daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

3702-udp-pentesting-ws-discovery.md (7421B)


      1 ---
      2 title: "3702/UDP - Pentesting WS-Discovery"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/3702-udp-pentesting-ws-discovery.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3702-udp-pentesting-ws-discovery.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 3702/UDP - Pentesting WS-Discovery
     14 
     15 ## Basic Information
     16 
     17 The **Web Services Dynamic Discovery Protocol (WS-Discovery / WSD)** is a multicast discovery protocol used to find services in the local network using **SOAP over UDP**. It is very common in **ONVIF cameras**, **printers**, **Windows WSD services**, and other embedded/IoT devices.
     18 
     19 A target service usually sends:
     20 
     21 - **Hello** when it joins the network
     22 - **Bye** when it leaves
     23 - **ProbeMatch** when it answers a discovery **Probe**
     24 - **ResolveMatch** when it answers a **Resolve** request
     25 
     26 The most relevant offensive detail is that the response usually leaks:
     27 - **`Types`**: the advertised device/service class (`dn:NetworkVideoTransmitter`, `wprt:PrintDeviceType`, `pub:Computer`, ...)
     28 - **`Scopes`**: useful metadata such as profile, model, MAC, hardware family, location-like labels, or vendor-specific attributes
     29 - **`XAddrs`**: the follow-up management endpoint, commonly an HTTP(S) SOAP URL such as `http://<ip>/onvif/device_service`
     30 
     31 **Default port:** 3702/UDP  
     32 **IPv4 multicast:** `239.255.255.250`  
     33 **IPv6 multicast:** `ff02::c`
     34 
     35 ```text
     36 PORT     STATE         SERVICE
     37 3702/udp open|filtered unknown
     38 | wsdd-discover:
     39 |   Devices
     40 |     Message id: 39a2b7f2-fdbd-690c-c7c9-deadbeefceb3
     41 |     Address: http://10.0.200.116:50000
     42 |_    Type: Device wprt:PrintDeviceType
     43 ```
     44 
     45 ![3702/UDP - Pentesting WS-Discovery: Upon joining a network, a Target Service announces its presence by broadcasting a multicast Hello . It remains open to receiving multicast Probes from...](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28689%29.png)
     46 
     47 ## Enumeration
     48 
     49 ### Nmap
     50 
     51 - Query a specific host exposing UDP/3702:
     52   ```bash
     53   nmap -sU -p 3702 --script wsdd-discover <IP>
     54   ```
     55 - Discover devices in the current L2 segment via multicast:<sup>[[1]](#references)</sup>
     56   ```bash
     57   sudo nmap --script broadcast-wsdd-discover
     58   ```
     59 
     60 The returned `XAddrs` are usually more valuable than the WS-Discovery response itself because they tell you **where to pivot next** (ONVIF, printer SOAP endpoints, Windows WCF services, etc.).
     61 
     62 ### Manual Probe (useful when you want full raw XML)
     63 
     64 ```python
     65 import socket, uuid
     66 probe = f'''<?xml version="1.0" encoding="UTF-8"?><e:Envelope xmlns:e="http://www.w3.org/2003/05/soap-envelope" xmlns:w="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:d="http://schemas.xmlsoap.org/ws/2005/04/discovery" xmlns:dn="http://www.onvif.org/ver10/network/wsdl"><e:Header><w:MessageID>uuid:{uuid.uuid4()}</w:MessageID><w:To>urn:schemas-xmlsoap-org:ws:2005:04:discovery</w:To><w:Action>http://schemas.xmlsoap.org/ws/2005/04/discovery/Probe</w:Action></e:Header><e:Body><d:Probe><d:Types>dn:NetworkVideoTransmitter</d:Types></d:Probe></e:Body></e:Envelope>'''.encode()
     67 s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
     68 s.setsockopt(socket.IPPROTO_IP, socket.IP_MULTICAST_TTL, 1)
     69 s.bind(("0.0.0.0", 0))
     70 s.settimeout(3)
     71 s.sendto(probe, ("239.255.255.250", 3702))
     72 while True:
     73     try:
     74         data, addr = s.recvfrom(65535)
     75         print(addr[0], data.decode(errors="ignore"))
     76     except TimeoutError:
     77         break
     78 ```
     79 
     80 Useful filters:
     81 - Cameras often answer to `dn:NetworkVideoTransmitter`
     82 - ONVIF devices commonly expose `tds:Device` and an `XAddrs` like `http://<ip>/onvif/device_service`
     83 - Printers may expose `wprt:PrintDeviceType`
     84 
     85 ### Packet capture
     86 
     87 ```bash
     88 sudo tcpdump -ni <iface> udp port 3702
     89 sudo tshark -i <iface> -f "udp port 3702" -Y 'xml.tag == "d:ProbeMatch" || xml.tag == "wsdd:ProbeMatch"'
     90 ```
     91 
     92 ## Interesting offensive notes
     93 
     94 ### Multicast is local, but unicast sweeps are still useful
     95 
     96 Multicast WS-Discovery usually does **not** cross routers, so a camera or printer in another VLAN may stay invisible to `broadcast-wsdd-discover`. In practice, if you already know or can guess the target subnet, sending the same **Probe** as **unicast UDP/3702** to each host is a good way to find devices in routed environments.
