daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit 742c5791258440ee1c018c0479138f9ace814ef2
parent 0f04b61e66d7acda4a3318358502a85dbe3f0010
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Fri, 18 Sep 2026 23:26:34 +0100

update

Diffstat:
Msrc/content/sheets/pentest-workflow/recon-and-host-discovery.md | 41+++++++++++++++++++++++++++++++++++++++--
1 file changed, 39 insertions(+), 2 deletions(-)

diff --git a/src/content/sheets/pentest-workflow/recon-and-host-discovery.md b/src/content/sheets/pentest-workflow/recon-and-host-discovery.md @@ -7,7 +7,7 @@ order: 2 tags: ["htb", "cpts", "htb-attack-flow", "htb-attack-flow-stage-01", "pentest-workflow"] tools: ["RustScan", "Nmap", "dig", "Kerberos"] difficulty: intermediate -updated: "2026-08-29" +updated: "2026-09-17" source: "vault:Pentest Attack Flow/02 - Stage 01 - Recon and Host Discovery.md" --- > [!dashboard] Attack-flow navigation @@ -346,10 +346,16 @@ nmap -sn -PS22,80,135,445,3389 10.10.110.0/24 -oA ./recon/lan-discover ### 10. Vhosts & DNS → feed `/etc/hosts` -**What to look for** → hostnames the IP scan hints at but doesn't route: cert CN/SANs, HTTP redirects/titles, and DNS zone data. Every new name goes into `/etc/hosts` so web + Kerberos work. +**What to look for** → hostnames the IP scan hints at but doesn't route: cert CN/SANs, HTTP redirects/titles, DNS zone data, and reverse-PTR records. Every new name goes into `/etc/hosts` so web + Kerberos work. **Enumerate** ```bash +# Reverse PTR lookup — ask the box's own DNS server to resolve its own IP. +# On plenty of HTB/AD boxes the reverse zone is auto-populated for the DC, +# so this hands you $DOMAIN from nothing but $IP, before nmap even finishes. +dig -x $IP @$IP +noall +answer +# 166.11.10.10.in-addr.arpa. 604800 IN PTR trick.htb. + # Names leak from TLS certs and HTTP on web ports nmap -p443,8443 --script=ssl-cert $IP nmap -sV -p80,443,8080,8443 --script=http-title,http-headers,http-server-header $IP @@ -362,8 +368,39 @@ dig axfr $DOMAIN @$IP echo "$IP $DOMAIN www.$DOMAIN mail.$DOMAIN" | sudo tee -a /etc/hosts ``` +> [!tip] Reading the PTR answer +> `dig -x` is shorthand for a `PTR` query against `<reversed-octets>.in-addr.arpa` — `@$IP` points it at the target's *own* resolver since that's usually the only DNS server that has the zone. The FQDN in the `ANSWER` section (`trick.htb.` above) is your `$DOMAIN` — export it and go straight to §0's `/etc/hosts`/krb5.conf setup. No PTR record / `NXDOMAIN` is common and means try TLS-cert CNs or AXFR instead, not that something's broken. + > [!note] If a web port serves a different site per `Host:` header, that's vhost routing — fuzz it in STAGE 2 (`ffuf ... -H "Host: FUZZ.$DOMAIN"`). Zone transfer denied is the *expected* result on a sane DNS server, not an error. Port→service reference: Common Ports and Services Cheatsheet 2026. +**SRV records — AD publishes its own service map, unauthenticated** + +**What to look for** → every DC, the PDC emulator, and Global Catalog servers, straight from DNS — no LDAP bind or Kerberos ticket needed. + +```bash +# _msdcs is the AD-specific subzone; these four cover 95% of what you need +dig srv _ldap._tcp.dc._msdcs.$DOMAIN @$DC +short # every domain controller +dig srv _kerberos._tcp.dc._msdcs.$DOMAIN @$DC +short # every KDC (usually == DC list) +dig srv _ldap._tcp.pdc._msdcs.$DOMAIN @$DC +short # the PDC emulator specifically +dig srv _gc._tcp.$DOMAIN @$DC +short # Global Catalog (multi-DC forest only) + +# nslookup form — same data, useful from a Windows foothold where dig isn't installed +nslookup -type=srv _ldap._tcp.dc._msdcs.$DOMAIN $DC +``` + +> [!tools] dnsrecon / adidnsdump +> [dnsrecon](https://github.com/darkoperator/dnsrecon) automates the whole DNS pass above in one command: +> ```bash +> dnsrecon -d $DOMAIN -n $DC -t std,srv,axfr # std = A/AAAA/MX/NS/TXT/SOA, srv = the AD SRV set, axfr = zone transfer attempt +> ``` +> [adidnsdump](https://github.com/dirkjanm/adidnsdump) is a different job — it needs **any** authenticated domain account (any tier) and dumps the *entire* AD-integrated DNS zone via LDAP, not just the public SRV/PTR subset. Revisit once creds land in [Stage 04](/sheets/pentest-workflow/active-directory-enumeration): +> ```bash +> adidnsdump -u $DOMAIN\$U -p $P $DC # writes records.csv — every internal name, including ones with no PTR +> ``` + +> [!tip] Why bother when nmap already found the DC +> A single-DC lab box makes SRV records feel redundant — but on a multi-DC forest they're how you find the **PDC emulator** (the one DC that matters for password/lockout state and time sync) and the **Global Catalog** (needed for forest-wide LDAP searches in Stage 04) without guessing which of five DCs to point tools at. `_msdcs.$DOMAIN` is also queryable straight off an external resolver on internet-facing AD — same passive-recon value as the PTR trick in §8 of [Stage 00](/sheets/pentest-workflow/passive-external-recon). + --- ### 11. Kerberos on 88 = it's AD (tell + first users)