ldap-search.md (11744B)
1 --- 2 title: "LDAP Search" 3 description: "Here's the updated cheat sheet using the specific credentials from the Support box:" 4 category: active-directory 5 subcategory: "Tooling & Recon" 6 tags: ["active-directory"] 7 tools: ["NetExec", "BloodHound", "ldapsearch"] 8 difficulty: intermediate 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/LDAP Search.md" 11 --- 12 # LDAP Enumeration Cheat Sheet for HTB Support 13 14 Here's the updated cheat sheet using the specific credentials from the Support box: 15 16 **Credentials:** 17 - Username: `ldap@support.htb` 18 - Password: `nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz` 19 - Domain: `support.htb` 20 - Base DN: `DC=support,DC=htb` 21 22 ## Basic ldapsearch Syntax (Modern) 23 24 ### Initial Reconnaissance 25 26 #### Get Naming Contexts (Anonymous) 27 ```bash 28 ldapsearch -x -H ldap://support.htb -b "" -s base namingContexts 29 ``` 30 31 #### Test Authentication 32 ```bash 33 ldapsearch -x -H ldap://support.htb \ 34 -D 'ldap@support.htb' \ 35 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 36 -b "DC=support,DC=htb" \ 37 -s base 38 ``` 39 40 #### Full Domain Dump 41 ```bash 42 ldapsearch -x -H ldap://support.htb \ 43 -D 'ldap@support.htb' \ 44 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 45 -b "DC=support,DC=htb" | less 46 ``` 47 48 #### Clean Output (Recommended) 49 ```bash 50 ldapsearch -LLL -x -H ldap://support.htb \ 51 -D 'ldap@support.htb' \ 52 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 53 -b "DC=support,DC=htb" 54 ``` 55 56 ## User Enumeration 57 58 #### All Users 59 ```bash 60 ldapsearch -x -H ldap://support.htb \ 61 -D 'ldap@support.htb' \ 62 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 63 -b "DC=support,DC=htb" \ 64 "(objectClass=person)" cn mail 65 ``` 66 67 #### All AD User Objects 68 ```bash 69 ldapsearch -x -H ldap://support.htb \ 70 -D 'ldap@support.htb' \ 71 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 72 -b "DC=support,DC=htb" \ 73 "(&(objectClass=user)(objectCategory=person))" \ 74 sAMAccountName mail displayName 75 ``` 76 77 #### Users with Extended Attributes 78 ```bash 79 ldapsearch -x -H ldap://support.htb \ 80 -D 'ldap@support.htb' \ 81 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 82 -b "DC=support,DC=htb" \ 83 "(objectClass=user)" \ 84 sAMAccountName mail userAccountControl description info memberOf 85 ``` 86 87 #### Search for Passwords in Description/Info Fields 88 ```bash 89 # Check description fields 90 ldapsearch -x -H ldap://support.htb \ 91 -D 'ldap@support.htb' \ 92 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 93 -b "DC=support,DC=htb" \ 94 "(description=*)" description cn | grep -i "pass\|pwd" 95 96 # Check info field (critical for this box!) 97 ldapsearch -x -H ldap://support.htb \ 98 -D 'ldap@support.htb' \ 99 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 100 -b "DC=support,DC=htb" \ 101 "(info=*)" info cn sAMAccountName 102 ``` 103 104 #### Find the Support User Specifically 105 ```bash 106 ldapsearch -x -H ldap://support.htb \ 107 -D 'ldap@support.htb' \ 108 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 109 -b "DC=support,DC=htb" \ 110 "(cn=support)" \ 111 cn info memberOf distinguishedName 112 ``` 113 114 #### Active Users Only (Exclude Disabled) 115 ```bash 116 ldapsearch -x -H ldap://support.htb \ 117 -D 'ldap@support.htb' \ 118 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 119 -b "DC=support,DC=htb" \ 120 '(&(objectClass=user)(!(userAccountControl:1.2.840.113556.1.4.803:=2)))' \ 121 sAMAccountName cn 122 ``` 123 124 #### Service Accounts (Kerberoastable) 125 ```bash 126 ldapsearch -x -H ldap://support.htb \ 127 -D 'ldap@support.htb' \ 128 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 129 -b "DC=support,DC=htb" \ 130 "(&(objectClass=user)(servicePrincipalName=*))" \ 131 sAMAccountName servicePrincipalName 132 ``` 133 134 ## Group Enumeration 135 136 #### All Groups 137 ```bash 138 ldapsearch -x -H ldap://support.htb \ 139 -D 'ldap@support.htb' \ 140 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 141 -b "DC=support,DC=htb" \ 142 "(objectClass=group)" cn description member 143 ``` 144 145 #### Groups with "Admin" in Name 146 ```bash 147 ldapsearch -LLL -x -H ldap://support.htb \ 148 -D 'ldap@support.htb' \ 149 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 150 -b "DC=support,DC=htb" \ 151 "(&(objectClass=group)(name=*admin*))" name