文章前言
本篇文章中我们将重点介绍如何通过SMB协议和RPC协议来枚举域内信息,下文中使用的工具为rpcclient
信息枚举
Server Information
rpcclient -U Administrator%Ignite@123 192.168.1.172
Domain Information
querydominfo
Enumerating Domain Users
enumdomusers

Enumerating Domain Groups
enumdomgroups

Group Information Queries
querygroup 0x200

User Information Queries
queryuser yashika

Enumerating Privileges
enumprivs

Domain Password Information
getdompwinfo

User Password Information
getusrdompwinfo 0x1f4

Enumerating SID from LSA
lsaenumsid

Creating Domain User
createdomuser hackersetuserinfo2 hacker 24 Password@1enumdomusers

Lookup User Names
lookupnames hacker

Enumerating Alias Groups
enumalsgroups builtin

Delete Domain User
deletedomuser hacker

Net Share Enumeration
netshareenumnetshareenumall

Net Share Get Information
netsharegetinfo Confidential

Enumerating Domains
enumdomains

Enumerating Domain Groups
enumdomgroupsenumdomusersqueryusersgroups 0x44fquerygroupmem 0x201

Change Password of User
chgpasswd raj Password@1 Password@987

Create Domain Group
createdomgroup newgroupenumdomgroups

Delete Domain Group
deletedomgroup newgroupenumdomgroup

Domain Lookup
lookupdomain ignite

SAM Lookup
samlookupnames domain rajsamlookuprids domain 0x44f

SID Lookup
lsaenumsid

LSA Query
lsaquerydsroledominfo

LSA Create Account
lookupnames rajlsacreateaccount S-1-5-21-3232368669-2512470540-2741904768-1103

LSA Group Privileges
lsaenumsidlookupsids S-1-1-0lsaenumacctrights S-1-1-0

lsaaddpriv S-1-1-0 SeCreateTokenPrivilegelsaenumprivsaccount S-1-1-0lsadelpriv S-1-1-0 SeCreateTokenPrivilegelsaenumprivsaccount S-1-1-0

LSA Account Privileges
lookupnames rajlsaaddacctrights S-1-5-21-3232368669-2512470540-2741904768-1103 SeCreateTokenPrivilegelsaenumprivsaccount S-1-5-21-3232368669-2512470540-2741904768-1103lsaremoveacctrights S-1-5-21-3232368669-2512470540-2741904768-1103 SeCreateTokenPrivilegelsaenumprivsaccount S-1-5-21-3232368669-2512470540-2741904768-1103

lsalookupprivvalue SeCreateTokenPrivielge
LSA Security Objects
lsaquerysecobj文末小结
在本文中,我们能够使用rpcclient工具通过域内的SMB和RPC枚举大量信息,本文可以作为红队攻击和列举域的参考,但也有助于蓝队了解和测试在域上应用的保护及其用户的措施~
原创文章,作者:七芒星实验室,如若转载,请注明出处:https://www.sudun.com/ask/34267.html