DC通常开了88和389,但ldap不只是域才用,464端口用于复制、用户和计算机身份验证、信任,所以也可以探测464端口
来判断是否是DC。
net group “domain controllers” /do
nslookup -type=all _ldap._tcp.dc._msdcs.redteam.lab (`会返回所有dcip`)
net time /do
systeminfo
net config workstation
ipconfig /all
nltest /domain_trusts /all_trusts #返回受信任域列表
nltest /dclist:redteam.lab
nltest /dsgetdc:redteam.lab
通过DNS指向 (需要绑定DNS)
Windows
nslookup –qt=ns redteam.lab
Nslookup -type=SRV _ldap._tcp.redteam.lab
data:image/s3,"s3://crabby-images/61e01/61e01719ea371c45520d00df3b06d7a80cd55b23" alt=""
linux
dig redteam.lab @192.168.129.130
dig _ldap._tcp.redteam.lab srv @192.168.129.130
data:image/s3,"s3://crabby-images/72cf1/72cf1e7e7db1651981d19c2dadde95003f346f73" alt=""
域外定位域机器 (无需绑定DNS)
nslookup redteam.lab 192.168.129.130
nslookup dmwin10.redteam.lab 192.168.129.130
data:image/s3,"s3://crabby-images/8a03d/8a03d207e922d5df89851fef51e6a0944f2db082" alt=""
History
- Created 2022-10-22 14:53
- Published 2020-09-22 14:54
- Updated 2024-10-20 23:14