daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

8333-18333-38333-18444-pentesting-bitcoin.md (2712B)


      1 ---
      2 title: "8333, 18333, 38333, 48333, 18444 - Pentesting Bitcoin"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/8333-18333-38333-18444-pentesting-bitcoin.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/8333-18333-38333-18444-pentesting-bitcoin.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 8333, 18333, 38333, 48333, 18444 - Pentesting Bitcoin
     14 
     15 ## Basic Information
     16 
     17 - **8333/TCP** is Bitcoin Core's default mainnet peer-to-peer port.
     18 - **18333/TCP** is the default testnet3 peer-to-peer port.
     19 - **38333/TCP** is the default signet peer-to-peer port.
     20 - **48333/TCP** is the default testnet4 peer-to-peer port.
     21 - **18444/TCP** is the default regtest peer-to-peer port.
     22 
     23 These defaults come from Bitcoin Core's chain parameters and can be overridden in a node's configuration.<sup>[[1]](#references)</sup> Bitcoin peer-to-peer traffic uses TCP.<sup>[[2]](#references)</sup>
     24 
     25 **Default ports:** 8333, 18333, 38333, 48333, 18444
     26 
     27 ```text
     28 PORT      STATE SERVICE
     29 8333/tcp open  bitcoin
     30 ```
     31 
     32 ### Shodan
     33 
     34 - `port:8333 bitcoin`
     35 - `User-Agent: /Satoshi`
     36 
     37 ## Enumeration
     38 
     39 Bitcoin peers exchange version and address messages as part of the peer-to-peer protocol. Nmap's `bitcoin-info` script extracts version and node information, while `bitcoin-getaddr` asks a peer for known node addresses.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup>
     40 
     41 ```text
     42 sudo nmap -p 8333 --script bitcoin-info --script bitcoin-getaddr <IP>
     43 PORT     STATE SERVICE
     44 8333/tcp open  bitcoin
     45 | bitcoin-info:
     46 |   Timestamp: 2022-04-08T22:33:58
     47 |   Network: main
     48 |   Version: 0.7.0
     49 |   Node Id: 1bea074ea4f6eca3
     50 |   Lastblock: 731027
     51 |_  User Agent: /Satoshi:0.19.1/
     52 
     53 sudo nmap -p 8333 --script bitcoin-getaddr <IP>
     54 PORT     STATE SERVICE
     55 8333/tcp open  bitcoin
     56 | bitcoin-getaddr:
     57 |   ip                                            timestamp
     58 |   2a02:c7e:486a:2b00:3d26:db39:537f:59f2:8333   2022-03-25T07:30:45
     59 |   2600:1f1c:2d3:2403:7b7d:c11c:ca61:f6e2:8333   2022-04-08T07:16:38
     60 |   75.128.4.27:8333                              2022-04-02T08:10:45
     61 [...]
     62 ```
     63 
     64 ## References
     65 
     66 - [1] [Bitcoin Core - Network chain parameters](https://github.com/bitcoin/bitcoin/blob/master/src/kernel/chainparams.cpp)
     67 - [2] [Bitcoin Developer Reference - P2P network](https://developer.bitcoin.org/reference/p2p_networking.html)
     68 - [3] [Nmap NSE documentation - bitcoin-info](https://nmap.org/nsedoc/scripts/bitcoin-info.html)
     69 - [4] [Nmap NSE documentation - bitcoin-getaddr](https://nmap.org/nsedoc/scripts/bitcoin-getaddr.html)