47808-udp-bacnet.md (2615B)
1 --- 2 title: "47808/udp - BACnet" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/47808-udp-bacnet.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/47808-udp-bacnet.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 47808/udp - BACnet 14 15 ## Protocol Information 16 17 **BACnet** is a vendor-independent data-communications protocol for building automation and control networks. It is standardized as ANSI/ASHRAE 135 and ISO 16484-5 and supports systems such as HVAC, lighting, access control, elevators, security, and fire detection.<sup>[[1]](#references)</sup> 18 19 **Default port:** 47808 20 21 ```text 22 PORT STATE SERVICE 23 47808/udp open bacnet Building Automation and Control Networks 24 ``` 25 26 ## Enumeration 27 28 ### BAC0 29 30 The BAC0 Python library can issue a `Who-Is` broadcast and read properties from discovered devices. The host generally needs network reachability to the target BACnet/IP network.<sup>[[2]](#references)</sup> 31 32 ```bash 33 pip3 install BAC0 34 pip3 install netifaces 35 ``` 36 37 ```python 38 import BAC0 39 import time 40 41 myIP = '<YOUR_IP>/<MASK>' # Example: '192.168.1.4/24' 42 bacnet = BAC0.connect(ip=myIP) 43 bacnet.whois() # Broadcast a BACnet Who-Is request 44 time.sleep(5) # Wait for devices to respond 45 for i, (deviceId, companyId, devIp, numDeviceId) in enumerate(bacnet.devices): 46 print(f"-------- Device #{numDeviceId} --------") 47 print(f"Device: {deviceId}") 48 print(f"IP: {devIp}") 49 print(f"Company: {companyId}") 50 readDevice = bacnet.readMultiple(f"{devIp} device {numDeviceId} all") 51 print(f"Model Name: {readDevice[11]}") 52 print(f"Version: {readDevice[2]}") 53 # print(readDevice) # List all available device information 54 ``` 55 56 ### Automatic 57 58 ```bash 59 nmap --script bacnet-info --script-args full=yes -sU -n -sV -p 47808 <IP> 60 ``` 61 62 The Nmap script does not register as a BACnet foreign device. It sends standard BACnet requests directly to an IP-addressable device and reports properties such as its vendor, instance number, firmware, model, and description.<sup>[[3]](#references)</sup> 63 64 ### Shodan 65 66 - `port:47808 instance` 67 - `"Instance ID" "Vendor Name"` 68 69 ## References 70 71 - [1] [BACnet Committee: About the BACnet Standard](https://bacnet.org/about-bacnet-standard/) 72 - [2] [BAC0 documentation: Getting Started](https://bac0.readthedocs.io/en/latest/getstarted.html) 73 - [3] [Nmap NSE documentation: `bacnet-info`](https://nmap.org/nsedoc/scripts/bacnet-info.html)