Converting msSFU30Password from ldapsearch command to plain text

Posted on 2006-04-27
Last Modified: 2013-12-26
I am trying to write a script that will go out to my Active Directory server and return the password for a list of users, so I can update the passwords into another system.

I am using ldapsearch to return the msSFU30Password property from their account, the problem is that this is encrypted.  Does anyone know a way to get this in plain text?

This script is running on HP-UX 11i and accessing a Windows 2003 server AD

Question by:sbhegel
    LVL 27

    Accepted Solution

    Server for NIS includes an attribute called msSFU30Password, which is the password in the UNIX format.
    That means, your retrieved password is a one-way-hash. And no decryption is possible.
    You may update passwords on another system only if they are also in the same format.
    LVL 51

    Expert Comment

    >  Does anyone know a way to get this in plain text?
    only brute force methods (except you have a misconfigured LDAP:)
    The password is stored as one-way hash, ther is no way back.

    Author Comment

    Mabe this is a better way to ask the question.  

    Is there any attribute in Active Directory (LDAP) that stores the password so it can be retrieved and converted to plain text on a Unix system, namely HP-UX 11i

    Thanks again
    LVL 27

    Expert Comment

    AFAIK unicodePwd attribute stores clear text password in AD (in unicode format).
    To retrieve it you must use TLS connection (LDAPS://) with AD  administrator priveleges.
    Non enctypted connection (LDAP://) is not enough.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Free Trending Threat Insights Every Day

    Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

    Suggested Solutions

    Title # Comments Views Activity
    Process filename extension 3 138
    iSeries DB2 Query 2 66
    format the code in java 6 60
    scoreUp challenge 14 40
    Introduction: Dynamic window placements and drawing on a form, simple usage of windows registry as a storage place for information. Continuing from the first article about sudoku.  There we have designed the application and put a lot of user int…
    Have you tried to learn about Unicode, UTF-8, and multibyte text encoding and all the articles are just too "academic" or too technical? This article aims to make the whole topic easy for just about anyone to understand.
    This video will show you how to get GIT to work in Eclipse.   It will walk you through how to install the EGit plugin in eclipse and how to checkout an existing repository.
    In this seventh video of the Xpdf series, we discuss and demonstrate the PDFfonts utility, which lists all the fonts used in a PDF file. It does this via a command line interface, making it suitable for use in programs, scripts, batch files — any pl…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    17 Experts available now in Live!

    Get 1:1 Help Now