2020-08-20 07:42:18 +00:00
|
|
|
id: ntlm-directories
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: Discovering directories w/ NTLM
|
2021-08-13 23:42:43 +00:00
|
|
|
author: puzzlepeaches,incogbyte
|
2020-08-20 07:42:18 +00:00
|
|
|
severity: info
|
2022-04-22 10:38:41 +00:00
|
|
|
reference:
|
|
|
|
- https://medium.com/swlh/internal-information-disclosure-using-hidden-ntlm-authentication-18de17675666
|
2023-04-28 08:11:21 +00:00
|
|
|
metadata:
|
2023-06-21 21:03:53 +00:00
|
|
|
max-request: 47
|
2024-02-28 05:11:31 +00:00
|
|
|
tags: miscellaneous,misc,bruteforce,windows
|
2020-08-20 07:42:18 +00:00
|
|
|
|
2023-06-01 11:03:16 +00:00
|
|
|
http:
|
2021-08-22 18:09:33 +00:00
|
|
|
- raw:
|
|
|
|
- |
|
|
|
|
GET {{path}} HTTP/1.1
|
|
|
|
Host: {{Hostname}}
|
|
|
|
Authorization: NTLM TlRMTVNTUAABAAAAB4IIAAAAAAAAAAAAAAAAAAAAAAA=
|
|
|
|
|
2022-01-28 10:24:49 +00:00
|
|
|
threads: 10
|
2021-08-22 18:09:33 +00:00
|
|
|
payloads:
|
2021-08-13 23:42:43 +00:00
|
|
|
path:
|
|
|
|
- /
|
|
|
|
- /abs/
|
|
|
|
- /ecp/
|
|
|
|
- /etc/
|
|
|
|
- /ews/
|
|
|
|
- /mcx/
|
|
|
|
- /oab/
|
|
|
|
- /owa/
|
|
|
|
- /rgs/
|
|
|
|
- /rpc/
|
|
|
|
- /conf/
|
|
|
|
- /meet/
|
|
|
|
- /ocsp/
|
|
|
|
- /ucwa/
|
|
|
|
- /adfs/
|
|
|
|
- /dialin/
|
|
|
|
- /public/
|
|
|
|
- /certsrv/
|
|
|
|
- /exchweb/
|
|
|
|
- /meeting/
|
|
|
|
- /certprov/
|
|
|
|
- /exchange/
|
|
|
|
- /scheduler/
|
|
|
|
- /webticket/
|
|
|
|
- /autoupdate/
|
|
|
|
- /certenroll/
|
|
|
|
- /powershell/
|
|
|
|
- /rgsclients/
|
|
|
|
- /rpcwithcert/
|
|
|
|
- /autodiscover/
|
|
|
|
- /hybridconfig/
|
|
|
|
- /reach/sip.svc
|
|
|
|
- /aspnet_client/
|
|
|
|
- /groupexpansion/
|
|
|
|
- /persistentchat/
|
|
|
|
- /requesthandler/
|
|
|
|
- /unifiedmessaging/
|
|
|
|
- /mcx/mcxservice.svc
|
|
|
|
- /phoneconferencing/
|
|
|
|
- /requesthandlerext/
|
|
|
|
- /deviceupdatefiles_ext/
|
|
|
|
- /deviceupdatefiles_int/
|
|
|
|
- /microsoft-server-activesync/
|
|
|
|
- /webticket/webticketservice.svc
|
|
|
|
- /webticket/webticketservice.svcabs/
|
|
|
|
- /adfs/services/trust/2005/windowstransport
|
2023-06-01 10:07:54 +00:00
|
|
|
- /internal_windows_authentication/
|
2023-06-01 11:03:16 +00:00
|
|
|
|
2020-09-09 11:30:30 +00:00
|
|
|
matchers-condition: and
|
2020-08-20 07:42:18 +00:00
|
|
|
matchers:
|
2021-08-13 23:42:43 +00:00
|
|
|
- type: dsl
|
|
|
|
dsl:
|
2023-06-19 21:10:30 +00:00
|
|
|
- "contains(tolower(header), 'www-authenticate: ntlm')"
|
2020-09-09 11:30:30 +00:00
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 401
|
2021-08-13 23:42:43 +00:00
|
|
|
|
|
|
|
extractors:
|
|
|
|
- type: kval
|
|
|
|
kval:
|
|
|
|
- 'www_authenticate'
|
2024-02-28 07:36:01 +00:00
|
|
|
# digest: 490a0046304402200998332a900ab3a010afc671de86d7e0dce353842f87b01101f55fc8d3dfa8680220470194bf7c344099f16ae411b214e3f983275e7c5eb172f3d2fb448b8b16921a:922c64590222798bb761d5b6d8e72950
|