daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

network-discovery.md (13060B)


      1 ---
      2 title: "Network Discovery"
      3 section: "Cheatsheets"
      4 sectionSlug: "cheatsheets"
      5 sourcePath: "docs/cheatsheets/network-discovery.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/network-discovery.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Network Discovery
     12 
     13 ## MAC Address
     14 
     15 * [mac2vendor.com](https://mac2vendor.com/) - OUI Database Lookup
     16 * [oui.is](https://oui.is/) - MAC Address Vendor Lookup
     17 
     18 | MAC Prefix | Description           |
     19 | ---------- | --------------------- |
     20 | FC:D4:F2   | Coca Cola Company     |
     21 | 00:9E:C8   | Xiaomi Communications |
     22 | 08:9E:08   | Google                |
     23 
     24 ```ps1
     25 sudo ifconfig <interface-name> down
     26 sudo ifconfig <interface-name> hw ether <new-mac-address> 
     27 sudo ifconfig <interface-name> up
     28 ```
     29 
     30 ## DHCP
     31 
     32 DHCP (Dynamic Host Configuration Protocol) is a networking protocol used to automatically assign IP addresses and other network configuration parameters to devices on a network. DHCP allows devices to obtain necessary network configuration information from a DHCP server, rather than having to be manually configured.
     33 
     34 ```ps1
     35 sudo nmap --script broadcast-dhcp-discover
     36 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-03-04 11:15 CET
     37 Pre-scan script results:
     38 | broadcast-dhcp-discover: 
     39 |   Response 1 of 1: 
     40 |     Interface: eth0
     41 |     IP Offered: 192.168.1.111
     42 |     DHCP Message Type: DHCPOFFER
     43 |     Server Identifier: 192.168.1.254
     44 |     IP Address Lease Time: 1d00h00m00s
     45 |     Renewal Time Value: 12h00m00s
     46 |     Rebinding Time Value: 21h00m00s
     47 |     Broadcast Address: 192.168.1.255
     48 |     Hostname: Host-005
     49 |     Domain Name Server: 192.168.1.254
     50 |     Domain Name: lan
     51 |     Router: 192.168.1.254
     52 |_    Subnet Mask: 255.255.255.0
     53 ```
     54 
     55 ## DNS
     56 
     57 * AD DNS
     58     * LDAP: `nslookup -type=srv _ldap._tcp.dc._msdcs.<domain name>`
     59     * KDC: `nslookup -type=srv _kerberos._tcp.<domain name>`
     60     * Global catalog: `nslookup -type=srv _ldap._tcp.<domain name>`
     61 
     62 ## NBT-NS
     63 
     64 NS (Name Service) is a component of NBT that provides name resolution services for NETBIOS names. In the context of NBT, NS is responsible for mapping NETBIOS names to IP addresses.
     65 
     66 NBT NS uses a distributed database to store NETBIOS name-to-IP address mappings. Each computer on the network is responsible for registering its own name and IP address in the database, and for resolving names to IP addresses when necessary. When a computer needs to resolve a NETBIOS name to an IP address, it sends a query to the NBT NS service on another computer on the network. The NBT NS service responds with the IP address associated with the requested name, if it is known. It works on `UDP, Port 137`.
     67 
     68 * Get names:  `nbtscan -r 192.168.1.0/24`
     69 * Get the name for a single IP: `nmblookup -A <IP>`
     70 
     71 ## MDNS
     72 
     73 MDNS (Multicast Domain Name System) is a protocol used for zero-configuration networking, also known as "zeroconf". It allows devices on a local network to automatically discover each other and resolve hostnames to IP addresses without the need for a centralized DNS server.
     74 
     75 MDNS works by using multicast addresses to send DNS queries and responses. When a device wants to resolve a hostname to an IP address, it sends a multicast DNS query to a special multicast address (224.0.0.251 for IPv4 and ff02::fb for IPv6). Any device on the network that is listening for multicast DNS queries and has a matching hostname will respond with its IP address.
     76 
     77 ```ps1
     78 mdns-scan
     79 ```
     80 
     81 ## ARP
     82 
     83 ARP (Address Resolution Protocol) is a networking protocol used to map IP addresses to MAC (Media Access Control) addresses on a local area network (LAN).
