Monteverde
Recon
LDAP
└─$ netexec ldap 10.129.228.111 -u '' -p '' --users | tee ldap_users.txt
SMB 10.129.228.111 445 MONTEVERDE [*] Windows 10 / Server 2019 Build 17763 x64 (name:MONTEVERDE) (domain:MEGABANK.LOCAL) (signing:True) (SMBv1:False)
LDAP 10.129.228.111 389 MONTEVERDE [+] MEGABANK.LOCAL\:
LDAP 10.129.228.111 389 MONTEVERDE [*] Total records returned: 270
...Too much garbage...
└─$ enum4linux-ng megabank.local | tee enum4linux.log
ENUM4LINUX - next generation (v1.3.4)
==========================
| Target Information |
==========================
[*] Target ........... megabank.local
[*] Username ......... ''
[*] Random Username .. 'kapyieei'
[*] Password ......... ''
[*] Timeout .......... 5 second(s)
=======================================
| Listener Scan on megabank.local |
=======================================
[*] Checking LDAP
[+] LDAP is accessible on 389/tcp
[*] Checking LDAPS
[+] LDAPS is accessible on 636/tcp
[*] Checking SMB
[+] SMB is accessible on 445/tcp
[*] Checking SMB over NetBIOS
[+] SMB over NetBIOS is accessible on 139/tcp
======================================================
| Domain Information via LDAP for megabank.local |
======================================================
[*] Trying LDAP
[+] Appears to be root/parent DC
[+] Long domain name is: MEGABANK.LOCAL
===========================================
| SMB Dialect Check on megabank.local |
===========================================
[*] Trying on 445/tcp
[+] Supported dialects and settings:
Supported dialects:
SMB 1.0: false
SMB 2.02: true
SMB 2.1: true
SMB 3.0: true
SMB 3.1.1: true
Preferred dialect: SMB 3.0
SMB1 only: false
SMB signing required: true
=============================================================
| Domain Information via SMB session for megabank.local |
=============================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found domain information via SMB
NetBIOS computer name: MONTEVERDE
NetBIOS domain name: MEGABANK
DNS domain: MEGABANK.LOCAL
FQDN: MONTEVERDE.MEGABANK.LOCAL
Derived membership: domain member
Derived domain: MEGABANK
===========================================
| RPC Session Check on megabank.local |
===========================================
[*] Check for null session
[+] Server allows session using username '', password ''
[*] Check for random user
[-] Could not establish random user session: STATUS_LOGON_FAILURE
=====================================================
| Domain Information via RPC for megabank.local |
=====================================================
[+] Domain: MEGABANK
[+] Domain SID: S-1-5-21-391775091-850290835-3566037492
[+] Membership: domain member
=================================================
| OS Information via RPC for megabank.local |
=================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found OS information via SMB
[*] Enumerating via 'srvinfo'
[-] Could not get OS info via 'srvinfo': STATUS_ACCESS_DENIED
[+] After merging OS information we have the following result:
OS: Windows 10, Windows Server 2019, Windows Server 2016
OS version: '10.0'
OS release: '1809'
OS build: '17763'
Native OS: not supported
Native LAN manager: not supported
Platform id: null
Server type: null
Server type string: null
=======================================
| Users via RPC on megabank.local |
=======================================
[*] Enumerating users via 'querydispinfo'
[+] Found 10 user(s) via 'querydispinfo'
[*] Enumerating users via 'enumdomusers'
[+] Found 10 user(s) via 'enumdomusers'
[+] After merging user results we have 10 user(s) total:
'1104':
username: AAD_987d7f2f57d2
name: AAD_987d7f2f57d2
acb: '0x00000210'
description: Service account for the Synchronization Service with installation identifier 05c97990-7587-4a3d-b312-309adfc172d9 running on computer MONTEVERDE.
'1601':
username: mhope
name: Mike Hope
acb: '0x00000210'
description: (null)
'2602':
username: SABatchJobs
name: SABatchJobs
acb: '0x00000210'
description: (null)
'2603':
username: svc-ata
name: svc-ata
acb: '0x00000210'
description: (null)
'2604':
username: svc-bexec
name: svc-bexec
acb: '0x00000210'
description: (null)
'2605':
username: svc-netapp
name: svc-netapp
acb: '0x00000210'
description: (null)
'2613':
username: dgalanos
name: Dimitris Galanos
acb: '0x00000210'
description: (null)
'2614':
username: roleary
name: Ray O'Leary '#
acb: '0x00000210'
description: (null)
'2615':
username: smorgan
name: Sally Morgan
acb: '0x00000210'
description: (null)
'501':
username: Guest
name: (null)
acb: '0x00000215'
description: Built-in account for guest access to the computer/domain
Completed after 23.82 secondsSMB
WinRM
User.txt
Privilege Escalation
Root.txt
Last updated