Enumerate Trust

  • Let’s enumerate the trusts:

ldeep ldap -u Donald.Trump -p 'MaKeam3ricaGr3at' -d newyork.local -s ldap://192.168.56.10 trusts
ldeep ldap -u Donald.Trump -p 'MaKeam3ricaGr3at' -d newyork.local -s ldap://192.168.56.12 trusts
  • The newyork to maryland trust link is FOREST_TRANSITIVE | TREAT_AS_EXTERNAL due to Sid history enabled

  • The Maryland to newyork trust link is just FOREST_TRANSITIVE

  • The corresponding ldap query is : (objectCategory=trustedDomain)

  • We can observe this with bloodhound too (button map domain trusts)

Last updated