daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

47808-udp-bacnet.md (2615B)


      1 ---
      2 title: "47808/udp - BACnet"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/47808-udp-bacnet.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/47808-udp-bacnet.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 47808/udp - BACnet
     14 
     15 ## Protocol Information
     16 
     17 **BACnet** is a vendor-independent data-communications protocol for building automation and control networks. It is standardized as ANSI/ASHRAE 135 and ISO 16484-5 and supports systems such as HVAC, lighting, access control, elevators, security, and fire detection.<sup>[[1]](#references)</sup>
     18 
     19 **Default port:** 47808
     20 
     21 ```text
     22 PORT      STATE SERVICE
     23 47808/udp open  bacnet  Building Automation and Control Networks
     24 ```
     25 
     26 ## Enumeration
     27 
     28 ### BAC0
     29 
     30 The BAC0 Python library can issue a `Who-Is` broadcast and read properties from discovered devices. The host generally needs network reachability to the target BACnet/IP network.<sup>[[2]](#references)</sup>
     31 
     32 ```bash
     33 pip3 install BAC0
     34 pip3 install netifaces
     35 ```
     36 
     37 ```python
     38 import BAC0
     39 import time
     40 
     41 myIP = '<YOUR_IP>/<MASK>'  # Example: '192.168.1.4/24'
     42 bacnet = BAC0.connect(ip=myIP)
     43 bacnet.whois()  # Broadcast a BACnet Who-Is request
     44 time.sleep(5)   # Wait for devices to respond
     45 for i, (deviceId, companyId, devIp, numDeviceId) in enumerate(bacnet.devices):
     46     print(f"-------- Device #{numDeviceId} --------")
     47     print(f"Device:     {deviceId}")
     48     print(f"IP:         {devIp}")
     49     print(f"Company:    {companyId}")
     50     readDevice = bacnet.readMultiple(f"{devIp} device {numDeviceId} all")
     51     print(f"Model Name: {readDevice[11]}")
     52     print(f"Version:    {readDevice[2]}")
     53     # print(readDevice)  # List all available device information
     54 ```
     55 
     56 ### Automatic
     57 
     58 ```bash
     59 nmap --script bacnet-info --script-args full=yes -sU -n -sV -p 47808 <IP>
     60 ```
     61 
     62 The Nmap script does not register as a BACnet foreign device. It sends standard BACnet requests directly to an IP-addressable device and reports properties such as its vendor, instance number, firmware, model, and description.<sup>[[3]](#references)</sup>
     63 
     64 ### Shodan
     65 
     66 - `port:47808 instance`
     67 - `"Instance ID" "Vendor Name"`
     68 
     69 ## References
     70 
     71 - [1] [BACnet Committee: About the BACnet Standard](https://bacnet.org/about-bacnet-standard/)
     72 - [2] [BAC0 documentation: Getting Started](https://bac0.readthedocs.io/en/latest/getstarted.html)
     73 - [3] [Nmap NSE documentation: `bacnet-info`](https://nmap.org/nsedoc/scripts/bacnet-info.html)