1 00:00:09,300 --> 00:00:15,510 All right, so in the last lecture, we joined our workstations to the domain, and now that we have 2 00:00:15,750 --> 00:00:21,840 both PC one and CPU joint, we can push out a group policy object, which is basically going to be a 3 00:00:21,840 --> 00:00:28,740 log on script so that whenever Randy or Jacklin logs into their system, it will see the hostname, 4 00:00:28,740 --> 00:00:34,200 the IP address, the user name and the domain name of that particular system. 5 00:00:35,130 --> 00:00:39,090 So we're going to use BGM flow for this and let me show you what it is. 6 00:00:39,870 --> 00:00:41,220 So this is on my hotbox. 7 00:00:41,250 --> 00:00:46,350 Not just the VM doesn't have Internet connectivity yet because we haven't configured open sense, which 8 00:00:46,350 --> 00:00:47,220 is our default gateway. 9 00:00:47,520 --> 00:00:48,300 We'll do that later. 10 00:00:48,720 --> 00:00:53,820 In the meantime, we're going to use B.G. info because it automatically displays relevant information 11 00:00:53,820 --> 00:00:56,400 about a Windows computer on the desktop background. 12 00:00:57,180 --> 00:00:57,400 Right. 13 00:00:57,420 --> 00:00:59,550 So this is exactly what we want. 14 00:00:59,970 --> 00:01:02,400 OK, so let me show you how we can configure it. 15 00:01:02,610 --> 00:01:05,220 I've already downloaded it to my host machine. 16 00:01:06,260 --> 00:01:08,630 And I'm just going to drag and drop it and. 17 00:01:09,880 --> 00:01:10,840 Into the system. 18 00:01:12,930 --> 00:01:15,240 Let's just open up the download folder. 19 00:01:16,750 --> 00:01:19,270 Control alt to keep them click on onto the host. 20 00:01:21,400 --> 00:01:23,020 Drag and drop. 21 00:01:24,110 --> 00:01:29,410 And if drag and drop doesn't work, you can always right click copy and then click on the VM and paste, 22 00:01:30,020 --> 00:01:30,970 but we've got it here. 23 00:01:30,980 --> 00:01:31,670 So now we can right. 24 00:01:31,670 --> 00:01:35,420 Click extract or and we'll just put it here. 25 00:01:35,420 --> 00:01:37,130 Show extracted files when complete. 26 00:01:42,120 --> 00:01:42,960 All right, very good. 27 00:01:43,010 --> 00:01:46,440 Now we can double click B.G. info except the end user license agreement. 28 00:01:48,350 --> 00:01:49,760 And then we can get started. 29 00:01:50,000 --> 00:01:51,980 So what we're going to do here. 30 00:01:53,720 --> 00:01:55,670 Is first set this up, so if I click apply. 31 00:01:57,460 --> 00:02:01,600 We'll see, it's a little bit too verbose, right, we don't want to look like this and we want it to 32 00:02:01,600 --> 00:02:05,860 be in the upper right corner so that when all of our users log in, it's in, you know, it's easier 33 00:02:05,860 --> 00:02:09,700 to read it than one consistent place for press control. 34 00:02:09,700 --> 00:02:12,400 We can delete this click apply. 35 00:02:12,910 --> 00:02:13,260 It's gone. 36 00:02:14,050 --> 00:02:14,740 So what do we want? 37 00:02:14,770 --> 00:02:15,970 Well, we want the hostname. 38 00:02:16,060 --> 00:02:21,820 So my double click that we want the username we want. 39 00:02:23,260 --> 00:02:26,140 The machine domain, then, of course, my memory. 40 00:02:26,820 --> 00:02:27,820 I mean, what the IP addresses. 41 00:02:27,850 --> 00:02:31,440 Well, let me show you what happens if I include the IP address. 42 00:02:32,740 --> 00:02:33,700 So we got a preview. 