A new look at null sessions and user enumeration
ID: 6faf2006-083e-514f-b7b1-e73ec0db2dcc
STIX ID: report--6faf2006-083e-514f-b7b1-e73ec0db2dcc
Feed Name: SensePost Blog
Technical analysis detailing three unauthenticated user-enumeration techniques against Windows domain controllers: calling NETLOGON’s DsrGetDcNameEx2 via RPC, crafting CLDAP “LDAP ping” queries, and using NetBIOS mailslot pings. It explains why common tools (e.g., rpcclient) can yield false negatives due to pre-checks on LSARPC, outlines protocol flows and response codes that differentiate valid vs. nonexistent users, and compares speed and detectability (CLDAP fastest, mailslot second, RPC slowest; minimal logging except an anonymous logon for RPC). Proof-of-concept scripts are provided for practical use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
