MSRPC (Microsoft Remote Procedure Call) Pentesting
MSRPC (Microsoft Remote Procedure Call) Pentesting
Enumeration
nmap --script msrpc-enum -p 135 <target-ip>RPC Endpoints
impacket-rpcdump -port 135 <target-ip> | grep -E 'MS-EFSRPC|MS-RPRN|MS-PAR'Metasploit
msfconsole
msf> use auxiliary/scanner/dcerpc/endpoint_mapper
msf> use auxiliary/scanner/dcerpc/hidden
msf> use auxiliary/scanner/dcerpc/management
msf> use auxiliary/scanner/dcerpc/tcp_dcerpc_auditorConnect
Commands
Last updated