-
Notifications
You must be signed in to change notification settings - Fork 18
/
spn_enum.py
61 lines (43 loc) · 1.62 KB
/
spn_enum.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
from PyADhack.ad_ldap import *
def parse_info(ldap_record):
temp = dict()
temp['pwdLastSet'] = long_to_dateime(ldap_record['pwdLastSet'][0])
temp['sAMAccountName'] = ldap_record['sAMAccountName'][0]
temp['userPrincipalName'] = ldap_record.get('userPrincipalName',['',''])[0]
temp['lastLogon'] = long_to_dateime(ldap_record.get('lastLogon',['0','0'])[0])
temp['whenCreated'] = long_to_dateime(ldap_record.get('whenCreated',['0','0'])[0])
temp['servicePrincipalName'] = list()
for t in ldap_record['servicePrincipalName']:
temp['servicePrincipalName'].append(t)
return temp
def getSPNaccounts(url, base, user, password):
l = AD_LDAP( url, base, user, password)
l.connect()
entries = list()
#print 'Enumerating service users'
for resultList in l.get_all_service_account():
for entry, result in resultList:
if entry is None:
continue
if entry.lower().find('watchdog') != -1:
continue
try:
entries.append(parse_info(result))
except Exception as e:
print 'err data: ' + str(result)
print 'Exception : ' + str(e)
return entries
if __name__ == '__main__':
from getpass import getpass
import json
output_filename = ''
url = '' # needs format "ldap://server_ip:port" could be ldaps
user = '' #needs format DOMAIN\\user
password = getpass()
base = '' #needs format "dc=<COMPANY>,dc=corp"
accounts = getSPNaccounts(url, base, user, password)
print 'Successfully enumerated' + str(len(accounts)) + 'users'
print 'Writing results to file...'
with open(output_filename,'wb') as f:
json.dump(accounts,f, default=json_serial)
print 'Done!'