sAMAccountName member 152 ``` 153 154 #### Shared Support Accounts Group 155 ```bash 156 ldapsearch -x -H ldap://support.htb \ 157 -D 'ldap@support.htb' \ 158 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 159 -b "DC=support,DC=htb" \ 160 "(cn=Shared Support Accounts)" member 161 ``` 162 163 #### Remote Management Users Group 164 ```bash 165 ldapsearch -x -H ldap://support.htb \ 166 -D 'ldap@support.htb' \ 167 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 168 -b "DC=support,DC=htb" \ 169 "(cn=Remote Management Users)" member 170 ``` 171 172 #### Domain Admins 173 ```bash 174 ldapsearch -x -H ldap://support.htb \ 175 -D 'ldap@support.htb' \ 176 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 177 -b "DC=support,DC=htb" \ 178 "(cn=Domain Admins)" member 179 ``` 180 181 #### User's Group Memberships 182 ```bash 183 ldapsearch -x -H ldap://support.htb \ 184 -D 'ldap@support.htb' \ 185 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 186 -b "DC=support,DC=htb" \ 187 "(sAMAccountName=support)" memberOf 188 ``` 189 190 ## Computer Enumeration 191 192 #### All Computers 193 ```bash 194 ldapsearch -x -H ldap://support.htb \ 195 -D 'ldap@support.htb' \ 196 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 197 -b "DC=support,DC=htb" \ 198 "(objectClass=computer)" cn operatingSystem dNSHostName 199 ``` 200 201 #### Domain Controllers Only 202 ```bash 203 ldapsearch -x -H ldap://support.htb \ 204 -D 'ldap@support.htb' \ 205 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 206 -b "DC=support,DC=htb" \ 207 "(userAccountControl:1.2.840.113556.1.4.803:=8192)" cn dNSHostName 208 ``` 209 210 #### Computers with Unconstrained Delegation 211 ```bash 212 ldapsearch -x -H ldap://support.htb \ 213 -D 'ldap@support.htb' \ 214 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 215 -b "DC=support,DC=htb" \ 216 "(userAccountControl:1.2.840.113556.1.4.803:=524288)" cn 217 ``` 218 219 ## Organizational Units 220 221 ```bash 222 ldapsearch -x -LLL -H ldap://support.htb \ 223 -D 'ldap@support.htb' \ 224 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 225 -b "DC=support,DC=htb" \ 226 -s sub \ 227 "(|(objectClass=organizationalUnit)(objectClass=group))" 228 ``` 229 230 ## Operational Attributes 231 232 ```bash 233 # Get all operational attributes 234 ldapsearch -x -H ldap://support.htb \ 235 -D 'ldap@support.htb' \ 236 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 237 -b "DC=support,DC=htb" \ 238 "(objectClass=*)" '+' 239 240 # Specific operational attributes 241 ldapsearch -x -H ldap://support.htb \ 242 -D 'ldap@support.htb' \ 243 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 244 -b "DC=support,DC=htb" \ 245 "(objectClass=*)" \ 246 creatorsName createTimestamp modifiersName modifyTimestamp 247 ``` 248 249 ## Modern Tools 250 251 ### ldapdomaindump 252 ```bash 253 # Comprehensive domain dump 254 ldapdomaindump -u 'support.htb\ldap' \ 255 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 256 support.htb \ 257 -o ldap_output 258 259 # Output creates: 260 # - domain_users.json/html 261 # - domain_groups.json/html 262 # - domain_computers.json/html 263 # - domain_trusts.json/html 264 # - domain_policy.json/html 265 ``` 266 267 ### BloodHound Python 268 ```bash 269 bloodhound-python -c All \ 270 -u ldap \ 271 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 272 -d support.htb \ 273 -ns 10.10.11.174 274 ``` 275 276 ### CrackMapExec / NetExec 277 ```bash 278 # Verify credentials 279 crackmapexec smb support.htb \ 280 -u ldap \ 281 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' 282 283 # LDAP enumeration 284 netexec ldap support.htb \ 285 -u ldap \ 286 -p 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 287 --users --groups --computers 288 ``` 289 290 ## Secure Alternative (Password Prompt) 291 292 Instead of putting the password in the command, use `-W` for a prompt: 293 294 ```bash 295 ldapsearch -x -H ldap://support.htb \ 296 -D 'ldap@support.htb' \ 297 -W \ 298 -b "DC=support,DC=htb" 299 ``` 300 301 ## LDAPS (Secure LDAP) 302 303 ```bash 304 ldapsearch -x -H ldaps://support.htb:636 \ 305 -D 'ldap@support.htb' \ 306 -w 'nvEfEK16^1aM4$e7AclUf8x$tRWxPWO1%lmz' \ 307 -b "DC=support,DC=htb" 308 ``` 309 310 ## Key Takeaways 311 312 1. **Always use `-H ldap://`** instead of deprecated `-h` hostname 313 2. **Add `-x`** for simple authentication in modern versions 314 3. **Use `-LLL`** for cleaner