159 lines
6.1 KiB
Plaintext
159 lines
6.1 KiB
Plaintext
Starting enum4linux v0.9.1 ( http://labs.portcullis.co.uk/application/enum4linux/ ) on Wed Oct 15 16:46:08 2025
|
||
|
||
[34m =========================================( [0m[32mTarget Information[0m[34m )=========================================
|
||
|
||
[0mTarget ........... 10.10.241.222
|
||
RID Range ........ 500-550,1000-1050
|
||
Username ......... ''
|
||
Password ......... ''
|
||
Known Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none
|
||
|
||
|
||
[34m ===========================( [0m[32mEnumerating Workgroup/Domain on 10.10.241.222[0m[34m )===========================
|
||
|
||
[0m[33m
|
||
[E] [0m[31mCan't find workgroup/domain
|
||
|
||
[0m
|
||
|
||
[34m ===============================( [0m[32mNbtstat Information for 10.10.241.222[0m[34m )===============================
|
||
|
||
[0mLooking up status of 10.10.241.222
|
||
No reply from 10.10.241.222
|
||
|
||
[34m ===================================( [0m[32mSession Check on 10.10.241.222[0m[34m )===================================
|
||
|
||
[0m[33m
|
||
[+] [0m[32mServer 10.10.241.222 allows sessions using username '', password ''
|
||
|
||
[0m
|
||
[34m ================================( [0m[32mGetting domain SID for 10.10.241.222[0m[34m )================================
|
||
|
||
[0mDomain Name: THM-AD
|
||
Domain Sid: S-1-5-21-3591857110-2884097990-301047963
|
||
[33m
|
||
[+] [0m[32mHost is part of a domain (not a workgroup)
|
||
|
||
[0m
|
||
[34m ==================================( [0m[32mOS information on 10.10.241.222[0m[34m )==================================
|
||
|
||
[0m[33m
|
||
[E] [0m[31mCan't get OS info with smbclient
|
||
|
||
[0m[33m
|
||
[+] [0m[32mGot OS info for 10.10.241.222 from srvinfo:
|
||
[0mdo_cmd: Could not initialise srvsvc. Error was NT_STATUS_ACCESS_DENIED
|
||
|
||
|
||
[34m =======================================( [0m[32mUsers on 10.10.241.222[0m[34m )=======================================
|
||
|
||
[0m[33m
|
||
[E] [0m[31mCouldn't find users using querydispinfo: NT_STATUS_ACCESS_DENIED
|
||
|
||
[0m
|
||
[33m
|
||
[E] [0m[31mCouldn't find users using enumdomusers: NT_STATUS_ACCESS_DENIED
|
||
|
||
[0m
|
||
[34m =================================( [0m[32mShare Enumeration on 10.10.241.222[0m[34m )=================================
|
||
|
||
[0mdo_connect: Connection to 10.10.241.222 failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
|
||
|
||
Sharename Type Comment
|
||
--------- ---- -------
|
||
Reconnecting with SMB1 for workgroup listing.
|
||
Unable to connect with SMB1 -- no workgroup available
|
||
[33m
|
||
[+] [0m[32mAttempting to map shares on 10.10.241.222
|
||
|
||
[0m
|
||
[34m ===========================( [0m[32mPassword Policy Information for 10.10.241.222[0m[34m )===========================
|
||
|
||
[0m[33m
|
||
[E] [0m[31mUnexpected error from polenum:
|
||
|
||
[0m
|
||
|
||
[+] Attaching to 10.10.241.222 using a NULL share
|
||
|
||
[+] Trying protocol 139/SMB...
|
||
|
||
[!] Protocol failed: Cannot request session (Called Name:10.10.241.222)
|
||
|
||
[+] Trying protocol 445/SMB...
|
||
|
||
[!] Protocol failed: SMB SessionError: code: 0xc000006d - STATUS_LOGON_FAILURE - The attempted logon is invalid. This is either due to a bad username or authentication information.