     84 
     85 * ARP neighbors
     86 
     87     ```ps1
     88     :~$ ip neigh
     89     192.168.122.1 dev enp1s0 lladdr 52:54:00:ff:0a:2c STALE
     90     192.168.122.98 dev enp1s0 lladdr 52:54:00:ff:aa:bb STALE
     91     ```
     92 
     93 * ARP scan with `nmap` - note, needs root privileges. Check what packets nmap is sending with `--packet-trace`
     94 
     95     ```ps1
     96     :~# nmap -sn -n 192.168.122.0/24 
     97     Starting Nmap 7.93 ( https://nmap.org )
     98     Nmap scan report for 192.168.122.1
     99     Host is up (0.00032s latency).
    100     MAC Address: 52:54:00:FF:0A:2C (QEMU virtual NIC)
    101     ```
    102 
    103 * ARP scan with `arp-scan`
    104 
    105     ```ps1
    106     root@kali:~# arp-scan -l
    107     Interface: eth0, datalink type: EN10MB (Ethernet)
    108     Starting arp-scan 1.9 with 256 hosts (http://www.nta-monitor.com/tools/arp-scan/)
    109     172.16.193.1 00:50:56:c0:00:08 VMware, Inc.
    110     172.16.193.2 00:50:56:f1:18:a8 VMware, Inc.
    111     172.16.193.254 00:50:56:e5:7b:87 VMware, Inc.
    112     ```
    113 
    114 * ARP spoof with `arpspoof`
    115 
    116     ```ps1
    117     arpspoof [-i interface] [-c own|host|both] [-t target] [-r] host
    118     arpspoof -i wlan0 -t 10.0.0.X 10.0.0.Y
    119     ```
    120 
    121 * ARP spoof with `Bettercap`
    122 
    123     ```ps1
    124     sudo bettercap -iface wlan0
    125     net.probe on
    126     set arp.spoof.targets <target_IP>
    127     arp.spoof on
    128     net.sniff on
    129     ```
    130 
    131 ## Ping
    132 
    133 * Ping sweep with `nmap`: no port scan, no DNS resolution
    134 
    135     ```powershell
    136     nmap -sn -n --disable-arp-ping 192.168.1.1-254 | grep -v "host down"
    137     -sn : Disable port scanning. Host discovery only.
    138     -n : Never do DNS resolution
    139     ```
    140 
    141 ## LDAP
    142 
    143 * Null bind connection: `ldapsearch -x -h <ip> -s base`
    144 
    145 ## Port Scans and Enumeration
    146 
    147 ### Nmap
    148 
    149 * Basic NMAP
    150 
    151 ```bash
    152 sudo nmap -sSV -p- 192.168.0.1 -oA OUTPUTFILE -T4
    153 sudo nmap -sSV -oA OUTPUTFILE -T4 -iL INPUTFILE.csv
    154 
    155 • the flag -sSV defines the type of packet to send to the server and tells Nmap to try and determine any service on open ports
    156 • the -p- tells Nmap to check all 65,535 ports (by default it will only check the most popular 1,000)
    157 • 192.168.0.1 is the IP address to scan
    158 • -oA OUTPUTFILE tells Nmap to output the findings in its three major formats at once using the filename "OUTPUTFILE"
    159 • -iL INPUTFILE tells Nmap to use the provided file as inputs
    160 ```
    161 
    162 * CTF NMAP
    163 
    164 This configuration is enough to do a basic check for a CTF VM
    165 
    166 ```bash
    167 nmap -sV -sC -oA ~/nmap-initial 192.168.1.1
    168 
    169 -sV : Probe open ports to determine service/version info
    170 -sC : to enable the script
    171 -oA : to save the results
    172 
    173 After this quick command you can add "-p-" to run a full scan while you work with the previous result
    174 ```
    175 
    176 * Aggressive NMAP
    177 
    178 ```bash
    179 nmap -A -T4 scanme.nmap.org
    180 • -A: Enable OS detection, version detection, script scanning, and traceroute
    181 • -T4: Defines the timing for the task (options are 0-5 and higher is faster)
    182 ```
    183 
    184 * Using searchsploit to detect vulnerable services
    185 
    186 ```bash
    187 nmap -p- -sV -oX a.xml IP_ADDRESS; searchsploit --nmap a.xml
    188 ```
    189 
    190 * Generating nice scan report
    191 
    192 ```bash
    193 nmap -sV IP_ADDRESS -oX scan.xml && xsltproc scan.xml -o "`date +%m%d%y`_report.html"
    194 ```
    195 
    196 * NMAP Scripts
    197 
    198 ```bash
    199 nmap -sC : equivalent to --script=default
    200 
    201 nmap --script 'http-enum' -v web.xxxx.com -p80 -oN http-enum.nmap
    202 PORT   STATE SERVICE
    203 80/tcp open  http
    204 | http-enum:
    205 |   /phpmyadmin/: phpMyAdmin
    206 |   /.git/HEAD: Git folder
    207 |   /css/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)'
    208 |_  /image/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)'
    209 
    210 nmap --script smb-enum-users.nse -p 445 [target host]
    211 Host script results:
    212 | smb-enum-users:
    213 |   METASPLOITABLE\backup (RID: 1068)
    214 |     Full name:   backup
    215 |     Flags:       Account disabled, Normal user account
    216 |   METASPLOITABLE\bin (RID: 1004)
    217 |     Full name:   bin
    218 |     Flags:       Account disabled, Normal user account
    219 |   METASPLOITABLE\msfadmin (RID: 3000)
    220 |     Full name:   msfadmin,,,
    221 |     Flags:       Normal user account
    222 
    223 List Nmap scripts : ls /usr/share/nmap/scripts/
    224 ```
    225 
    226 ### Network Scan with nc and ping
    227 
    228 Sometimes we want to perform network scan without any tools like nmap. So we can use the commands `ping` and `nc` to check if a host is up and which port is open.
