LDAP
Manual Enumeration
Even without credentials, you can always query the RootDSE for naming contexts and potentially other information, such as the DnsHostName:
Once you have the naming context(s), you can dump them (in this example, the naming context is dc=cascade,dc=local
):
Note: The output of this ldapsearch contains more information than the ldap-search
nmap script. For example, in HTB cascade, it displayed info about users on the machine while ldap-search
did not.
Dumping LDAP
Use ldapdomaindump (with credentials):
Last updated