linWinPwn
Dec 23, 2024
1 min read
linWinPwn is a bash script that automates a number of Active Directory Enumeration and Vulnerability checks.
The script uses a number of tools and serves as wrapper of them. Tools include: impacket, bloodhound, crackmapexec, enum4linux-ng, ldapdomaindump, lsassy, smbmap, kerbrute, adidnsdump, certipy, silenthound, and others.
linWinPwn is particularly useful when you have access to an Active Directory environment for a limited time only, and you wish to automate the enumeration process and collect evidence efficiently.
Install:
git clone https://github.com/lefayjey/linWinPwn
cd linWinPwn; chmod +x linWinPwn.sh
chmod +x install.sh
./install.shUsage:
# Default: interactive - Open interactive menu to run checks separately
./linWinPwn.sh -t <Domain_Controller_IP> [-d <AD_domain> -u <AD_user> -p <AD_password_or_hash[LM:NT]_or_kerbticket[./krb5cc_ticket]> -o <output_dir>]
# Auto config - Run NTP sync with target DC and add entry to /etc/hosts before running the modules
./linWinPwn.sh -t <Domain_Controller_IP> --auto-config
# LDAPS - Use LDAPS instead of LDAP (port 636)
./linWinPwn.sh -t <Domain_Controller_IP> --ldaps
# Module pwd_dump: Password Dump
./linWinPwn.sh -t <Domain_Controller_IP> -M pwd_dump [-d <AD_domain> -u <AD_user> -p <AD_password_or_hash[LM:NT]_or_kerbticket[./krb5cc_ticket]> -o <output_dir>]Full usage information here.




Mình thỉnh thoảng cũng xem soi cầu cho vui thôi, coi như một cách tự tập nhìn dàn số và đối chiếu lại linh cảm của mình. Hồi trước hay nghe người quen mách nước rồi ghi bừa, trượt cái là khó chịu cả ngày, nên giờ mình ưu tiên đọc mấy chỗ có giải thích rõ ràng hơn, đúng sai gì cũng rút được chút cách suy luận. Có lần lướt thấy https://soicauxsmb.pro/ họ hay nói về chuyện lọc theo chu kỳ, mình thử áp dụng kiểu chọn bớt số để tham khảo chứ không đặt niềm tin tuyệt đối, thấy đầu óc đỡ bị cảm xúc kéo đi. Với mình mấy thứ này chỉ nên xem như gợi…