network-discovery.md (13060B)
1 --- 2 title: "Network Discovery" 3 section: "Cheatsheets" 4 sectionSlug: "cheatsheets" 5 sourcePath: "docs/cheatsheets/network-discovery.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cheatsheets/network-discovery.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Network Discovery 12 13 ## MAC Address 14 15 * [mac2vendor.com](https://mac2vendor.com/) - OUI Database Lookup 16 * [oui.is](https://oui.is/) - MAC Address Vendor Lookup 17 18 | MAC Prefix | Description | 19 | ---------- | --------------------- | 20 | FC:D4:F2 | Coca Cola Company | 21 | 00:9E:C8 | Xiaomi Communications | 22 | 08:9E:08 | Google | 23 24 ```ps1 25 sudo ifconfig <interface-name> down 26 sudo ifconfig <interface-name> hw ether <new-mac-address> 27 sudo ifconfig <interface-name> up 28 ``` 29 30 ## DHCP 31 32 DHCP (Dynamic Host Configuration Protocol) is a networking protocol used to automatically assign IP addresses and other network configuration parameters to devices on a network. DHCP allows devices to obtain necessary network configuration information from a DHCP server, rather than having to be manually configured. 33 34 ```ps1 35 sudo nmap --script broadcast-dhcp-discover 36 Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-03-04 11:15 CET 37 Pre-scan script results: 38 | broadcast-dhcp-discover: 39 | Response 1 of 1: 40 | Interface: eth0 41 | IP Offered: 192.168.1.111 42 | DHCP Message Type: DHCPOFFER 43 | Server Identifier: 192.168.1.254 44 | IP Address Lease Time: 1d00h00m00s 45 | Renewal Time Value: 12h00m00s 46 | Rebinding Time Value: 21h00m00s 47 | Broadcast Address: 192.168.1.255 48 | Hostname: Host-005 49 | Domain Name Server: 192.168.1.254 50 | Domain Name: lan 51 | Router: 192.168.1.254 52 |_ Subnet Mask: 255.255.255.0 53 ``` 54 55 ## DNS 56 57 * AD DNS 58 * LDAP: `nslookup -type=srv _ldap._tcp.dc._msdcs.<domain name>` 59 * KDC: `nslookup -type=srv _kerberos._tcp.<domain name>` 60 * Global catalog: `nslookup -type=srv _ldap._tcp.<domain name>` 61 62 ## NBT-NS 63 64 NS (Name Service) is a component of NBT that provides name resolution services for NETBIOS names. In the context of NBT, NS is responsible for mapping NETBIOS names to IP addresses. 65 66 NBT NS uses a distributed database to store NETBIOS name-to-IP address mappings. Each computer on the network is responsible for registering its own name and IP address in the database, and for resolving names to IP addresses when necessary. When a computer needs to resolve a NETBIOS name to an IP address, it sends a query to the NBT NS service on another computer on the network. The NBT NS service responds with the IP address associated with the requested name, if it is known. It works on `UDP, Port 137`. 67 68 * Get names: `nbtscan -r 192.168.1.0/24` 69 * Get the name for a single IP: `nmblookup -A <IP>` 70 71 ## MDNS 72 73 MDNS (Multicast Domain Name System) is a protocol used for zero-configuration networking, also known as "zeroconf". It allows devices on a local network to automatically discover each other and resolve hostnames to IP addresses without the need for a centralized DNS server. 74 75 MDNS works by using multicast addresses to send DNS queries and responses. When a device wants to resolve a hostname to an IP address, it sends a multicast DNS query to a special multicast address (224.0.0.251 for IPv4 and ff02::fb for IPv6). Any device on the network that is listening for multicast DNS queries and has a matching hostname will respond with its IP address. 