# earthworks.local - Active Directory Domain Analysis

## Target Information
- **IP:** 74.208.53.72
- **Hostname:** ClientA.earthworks.local (SSL certificate)
- **Domain:** earthworks.local (Active Directory)
- **OS:** Windows Server 2019 (93% confidence, Nmap OS detection)
- **IIS:** 10.0
- **Services:**
  - Port 80: HTTP (IIS default page)
  - Port 443: HTTPS (RDWeb portal)
  - Port 3389: RDP (Microsoft Terminal Services)
  - Port 445: SMB (filtered)
  - Port 135: RPC (filtered)
  - Port 1433: MSSQL (filtered)
  - Port 8443: HTTPS-alt (filtered)

## RDWeb Portal
- **URL:** https://74.208.53.72/RDWeb/Pages/en-US/login.aspx
- **Status:** Active
- **Note:** Requires correct Remote Desktop Connection version
- **Warning:** "You don't have the right version of Remote Desktop Connection to use RD Web Access"

## Vulnerability Assessment

### RDP (Port 3389)
- **BlueKeep (CVE-2019-0708):** NOT VULNERABLE
  - Windows Server 2019 is not affected by BlueKeep
  - BlueKeep only affects Windows 7/Server 2008 R2 and earlier
- **Other RDP vulnerabilities:** Need further investigation
- **Brute-force:** Possible through RDWeb portal

### RDWeb Portal (Port 443)
- **IIS/ASP.NET:** Need to check for:
  - CVE-2023-36884 (IIS/Windows HTML Injection)
  - CVE-2024-38014 (Windows Licensing RCE)
  - ASP.NET ViewState deserialization
- **Authentication:** Active Directory domain authentication
- **Enumeration:** May be possible through RDWeb

### SMB (Port 445)
- **Status:** Filtered (firewall blocking)
- **Direct attacks:** Not possible
- **Indirect:** May be accessible from internal network

### MSSQL (Port 1433)
- **Status:** Filtered (firewall blocking)
- **Direct attacks:** Not possible
- **Indirect:** May be accessible from internal network

## Attack Vectors

### High Priority
1. **RDWeb Brute-force**
   - Active Directory domain credentials
   - May use credentials from database dumps
   - Potential for domain compromise

2. **RDP Credential Stuffing**
   - Direct RDP authentication
   - May use credentials from database dumps
   - Potential for domain compromise

3. **IIS/RDWeb Vulnerabilities**
   - Check for known CVEs
   - ASP.NET deserialization
   - ViewState attacks

### Medium Priority
4. **Domain Enumeration**
   - Username enumeration through RDWeb
   - Domain structure discovery
   - Potential for targeted attacks

5. **Certificate Analysis**
   - SSL certificate details
   - Domain structure
   - Potential for additional hosts

### Low Priority
6. **Lateral Movement**
   - Once inside, access to domain resources
   - Potential for domain admin compromise
   - Access to other systems in domain

## Assessment
**Priority:** HIGH
**Value:** Высокая. Это домен Active Directory с полным контролем над всеми системами в домене.
**Complexity:** Средняя. Требует валидные credentials или эксплуатацию уязвимостей.

## Next Steps
1. [ ] Brute-force RDWeb with credentials from database dumps
2. [ ] Check IIS/RDWeb vulnerabilities
3. [ ] Enumerate domain users through RDWeb
4. [ ] Analyze SSL certificate for additional information
5. [ ] Check for other hosts in earthworks.local domain

## Notes
- Windows Server 2019 is well-patched (not vulnerable to BlueKeep)
- RDWeb requires correct RDP client version
- SMB and other ports are filtered (firewall)
- This is a corporate AD domain with significant value
