Reconnaisance

  • Identify SCCM Environment

  • Identify PXE Boot Media

Scan

Ports

  • TCP Port : 8530, 8531, 10123 (Site Server, Management Point) ; 49152-49159 (Distribution Point)

  • UDP Port : 4011 (Operating System Deployment OSD)

  • Nessus Plugin: Microsoft System Center Configuration Manager Management Point Detection

Tools

Windows

  • SCCM native client (Control Panel, Configuration Manager)

([ADSISearcher]("objectClass=mSSMSManagementPoint")).FindAll() | % {$_.Properties}

Get-WmiObject -Class SMS_Authority -Namespace root\CCM (need enrolled SCCM client)

.\SharpSCCM.exe local site-info

Linux

Resources

SCCM Exploitation, the First cred Is the deepest - BlackHillsInfoSec

Last updated

Was this helpful?