3702-udp-pentesting-ws-discovery.md (7421B)
1 --- 2 title: "3702/UDP - Pentesting WS-Discovery" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/3702-udp-pentesting-ws-discovery.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/3702-udp-pentesting-ws-discovery.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 3702/UDP - Pentesting WS-Discovery 14 15 ## Basic Information 16 17 The **Web Services Dynamic Discovery Protocol (WS-Discovery / WSD)** is a multicast discovery protocol used to find services in the local network using **SOAP over UDP**. It is very common in **ONVIF cameras**, **printers**, **Windows WSD services**, and other embedded/IoT devices. 18 19 A target service usually sends: 20 21 - **Hello** when it joins the network 22 - **Bye** when it leaves 23 - **ProbeMatch** when it answers a discovery **Probe** 24 - **ResolveMatch** when it answers a **Resolve** request 25 26 The most relevant offensive detail is that the response usually leaks: 27 - **`Types`**: the advertised device/service class (`dn:NetworkVideoTransmitter`, `wprt:PrintDeviceType`, `pub:Computer`, ...) 28 - **`Scopes`**: useful metadata such as profile, model, MAC, hardware family, location-like labels, or vendor-specific attributes 29 - **`XAddrs`**: the follow-up management endpoint, commonly an HTTP(S) SOAP URL such as `http://<ip>/onvif/device_service` 30 31 **Default port:** 3702/UDP 32 **IPv4 multicast:** `239.255.255.250` 33 **IPv6 multicast:** `ff02::c` 34 35 ```text 36 PORT STATE SERVICE 37 3702/udp open|filtered unknown 38 | wsdd-discover: 39 | Devices 40 | Message id: 39a2b7f2-fdbd-690c-c7c9-deadbeefceb3 41 | Address: http://10.0.200.116:50000 42 |_ Type: Device wprt:PrintDeviceType 43 ``` 44 45  46 47 ## Enumeration 48 49 ### Nmap 50 51 - Query a specific host exposing UDP/3702: 52 ```bash 53 nmap -sU -p 3702 --script wsdd-discover <IP> 54 ``` 55 - Discover devices in the current L2 segment via multicast:<sup>[[1]](#references)</sup> 56 ```bash 57 sudo nmap --script broadcast-wsdd-discover 58 ``` 59 60 The returned `XAddrs` are usually more valuable than the WS-Discovery response itself because they tell you **where to pivot next** (ONVIF, printer SOAP endpoints, Windows WCF services, etc.). 61 62 ### Manual Probe (useful when you want full raw XML) 63 64 ```python 65 import socket, uuid 66 probe = f'''<?xml version="1.0" encoding="UTF-8"?><e:Envelope xmlns:e="http://www.w3.org/2003/05/soap-envelope" xmlns:w="http://schemas.xmlsoap.org/ws/2004/08/addressing" xmlns:d="http://schemas.xmlsoap.org/ws/2005/04/discovery" xmlns:dn="http://www.onvif.org/ver10/network/wsdl"><e:Header><w:MessageID>uuid:{uuid.uuid4()}</w:MessageID><w:To>urn:schemas-xmlsoap-org:ws:2005:04:discovery</w:To><w:Action>http://schemas.xmlsoap.org/ws/2005/04/discovery/Probe</w:Action></e:Header><e:Body><d:Probe><d:Types>dn:NetworkVideoTransmitter</d:Types></d:Probe></e:Body></e:Envelope>'''.encode() 67 s = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) 68 s.setsockopt(socket.IPPROTO_IP, socket.IP_MULTICAST_TTL, 1) 69 s.bind(("0.0.0.0", 0)) 70 s.settimeout(3) 71 s.sendto(probe, ("239.255.255.250", 3702)) 72 while True: 73 try: 74 data, addr = s.recvfrom(65535) 75 print(addr[0], data.decode(errors="ignore")) 76 except TimeoutError: 77 break 78 ``` 79 80 Useful filters: 81 - Cameras often answer to `dn:NetworkVideoTransmitter` 82 - ONVIF devices commonly expose `tds:Device` and an `XAddrs` like `http://<ip>/onvif/device_service` 83 - Printers may expose `wprt:PrintDeviceType` 84 85 ### Packet capture 86 87 ```bash 88 sudo tcpdump -ni <iface> udp port 3702 89 sudo tshark -i <iface> -f "udp port 3702" -Y 'xml.tag == "d:ProbeMatch" || xml.tag == "wsdd:ProbeMatch"' 90 ``` 91 92 ## Interesting offensive notes 93 94 ### Multicast is local, but unicast sweeps are still useful 95 96 Multicast WS-Discovery usually does **not** cross routers, so a camera or printer in another VLAN may stay invisible to `broadcast-wsdd-discover`. In practice, if you already know or can guess the target subnet, sending the same **Probe** as **unicast UDP/3702** to each host is a good way to find devices in routed environments. 