OxidBindings icon indicating copy to clipboard operation
OxidBindings copied to clipboard

Extract all IP of a computer using DCOM without authentication (aka detect network used for administration)

OxidBindings

Retrieve the string bindings from the Oxid Resoldver

These string bindings include all the IP of the computer. It can then be used to identify the other networks (such as the network used for administration). It doesn't require any authentication.

This is a follow-up from the article edited by Airbus Cybersecurity named The OXID Resolver

Reference:

  • https://airbus-cyber-security.com/fr/the-oxid-resolver-part-1-remote-enumeration-of-network-interfaces-without-any-authentication/amp/
  • https://docs.microsoft.com/en-us/openspecs/windows_protocols/ms-dcom/c898afd6-b75d-4641-a2cd-b50cb9f5556d