    229 
    230 To check if hosts are up on a /24 range
    231 
    232 ```bash
    233 for i in `seq 1 255`; do ping -c 1 -w 1 192.168.1.$i > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "192.168.1.$i is UP"; fi ; done
    234 ```
    235 
    236 To check which ports are open on a specific host
    237 
    238 ```bash
    239 for i in {21,22,80,139,443,445,3306,3389,8080,8443}; do nc -z -w 1 192.168.1.18 $i > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "192.168.1.18 has port $i open"; fi ; done
    240 ```
    241 
    242 Both at the same time on a /24 range
    243 
    244 ```bash
    245 for i in `seq 1 255`; do ping -c 1 -w 1 192.168.1.$i > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "192.168.1.$i is UP:"; for j in {21,22,80,139,443,445,3306,3389,8080,8443}; do nc -z -w 1 192.168.1.$i $j > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "\t192.168.1.$i has port $j open"; fi ; done ; fi ; done
    246 ```
    247 
    248 Not in one-liner version:
    249 
    250 ```bash
    251 for i in `seq 1 255`; 
    252 do 
    253     ping -c 1 -w 1 192.168.1.$i > /dev/null 2>&1; 
    254     if [ $? -eq 0 ]; 
    255     then 
    256         echo "192.168.1.$i is UP:"; 
    257         for j in {21,22,80,139,443,445,3306,3389,8080,8443}; 
    258         do 
    259             nc -z -w 1 192.168.1.$i $j > /dev/null 2>&1; 
    260             if [ $? -eq 0 ]; 
    261             then 
    262                 echo "\t192.168.1.$i has port $j open"; 
    263             fi ; 
    264         done ; 
    265     fi ; 
    266 done
    267 ```
    268 
    269 ### Network Scan with PowerShell
    270 
    271 ```powershell
    272 # ping scan
    273 tnc 8.8.8.8
    274 
    275 # port scan
    276 tnc 8.8.8.8 -port 443
    277 ```
    278 
    279 ### Masscan
    280 
    281 ```powershell
    282 masscan -iL ips-online.txt --rate 10000 -p1-65535 --only-open -oL masscan.out
    283 masscan -e tun0 -p1-65535,U:1-65535 10.10.10.97 --rate 1000
    284 
    285 # find machines on the network
    286 sudo masscan --rate 500 --interface tap0 --router-ip $ROUTER_IP --top-ports 100 $NETWORK -oL masscan_machines.tmp
    287 cat masscan_machines.tmp | grep open | cut -d " " -f4 | sort -u > masscan_machines.lst
    288 
    289 # find open ports for one machine
    290 sudo masscan --rate 1000 --interface tap0 --router-ip $ROUTER_IP -p1-65535,U:1-65535 $MACHINE_IP --banners -oL $MACHINE_IP/scans/masscan-ports.lst
    291 
    292 
    293 # TCP grab banners and services information
    294 TCP_PORTS=$(cat $MACHINE_IP/scans/masscan-ports.lst| grep open | grep tcp | cut -d " " -f3 | tr '\n' ',' | head -c -1)
    295 [ "$TCP_PORTS" ] && sudo nmap -sT -sC -sV -v -Pn -n -T4 -p$TCP_PORTS --reason --version-intensity=5 -oA $MACHINE_IP/scans/nmap_tcp $MACHINE_IP
    296 
    297 # UDP grab banners and services information
    298 UDP_PORTS=$(cat $MACHINE_IP/scans/masscan-ports.lst| grep open | grep udp | cut -d " " -f3 | tr '\n' ',' | head -c -1)
    299 [ "$UDP_PORTS" ] && sudo nmap -sU -sC -sV -v -Pn -n -T4 -p$UDP_PORTS --reason --version-intensity=5 -oA $MACHINE_IP/scans/nmap_udp $MACHINE_IP
    300 ```
    301 
    302 ### Reconnoitre
    303 
    304 Dependencies:
    305 
    306 * nbtscan
    307 * nmap
    308 
    309 ```powershell
    310 python2.7 ./reconnoitre.py -t 192.168.1.2-252 -o ./results/ --pingsweep --hostnames --services --quick
