Escape
Overview
Reconnaissance
Services Discovery
$ sudo nmap -n -p- -Pn -v -sS -T4 --min-rate 1000 10.129.140.112 -oN ports.nmap
...
PORT STATE SERVICE
53/tcp open domain
88/tcp open kerberos-sec
135/tcp open msrpc
139/tcp open netbios-ssn
389/tcp open ldap
445/tcp open microsoft-ds
464/tcp open kpasswd5
593/tcp open http-rpc-epmap
636/tcp open ldapssl
1433/tcp open ms-sql-s
3268/tcp open globalcatLDAP
3269/tcp open globalcatLDAPssl
...RootDSE
SMB
SQL Server Procedures.pdf
MSSQL
Initial Access
UNC Path Injection
WinRM
Discovery
LDAP Search
User Ryan.Cooper
Group
Privilege Escalation
Certified Pre-Owned
Technique ESC1
Certificate Signing Request
Authentication
Miscellaneous
Silver Ticket Attack
Last updated