pentesting-rpcbind.md (9985B)
1 --- 2 title: "111/TCP/UDP - Pentesting Portmapper" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-rpcbind.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-rpcbind.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 111/TCP/UDP - Pentesting Portmapper 14 15 ## Basic Information 16 17 **rpcbind** (historically portmapper) maps ONC RPC program/version numbers to the transport addresses on which their services listen. Enumerating it can reveal NFS, NIS/YP, mountd, rusersd, and vendor-specific RPC programs, although the program list alone does not reliably identify the operating-system version.<sup>[[4]](#references)</sup> 18 19 **Default port:** 111/TCP and 111/UDP. Individual RPC programs may use fixed or dynamically assigned high ports; do not treat a historical Solaris high port such as 32771 as a universal rpcbind default.<sup>[[4]](#references)</sup> 20 21 ```text 22 PORT STATE SERVICE 23 111/tcp open rpcbind 24 ``` 25 26 ## Enumeration 27 28 ```text 29 rpcinfo -p irked.htb 30 nmap -sSUC -p111 192.168.10.1 31 ``` 32 33 Sometimes it doesn't give you any information, in other occasions you will get something like this: 34 35  36 37 ### Advanced `rpcinfo` usage 38 39 Leverage `rpcinfo -T udp -p <target>` to pull the UDP program list even when TCP/111 is filtered, then immediately run `showmount -e <target>` to spot world-readable NFS exports registered through rpcbind. 40 41 ```bash 42 rpcinfo -T udp -p 10.10.10.10 43 showmount -e 10.10.10.10 44 ``` 45 46 ### Exhaustive mapping with Nmap NSE 47 48 Pair the classic scan with `nmap --script=rpcinfo,rpc-grind -p111 <target>` to brute-force RPC program numbers. `rpc-grind` hammers the portmapper with null calls that walk the `nmap-rpc` database, extracting supported versions whenever the remote daemon replies with "can't support version," which often reveals quietly registered services such as rusersd, rquotad or custom daemons. Multi-threading via `--script-args 'rpc-grind.threads=8'` speeds up large targets while the companion `rpcinfo` script prints human-readable tables you can diff against host baselines.<sup>[[1]](#references)</sup> 49 50 ### Shodan 51 52 - `port:111 portmap` 53 54 ## RPCBind + NFS 55 56 If you find the service NFS then probably you will be able to list and download(and maybe upload) files: 57 58  59 60 Read [2049 - Pentesting NFS service](/hacktricks/network-services-pentesting/nfs-service-pentesting) to learn more about how to test this protocol. 61 62 ## NIS / YP 63 64 **NIS** (also called **YP / Yellow Pages**) frequently appears behind `rpcbind` as `ypbind`, `ypserv`, or `yppasswdd`. On a compromised Unix/Linux host, first verify whether identities are being resolved from NIS before talking directly to the server.<sup>[[2]](#references)</sup> 65 66  67 68 ### Detect NIS-backed accounts from a client 69 70 ```bash 71 grep -nE '^\+' /etc/passwd /etc/group 2>/dev/null 72 grep -E '^(passwd|group|shadow|hosts|services|netgroup|rpc):' /etc/nsswitch.conf 73 domainname 74 ypwhich 75 rpcinfo -p <target> | egrep 'ypbind|ypserv|yppasswdd' 76 ``` 77 78 - **`+user`** / **`+@netgroup`** entries inside `/etc/passwd` or `/etc/group` usually mean users or netgroups are being imported from NIS. 79 - **`passwd: files nis`** or **`shadow: files nis`** in `/etc/nsswitch.conf` confirms that NSS lookups fall back to NIS. 80 - From a host already enrolled in the NIS domain, `getent passwd` / `getent group` will usually return the merged local + NIS view. 81 82 ### Query maps without authentication 83 84 Many legacy NIS deployments still allow **unauthenticated map queries** from any reachable client. Try both direct YP queries and NSS lookups from an enrolled machine: 85 86 ```bash 87 # Directly query a specific NIS domain/server 88 ypcat -d <nis-domain> -h <nis-server> passwd 89 ypcat -d <nis-domain> -h <nis-server> passwd.byname 90 ypcat -d <nis-domain> -h <nis-server> passwd.byuid 91 ypcat -d <nis-domain> -h <nis-server> group.byname 92 ypcat -d <nis-domain> -h <nis-server> hosts.byname 93 ypcat -d <nis-domain> -h <nis-server> netgroup 94 95 # Query through NSS from a joined client 96 getent passwd 97 getent group 98 ``` 99 100 The returned records can expose **usernames, UIDs, GIDs, comments/GECOS fields, home directories, login shells, hosts, and netgroup memberships**. 