logo

A new look at null sessions and user enumeration

ID: 6faf2006-083e-514f-b7b1-e73ec0db2dcc

STIX ID: report--6faf2006-083e-514f-b7b1-e73ec0db2dcc

Feed Name: SensePost Blog

Date Published: 2018-05-11

Date Updated: 2026-04-29

...
...

Technical analysis detailing three unauthenticated user-enumeration techniques against Windows domain controllers: calling NETLOGON’s DsrGetDcNameEx2 via RPC, crafting CLDAP “LDAP ping” queries, and using NetBIOS mailslot pings. It explains why common tools (e.g., rpcclient) can yield false negatives due to pre-checks on LSARPC, outlines protocol flows and response codes that differentiate valid vs. nonexistent users, and compares speed and detectability (CLDAP fastest, mailslot second, RPC slowest; minimal logging except an anonymous logon for RPC). Proof-of-concept scripts are provided for practical use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.