βš”οΈ1 - Scans & Recon

Enumerate Network

We will starting to sacan all ip range for found servers/pc/availables IPs -->


We can see with this scan the availables ips with smb active and enumerate a lot of info:

  • Domain: sevenkingdoms.local - 1 ip

    • KINGSLANDING (windows server 2019) - 192.168.56.10

  • Domain: north.sevenkingdoms.local - 2 ips

    • CASTELBLACK (windows server 2019) (signing false) - 192.168.56.22

    • WINTERFELL (windows server 2019) - 192.168.56.11

  • Domain: essos.local - 2 ips

    • BRAAVOS (windows server 2016) (signing false) - 192.168.56.23

    • MEEREEN (windows server 2016) - 192.168.56.12


Nmap


Find DC IP

I can see we have a domain : (sevenkingdoms.local) and a sub domain about this: (north.sevenkingdoms.local), for end another domain: (essos.local)

I replaced <domain> in the command for the name of domain and subdomains we have

Setup /etc/hosts and Kerberos

All right, for we can use kerberos in linux we need configurate the /etc/hosts file and add the domains, subdomains and ips -->

The order of implementing this is: ip -> domain name -> PcName+domain name -> PcName

Linux kerberos client

We answer the questions with :

  • realm : essos.local

  • servers : meereen.essos.local

    • admin_server : meereen.essos.local

The /etc/krb5.conf archive should be content this -->

If you doesnt understant any of this file, no problema, send this content at your chatGPT friend and he tell you xd

Last updated