Microsoft Remote Procedure Call (MSRPC)
Port: 135
1) Nmap scan
nmap -p 135 --script msrpc-enum IP2) Impacket-rpcdump enumeration
impacket-rpcdump IP -p 1353) RPC over HTTP services enumeration
nmap -p 593 --script http-rpc-epmap IP 4) Rpcclient
rpcclient -U "" -N IPrpcclient -U "" -N IP -c "srvinfo"rpcclient -U "" -N IP -c "enumdomusers"Rpcclient commands
5) Brute force User/Password/SID
6) Additional SID information
7) Set User Info (Change Password)
Last updated