TCP/UDP: LDAP - 389 / 636 / 3268
Scanning
Basic
nmap -n -sV --script "ldap* and not brute" <Target IP Address>nmap -p 389 --script ldap-search -Pn <Target IP Address>LDAPSearch
ldapsearch -H ldap://<Target IP Address> -xldapsearch -x -H ldap://<Target IP Address> -s base namingcontextsnamingContexts: DC=corp, DC=local
ldapsearch -x -H ldap://<Target IP Address> -s sub -b "<Naming Contexts>"Enumeration
Bruteforce
Last updated