43 00:02:36,370 --> 00:02:41,630 It looks fine here, OK, but some of our workstations are being workstations actually have multiple 44 00:02:41,630 --> 00:02:46,280 adapters, and so if some of those adapters don't have IP settings, it'll show up as none. 45 00:02:46,280 --> 00:02:49,150 And it just messes up the entire formatting of what this looks like. 46 00:02:49,160 --> 00:02:50,450 So we're going to create a custom field. 47 00:02:51,250 --> 00:02:51,970 And fix that. 48 00:02:53,170 --> 00:02:57,040 So what we'll do is we'll click on Custom New. 49 00:02:58,620 --> 00:03:00,990 And will name an IP address. 50 00:03:02,580 --> 00:03:06,420 It's going to be a McQuary and we'll Brownes to create it. 51 00:03:07,440 --> 00:03:14,160 What we want is a W in my class that is the Win32 network configuration, the adapter configuration 52 00:03:14,940 --> 00:03:16,680 and the property will be the IP address. 53 00:03:18,180 --> 00:03:20,130 So you see here it's showing no right. 54 00:03:20,340 --> 00:03:22,710 This is a preview of what we could see on some of our workstations. 55 00:03:22,710 --> 00:03:23,550 So we don't want that. 56 00:03:24,450 --> 00:03:30,030 So what we can do is we can say we're IP enabled equals true. 57 00:03:33,290 --> 00:03:40,180 Now it's only going to show the adapters that actually have an IP address enabled so we can click OK. 58 00:03:42,000 --> 00:03:43,410 OK, here you can click on. 59 00:03:45,080 --> 00:03:46,880 And now what we can do is we can delete this field. 60 00:03:49,900 --> 00:03:58,960 And we can put in our IP address now and then it so that looks the same because we don't have an adapter 61 00:03:58,960 --> 00:04:03,720 on the system that didn't have that wasn't enabled, but on other systems, it might not look that way. 62 00:04:04,000 --> 00:04:09,240 The point is, we've got the way we want it to be, pretty much just format this a little bit. 63 00:04:09,790 --> 00:04:11,680 So I'm going to take this part out. 64 00:04:12,560 --> 00:04:13,450 That's just metadata. 65 00:04:13,690 --> 00:04:15,610 I'm going to make this 72 font. 66 00:04:17,510 --> 00:04:18,330 No, it's really big. 67 00:04:18,360 --> 00:04:20,630 Don't worry, you'll see it's all going to look really nice in a second. 68 00:04:21,340 --> 00:04:26,790 Let's clear out this, a little divider here that looks good. 69 00:04:29,330 --> 00:04:33,990 Put a divider between the domain and the user name and then we'll do. 70 00:04:35,050 --> 00:04:43,110 Something similar for memory preview that looks pretty good, but we just need to change the position. 71 00:04:44,470 --> 00:04:47,470 To the upper right corner, click, OK, apply. 72 00:04:48,460 --> 00:04:53,710 It's pretty sweet, right, I.P. address user logged in the domain and the amount of RAM provision for 73 00:04:53,710 --> 00:04:54,080 the VM. 74 00:04:54,610 --> 00:04:55,780 Now what we do is we save it. 75 00:04:57,500 --> 00:04:58,670 As a configuration file. 76 00:05:00,000 --> 00:05:00,570 Let's go here. 77 00:05:02,220 --> 00:05:06,640 We'll just in the config and click OK to close it now. 78 00:05:06,710 --> 00:05:08,710 We're going to do I think is right there, right. 79 00:05:09,150 --> 00:05:11,420 We're going to create a VBS script. 80 00:05:12,030 --> 00:05:14,700 So what we'll do is we'll type Notepad to open it up. 81 00:05:14,970 --> 00:05:18,090 And the script is basically going to be with responsible for making the magic work. 82 00:05:18,720 --> 00:05:33,670 So first, we need to create a script that shall object since they set up Shell script that create object, 83 00:05:35,280 --> 00:05:37,020 the script that show. 84 00:05:38,490 --> 00:05:38,850 All right. 85 00:05:39,600 --> 00:05:44,640 And then we want to run it so we can call this one method. 