ldapdomaindump


Using the valid domain credential, I can use ldapdomaindump to get a overview of the target domain

┌──(kali㉿kali)-[~/…/htb/labs/ghost/ldapdomaindump]
└─$ ldapdomaindump ldap://$IP:389 -u 'GHOST.HTB\florence.ramirez' -p 'uxLmt*udNc6t3HrF' -n $IP --no-json --no-grep
[*] Connecting to host...
[*] Binding to host
[+] Bind OK
[*] Starting domain dump
[+] Domain dump finished

done

Computers


linux-dev-ws01.ghost.htb federation.ghost.htb

Domain Trust


corp.ghost.htb

Domain Groups (none default)


Domain Users