nmap-A-sT-Pn10.129.227.105 StartingNmap7.94SVN ( https://nmap.org ) at 2023-12-26 14:10 CST Nmap scan report for bogon (10.129.227.105) Host is up (0.41s latency). Notshown: 989 filtered tcp ports (no-response) PORT STATE SERVICE VERSION 53/tcp open domain Simple DNS Plus 88/tcp open kerberos-sec Microsoft Windows Kerberos (server time: 2023-12-2614:11:20Z) 135/tcp open msrpc Microsoft Windows RPC 139/tcp open netbios-ssn Microsoft Windows netbios-ssn 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: timelapse.htb0., Site: Default-First-Site-Name) 445/tcp open microsoft-ds? 464/tcp open kpasswd5? 593/tcp open ncacn_http Microsoft Windows RPC over HTTP 1.0 636/tcp open tcpwrapped 3268/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: timelapse.htb0., Site: Default-First-Site-Name) 3269/tcp open tcpwrapped Service Info: Host: DC01; OS: Windows; CPE: cpe:/o:microsoft:windows
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ . Nmap done: 1 IP address (1 host up) scanned in 145.11 seconds
smbclient -N \\\\10.129.227.105\\Shares Try "help" to get a list of possible commands. smb: \> ls . D 0 Mon Oct 25 23:39:15 2021 .. D 0 Mon Oct 25 23:39:15 2021 Dev D 0 Tue Oct 26 03:40:06 2021 HelpDesk D 0 Mon Oct 25 23:48:42 2021
6367231 blocks of size 4096. 1407914 blocks available smb: \> cd Dev smb: \Dev\> ls . D 0 Tue Oct 26 03:40:06 2021 .. D 0 Tue Oct 26 03:40:06 2021 winrm_backup.zip A 2611 Mon Oct 25 23:46:42 2021
6367231 blocks of size 4096. 1410285 blocks available smb: \Dev\> cd ../HeipDesk cd \HeipDesk\: NT_STATUS_OBJECT_NAME_NOT_FOUND smb: \Dev\> ls . D 0 Tue Oct 26 03:40:06 2021 .. D 0 Tue Oct 26 03:40:06 2021 winrm_backup.zip A 2611 Mon Oct 25 23:46:42 2021
6367231 blocks of size 4096. 1411840 blocks available smb: \Dev\> cd ../HelpDesk smb: \HelpDesk\> ls . D 0 Mon Oct 25 23:48:42 2021 .. D 0 Mon Oct 25 23:48:42 2021 LAPS.x64.msi A 1118208 Mon Oct 25 22:57:50 2021 LAPS_Datasheet.docx A 104422 Mon Oct 25 22:57:46 2021 LAPS_OperationsGuide.docx A 641378 Mon Oct 25 22:57:40 2021 LAPS_TechnicalSpecification.docx A 72683 Mon Oct 25 22:57:44 2021
6367231 blocks of size 4096. 1414662 blocks available smb: \HelpDesk\>
GroupNameType SID Attributes =========================================== ================ ============================================ ================================================== Everyone Well-known groupS-1-1-0 Mandatory group, Enabled by default, Enabled group BUILTIN\Remote Management Users Alias S-1-5-32-580 Mandatory group, Enabled by default, Enabled group BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group BUILTIN\Pre-Windows 2000 Compatible Access Alias S-1-5-32-554 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NETWORK Well-known groupS-1-5-2 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\Authenticated Users Well-known groupS-1-5-11 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\This Organization Well-known groupS-1-5-15 Mandatory group, Enabled by default, Enabled group TIMELAPSE\LAPS_Readers GroupS-1-5-21-671920749-559770252-3318990721-2601 Mandatory group, Enabled by default, Enabled group NT AUTHORITY\NTLM Authentication Well-known groupS-1-5-64-10 Mandatory group, Enabled by default, Enabled group Mandatory Label\Medium Plus Mandatory Level Label S-1-16-8448