86 00:05:46,590 --> 00:05:50,040 And in between here, we need to pass in BGN info executable path. 87 00:05:51,580 --> 00:05:55,790 Hold down shift right, quick copy path. 88 00:05:57,280 --> 00:05:57,760 Toby. 89 00:05:59,800 --> 00:06:02,290 A little bit too many quotes to get into that quote. 90 00:06:04,740 --> 00:06:06,170 Right now, the courts are unbalanced. 91 00:06:06,220 --> 00:06:07,210 Don't worry, we're going to fix that. 92 00:06:08,100 --> 00:06:09,510 We now need to put it in the configuration. 93 00:06:09,510 --> 00:06:12,060 File clerk hold and shift, right. 94 00:06:12,060 --> 00:06:13,410 Click copy as path. 95 00:06:17,430 --> 00:06:22,370 To read of this quote, and then we're going to set up some flags here controlled. 96 00:06:23,320 --> 00:06:27,670 Go back to my host operating system and you can see this, a few flags we might want. 97 00:06:29,000 --> 00:06:29,820 One is the timer. 98 00:06:30,650 --> 00:06:33,090 This will be specified to zero. 99 00:06:33,110 --> 00:06:37,280 It will update the display without displaying the configuration dialogue, which is what we want, and 100 00:06:37,280 --> 00:06:39,020 we also want to suppress error messages. 101 00:06:40,830 --> 00:06:42,110 And accept the license. 102 00:06:42,660 --> 00:06:43,680 So let me show you how to do that. 103 00:06:45,600 --> 00:06:55,950 Going here forward slash timer that Israel silent, no, look around, that means there's no license 104 00:06:55,950 --> 00:06:57,090 prompt, right? 105 00:06:57,540 --> 00:07:04,730 So I'll have a I'm just going to say that as b'day info that VVS. 106 00:07:05,520 --> 00:07:05,840 All right. 107 00:07:05,850 --> 00:07:06,310 Very cool. 108 00:07:06,750 --> 00:07:08,850 So now we need to do something with this. 109 00:07:09,850 --> 00:07:10,920 It's what I'm going to do. 110 00:07:11,320 --> 00:07:13,020 I'm going to cut this folder. 111 00:07:14,080 --> 00:07:16,830 I'm going to put it in our net log on share. 112 00:07:17,430 --> 00:07:18,060 So if I type 113 00:07:20,960 --> 00:07:23,970 log in server between two percent. 114 00:07:29,260 --> 00:07:29,730 Log on. 115 00:07:31,360 --> 00:07:37,480 It's a little typo there and then you go to net log on and you can see the footpath is just whack whack 116 00:07:37,480 --> 00:07:40,840 D.C., which is my hostname, and then backslash net log on here. 117 00:07:40,840 --> 00:07:43,410 We can paste in everything we need. 118 00:07:44,230 --> 00:07:47,380 First, we need to close this out and then we can try again. 119 00:07:52,380 --> 00:07:53,400 All right, very good. 120 00:07:54,030 --> 00:07:58,290 The other thing we need to do is in this VB script, the other thing we need to do is in this script, 121 00:07:58,290 --> 00:07:59,400 we need to just make one like. 122 00:08:03,010 --> 00:08:04,440 And this path needs to be the share. 123 00:08:05,980 --> 00:08:09,340 This is actually carbon bike, that local. 124 00:08:11,350 --> 00:08:15,670 Net log on, big info, what to say about control, see? 125 00:08:17,830 --> 00:08:22,070 It's the same thing here if the net log on BGN four right there, OK, so that looks good to me. 126 00:08:22,860 --> 00:08:24,100 I'd have to save it. 127 00:08:24,650 --> 00:08:26,740 And now let's link the GPO. 128 00:08:28,280 --> 00:08:33,430 This will be in the server manager and close this out and let's load the group policy. 129 00:08:33,740 --> 00:08:41,660 Ed, click on tools, go to group policy management, expand the forest, expand the domain. 130 00:08:44,510 --> 00:08:46,910 Keep going down, good policy objects. 