Download presentation
Presentation is loading. Please wait.
1
Windows Enumeration Tools Roy INSA@CCU
2
Introduction SMB Protocol Inter Process Communication(IPC)
3
Winfingerprint SMB, TCP, UDP, ICMP, RPC, and SNMP scans http://winfingerprint.sourceforge.net/wi nfingerprint.php Ping Response NetBIOS Share Fingerprint NetBIOS Share Password Policy Running Services Users SID Groups Network Service Pack Session Disks Ports
4
GetUserInfo TCP port 139 http://www.joeware.net/win32/zips/Get UserInfo.zip
5
Enum http://www.bindview.com/Resources/R AZOR/Files/enum.tar.gz
6
PsTools Using NetBIOS port Services –NetLogon –Server –RemoteRegistry IPC$ share must be available http://www.sysinternals.com/files/Pstools.zip
7
Psfile shows files opened remotely
8
PsLoggedon see who's logged on locally and via resource sharing 192.168.1.9 FATCAT-E6GDFAFE CAT User:Administrator
9
PsGetSid mike
10
PsInfo Get information about local or remote windows system
11
PsService local and remote services viewer/controller
12
PsList List the Process information Open taskmgr.exe
13
PsKill kill processes by name or process ID
14
PsSuspend suspend or resume processes on a local or remote NT system.
15
PsLogList local and remote event log viewer System Security Application I->Information E->Errors W->Warning Audit Success Audit Failure Clean Log -> -c
16
PsExec executes a program on a remote system Access to the ADMIN$ share
17
PsShutdown Shutdown, logoff and power manage local and remote systems
18
Summary SMB
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.