97 98 ### `Scopes` often leak useful metadata 99 100 Even when the service is not directly exploitable, `Scopes` frequently reveal: 101 - vendor/model family 102 - MAC addresses 103 - ONVIF profile support 104 - product role (`video_encoder`, printer type, etc.) 105 - asset naming/location hints 106 107 That is very helpful for **password spraying prioritization**, **firmware hunting**, and selecting the best **post-discovery pivot**. 108 109 ### `XAddrs` are the real target 110 111 Treat the WS-Discovery response as a directory service: 112 - ONVIF camera: pivot to the ONVIF SOAP endpoint and then to RTSP/media/profile enumeration 113 - Printer/WSD device: pivot to IPP/HTTP(S)/SOAP admin endpoints 114 - Windows/WCF service: pivot to the published HTTP(S) service URI 115 116 ## Attacks 117 118 ### Rogue responder / service impersonation 119 120 In flat networks, a rogue host can answer multicast **Probe** requests faster than the legitimate device and advertise attacker-controlled `XAddrs`. This is useful when a management platform auto-discovers devices and then blindly connects to the supplied HTTP(S) endpoint. 121 122 Interesting abuse cases: 123 - redirect onboarding workflows to an attacker-controlled ONVIF or SOAP endpoint 124 - capture credentials if the client automatically attempts authentication to the advertised endpoint 125 - coerce operators into connecting to a fake camera/printer/service that mimics expected metadata 126 127 If you see auto-enrollment behavior, test whether the client **trusts the first responder**, whether it validates the endpoint identity, and whether it reuses credentials automatically. 128 129 ### Reflection / amplification DDoS 130 131 If UDP/3702 is exposed to the Internet, WS-Discovery can be abused as a **reflection/amplification** vector because the attacker can spoof the source IP and trigger larger responses from many devices.<sup>[[2]](#references)</sup> 132 133 From a pentest perspective, finding Internet-exposed WS-Discovery means: 134 - the device is often **badly segmented** 135 - it may be part of a larger **camera/IoT fleet** with weak hardening 136 - the same exposed device commonly exposes follow-up management interfaces discovered in `XAddrs` 137 138 ### Fast device classification in camera-heavy environments 139 140 In CCTV environments, WS-Discovery is often the quickest way to separate: 141 - ONVIF-capable cameras 142 - Windows hosts exposing WSD/WCF services 143 - printers and multi-function devices 144 145 This makes UDP/3702 a good **first-pass recon target** before moving into more specific pages such as: 146 147 [554 8554 Pentesting Rtsp](/hacktricks/network-services-pentesting/554-8554-pentesting-rtsp) 148 149 [Pentesting 631 Internet Printing Protocol Ipp](/hacktricks/network-services-pentesting/pentesting-631-internet-printing-protocol-ipp) 150 151 ## References 152 153 - [1] [Nmap NSE - wsdd-discover / broadcast-wsdd-discover](https://nmap.org/nsedoc/scripts/wsdd-discover.html) 154 - [2] [Axis security advisory - DDoS attacks using WS Discovery](https://www.axis.com/dam/public/f3/ef/29/advisory-onvif-ws-discovery-ddos-en-US-115247.pdf)