PNPT notes
// rcpclinet orqali enum qilish mumkin # rpcclient -U sfsd -p sfs Adress
// tizim haqida ma'lumot olish
# rpcclient srvinfo
// domain users
# rpccleint enumdomusers
// domain (bult in)groups
# rpcclient enumalsgroups domain
# rpcclient enumalsgroups bultin
// SID topish
rpccleint > lookupnames name
//RIDs orqali malumot olish:
queryuser 500 // admin
# rpcclient srvinfo
// domain users
# rpccleint enumdomusers
// domain (bult in)groups
# rpcclient enumalsgroups domain
# rpcclient enumalsgroups bultin
// SID topish
rpccleint > lookupnames name
//RIDs orqali malumot olish:
queryuser 500 // admin
PNPT notes
// Powerview / has a session , etc
> Invoke-UserHunter
> Invoke-UserView
shovqinsizroq:
> Invoke-StealthUserHunter
> Invoke-UserView
shovqinsizroq:
> Invoke-StealthUserHunter
// ACL abuse check
> Get-ObjectAcl -SamAccountName delegate -ResolveGUIDs | ? {$_.ActiveDirectoryRights -eq "GenericAll"}
> Get-ObjectAcl -SamAccountName delegate -ResolveGUIDs | ? {$_.ActiveDirectoryRights -eq "GenericAll"}
// Tip
Antiviruslar faylni o'chirishga kirganda url fayl attack qilish mumkin.
rpcclient $> querydispinfo
Antiviruslar faylni o'chirishga kirganda url fayl attack qilish mumkin.
rpcclient $> querydispinfo
// HTB fuse // enumeration is key!
root@kali# smbclient -U bhult -L \\\\10.10.10.193
Enter WORKGROUP\bhult's password:
session setup failed: NT_STATUS_PASSWORD_MUST_CHANGE
SMB passwordni qabul qilmasa parol hato deganimas.
root@kali# smbclient -U bhult -L \\\\10.10.10.193
Enter WORKGROUP\bhult's password:
session setup failed: NT_STATUS_PASSWORD_MUST_CHANGE
SMB passwordni qabul qilmasa parol hato deganimas.
PNPT notes pinned «// Domain controllerni topish # dig -t NS domain_name # dig _gc. domain_name»