Advertisement
Guest User

Untitled

a guest
Dec 7th, 2019
1,887
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 10.89 KB | None | 0 0
  1. enum4linux
  2. Starting enum4linux v0.8.9 ( http://labs.portcullis.co.uk/application/enum4linux/ ) on Sat Dec 7 11:28:35 2019
  3.  
  4. ==========================
  5. | Target Information |
  6. ==========================
  7. Target ........... resolute.htb
  8. RID Range ........ 500-550,1000-1050
  9. Username ......... ''
  10. Password ......... ''
  11. Known Usernames .. administrator, guest, krbtgt, domain admins, root, bin, none
  12.  
  13.  
  14. ====================================================
  15. | Enumerating Workgroup/Domain on resolute.htb |
  16. ====================================================
  17. [E] Can't find workgroup/domain
  18.  
  19.  
  20. ============================================
  21. | Nbtstat Information for resolute.htb |
  22. ============================================
  23. Looking up status of 10.10.10.169
  24. No reply from 10.10.10.169
  25.  
  26. =====================================
  27. | Session Check on resolute.htb |
  28. =====================================
  29. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 437.
  30. [+] Server resolute.htb allows sessions using username '', password ''
  31. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 451.
  32. [+] Got domain/workgroup name:
  33.  
  34. ===========================================
  35. | Getting domain SID for resolute.htb |
  36. ===========================================
  37. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 359.
  38. Domain Name: MEGABANK
  39. Domain Sid: S-1-5-21-1392959593-3013219662-3596683436
  40. [+] Host is part of a domain (not a workgroup)
  41.  
  42. ======================================
  43. | OS information on resolute.htb |
  44. ======================================
  45. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 458.
  46. Use of uninitialized value $os_info in concatenation (.) or string at ./enum4linux.pl line 464.
  47. [+] Got OS info for resolute.htb from smbclient:
  48. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 467.
  49. [+] Got OS info for resolute.htb from srvinfo:
  50. Could not initialise srvsvc. Error was NT_STATUS_ACCESS_DENIED
  51.  
  52. =============================
  53. | Users on resolute.htb |
  54. =============================
  55. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 866.
  56. index: 0x10b0 RID: 0x19ca acb: 0x00000010 Account: abigail Name: (null) Desc: (null)
  57. index: 0xfbc RID: 0x1f4 acb: 0x00000210 Account: Administrator Name: (null) Desc: Built-in account for administering the computer/domain
  58. index: 0x10b4 RID: 0x19ce acb: 0x00000010 Account: angela Name: (null) Desc: (null)
  59. index: 0x10bc RID: 0x19d6 acb: 0x00000010 Account: annette Name: (null) Desc: (null)
  60. index: 0x10bd RID: 0x19d7 acb: 0x00000010 Account: annika Name: (null) Desc: (null)
  61. index: 0x10b9 RID: 0x19d3 acb: 0x00000010 Account: claire Name: (null) Desc: (null)
  62. index: 0x10bf RID: 0x19d9 acb: 0x00000010 Account: claude Name: (null) Desc: (null)
  63. index: 0xfbe RID: 0x1f7 acb: 0x00000215 Account: DefaultAccount Name: (null) Desc: A user account managed by the system.
  64. index: 0x10b5 RID: 0x19cf acb: 0x00000010 Account: felicia Name: (null) Desc: (null)
  65. index: 0x10b3 RID: 0x19cd acb: 0x00000010 Account: fred Name: (null) Desc: (null)
  66. index: 0xfbd RID: 0x1f5 acb: 0x00000215 Account: Guest Name: (null) Desc: Built-in account for guest access to the computer/domain
  67. index: 0x10b6 RID: 0x19d0 acb: 0x00000010 Account: gustavo Name: (null) Desc: (null)
  68. index: 0xff4 RID: 0x1f6 acb: 0x00000011 Account: krbtgt Name: (null) Desc: Key Distribution Center Service Account
  69. index: 0x10b1 RID: 0x19cb acb: 0x00000010 Account: marcus Name: (null) Desc: (null)
  70. index: 0x10a9 RID: 0x457 acb: 0x00000210 Account: marko Name: Marko Novak Desc: Account created. Password set to Welcome123!
