Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 33 guests and 2 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow Gaining Domain access via local administrator
Ethical Hacker Community Forums
December 02, 2008, 07:44:28 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Gaining Domain access via local administrator  (Read 1547 times)
0 Members and 1 Guest are viewing this topic.
det_security08
Newbie
*
Offline Offline

Posts: 8


View Profile
« on: June 23, 2008, 07:38:05 PM »

Are there any Windows commands or privilege escalation techniques one might be able to employ in order to gain access to add a domain user?  In a mixed mode (Windows 2000 and 2003) environment, I've successfully gained access to many Windows 2000 servers thanks to some unpatched vulnerabilities and weak local administrator passwords.  However none of the 2000 hosts are DCs. 

My question is, with either the local admin account or even the "system" shell I gain through the exploits, is there a way for me to somehow access AD and add start making my way into the directory instead of simply winning access to the local machines?  Short of ARP poisoning or sniffing telnet sessions to network hardware devices and attemtping to guess/use those captured admin credentials in the domain, I'm curious if I can bridge the gap somehow between local admin and domain user (eventually domain admin)?  Obviously local creds and AD are two different repositories...but I feel I may be missing something in the Windows world.

Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #1 on: June 23, 2008, 08:12:47 PM »

use pass the hash and token stealing if any of the boxes have been logged into by an admin.

everything you need has been built into meterpreter
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
det_security08
Newbie
*
Offline Offline

Posts: 8


View Profile
« Reply #2 on: June 25, 2008, 12:14:56 AM »

Chris,

That was my goal...but I was thinking I'm missing something with the SAM and local logins vs. domain logins.  On several of the servers, dumping the passwords from the SAM only produces local users.  However, with those local creds, when I map drives and browse the C: drive, I notice that several profiles have been created for domain users, sometimes even the Admin ID for the domain.  But, no such credentials exist in the SAM. 

Also..this is a 2003/2000 mixed domain. 
Logged
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #3 on: June 25, 2008, 08:59:50 AM »

thats because MS AD stores user accounts on the domain  controller not local sams, so you either have to hack the DC, or cross your fingers and use pass the hash.  thankfully local admin and system can run all those  hash tools
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.041 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.