131 00:08:48,110 --> 00:08:51,800 All right, to regulatory policy objects, new MBG info. 132 00:08:55,190 --> 00:08:55,700 OK. 133 00:08:57,710 --> 00:09:03,860 And we can right click it and we can say, edit, and now we go to user configuration policies, window 134 00:09:03,870 --> 00:09:05,870 settings, scripts. 135 00:09:07,330 --> 00:09:09,820 Log on at. 136 00:09:10,720 --> 00:09:11,230 Brouse. 137 00:09:12,750 --> 00:09:15,160 I guess what I'm doing, I'm just creating this as a log on script. 138 00:09:19,910 --> 00:09:20,370 Copy that. 139 00:09:20,390 --> 00:09:21,100 Let's put it here. 140 00:09:26,030 --> 00:09:28,310 And we want to log on script, which is the VBAC file. 141 00:09:29,790 --> 00:09:39,090 Like, OK, like appli click, OK, and then back in the group policy, you can right click on the domain 142 00:09:39,090 --> 00:09:42,180 and say link to an existing GPO, which is the new one. 143 00:09:42,180 --> 00:09:44,850 We just created BGN info click OK. 144 00:09:46,230 --> 00:09:51,860 And we should be good to go now, we just need to give it a quick test, so I'm going to double click 145 00:09:51,870 --> 00:09:52,040 it. 146 00:09:53,660 --> 00:09:55,600 I want to make sure I get no error messages when I run it. 147 00:09:56,140 --> 00:09:57,050 All right, that's good. 148 00:09:57,070 --> 00:09:58,810 You want nothing to happen, right? 149 00:09:58,850 --> 00:10:00,010 You don't want to see any error messages. 150 00:10:00,860 --> 00:10:01,660 That's a really good sign. 151 00:10:02,110 --> 00:10:05,980 Now, what we need to do is move over to the clients and rebuild those machines, and it should work 152 00:10:06,280 --> 00:10:07,360 its way for this to come back. 153 00:10:09,360 --> 00:10:12,770 All right, so I'll give it about five minutes, that's usually how long it takes before the logging 154 00:10:12,770 --> 00:10:14,630 script executes and launches. 155 00:10:14,830 --> 00:10:15,230 All right. 156 00:10:15,230 --> 00:10:16,580 And it's back took about three minutes. 157 00:10:16,580 --> 00:10:18,860 And you may notice that it includes the IPV six address. 158 00:10:19,550 --> 00:10:21,250 That's because this adapter is currently enabled. 159 00:10:21,480 --> 00:10:25,890 Microsoft actually recommends leaving IPV six on like you're not supposed to disable it. 160 00:10:25,910 --> 00:10:27,430 It can break future functionality. 161 00:10:27,800 --> 00:10:29,450 So we're just going to leave that on. 162 00:10:30,140 --> 00:10:32,060 If we disable that, of course, they would get rid of this. 163 00:10:32,810 --> 00:10:36,800 And there may be a WMI query that we can use to actually filter out IPV six. 164 00:10:36,800 --> 00:10:40,910 But instead of going into those details, I think it's sufficient to show that we've got this thing 165 00:10:40,910 --> 00:10:41,860 working right. 166 00:10:41,870 --> 00:10:43,150 The group, the object is linked. 167 00:10:43,880 --> 00:10:48,580 We are now pushing it's running the B.G. info configuration and we're good to go. 168 00:10:48,920 --> 00:10:55,610 So in the next lecture, we are actually going to set up to set up our Microsoft Outlook client with 169 00:10:55,610 --> 00:10:56,270 the email address. 170 00:10:56,270 --> 00:11:00,680 We got log in just to make sure that we have that configured so that when we do the initial access part 171 00:11:00,680 --> 00:11:09,560 of this cyber age will have a way of spearfishing our targets all within the safe legal confines of 172 00:11:09,560 --> 00:11:11,610 our cyber age, it's going to be really, really cool. 173 00:11:12,230 --> 00:11:14,990 So I will see you guys in the next election. 174 00:11:15,350 --> 00:11:15,890 All right, Mike.