  71. index: 0x10c0 RID: 0x2775 acb: 0x00000010 Account: melanie Name: (null) Desc: (null)
  72. index: 0x10c3 RID: 0x2778 acb: 0x00000010 Account: naoki Name: (null) Desc: (null)
  73. index: 0x10ba RID: 0x19d4 acb: 0x00000010 Account: paulo Name: (null) Desc: (null)
  74. index: 0x10be RID: 0x19d8 acb: 0x00000010 Account: per Name: (null) Desc: (null)
  75. index: 0x10a3 RID: 0x451 acb: 0x00000210 Account: ryan Name: Ryan Bertrand Desc: (null)
  76. index: 0x10b2 RID: 0x19cc acb: 0x00000010 Account: sally Name: (null) Desc: (null)
  77. index: 0x10c2 RID: 0x2777 acb: 0x00000010 Account: simon Name: (null) Desc: (null)
  78. index: 0x10bb RID: 0x19d5 acb: 0x00000010 Account: steve Name: (null) Desc: (null)
  79. index: 0x10b8 RID: 0x19d2 acb: 0x00000010 Account: stevie Name: (null) Desc: (null)
  80. index: 0x10af RID: 0x19c9 acb: 0x00000010 Account: sunita Name: (null) Desc: (null)
  81. index: 0x10b7 RID: 0x19d1 acb: 0x00000010 Account: ulf Name: (null) Desc: (null)
  82. index: 0x10c1 RID: 0x2776 acb: 0x00000010 Account: zach Name: (null) Desc: (null)
  83.  
  84. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 881.
  85. user:[Administrator] rid:[0x1f4]
  86. user:[Guest] rid:[0x1f5]
  87. user:[krbtgt] rid:[0x1f6]
  88. user:[DefaultAccount] rid:[0x1f7]
  89. user:[ryan] rid:[0x451]
  90. user:[marko] rid:[0x457]
  91. user:[sunita] rid:[0x19c9]
  92. user:[abigail] rid:[0x19ca]
  93. user:[marcus] rid:[0x19cb]
  94. user:[sally] rid:[0x19cc]
  95. user:[fred] rid:[0x19cd]
  96. user:[angela] rid:[0x19ce]
  97. user:[felicia] rid:[0x19cf]
  98. user:[gustavo] rid:[0x19d0]
  99. user:[ulf] rid:[0x19d1]
  100. user:[stevie] rid:[0x19d2]
  101. user:[claire] rid:[0x19d3]
  102. user:[paulo] rid:[0x19d4]
  103. user:[steve] rid:[0x19d5]
  104. user:[annette] rid:[0x19d6]
  105. user:[annika] rid:[0x19d7]
  106. user:[per] rid:[0x19d8]
  107. user:[claude] rid:[0x19d9]
  108. user:[melanie] rid:[0x2775]
  109. user:[zach] rid:[0x2776]
  110. user:[simon] rid:[0x2777]
  111. user:[naoki] rid:[0x2778]
  112.  
  113. =========================================
  114. | Share Enumeration on resolute.htb |
  115. =========================================
  116. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 640.
  117. smb1cli_req_writev_submit: called for dialect[SMB3_11] server[resolute.htb]
  118. do_connect: Connection to resolute.htb failed (Error NT_STATUS_RESOURCE_NAME_NOT_FOUND)
  119.  
  120. Sharename Type Comment
  121. --------- ---- -------
  122. Error returning browse list: NT_STATUS_REVISION_MISMATCH
  123. Reconnecting with SMB1 for workgroup listing.
  124. Failed to connect with SMB1 -- no workgroup available
  125.  
  126. [+] Attempting to map shares on resolute.htb
  127.  
  128. ====================================================
  129. | Password Policy Information for resolute.htb |
  130. ====================================================
  131.  
  132.  
  133. [+] Attaching to resolute.htb using a NULL share
  134.  
  135. [+] Trying protocol 445/SMB...
  136.  
  137. [+] Found domain(s):
  138.  
  139. [+] MEGABANK
  140. [+] Builtin
  141.  
  142. [+] Password Info for Domain: MEGABANK
  143.  
  144. [+] Minimum password length: 7
  145. [+] Password history length: 24
  146. [+] Maximum password age: Not Set
  147. [+] Password Complexity Flags: 000000
  148.  
  149. [+] Domain Refuse Password Change: 0
  150. [+] Domain Password Store Cleartext: 0
  151. [+] Domain Password Lockout Admins: 0
  152. [+] Domain Password No Clear Change: 0
  153. [+] Domain Password No Anon Change: 0
  154. [+] Domain Password Complex: 0
  155.  
  156. [+] Minimum password age: 1 day 4 minutes
  157. [+] Reset Account Lockout Counter: 30 minutes
  158. [+] Locked Account Duration: 30 minutes
  159. [+] Account Lockout Threshold: None
  160. [+] Forced Log off Time: Not Set
  161.  