101 102 ### Password-hash extraction and cracking workflow 103 104 In insecure environments the `passwd` maps can expose password hashes directly: 105 106 ```bash 107 ypcat -d <nis-domain> -h <nis-server> passwd.byname | tee nis-passwd.txt 108 cut -d: -f1,2 nis-passwd.txt | grep -vE '^[^:]+:[x*!]*$' > nis-hashes.txt 109 110 # Quick format triage 111 grep ':\$1\$' nis-hashes.txt # MD5Crypt 112 grep ':\$5\$' nis-hashes.txt # SHA256Crypt 113 grep ':\$6\$' nis-hashes.txt # SHA512Crypt 114 115 john --format=md5crypt nis-hashes.txt 116 hashcat --username -m 500 nis-hashes.txt <wordlist> 117 hashcat --username -m 7400 nis-hashes.txt <wordlist> # $5$ SHA256Crypt 118 hashcat --username -m 1800 nis-hashes.txt <wordlist> # $6$ SHA512Crypt 119 ``` 120 121 - Hashes beginning with **`$1$`** are **MD5Crypt** (Hashcat **`-m 500`**). 122 - If the map only returns `x`/`*` placeholders, try other maps or query from an actual NIS client with `getent passwd`. 123 - After recovering a reused Unix password, spray the **same username/password pair** against other authorized SSH targets before assuming it matches Active Directory credentials. 124 125 ```bash 126 netexec ssh hosts.txt -u <user> -p '<password>' 127 ``` 128 129 ### Useful NIS master files / maps 130 131 | **Master file** | **Map(s)** | **Notes** | 132 | ---------------- | --------------------------- | ---------------------------------------- | 133 | /etc/passwd | passwd.byname, passwd.byuid | Usernames, shells, home dirs, maybe hash | 134 | /etc/group | group.byname, group.bygid | Group memberships | 135 | /etc/hosts | hosts.byname, hosts.byaddr | Hostnames and IPs | 136 | /etc/netgroup | netgroup | Netgroup-based trust / access rules | 137 | /etc/services | services.byname | Service name mappings | 138 | /etc/rpc | rpc.bynumber | RPC service mappings | 139 | /usr/lib/aliases | mail.aliases | Mail aliases | 140 141 ## RPC Users 142 143 If you find the **rusersd** service listed like this: 144 145  146 147 You could enumerate users of the box. To learn how read [1026 - Pentesting Rsusersd](/hacktricks/network-services-pentesting/1026-pentesting-rusersd). 148 149 ## Bypass Filtered Portmapper port 150 151 For NFSv2/v3, client tools often need rpcbind plus auxiliary services such as `mountd`; if port 111 is filtered but those discovered service ports are reachable through a pivot, a local rpcbind shim and port forwards can make standard clients usable.<sup>[[3]](#references)</sup> NFSv4 normally uses TCP/2049 directly, so first determine the negotiated NFS version before building this workaround. 152 153 154 ## Labs to practice 155 156 - Practice these techniques in the [**Irked HTB machine**](https://app.hackthebox.com/machines/Irked). 157 158 159 ## HackTricks Automatic Commands 160 161 ```text 162 Protocol_Name: Portmapper #Protocol Abbreviation if there is one. 163 Port_Number: 111 164 Protocol_Description: PM or RPCBind #Protocol Abbreviation Spelled out 165 166 Entry_1: 167 Name: Notes 168 Description: Notes for PortMapper 169 Note: | 170 Portmapper is a service that is utilized for mapping network service ports to RPC (Remote Procedure Call) program numbers. It acts as a critical component in Unix-based systems, facilitating the exchange of information between these systems. The port associated with Portmapper is frequently scanned by attackers as it can reveal valuable information. This information includes the type of Unix Operating System (OS) running and details about the services that are available on the system. Additionally, Portmapper is commonly used in conjunction with NFS (Network File System), NIS (Network Information Service), and other RPC-based services to manage network services effectively. 171 172 https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-rpcbind.html 173 174 Entry_2: 175 Name: rpc info 176 Description: May give netstat-type info 177 Command: rpcinfo -p {IP} 178 179 Entry_3: 180 Name: nmap 181 Description: May give netstat-type info 182 Command: nmap -sSUC -p 111 {IP} 183 ``` 184 185 ## References 186 187 - [1] [Nmap NSE: rpc-grind](https://nmap.org/nsedoc/scripts/rpc-grind.html) 188 - [2] [NetSPI - Legacy Meets Modern: Breaking AD Through NIS & MFA Infrastructure](https://www.netspi.com/blog/technical-blog/network-pentesting/legacy-meets-modern-breaking-ad-through-nis-mfa-infrastructure/) 189 - [3] [How to Bypass Filtered Portmapper Port 111](https://medium.com/@sebnemK/how-to-bypass-filtered-portmapper-port-111-27cee52416bc) 190 - [4] [RFC 1833 - Binding Protocols for ONC RPC Version 2](https://www.rfc-editor.org/rfc/rfc1833)