Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 36 guests and 2 members online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Quick n Easy Domain account bruteforcer
EH-Net
May 22, 2013, 07:02:49 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Quick n Easy Domain account bruteforcer  (Read 1562 times)
0 Members and 1 Guest are viewing this topic.
seanuk
Newbie
*
Offline Offline

Posts: 4



View Profile WWW
« on: November 09, 2010, 01:22:08 PM »

Hi all,


I thought you may be the best people to approach for an issue I have...

I look after around 200 small businesses and wanted to produce a script that I could use to quickly pull usernames from the server and crack them in a few simple clicks to demonstrate the dangers of weak passwords.

I came up with the following which I have posted to my blog.

http://www.anotherwayin.net/2010/09/fast-password-auditing-with-nmap-and.html

this is working great for win2k/2003 domain controllers, but now seeing as many of my clients are moving over to server 2008 (sbs2008) I need to find a way of achieving the same results.
So far the only way I can get get it to pull down the usernames is to enter the domain admin credentials  via the script-args.
 
There is very little, if no research out there for doing this so I am wondering if anyone can think of a way to make this work.
I am a bit of a begginner when it comes to programming, so I have used this opportunity to help me learn some bash scripting.

From the testing i've done it seems that it will not work with just a regular domain user/pass, ONLY the domain admin account.

There must be a way around this since domain users can join their pc's to the domain and then enumerate via net users /domain. (no domain admin account required)

thanks in advance.
« Last Edit: December 06, 2011, 05:07:37 AM by seanuk » Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.069 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.