ntlm-info
Get system information from NTLM supported endpoints.
Supported protocols:
- HTTP[S]
- SMB 1,2,3
Setup
Installation:
git clone https://gitlab.com/Zer1t0/ntlm-info
cd ntlm-info
python3 setup.py install
Examples
Usage:
ntlm-info -h
Use it with subfinder and httprobe to find internal domains:
$ subfinder -d contoso.com | httprobe | ntlm-info
Url: https://adminit.contoso.com
Target (Domain): ITCONTOSO
OS Version: 10.0.14393
OS Name: Server 2016 | Server 2019 | Windows 10
MsvAvNbComputerName: IT-01
MsvAvNbDomainName: ITCONTOSO
MsvAvDnsComputerName: it-01.it.contoso.com
MsvAvDnsDomainName: it.contoso.com
MsvAvDnsTreeName: it.contoso.com
MsvAvTimestamp: Sep 03, 2020 09:10:47.698890
Negotiate Flags: 0x2898205
NTLMSSP_NEGOTIATE_UNICODE
NTLMSSP_REQUEST_TARGET
NTLMSSP_NEGOTIATE_NTLM
NTLMSSP_NEGOTIATE_ALWAYS_SIGN
NTLMSSP_TARGET_TYPE_DOMAIN
NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
NTLMSSP_NEGOTIATE_TARGET_INFO
NTLMSSP_NEGOTIATE_VERSION
Server challenge: da2f377fae4e8ba0
Url: https://test.contoso.com
Target (Domain): EMPCONTOSO
OS Version: 10.0.14393
OS Name: Server 2016 | Server 2019 | Windows 10
MsvAvNbComputerName: TEST
MsvAvNbDomainName: EMPCONTOSO
MsvAvDnsComputerName: test.employees.contoso.com
MsvAvDnsDomainName: employees.contoso.com
MsvAvDnsTreeName: employees.contoso.com
MsvAvTimestamp: Sep 03, 2020 09:10:47.698890
Negotiate Flags: 0x2898205
NTLMSSP_NEGOTIATE_UNICODE
NTLMSSP_REQUEST_TARGET
NTLMSSP_NEGOTIATE_NTLM
NTLMSSP_NEGOTIATE_ALWAYS_SIGN
NTLMSSP_TARGET_TYPE_DOMAIN
NTLMSSP_NEGOTIATE_EXTENDED_SESSIONSECURITY
NTLMSSP_NEGOTIATE_TARGET_INFO
NTLMSSP_NEGOTIATE_VERSION
Server challenge: 3d66a70eb2f14e93
Acknowledgment
@b17zr for ntlm_challenger.
Release files for ntlm-info 0.0.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ntlm-info-0.0.1.tar.gz | 7.7 kB | Details |
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ntlm_info-0.0.1-py3.7.egg | Legacy Egg format | - | - | Details |
| ntlm_info-0.0.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 47.4 kB
Release files / ntlm-info-0.0.1.tar.gz
| Download URL | ntlm-info-0.0.1.tar.gz |
|---|---|
| Size | 7.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
91bd26c82cd227347a7e3eca35ff721dfc51fec27699c7ba704e7d8d9e2bd8cc
|
|
BLAKE2b-256 checksum How to use checksums |
586532562e251797aa61868fe6f834e5c6896791e6ffe3232dd24f5fe7c3c86d
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.2.0 pkginfo/1.5.0.1 requests/2.23.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.50.2 CPython/3.7.3
|
Release files / ntlm_info-0.0.1-py3.7.egg
| Download URL | ntlm_info-0.0.1-py3.7.egg |
|---|---|
| Size | 18.5 kB |
| Tags | Egg |
|
SHA-256 checksum How to use checksums |
5aaecda9ef784f2e8095cb8418dc274698c94023eeedc1c96806176a32006d0e
|
|
BLAKE2b-256 checksum How to use checksums |
b7310b4b940227d00e87030c0306aa1ebf695426b6dba22bd18ad92613e0e906
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.2.0 pkginfo/1.5.0.1 requests/2.23.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.50.2 CPython/3.7.3
|
Release files / ntlm_info-0.0.1-py3-none-any.whl
| Download URL | ntlm_info-0.0.1-py3-none-any.whl |
|---|---|
| Size | 21.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9ee24275c3f461b4c6fb38b0de918094038f41844cfa5aabd30d8c44eaceb3c6
|
|
BLAKE2b-256 checksum How to use checksums |
0208dfc57a75bf6e9bd167d80efb10c203c511b85eb797b32c56c02c9c06278b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/3.2.0 pkginfo/1.5.0.1 requests/2.23.0 setuptools/40.8.0 requests-toolbelt/0.9.1 tqdm/4.50.2 CPython/3.7.3
|