Services
7 - Echo
nc -uvn <IP> 7
Hello echo #This is what you send
Hello echo #This is the response21 - FTP
Fingerprint
telnet <IP> 21use auxiliary/scanner/ftp/ftp_versionAnonymous access
ftp <IP>
> anonymous
> anonymous
> ls -ab
> binary
> ascii
> byeBrute Force
FTP Bounce Port Scanner
Configuration files
22 - SSH
Fingerprint/Enumerate
Brute Force
Configuration files
23 - Telnet
Fingerprint
Brute Force
Configuration files
25, 587 - SMTP
Fingerprint / SASL Methods
Enumerate users
Brute Force
Open Mail Relay
53 - DNS
DNS Enumeration
Zones/Zone Transfer
Recursion
DNS Lookup
Reverse DNS Lookup
Brute Force
DNS Amplification Scanner
DNS Non-Recursive Record Scraper
Configuration Files
69 - TFTP
Enumeration
Bruteforcing
79 - Finger
User enumeration
Command execution
Finger Bounce
Funny Bit
80, 8080, 443 - Web Ports
88 - Kerberos
Enumerate Users
110 - POP3
Enumeration
Brute Force
Retrieve email
111 - Portmapper
Enumerate RPC-based services
RPCBind + NFS
113 - Ident
Enumeration
119 - NNTP Network News Transfer Protocol
Enumeration
Brute Force
123 - NTP
Enumeration
Mode 6 Query
Configuration files
135-139, 445 - NetBIOS
Enumeration
SMB/Samba shares
Null Session
Connectin with PSExec
Configuration Files
135, 593 - Microsoft Windows RPC Services and Microsoft RPC Services over HTTP
Enumeration
161 - SNMP
Enumeration
Bruteforce
Configuration files
264 - Check Point FireWall-1 Topology
Enumeration
389, 636 - LDAP
Enumeration
Brute force
Configuration Files
500/1723 - PPTP/L2TP/VPN
Aggressive mode
Testing process would go as follows:
enumerate id
502 - Modbus
Discover
512 - rexec
Access
Brute Force
513 - rlogin
Enumeration
Manual Login
Brute force
514 - rsh
Enumeration
Brute force
548 - AFP - Apple Filing Protocol
Enumeration
Brute force
554, 8554 - RTSP
Enumeration
Brute Force
873 - Rsync
Enumeration
1099 - Java RMI
Enumeration
Notable Exploits
1433, 1434 - SQL Server
Metasploit
Hacking SQL Server Stored Procedures
1494 - Citrix
Enumeration
1521 - Oracle
Oracle Enumeration
Brute Force
nmap
odat
metasploit
PrivEsc
SQL Injection References
2049 - NFS
Enumeration
no_root_squash
Configuration Files
2301, 2381 - Compaq/HP Insight Manager
Enumeration
Configuration Files
3260 - ISCSI
Enumeration
Exploitation
3306 - MySQL
Enumeration
Quick testing
Brute Force
Privilege Escalation
Configuration Files
3389 - RDesktop
Network level auth NLA
Brute Force
5000+ - Sybase
Enumeration
5060 - SIP
Enumeration
Configuration Files
5432 - Postgresql
Enumeration
Brute Force
Exploitation
5555 - HPDataProtector
RCE
5900^ - VNC
Enumeration
Brute Force
Password Attacks
Configuration Files
5984 - CouchDB
Enumeration
6000^ - X11
Enumeration
Screenshots
Keyboard Command Injection
Manual
Metasploit
Sniff the keyboard keystrokes
Configuration Files
6379 - Redis
Enumeration
Exploitation
9001, 9030 - Tor
Enumeration
9100 - PJL - Jet Direct
Enumeration
9160 - Apache Cassandra
Enumeration
Brute Force
10000 - NDMP -Network Data Management Protocol
Enumeration
11211 - Memcache
Enumeration
27017, 27018 - MongoDB
Enumeration
Brute Force
44818 - EthernetIP-TCP-UDP
Enumeration
47808 - UDP BACNet
Enumeration
Last updated
Was this helpful?