output 315 4. **The `info` field** contained the password for the support user in this box 316 5. **Check group memberships** - support user was in "Remote Management Users" 317 318 *** 319 320 ## Command-Line Flags Reference Table 321 322 | Flag | Long Form | Description | Example | 323 |------|-----------|-------------|---------| 324 | `-H` | `--uri` | LDAP URI to connect to (replaces deprecated `-h`) | `-H ldap://support.htb` | 325 | `-h` | `--host` | **DEPRECATED** Hostname (use `-H` instead) | ~~`-h support.htb`~~ | 326 | `-p` | `--port` | Port number (default: 389 for LDAP, 636 for LDAPS) | `-p 389` | 327 | `-D` | `--binddn` | Bind Distinguished Name for authentication | `-D 'ldap@support.htb'` | 328 | `-w` | `--bindpw` | Bind password (plaintext - visible in process list) | `-w 'password'` | 329 | `-W` | `--bindpw-prompt` | Prompt for bind password (more secure) | `-W` | 330 | `-y` | `--bindpw-file` | Read password from file | `-y /path/to/passfile` | 331 | `-b` | `--basedn` | Base Distinguished Name for search | `-b "DC=support,DC=htb"` | 332 | `-s` | `--scope` | Search scope: `base`, `one`, `sub`, `children` | `-s sub` | 333 | `-x` | `--simple` | Use simple authentication instead of SASL | `-x` | 334 | `-Z` | `--starttls` | Issue StartTLS extended operation | `-Z` | 335 | `-L` | N/A | LDIFv1 format (one `-L`) | `-L` | 336 | `-LL` | N/A | Disable comments in output (two `-L`) | `-LL` | 337 | `-LLL` | N/A | Disable comments and version (three `-L`, cleanest) | `-LLL` | 338 | `-v` | `--verbose` | Verbose output | `-v` | 339 | `-d` | `--debug` | Debug level (0-9, higher = more verbose) | `-d 1` | 340 | `-A` | N/A | Retrieve attribute names only (no values) | `-A` | 341 | `-l` | `--timelimit` | Time limit for search in seconds | `-l 30` | 342 | `-z` | `--sizelimit` | Size limit for number of entries returned | `-z 100` | 343 | `-S` | N/A | Sort results by specified attribute | `-S cn` | 344 | `-E` | `--extensions` | LDAP extensions (e.g., paging) | `-E pr=1000/noprompt` | 345 | `-o` | N/A | Set general options | `-o ldif-wrap=no` | 346 | `-n` | N/A | Show what would be done (dry run) | `-n` | 347 | `-u` | N/A | Include User Friendly names in output | `-u` | 348 | `-t` | N/A | Write binary values to temp files | `-t` | 349 | `-T` | N/A | Directory for temp files (use with `-t`) | `-T /tmp` | 350 | `-F` | N/A | URL prefix for temp files | `-F file:///tmp/` | 351 | `-M` | N/A | Enable Manage DSA IT control | `-M` | 352 | `-C` | N/A | Chase referrals | `-C` | 353 | `-c` | N/A | Continuous operation mode (ignore errors) | `-c` | 354 355 ### Search Scope Values 356 357 | Scope | Description | 358 |-------|-------------| 359 | `base` | Search only the base DN itself | 360 | `one` | Search immediate children of base DN only (one level) | 361 | `sub` | Search base DN and all descendants (subtree - most common) | 362 | `children` | Search all descendants but not the base DN itself | 363 364 ### Common Attribute Shortcuts 365 366 | Shortcut | Meaning | 367 |----------|---------| 368 | `*` | All regular (non-operational) attributes | 369 | `+` | All operational attributes | 370 | `1.1` | No attributes (DN only) | 371 | `*` `+` | All attributes (regular + operational) | 372 373 ### LDAP URI Format 374 375 | Format | Description | 376 |--------|-------------| 377 | `ldap://host` | Standard LDAP on port 389 | 378 | `ldap://host:port` | LDAP on custom port | 379 | `ldaps://host` | LDAP over SSL/TLS on port 636 | 380 | `ldaps://host:port` | LDAPS on custom port | 381 | `ldapi://` | LDAP over Unix domain socket (local) | 382 383 ### Common Exit Codes 384 385 | Code | Meaning | 386 |------|---------| 387 | `0` | Success | 388 | `1` | Operations error | 389 | `2` | Protocol error | 390 | `32` | No such object | 391 | `49` | Invalid credentials | 392 | `50` | Insufficient access rights | 393 394 *** 395 396 ## Pro Tips 397 398 1. **Always use `-LLL`** for clean, parseable output 399 2. **Use `-W`** instead of `-w` to avoid password in shell history 400 3. **The `info` field** in AD often contains sensitive data 401 4. **Check group memberships** - Remote Management Users = WinRM access 402 5. **Operational attributes** (`+`) reveal creation/modification metadata 403 6. **Use `sub` scope** for comprehensive searches 404 7. **Combine filters** with `&` (AND) and `|` (OR) for precise queries 405 8. **Save output** to files for offline analysis with `> output.txt`