|
||
|
||
|
||
[33m
|
||
[E] [0m[31mFailed to get password policy with rpcclient
|
||
|
||
[0m
|
||
|
||
[34m ======================================( [0m[32mGroups on 10.10.241.222[0m[34m )======================================
|
||
|
||
[0m[33m
|
||
[+] [0m[32mGetting builtin groups:
|
||
|
||
[0m[33m
|
||
[+] [0m[32m Getting builtin group memberships:
|
||
|
||
[0m[33m
|
||
[+] [0m[32m Getting local groups:
|
||
|
||
[0m[33m
|
||
[+] [0m[32m Getting local group memberships:
|
||
|
||
[0m[33m
|
||
[+] [0m[32m Getting domain groups:
|
||
|
||
[0m[33m
|
||
[+] [0m[32m Getting domain group memberships:
|
||
|
||
[0m
|
||
[34m ==================( [0m[32mUsers on 10.10.241.222 via RID cycling (RIDS: 500-550,1000-1050)[0m[34m )==================
|
||
|
||
[0m[33m
|
||
[I] [0m[36mFound new SID:
|
||
[0mS-1-5-21-3591857110-2884097990-301047963
|
||
[33m
|
||
[I] [0m[36mFound new SID:
|
||
[0mS-1-5-21-3591857110-2884097990-301047963
|
||
[33m
|
||
[+] [0m[32mEnumerating users using SID S-1-5-21-3532885019-1334016158-1514108833 and logon username '', password ''
|
||
|
||
[0mS-1-5-21-3532885019-1334016158-1514108833-500 ATTACKTIVEDIREC\Administrator (Local User)
|
||
S-1-5-21-3532885019-1334016158-1514108833-501 ATTACKTIVEDIREC\Guest (Local User)
|
||
S-1-5-21-3532885019-1334016158-1514108833-503 ATTACKTIVEDIREC\DefaultAccount (Local User)
|
||
S-1-5-21-3532885019-1334016158-1514108833-504 ATTACKTIVEDIREC\WDAGUtilityAccount (Local User)
|
||
S-1-5-21-3532885019-1334016158-1514108833-513 ATTACKTIVEDIREC\None (Domain Group)
|
||
[33m
|
||
[+] [0m[32mEnumerating users using SID S-1-5-21-3591857110-2884097990-301047963 and logon username '', password ''
|
||
|
||
[0mS-1-5-21-3591857110-2884097990-301047963-500 THM-AD\Administrator (Local User)
|
||
S-1-5-21-3591857110-2884097990-301047963-501 THM-AD\Guest (Local User)
|
||
S-1-5-21-3591857110-2884097990-301047963-502 THM-AD\krbtgt (Local User)
|
||
S-1-5-21-3591857110-2884097990-301047963-512 THM-AD\Domain Admins (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-513 THM-AD\Domain Users (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-514 THM-AD\Domain Guests (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-515 THM-AD\Domain Computers (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-516 THM-AD\Domain Controllers (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-517 THM-AD\Cert Publishers (Local Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-518 THM-AD\Schema Admins (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-519 THM-AD\Enterprise Admins (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-520 THM-AD\Group Policy Creator Owners (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-521 THM-AD\Read-only Domain Controllers (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-522 THM-AD\Cloneable Domain Controllers (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-525 THM-AD\Protected Users (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-526 THM-AD\Key Admins (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-527 THM-AD\Enterprise Key Admins (Domain Group)
|
||
S-1-5-21-3591857110-2884097990-301047963-1000 THM-AD\ATTACKTIVEDIREC$ (Local User)
|
||
|
||
[34m ===============================( [0m[32mGetting printer info for 10.10.241.222[0m[34m )===============================
|
||
|
||
[0mdo_cmd: Could not initialise spoolss. Error was NT_STATUS_ACCESS_DENIED
|
||
|
||
|
||
enum4linux complete on Wed Oct 15 16:56:19 2025
|
||
|