smbclient //192.168.110.55/NETLOGON -U riley%P@ssw0rd
Try "help" to get a list of possible commands.
smb: \> ls
. D 0 Sun Mar 6 10:17:37 2022
.. D 0 Sun Mar 6 10:19:36 2022
5050623 blocks of size 4096. 1807364 blocks available
enum4linux-ng 192.168.110.55 -u 'riley' -p 'P@ssw0rd'
ENUM4LINUX - next generation (v1.3.4)
==========================
| Target Information |
==========================
[*] Target ........... 192.168.110.55
[*] Username ......... 'riley'
[*] Random Username .. 'ftfxxgaf'
[*] Password ......... 'P@ssw0rd'
[*] Timeout .......... 5 second(s)
=======================================
| Listener Scan on 192.168.110.55 |
=======================================
[*] Checking LDAP
[+] LDAP is accessible on 389/tcp
[*] Checking LDAPS
[+] LDAPS is accessible on 636/tcp
[*] Checking SMB
[+] SMB is accessible on 445/tcp
[*] Checking SMB over NetBIOS
[+] SMB over NetBIOS is accessible on 139/tcp
======================================================
| Domain Information via LDAP for 192.168.110.55 |
======================================================
[*] Trying LDAP
[+] Appears to be root/parent DC
[+] Long domain name is: painters.htb
=============================================================
| NetBIOS Names and Workgroup/Domain for 192.168.110.55 |
=============================================================
[+] Got domain/workgroup name: PAINTERS
[+] Full NetBIOS names information:
- DC <00> - B <ACTIVE> Workstation Service
- PAINTERS <00> - <GROUP> B <ACTIVE> Domain/Workgroup Name
- PAINTERS <1c> - <GROUP> B <ACTIVE> Domain Controllers
- DC <20> - B <ACTIVE> File Server Service
- PAINTERS <1b> - B <ACTIVE> Domain Master Browser
- MAC Address = 00-50-56-94-3B-BC
===========================================
| SMB Dialect Check on 192.168.110.55 |
===========================================
[*] Trying on 445/tcp
[+] Supported dialects and settings:
Supported dialects:
SMB 1.0: false
SMB 2.02: true
SMB 2.1: false
SMB 3.0: true
SMB 3.1.1: true
Preferred dialect: SMB 3.0
SMB1 only: false
SMB signing required: true
=============================================================
| Domain Information via SMB session for 192.168.110.55 |
=============================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found domain information via SMB
NetBIOS computer name: DC
NetBIOS domain name: PAINTERS
DNS domain: painters.htb
FQDN: DC.painters.htb
Derived membership: domain member
Derived domain: PAINTERS
===========================================
| RPC Session Check on 192.168.110.55 |
===========================================
[*] Check for null session
[+] Server allows session using username '', password ''
[*] Check for user session
[+] Server allows session using username 'riley', password 'P@ssw0rd'
[*] Check for random user
[-] Could not establish random user session: STATUS_LOGON_FAILURE
=====================================================
| Domain Information via RPC for 192.168.110.55 |
=====================================================
[-] Could not get domain information via 'lsaquery': timed out
=================================================
| OS Information via RPC for 192.168.110.55 |
=================================================
[*] Enumerating via unauthenticated SMB session on 445/tcp
[+] Found OS information via SMB
[*] Enumerating via 'srvinfo'
[+] Found OS information via 'srvinfo'
[+] After merging OS information we have the following result:
OS: Windows 10, Windows Server 2019, Windows Server 2016
OS version: '10.0'
OS release: ''
OS build: '20348'
Native OS: not supported
Native LAN manager: not supported
Platform id: '500'
Server type: '0x80102b'
Server type string: Wk Sv PDC Tim NT
=======================================
| Users via RPC on 192.168.110.55 |
=======================================
[*] Enumerating users via 'querydispinfo'
[-] Could not find users via 'querydispinfo': timed out
[*] Enumerating users via 'enumdomusers'
[-] Could not find users via 'enumdomusers': timed out
========================================
| Groups via RPC on 192.168.110.55 |
========================================
[*] Enumerating local groups
[-] Could not get groups via 'enumalsgroups domain': timed out
[*] Enumerating builtin groups
[-] Could not get groups via 'enumalsgroups builtin': timed out
[*] Enumerating domain groups
[-] Could not get groups via 'enumdomgroups': timed out
========================================
| Shares via RPC on 192.168.110.55 |
========================================
[*] Enumerating shares
[+] Found 5 share(s):
ADMIN$:
comment: Remote Admin
type: Disk
C$:
comment: Default share
type: Disk
IPC$:
comment: Remote IPC
type: IPC
NETLOGON:
comment: Logon server share
type: Disk
SYSVOL:
comment: Logon server share
type: Disk
[*] Testing share ADMIN$
[+] Mapping: DENIED, Listing: N/A
[*] Testing share C$
[+] Mapping: DENIED, Listing: N/A
[*] Testing share IPC$
[+] Mapping: OK, Listing: NOT SUPPORTED
[*] Testing share NETLOGON
[-] Could not check share: timed out
[*] Testing share SYSVOL
[-] Could not check share: timed out
===========================================
| Policies via RPC for 192.168.110.55 |
===========================================
[*] Trying port 445/tcp
[+] Found policy:
Domain password information:
Password history length: None
Minimum password length: 7
Maximum password age: 41 days 23 hours 53 minutes
Password properties:
- DOMAIN_PASSWORD_COMPLEX: true
- DOMAIN_PASSWORD_NO_ANON_CHANGE: false
- DOMAIN_PASSWORD_NO_CLEAR_CHANGE: false
- DOMAIN_PASSWORD_LOCKOUT_ADMINS: false
- DOMAIN_PASSWORD_PASSWORD_STORE_CLEARTEXT: false
- DOMAIN_PASSWORD_REFUSE_PASSWORD_CHANGE: false
Domain lockout information:
Lockout observation window: 30 minutes
Lockout duration: 30 minutes
Lockout threshold: None
Domain logoff information:
Force logoff time: not set
===========================================
| Printers via RPC for 192.168.110.55 |
===========================================
[+] No printers available
Completed after 94.27 seconds