common packets in a windows / active directory environment

22
SharkFest ‘16 Europe #sf16eu Common Packets in a Windows / Active Directory Environment Uli Heilmeier 2016 - 10 - 18

Upload: vothuy

Post on 08-Jan-2017

226 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

SharkFest ‘16 Europe

#sf16eu

Common Packets in a Windows /Active Directory Environment

Uli Heilmeier2016-10-18

Page 2: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Goals

Page 3: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Goals

• Overview of protocols used by Windows clients• DHCP• DC and Site discovery• Directory information• Authentication• PXE

Page 4: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Terms

• Active Directory (AD): Distributed multi-master database with user, computer, groups, etc. objects

• Domain: A set of users, groups, computers sharing a common directory database, security objects, trust relationship

• Domain Controller: A server running different services to control a AD

• Forest: Top level container houses domains

• Site: Groups of geo locations

Page 5: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Page 6: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

DHCP

Page 7: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

PCAP Time

Page 8: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Page 9: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

DC and Site discovery

Page 10: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

PCAP Time

Page 11: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

DC and Site discovery

• DNS• SRV _ldap._tcp.dc._msdcs.<domain-name>• SRV _ldap._tcp.<site-name>._sites.dc._msdcs.<domain-name>• A/AAAA <domain-name>

• CLDAP• Netlogon attribute

Page 12: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

DC and Site discovery

• Tools• nslookup

• nltest• nltest /dsgetsite

• nltest /dsaddresstosite:<computer-name> or <ip-address>

Page 13: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Directory Information

Page 14: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

PCAP Time

Page 15: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Directory Information

• LDAP• SMB• DCERPC

• Portmapper• UUID-Service

Page 16: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Authentication

Page 17: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

PCAP Time

Page 18: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Page 19: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Authentication

• Kerberos• setspn –L <account-name>

• NTLM

Page 20: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

PXE

Page 21: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

PCAP Time

Page 22: Common Packets in a Windows / Active Directory Environment

SharkFest ’16 Europe • Arnhem, Netherlands • October 17-19, 2016 • #sf16eu

Questions?

Email: [email protected]: @pizza_4u