76 77 ```ps1 78 mdns-scan 79 ``` 80 81 ## ARP 82 83 ARP (Address Resolution Protocol) is a networking protocol used to map IP addresses to MAC (Media Access Control) addresses on a local area network (LAN). 84 85 * ARP neighbors 86 87 ```ps1 88 :~$ ip neigh 89 192.168.122.1 dev enp1s0 lladdr 52:54:00:ff:0a:2c STALE 90 192.168.122.98 dev enp1s0 lladdr 52:54:00:ff:aa:bb STALE 91 ``` 92 93 * ARP scan with `nmap` - note, needs root privileges. Check what packets nmap is sending with `--packet-trace` 94 95 ```ps1 96 :~# nmap -sn -n 192.168.122.0/24 97 Starting Nmap 7.93 ( https://nmap.org ) 98 Nmap scan report for 192.168.122.1 99 Host is up (0.00032s latency). 100 MAC Address: 52:54:00:FF:0A:2C (QEMU virtual NIC) 101 ``` 102 103 * ARP scan with `arp-scan` 104 105 ```ps1 106 root@kali:~# arp-scan -l 107 Interface: eth0, datalink type: EN10MB (Ethernet) 108 Starting arp-scan 1.9 with 256 hosts (http://www.nta-monitor.com/tools/arp-scan/) 109 172.16.193.1 00:50:56:c0:00:08 VMware, Inc. 110 172.16.193.2 00:50:56:f1:18:a8 VMware, Inc. 111 172.16.193.254 00:50:56:e5:7b:87 VMware, Inc. 112 ``` 113 114 * ARP spoof with `arpspoof` 115 116 ```ps1 117 arpspoof [-i interface] [-c own|host|both] [-t target] [-r] host 118 arpspoof -i wlan0 -t 10.0.0.X 10.0.0.Y 119 ``` 120 121 * ARP spoof with `Bettercap` 122 123 ```ps1 124 sudo bettercap -iface wlan0 125 net.probe on 126 set arp.spoof.targets <target_IP> 127 arp.spoof on 128 net.sniff on 129 ``` 130 131 ## Ping 132 133 * Ping sweep with `nmap`: no port scan, no DNS resolution 134 135 ```powershell 136 nmap -sn -n --disable-arp-ping 192.168.1.1-254 | grep -v "host down" 137 -sn : Disable port scanning. Host discovery only. 138 -n : Never do DNS resolution 139 ``` 140 141 ## LDAP 142 143 * Null bind connection: `ldapsearch -x -h <ip> -s base` 144 145 ## Port Scans and Enumeration 146 147 ### Nmap 148 149 * Basic NMAP 150 151 ```bash 152 sudo nmap -sSV -p- 192.168.0.1 -oA OUTPUTFILE -T4 153 sudo nmap -sSV -oA OUTPUTFILE -T4 -iL INPUTFILE.csv 154 155 • the flag -sSV defines the type of packet to send to the server and tells Nmap to try and determine any service on open ports 156 • the -p- tells Nmap to check all 65,535 ports (by default it will only check the most popular 1,000) 157 • 192.168.0.1 is the IP address to scan 158 • -oA OUTPUTFILE tells Nmap to output the findings in its three major formats at once using the filename "OUTPUTFILE" 159 • -iL INPUTFILE tells Nmap to use the provided file as inputs 160 ``` 161 162 * CTF NMAP 163 164 This configuration is enough to do a basic check for a CTF VM 165 166 ```bash 167 nmap -sV -sC -oA ~/nmap-initial 192.168.1.1 168 169 -sV : Probe open ports to determine service/version info 170 -sC : to enable the script 171 -oA : to save the results 172 173 After this quick command you can add "-p-" to run a full scan while you work with the previous result 174 ``` 175 176 * Aggressive NMAP 177 178 ```bash 179 nmap -A -T4 scanme.nmap.org 180 • -A: Enable OS detection, version detection, script scanning, and traceroute 181 • -T4: Defines the timing for the task (options are 0-5 and higher is faster) 182 ``` 183 184 * Using searchsploit to detect vulnerable services 185 186 ```bash 187 nmap -p- -sV -oX a.xml IP_ADDRESS; searchsploit --nmap a.xml 188 ``` 189 190 * Generating nice scan report 191 192 ```bash 193 nmap -sV IP_ADDRESS -oX scan.xml && xsltproc scan.xml -o "`date +%m%d%y`_report.html" 194 ``` 195 196 * NMAP Scripts 197 198 ```bash 199 nmap -sC : equivalent to --script=default 200 201 nmap --script 'http-enum' -v web.xxxx.com -p80 -oN http-enum.nmap 202 PORT STATE SERVICE 203 80/tcp open http 204 | http-enum: 205 | /phpmyadmin/: phpMyAdmin 206 | /.git/HEAD: Git folder 207 | /css/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)' 208 |_ /image/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)' 209 210 nmap --script smb-enum-users.nse -p 445 [target host] 211 Host script results: 212 | smb-enum-users: 213 | METASPLOITABLE\backup (RID: 1068) 214 | Full name: backup 215 | Flags: Account disabled, Normal user account 216 | METASPLOITABLE\bin (RID: 1004) 217 | Full name: bin 218 | Flags: Account disabled, Normal user account 219 | METASPLOITABLE\msfadmin (RID: 3000) 220 | Full name: msfadmin,,, 221 | Flags: Normal user account 222 223 List Nmap scripts : ls /usr/share/nmap/scripts/ 224 ``` 225 226 ### Network Scan with nc and ping 227 228 Sometimes we want to perform network scan without any tools like nmap. So we can use the commands `ping` and `nc` to check if a host is up and which port is open. 229 230 To check if hosts are up on a /24 range 231 232 ```bash 233 for i in `seq 1 255`; do ping -c 1 -w 1 192.168.1.$i > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "192.168.1.$i is UP"; fi ; done 234 ``` 235 236 To check which ports are open on a specific host 237 238 ```bash 239 for i in {21,22,80,139,443,445,3306,3389,8080,8443}; do nc -z -w 1 192.168.1.18 $i > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "192.168.1.18 has port $i open"; fi ; done 240 ``` 241 242 Both at the same time on a /24 range 243 244 ```bash 245 for i in `seq 1 255`; do ping -c 1 -w 1 192.168.1.$i > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "192.168.1.$i is UP:"; for j in {21,22,80,139,443,445,3306,3389,8080,8443}; do nc -z -w 1 192.168.1.$i $j > /dev/null 2>&1; if [ $? -eq 0 ]; then echo "\t192.168.1.$i has port $j open"; fi ; done ; fi ; done 246 ``` 247 248 Not in one-liner version: 249 250 ```bash 251 for i in `seq 1 255`; 252 do 253 ping -c 1 -w 1 192.168.1.$i > /dev/null 2>&1; 254 if [ $? -eq 0 ]; 255 then 256 echo "192.168.1.$i is UP:"; 257 for j in {21,22,80,139,443,445,3306,3389,8080,8443}; 258 do 259 nc -z -w 1 192.168.1.$i $j > /dev/null 2>&1; 260 if [ $? -eq 0 ]; 261 then 262 echo "\t192.168.1.$i has port $j open"; 263 fi ; 264 done ; 265 fi ; 266 done 267 ``` 268 269 ### Network Scan with PowerShell 270 271 ```powershell 272 # ping scan 273 tnc 8.8.8.8 274 275 # port scan 276 tnc 8.8.8.8 -port 443 277 ``` 278 279 ### Masscan 280 281 ```powershell 282 masscan -iL ips-online.txt --rate 10000 -p1-65535 --only-open -oL masscan.out 283 masscan -e tun0 -p1-65535,U:1-65535 10.10.10.97 --rate 1000 284 285 # find machines on the network 286 sudo masscan --rate 500 --interface tap0 --router-ip $ROUTER_IP --top-ports 100 $NETWORK -oL masscan_machines.tmp 287 cat masscan_machines.tmp | grep open | cut -d " " -f4 | sort -u > masscan_machines.lst 288 289 # find open ports for one machine 290 sudo masscan --rate 1000 --interface tap0 --router-ip $ROUTER_IP -p1-65535,U:1-65535 $MACHINE_IP --banners -oL $MACHINE_IP/scans/masscan-ports.lst 291 292 293 # TCP grab banners and services information 294 TCP_PORTS=$(cat $MACHINE_IP/scans/masscan-ports.lst| grep open | grep tcp | cut -d " " -f3 | tr '\n' ',' | head -c -1) 295 [ "$TCP_PORTS" ] && sudo nmap -sT -sC -sV -v -Pn -n -T4 -p$TCP_PORTS --reason --version-intensity=5 -oA $MACHINE_IP/scans/nmap_tcp $MACHINE_IP 296 297 # UDP grab banners and services information 298 UDP_PORTS=$(cat $MACHINE_IP/scans/masscan-ports.lst| grep open | grep udp | cut -d " " -f3 | tr '\n' ',' | head -c -1) 299 [ "$UDP_PORTS" ] && sudo nmap -sU -sC -sV -v -Pn -n -T4 -p$UDP_PORTS --reason --version-intensity=5 -oA $MACHINE_IP/scans/nmap_udp $MACHINE_IP 300 ``` 301 302 ### Reconnoitre 303 304 Dependencies: 305 306 * nbtscan 307 * nmap 308 309 ```powershell 310 python2.7 ./reconnoitre.py -t 192.168.1.2-252 -o ./results/ --pingsweep --hostnames --services --quick 311 ``` 312 313 If you have a segfault with nbtscan, read the following quote. 314 > Permission is denied on the broadcast address (.0) and it segfaults on the gateway (.1) - all other addresses seem fine here.So to mitigate the problem: nbtscan 192.168.0.2-255 315 316 ## Netdiscover 317 318 ```powershell 319 netdiscover -i eth0 -r 192.168.1.0/24 320 Currently scanning: Finished! | Screen View: Unique Hosts 321 322 20 Captured ARP Req/Rep packets, from 4 hosts. Total size: 876 323 _____________________________________________________________________________ 324 IP At MAC Address Count Len MAC Vendor / Hostname 325 ----------------------------------------------------------------------------- 326 192.168.1.AA 68:AA:AA:AA:AA:AA 15 630 Sagemcom 327 192.168.1.XX 52:XX:XX:XX:XX:XX 1 60 Unknown vendor 328 192.168.1.YY 24:YY:YY:YY:YY:YY 1 60 QNAP Systems, Inc. 329 192.168.1.ZZ b8:ZZ:ZZ:ZZ:ZZ:ZZ 3 126 HUAWEI TECHNOLOGIES CO.,LTD 330 ``` 331 332 ## Responder 333 334 ```powershell 335 responder -I eth0 -A # see NBT-NS, BROWSER, LLMNR requests without responding. 336 responder.py -I eth0 -wrf 337 ``` 338 339 Alternatively you can use the [Windows version](https://github.com/lgandx/Responder-Windows) 340 341 ## MITM 342 343 * WSUS poisoning 344 * ARP poisoning 345 * DHCP poisoning: `responder --interface "eth0" --DHCP --wpad` 346 347 ### Bettercap 348 349 ```powershell 350 bettercap -X --proxy --proxy-https -T <target IP> 351 # better cap in spoofing, discovery, sniffer 352 # intercepting http and https requests, 353 # targetting specific IP only 354 ``` 355 356 ### SSL MITM with OpenSSL 357 358 This code snippet allows you to sniff/modify SSL traffic if there is a MITM vulnerability using only openssl. 359 If you can modify `/etc/hosts` of the client: 360 361 ```powershell 362 sudo echo "[OPENSSL SERVER ADDRESS] [domain.of.server.to.mitm]" >> /etc/hosts # On client host 363 ``` 364 365 On our MITM server, if the client accepts self signed certificates (you can use a legit certificate if you have the private key of the legit server): 366 367 ```powershell 368 openssl req -subj '/CN=[domain.of.server.to.mitm]' -batch -new -x509 -days 365 -nodes -out server.pem -keyout server.pem 369 ``` 370 371 On our MITM server, we setup our infra: 372 373 ```powershell 374 mkfifo response 375 sudo openssl s_server -cert server.pem -accept [INTERFACE TO LISTEN TO]:[PORT] -quiet < response | tee | openssl s_client -quiet -servername [domain.of.server.to.mitm] -connect[IP of server to MITM]:[PORT] | tee | cat > response 376 ``` 377 378 In this example, traffic is only displayed with `tee` but we could modify it using `sed` for example. 379 380 ## References 381 382 * [Pwning the Domain: Credentialess/Username - hadess - February 7, 2024](https://hadess.io/pwning-the-domain-credentialess-username/)