  162. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 501.
  163.  
  164. [+] Retieved partial password policy with rpcclient:
  165.  
  166. Password Complexity: Disabled
  167. Minimum Password Length: 7
  168.  
  169.  
  170. ==============================
  171. | Groups on resolute.htb |
  172. ==============================
  173. Use of uninitialized value $global_workgroup in concatenation (.) or string at ./enum4linux.pl line 542.
  174.  
  175. [+] Getting builtin groups:
  176. group:[Account Operators] rid:[0x224]
  177. group:[Pre-Windows 2000 Compatible Access] rid:[0x22a]
  178. group:[Incoming Forest Trust Builders] rid:[0x22d]
  179. group:[Windows Authorization Access Group] rid:[0x230]
  180. group:[Terminal Server License Servers] rid:[0x231]
  181. group:[Administrators] rid:[0x220]
  182. group:[Users] rid:[0x221]
  183. group:[Guests] rid:[0x222]
  184. group:[Print Operators] rid:[0x226]
  185. group:[Backup Operators] rid:[0x227]
  186. group:[Replicator] rid:[0x228]
  187. group:[Remote Desktop Users] rid:[0x22b]
  188. group:[Network Configuration Operators] rid:[0x22c]
  189. group:[Performance Monitor Users] rid:[0x22e]
  190. group:[Performance Log Users] rid:[0x22f]
  191. group:[Distributed COM Users] rid:[0x232]
  192. group:[IIS_IUSRS] rid:[0x238]
  193. group:[Cryptographic Operators] rid:[0x239]
  194. group:[Event Log Readers] rid:[0x23d]
  195. group:[Certificate Service DCOM Access] rid:[0x23e]
  196. group:[RDS Remote Access Servers] rid:[0x23f]
  197. group:[RDS Endpoint Servers] rid:[0x240]
  198. group:[RDS Management Servers] rid:[0x241]
  199. group:[Hyper-V Administrators] rid:[0x242]
  200. group:[Access Control Assistance Operators] rid:[0x243]
  201. group:[Remote Management Users] rid:[0x244]
  202. group:[System Managed Accounts Group] rid:[0x245]
  203. group:[Storage Replica Administrators] rid:[0x246]
  204. group:[Server Operators] rid:[0x225]
  205. Group 'Domain Users' (RID: 513) has member: MEGABANK\Administrator
  206. Group 'Domain Users' (RID: 513) has member: MEGABANK\DefaultAccount
  207. Group 'Domain Users' (RID: 513) has member: MEGABANK\krbtgt
  208. Group 'Domain Users' (RID: 513) has member: MEGABANK\ryan
  209. Group 'Domain Users' (RID: 513) has member: MEGABANK\marko
  210. Group 'Domain Users' (RID: 513) has member: MEGABANK\sunita
  211. Group 'Domain Users' (RID: 513) has member: MEGABANK\abigail
  212. Group 'Domain Users' (RID: 513) has member: MEGABANK\marcus
  213. Group 'Domain Users' (RID: 513) has member: MEGABANK\sally
  214. Group 'Domain Users' (RID: 513) has member: MEGABANK\fred
  215. Group 'Domain Users' (RID: 513) has member: MEGABANK\angela
  216. Group 'Domain Users' (RID: 513) has member: MEGABANK\felicia
  217. Group 'Domain Users' (RID: 513) has member: MEGABANK\gustavo
  218. Group 'Domain Users' (RID: 513) has member: MEGABANK\ulf
  219. Group 'Domain Users' (RID: 513) has member: MEGABANK\stevie
  220. Group 'Domain Users' (RID: 513) has member: MEGABANK\claire
  221. Group 'Domain Users' (RID: 513) has member: MEGABANK\paulo
  222. Group 'Domain Users' (RID: 513) has member: MEGABANK\steve
  223. Group 'Domain Users' (RID: 513) has member: MEGABANK\annette
  224. Group 'Domain Users' (RID: 513) has member: MEGABANK\annika
  225. Group 'Domain Users' (RID: 513) has member: MEGABANK\per
  226. Group 'Domain Users' (RID: 513) has member: MEGABANK\claude
  227. Group 'Domain Users' (RID: 513) has member: MEGABANK\melanie
  228. Group 'Domain Users' (RID: 513) has member: MEGABANK\zach
  229. Group 'Domain Users' (RID: 513) has member: MEGABANK\simon
  230. Group 'Domain Users' (RID: 513) has member: MEGABANK\naoki
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement