daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

anonymous-null-testing.md (36765B)


      1 ---
      2 title: "Anonymous Null Testing"
      3 description: "nxc smb <IP> -u '' -p '' # Test anonymous access nxc smb <IP> -u 'guest' -p '' # Test guest account nxc smb <IP> -u='' -p='' # Windows syntax"
      4 category: enumeration
      5 tags: ["enumeration", "privilege-escalation"]
      6 tools: ["smbmap", "NetExec", "ldapsearch"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/Anonymous  Null Testing.md"
     10 ---
     11 # Test null session
     12 nxc smb <IP> -u '' -p ''                                    # Test anonymous access
     13 nxc smb <IP> -u 'guest' -p ''                               # Test guest account
     14 nxc smb <IP> -u='' -p=''                                    # Windows syntax
     15 ```
     16 
     17 **Output interpretation**:
     18 
     19 1. Green **[+]**: Authentication succeeded
     20 2. Red **[-]**: Authentication failed
     21 3. **Pwn3d!**: Administrative privileges obtained
     22 4. **STATUS_LOGON_FAILURE**: Null session blocked
     23 5. **STATUS_ACCESS_DENIED**: Authenticated but no privileges
     24 
     25 ```bash
     26 # Basic enumeration
     27 nxc smb <IP> -u '' -p '' --shares                           # List shares
     28 nxc smb <IP> -u '' -p '' --users                            # List users
     29 nxc smb <IP> -u '' -p '' --groups                           # List groups
     30 nxc smb <IP> -u '' -p '' --pass-pol                         # Password policy
     31 nxc smb <IP> -u '' -p '' --sessions                         # Active sessions
     32 nxc smb <IP> -u '' -p '' --loggedon-users                   # Logged on users
     33 nxc smb <IP> -u '' -p '' --rid-brute                        # RID brute force (noisy)
     34 nxc smb <IP> -u '' -p '' --disks                            # List disks
     35 ```
     36 
     37 **RID brute force warning**: Generates hundreds of Windows Event ID 4625 (failed logon) events—extremely noisy
     38 
     39 ---
     40 
     41 ### SMB File Operations
     42 
     43 ```bash
     44 # List files in share
     45 nxc smb <IP> -u '' -p '' --ls SHARENAME                     # List root of share
     46 nxc smb <IP> -u '' -p '' --ls 'SHARENAME/folder'            # List subdirectory
     47 ```
     48 
     49 ```bash
     50 # Download files
     51 nxc smb <IP> -u '' -p '' --get-file 'SHARE\file.txt' ./local.txt        # Download file
     52 nxc smb <IP> -u '' -p '' --get-file 'C$\Windows\System32\drivers\etc\hosts' ./hosts    # Download specific file
     53 ```
     54 
     55 ```bash
     56 # Upload files
     57 nxc smb <IP> -u '' -p '' --put-file local.txt 'SHARE\remote.txt'        # Upload file
     58 ```
     59 
     60 ```bash
     61 # Spider shares (search files)
     62 nxc smb <IP> -u '' -p '' --spider SHARENAME                              # List all files
     63 nxc smb <IP> -u '' -p '' --spider SHARENAME --pattern txt                # Search by extension
     64 nxc smb <IP> -u '' -p '' --spider SHARENAME --pattern 'password|secret'  # Search by keyword
     65 nxc smb <IP> -u '' -p '' --spider SHARENAME --regex '.*\.config'         # Regex search
     66 nxc smb <IP> -u '' -p '' --spider SHARENAME --depth 3                    # Limit depth
     67 nxc smb <IP> -u '' -p '' --spider SHARENAME --only-files                 # Files only
     68 nxc smb <IP> -u '' -p '' --spider SHARENAME --content --pattern password # Search file content
     69 ```
     70 
     71 **Spider options**:
     72 
     73 1. **--pattern**: Match file names by keyword or extension
     74 2. **--regex**: Match file names by regular expression
     75 3. **--depth**: Limit recursion depth (reduces noise)
     76 4. **--only-files**: Skip directories in output
     77 5. **--content**: Search inside file contents (requires read access)