    311 ```
    312 
    313 If you have a segfault with nbtscan, read the following quote.
    314 > Permission is denied on the broadcast address (.0) and it segfaults on the gateway (.1) - all other addresses seem fine here.So to mitigate the problem: nbtscan 192.168.0.2-255
    315 
    316 ## Netdiscover
    317 
    318 ```powershell
    319 netdiscover -i eth0 -r 192.168.1.0/24
    320 Currently scanning: Finished!   |   Screen View: Unique Hosts
    321 
    322 20 Captured ARP Req/Rep packets, from 4 hosts.   Total size: 876
    323 _____________________________________________________________________________
    324 IP            At MAC Address     Count     Len  MAC Vendor / Hostname
    325 -----------------------------------------------------------------------------
    326 192.168.1.AA    68:AA:AA:AA:AA:AA     15     630  Sagemcom
    327 192.168.1.XX    52:XX:XX:XX:XX:XX      1      60  Unknown vendor
    328 192.168.1.YY    24:YY:YY:YY:YY:YY      1      60  QNAP Systems, Inc.
    329 192.168.1.ZZ    b8:ZZ:ZZ:ZZ:ZZ:ZZ      3     126  HUAWEI TECHNOLOGIES CO.,LTD  
    330 ```
    331 
    332 ## Responder
    333 
    334 ```powershell
    335 responder -I eth0 -A # see NBT-NS, BROWSER, LLMNR requests without responding.
    336 responder.py -I eth0 -wrf
    337 ```
    338 
    339 Alternatively you can use the [Windows version](https://github.com/lgandx/Responder-Windows)
    340 
    341 ## MITM
    342 
    343 * WSUS poisoning
    344 * ARP poisoning
    345 * DHCP poisoning: `responder --interface "eth0" --DHCP --wpad`
    346 
    347 ### Bettercap
    348 
    349 ```powershell
    350 bettercap -X --proxy --proxy-https -T <target IP>
    351 # better cap in spoofing, discovery, sniffer
    352 # intercepting http and https requests,
    353 # targetting specific IP only
    354 ```
    355 
    356 ### SSL MITM with OpenSSL
    357 
    358 This code snippet allows you to sniff/modify SSL traffic if there is a MITM vulnerability using only openssl.
    359 If you can modify `/etc/hosts` of the client:
    360 
    361 ```powershell
    362 sudo echo "[OPENSSL SERVER ADDRESS] [domain.of.server.to.mitm]" >> /etc/hosts  # On client host
    363 ```
    364 
    365 On our MITM server, if the client accepts self signed certificates (you can use a legit certificate if you have the private key of the legit server):
    366 
    367 ```powershell
    368 openssl req -subj '/CN=[domain.of.server.to.mitm]' -batch -new -x509 -days 365 -nodes -out server.pem -keyout server.pem
    369 ```
    370 
    371 On our MITM server, we setup our infra:
    372 
    373 ```powershell
    374 mkfifo response
    375 sudo openssl s_server -cert server.pem -accept [INTERFACE TO LISTEN TO]:[PORT] -quiet < response | tee | openssl s_client -quiet -servername [domain.of.server.to.mitm] -connect[IP of server to MITM]:[PORT] | tee | cat > response
    376 ```
    377 
    378 In this example, traffic is only displayed with `tee` but we could modify it using `sed` for example.
    379 
    380 ## References
    381 
    382 * [Pwning the Domain: Credentialess/Username - hadess - February 7, 2024](https://hadess.io/pwning-the-domain-credentialess-username/)