
.. image:: https://github.com/franc-pentest/ldeep/actions/workflows/python-test.yml/badge.svg :target: https://github.com/franc-pentest/ldeep/actions/workflows/python-test.yml :alt: Build status .. image:: https://badgen.net/pypi/v/ldeep :target: https://pypi.org/project/ldeep/ :alt: PyPi version .. image:: https://img.shields.io/pypi/dm/ldeep.svg :alt: Download rate :target: https://pypi.org/project/ldeep/
Kerberos를 사용하려면 ldeep이 네이티브 확장을 빌드해야 하며 일부 헤더가 필요할 수 있습니다:
Debian::
sudo apt-get install -y libkrb5-dev krb5-config gcc python3-dev
ArchLinux::
sudo pacman -S krb5
::
python -m pip install ldeep
::
python -m pip install git+https://github.com/franc-pentest/ldeep
프로젝트를 클론하고 백엔드 빌드 시스템 pdm을 설치합니다::
python -m pip install pdm git clone https://github.com/franc-pentest/ldeep && cd ldeep
클론하고 의존성을 설치합니다::
pdm install
로컬에서 실행::
pdm run ldeep
::
python -m pip install .
::
python -m build
도움말은 자명합니다. 확인해 봅시다::
$ ldeep -h usage: ldeep - 2.0.4.dev6+gf055cc0 [-h] [-o OUTFILE] [--security_desc] {ldap,cache,protections} ...
options: -h, --help show this help message and exit -o, --outfile OUTFILE Store the results in a file --security_desc Enable the retrieval of security descriptors in ldeep results
Mode: Available modes
{ldap,cache,protections}
Operation to be performed
ldeep은 Active Directory LDAP 서버에 대해 실행하거나 저장된 파일에 대해 로컬로 실행할 수 있습니다::
$ ldeep ldap -u Administrator -p 'password' -d winlab -s ldap://10.0.0.1 all backup/winlab [+] Retrieving auth_policies output [+] Retrieving auth_policies verbose output [+] Retrieving bitlockerkeys output [+] Retrieving bitlockerkeys verbose output [+] Retrieving computers output [+] Retrieving conf output [+] Retrieving delegations output [+] Retrieving delegations verbose output [+] Retrieving delegations verbose output [+] Retrieving delegations verbose output [+] Retrieving delegations verbose output [+] Retrieving dns_records output [+] Domain records: [+] Forest records: [+] Legacy records: [+] Retrieving dns_records verbose output [+] Retrieving domain_policy output [+] Retrieving domain_policy verbose output [+] Retrieving fsmo output [+] Retrieving fsmo verbose output [+] Retrieving fsp output [+] Retrieving fsp verbose output [+] Retrieving gmsa output [+] Retrieving gmsa verbose output [+] Retrieving gpo output [+] Retrieving gpo verbose output [+] Retrieving groups output [+] Retrieving groups verbose output [+] Retrieving machines output [+] Retrieving machines verbose output [+] Retrieving ou output [+] Retrieving ou verbose output [+] Retrieving pkis output [+] Retrieving pkis verbose output [+] Retrieving pso output [+] Retrieving sccm output [!] invalid attribute type mSSMSDefaultMP. Can't find SCCM management points [+] Retrieving sccm verbose output [!] invalid class in objectClass attribute: mssmsmanagementpoint. Can't find SCCM management points [+] Retrieving schema output [+] Retrieving server_info output [+] Retrieving server_info verbose output [+] Retrieving shadow_principals output [+] Retrieving shadow_principals verbose output [+] Retrieving silos output [+] Retrieving silos verbose output [+] Retrieving smsa output [+] Retrieving smsa verbose output [+] Retrieving subnets output [+] Retrieving subnets verbose output [+] Retrieving trusts output [+] Retrieving trusts verbose output [+] Retrieving users output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving users verbose output [+] Retrieving zones output [+] Domain zones: [+] Forest zones: [+] Retrieving zones verbose output
$ ldeep cache -d backup -p winlab users Administrator [...]
이 두 모드는 서로 다른 옵션을 가집니다:
::
$ ldeep ldap -h
usage: ldeep - 1.0.80 ldap [-h] -d DOMAIN -s LDAPSERVER [-b BASE] [-t {ntlm,simple}] [--throttle THROTTLE] [--page_size PAGE_SIZE] [-n] [-u USERNAME] [-p PASSWORD] [-H NTLM] [-k] [--pfx-file PFX_FILE]
[--pfx-pass PFX_PASS] [--cert-pem CERT_PEM] [--key-pem KEY_PEM] [-a]
{auth_policies,bitlockerkeys,computers,conf,delegations,domain_policy,fsmo,gmsa,gpo,groups,machines,ou,pkis,pso,sccm,shadow_principals,silos,smsa,subnets,templates,trusts,users,zones,from_guid,from_sid,laps,memberships,membersof,object,sddl,silo,zone,all,enum_users,search,whoami,add_to_group,change_uac,create_computer,create_user,modify_password,remove_from_group,unlock}
...
LDAP mode
options:
-h, --help show this help message and exit
-d DOMAIN, --domain DOMAIN
The domain as NetBIOS or FQDN
-s LDAPSERVER, --ldapserver LDAPSERVER
The LDAP path (ex : ldap://corp.contoso.com:389)
-b BASE, --base BASE LDAP base for query (by default, this value is pulled from remote Ldap)
-t {ntlm,simple}, --type {ntlm,simple}
Authentication type: ntlm (default) or simple. Simple bind will always be in cleartext with ldap (not ldaps)
--throttle THROTTLE Add a throttle between queries to sneak under detection thresholds (in seconds between queries: argument to the sleep function)
--page_size PAGE_SIZE
Configure the page size used by the engine to query the LDAP server (default: 1000)
-n, --no-encryption Encrypt the communication or not (default: encrypted, except with simple bind and ldap)
NTLM authentication:
-u USERNAME, --username USERNAME
The username
-p PASSWORD, --password PASSWORD
The password used for the authentication
-H NTLM, --ntlm NTLM NTLM hashes, format is LMHASH:NTHASH
Kerberos authentication:
-k, --kerberos For Kerberos authentication, ticket file should be pointed by $KRB5NAME env variable
Certificate authentication:
--pfx-file PFX_FILE PFX file
--pfx-pass PFX_PASS PFX password
--cert-pem CERT_PEM User certificate
--key-pem KEY_PEM User private key
Anonymous authentication:
-a, --anonymous Perform anonymous binds
commands:
available commands