LDAPDomainDump


Using the credential of the v.ventz user, I can get an overview of the target domain with ldapdomaindump

┌──(kali㉿kali)-[~/PEN-200/PG_PRACTICE/resourced/ldapdomaindump]
└─$ ldapdomaindump ResourceDC.resourced.local -u 'RESOURCED.LOCAL\v.ventz' -p 'HotelCalifornia194!' -n ResourceDC.resourced.local --no-json --no-grep 
[*] Connecting to host...
[*] Binding to host
[+] Bind OK
[*] Starting domain dump
[+] Domain dump finished

Complete

Computers


ResourceDC.resourced.local

Users


  • The same CLEARTEXT credential of the v.ventz user can be seen in the LDAP Description attribute; HotelCalifornia194!
  • The L.Livingstone user is the only user that can either WinRM or RDP to the target system

Groups


Groups are all default