binary provides us with all the functionality provided by the different binaries that were part of the Pass-the-Hash Toolkit, plus some new functionalities that until now we did not have, such as keeping on screen a list of users who at all times have an active login, in the purest style the "watch" command of Linux.

Focusing on the options that will be most directly useful for the realization of the pass-the-hash, first of all we must obtain the Hash that we want to supplant. For this there are a variety of ways to do it, but to give an example that was already used in our previous post, we could do it with the hashdump command of Meterpreter:
Once we have the Hash (in this or that way) we just have to call the wce.exe with the -s option to change our current Hash in memory for the new hash, and in this way usurp the identity:

wce.exe -s User:Domain:LMHash:NTHash

Once this is done, we can verify that the credentials have been successfully changed with the -l option:

Once this is done, we can use any tool that is authenticated through Windows (for example, shares) to access other computers with the credentials of the user whose Hash we had obtained. We can see a demonstration of this in our previous post.

- Publicidad -

One of the great advantages that I see to this tool with respect to the Pass-the-Hash Toolkit, apart from the fact that it is more comfortable to have all the functionality in a single binary, and the extra functions that we find, is that it seems to have a much improved recognition of the type of system in which it runs (that or Hernán has included the addresses of a Windows XP in Spanish).

If you remember, in the presentation we made in the FIST we commented that the Pass-the-Hash Toolkit had to know in which directions of the memory it should read and write the hashes, and that although it had a series of hardcoded hashes, for a Windows XP in Spanish it was necessary to provide them by hand through the -a option, since they did not come by default. There were several doubts about this process, so we ended up publishing another post on how to get these addresses for your system.

Well, with WCE this previous step will not be necessary, let's not dabemos if because Hernán has included a broader list of addresses or because the tool has a search mechanism that obtains these addresses by itself.

Source: Pentester

image

See original.

No comments

• If you're already registered, please log in first. Your email will not be published.

Comments are closed

The comments for this content are closed.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter