more with rpcclient

简介: http://www.foofus.net/~jmk/passhash.htmlGot asked to help remotely locate local admins on boxes on a network.

http://www.foofus.net/~jmk/passhash.html

Got asked to help remotely locate local admins on boxes on a network.

rpcclient $> enumalsgroups
Usage: enumalsgroups builtin|domain [access mask]


rpcclient $> enumalsgroups builtin

group:[Administrators] rid:[0x220]

group:[Backup Operators] rid:[0x227]

group:[Guests] rid:[0x222]

group:[Network Configuration Operators] rid:[0x22c]

group:[Power Users] rid:[0x223]

group:[Remote Desktop Users] rid:[0x22b]

group:[Replicator] rid:[0x228]

group:[Users] rid:[0x221]


Now you would think that doing a querygroup would give you the right output, but actually you get a:

rpcclient $> querygroup 0x220
result was NT_STATUS_NO_SUCH_GROUP


Honestly I have no idea why this doesn't work, it *should*. If anyone knows why it doesn't I know more than one person who would like to know.

Anyway it takes one more step but you can do it this way:

rpcclient $> queryaliasmem
Usage: queryaliasmem builtin|domain rid [access mask]


rpcclient $> queryaliasmem builtin 0x220
sid:[S-1-5-21-1214440339-1383384898-839522115-500]

sid:[S-1-5-21-1214440339-1383384898-839522115-1003]

sid:[S-1-5-21-2392188729-2485841371-4291725810-512]


Then you can look up who those SIDs belong to

rpcclient $> lookupsids

Usage: lookupsids [sid1 [sid2 [...]]]


rpcclient $> lookupsids S-1-5-21-1214440339- 1383384898-839522115-500
S-1-5-21-1214440339-1383384898-839522115-500 PC/Administrator (1)


rpcclient $> lookupsids
S-1-5-21-1214440339-1383384898-839522115-1003
S-1-5-21-1214440339-1383384898-839522115-1003 PC/user (1)


rpcclient $> lookupsids
S-1-5-21-2392188729-2485841371-4291725810-512 rpc_api_pipe: Remote machine 192.168.242.128 pipe /lsarpc fnum 0x4001 returned critical error. Error was Call timed out: server did not respond after 10000 milliseconds result was NT_STATUS_IO_TIMEOUT


Not sure about the 512 (its a MS built-in account I think) but the 1003 was the user I added to the local admins group.

目录
相关文章
|
Linux BI 网络架构
mtr网络监测工具
mtr网络监测工具
1083 2
mtr网络监测工具
|
网络安全 数据安全/隐私保护 Docker
GitLab安装使用
GitLab安装使用
488 0
GitLab安装使用
|
容器
多线程学习之生产者和消费者与阻塞队列的关系
多线程学习之生产者和消费者与阻塞队列的关系
|
缓存 Java 测试技术
day27:Java零基础 - 动态代理
【7月更文挑战第27天】🏆本文收录于「滚雪球学Java」专栏,专业攻坚指数级提升,希望能够助你一臂之力,帮你早日登顶实现财富自由🚀;同时,欢迎大家关注&&收藏&&订阅!持续更新中,up!up!up!!
91 2
day27:Java零基础 - 动态代理
|
Oracle 网络协议 关系型数据库
从零开始教你安装Oracle数据库!Oracle 数据库的安装和使用指导
本文是一篇Oracle数据库的安装和使用教程,不仅记录了Oracle数据库的下载,安装和配置,还通过表空间的创建示例分析Oracle数据库的具体使用。另外,文章中详细记录了Oracle数据库在连接配置中可能遇到的异常问题,并对相应的问题给出具体的解决方案。这篇文章完整记录了数据库的安装和使用,适合作为学习和Oracle相关异常问题修复的参考。
5939 0
从零开始教你安装Oracle数据库!Oracle 数据库的安装和使用指导
|
算法 安全 大数据
喜迎双十一:态势感知功能发布
喜迎双十一:态势感知功能发布
1812 0
|
JSON 数据格式 Ruby
ERROR: Error installing json:The 'json' native gem requires installed build tools.
版权声明:本文为 testcs_dn(微wx笑) 原创文章,非商用自由转载-保持署名-注明出处,谢谢。 https://blog.csdn.net/testcs_dn/article/details/50275683 ...
846 0
|
网络协议 Linux 网络性能优化
Linux kernel tcp 连接建立详解——由listen系统调用的backlog参数引发的长篇大论
原文是openoffice写的,图片什么不太好弄,我只把目录和第一章放在这里。 全文的pdf从这里下载。listen_backlog.pdf 再来个流程图。tcp连接建立流程图.
1680 0