     97 
     98 ### `Scopes` often leak useful metadata
     99 
    100 Even when the service is not directly exploitable, `Scopes` frequently reveal:
    101 - vendor/model family
    102 - MAC addresses
    103 - ONVIF profile support
    104 - product role (`video_encoder`, printer type, etc.)
    105 - asset naming/location hints
    106 
    107 That is very helpful for **password spraying prioritization**, **firmware hunting**, and selecting the best **post-discovery pivot**.
    108 
    109 ### `XAddrs` are the real target
    110 
    111 Treat the WS-Discovery response as a directory service:
    112 - ONVIF camera: pivot to the ONVIF SOAP endpoint and then to RTSP/media/profile enumeration
    113 - Printer/WSD device: pivot to IPP/HTTP(S)/SOAP admin endpoints
    114 - Windows/WCF service: pivot to the published HTTP(S) service URI
    115 
    116 ## Attacks
    117 
    118 ### Rogue responder / service impersonation
    119 
    120 In flat networks, a rogue host can answer multicast **Probe** requests faster than the legitimate device and advertise attacker-controlled `XAddrs`. This is useful when a management platform auto-discovers devices and then blindly connects to the supplied HTTP(S) endpoint.
    121 
    122 Interesting abuse cases:
    123 - redirect onboarding workflows to an attacker-controlled ONVIF or SOAP endpoint
    124 - capture credentials if the client automatically attempts authentication to the advertised endpoint
    125 - coerce operators into connecting to a fake camera/printer/service that mimics expected metadata
    126 
    127 If you see auto-enrollment behavior, test whether the client **trusts the first responder**, whether it validates the endpoint identity, and whether it reuses credentials automatically.
    128 
    129 ### Reflection / amplification DDoS
    130 
    131 If UDP/3702 is exposed to the Internet, WS-Discovery can be abused as a **reflection/amplification** vector because the attacker can spoof the source IP and trigger larger responses from many devices.<sup>[[2]](#references)</sup>
    132 
    133 From a pentest perspective, finding Internet-exposed WS-Discovery means:
    134 - the device is often **badly segmented**
    135 - it may be part of a larger **camera/IoT fleet** with weak hardening
    136 - the same exposed device commonly exposes follow-up management interfaces discovered in `XAddrs`
    137 
    138 ### Fast device classification in camera-heavy environments
    139 
    140 In CCTV environments, WS-Discovery is often the quickest way to separate:
    141 - ONVIF-capable cameras
    142 - Windows hosts exposing WSD/WCF services
    143 - printers and multi-function devices
    144 
    145 This makes UDP/3702 a good **first-pass recon target** before moving into more specific pages such as:
    146 
    147 [554 8554 Pentesting Rtsp](/hacktricks/network-services-pentesting/554-8554-pentesting-rtsp)
    148 
    149 [Pentesting 631 Internet Printing Protocol Ipp](/hacktricks/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp)
    150 
    151 ## References
    152 
    153 - [1] [Nmap NSE - wsdd-discover / broadcast-wsdd-discover](https://nmap.org/nsedoc/scripts/wsdd-discover.html)
    154 - [2] [Axis security advisory - DDoS attacks using WS Discovery](https://www.axis.com/dam/public/f3/ef/29/advisory-onvif-ws-discovery-ddos-en-US-115247.pdf)