[homepage]https://github.com/nyxgeek/lyncsmash[/homepage]
[tags]brute-force,derbycon,hacking,lync,pentesting,skype-for-business,user-enumeration[/tags]
[short_descr]Locate and attack Lync and Skype for Business.[/short_descr]
[long_descr]A collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations:
lyncsmash.py:
Enumerate users via auth timing bug while brute forcing, lock accounts, locate lync installs.
find_domain.sh:
Example of how to use Nmap with http-ntlm-info script to discover internal NetBIOS & domain names.
brute_force_ntlm.sh:
Example of a brute force attack against Skype/Lync using Medusa.
[homepage]https://github.com/nyxgeek/lyncsmash[/homepage] [tags]brute-force,derbycon,hacking,lync,pentesting,skype-for-business,user-enumeration[/tags] [short_descr]Locate and attack Lync and Skype for Business.[/short_descr] [long_descr]A collection of tools to enumerate and attack self-hosted Skype for Business and Microsoft Lync installations:
lyncsmash.py: Enumerate users via auth timing bug while brute forcing, lock accounts, locate lync installs.
find_domain.sh: Example of how to use Nmap with http-ntlm-info script to discover internal NetBIOS & domain names.
brute_force_ntlm.sh: Example of a brute force attack against Skype/Lync using Medusa.
ntlm-info.py: Script to get NetBIOS Domain name from NTLM auth.[/long_descr] [image]https://raw.githubusercontent.com/gwen001/offsectools_www/main/49e011534b79e6b72af15d88143e9caf.png[/image]