     78 
     79 ---
     80 
     81 ### SMB spider_plus Module
     82 
     83 The spider_plus module provides advanced recursive file enumeration with JSON output for parsing and filtering.
     84 
     85 **Output location**: `~/.nxc/logs/` or `/tmp/nxc_spider_plus/<IP>.json`
     86 
     87 **Module requirements**: NetExec 1.0.0+
     88 
     89 ```bash
     90 # List all files (creates JSON output)
     91 nxc smb <IP> -u '' -p '' -M spider_plus                                  # List files
     92 nxc smb <IP> -u '' -p '' -M spider_plus -o DOWNLOAD_FLAG=True            # Download all files
     93 nxc smb <IP> -u '' -p '' -M spider_plus -o PATTERN='*.txt,*.xml,*.config' # Filter extensions
     94 nxc smb <IP> -u '' -p '' -M spider_plus -o DEPTH=3                       # Limit depth
     95 nxc smb <IP> -u '' -p '' -M spider_plus -o EXCLUDE_EXTS='exe,dll'        # Exclude types
     96 ```
     97 
     98 **Module options**:
     99 
    100 1. **DOWNLOAD_FLAG=True**: Download all enumerated files
    101 2. **PATTERN='*.ext1,*.ext2'**: Filter by file extensions (comma-separated)
    102 3. **DEPTH=<n>**: Control recursion depth
    103 4. **EXCLUDE_EXTS='ext1,ext2'**: Exclude specific file types
    104 
    105 ```bash
    106 # Parse JSON output
    107 cat /tmp/nxc_spider_plus/<IP>.json | jq '.'                              # Pretty print
    108 cat ~/.nxc/logs/<output>.json | jq '.[] | select(.name | endswith(".txt"))'  # Filter .txt files
    109 cat ~/.nxc/logs/<output>.json | jq '.[] | select(.size > 10000)'         # Filter by size
    110 ```
    111 
    112 **JSON structure**: Array of objects with fields: `name`, `path`, `size`, `atime` (access time), `ctime` (creation time), `mtime` (modification time)
    113 
    114 ---
    115 
    116 ### SMB Vulnerability Checks
    117 
    118 ```bash
    119 nxc smb <IP> -u '' -p '' -M ms17-010                        # Check EternalBlue (CVE-2017-0144)
    120 nxc smb <IP> -u '' -p '' -M zerologon                       # Check ZeroLogon (CVE-2020-1472)
    121 nxc smb <IP> -u '' -p '' -M petitpotam                      # Check PetitPotam
    122 nxc smb <IP> -u '' -p '' -M printnightmare                  # Check PrintNightmare (CVE-2021-34527)
    123 nxc smb <IP> -u '' -p '' -M nopac                           # Check noPac (CVE-2021-42278/42287)
    124 nxc smb <IP> -u '' -p '' -M spooler                         # Check print spooler status
    125 nxc smb <IP> -u '' -p '' -M enum_av                         # Enumerate antivirus
    126 nxc smb <IP> -u '' -p '' -M enum_ca                         # Enumerate ADCS (Certificate Authority)
    127 nxc smb <IP> -u '' -p '' --gen-relay-list relay.txt         # Check SMB signing (relay attacks)
    128 ```
    129 
    130 **Vulnerability module notes**:
    131 
    132 1. Modules check for vulnerability presence—do not exploit
    133 2. **--gen-relay-list**: Identifies hosts without SMB signing (vulnerable to relay attacks)
    134 3. Some modules require valid credentials (not anonymous)
    135 
    136 ---
    137 
    138 ### LDAP Anonymous Bind Testing
    139 
    140 **Port**: 389/tcp (LDAP) or 636/tcp (LDAPS)
    141 
    142 **Anonymous bind**: Authenticates with empty credentials to query directory information
    143 
    144 ```bash
    145 # Test anonymous bind
    146 nxc ldap <IP> -u '' -p ''                                   # Test anonymous LDAP
    147 ```
    148 
    149 **Result codes**:
    150 
    151 1. **LDAP Result Code 0 (success)**: Anonymous bind allowed
    152 2. **LDAP Result Code 49 (invalidCredentials)**: Anonymous bind blocked
    153 
    154 ```bash
    155 # Basic enumeration
    156 nxc ldap <IP> -u '' -p '' --users                           # List users
    157 nxc ldap <IP> -u '' -p '' --groups                          # List groups
    158 nxc ldap <IP> -u '' -p '' --computers                       # List computers
    159 nxc ldap <IP> -u '' -p '' --get-sid                         # Get domain SID
    160 ```
    161 
    162 ```bash
    163 # LDAP modules
    164 nxc ldap <IP> -u '' -p '' -M get-desc-users                 # Get user descriptions
    165 nxc ldap <IP> -u '' -p '' -M maq                            # Machine Account Quota
    166 nxc ldap <IP> -u '' -p '' -M ldap-checker                   # LDAP signing check
    167 nxc ldap <IP> -u '' -p '' -M enum_trusts                    # Enumerate trusts
    168 nxc ldap <IP> -u '' -p '' -M whoami                         # Current context
    169 ```
    170 
    171 ```bash
    172 # Custom LDAP queries
    173 nxc ldap <IP> -u '' -p '' --query "(objectClass=user)" "sAMAccountName,description"
    174 nxc ldap <IP> -u '' -p '' --query "(objectClass=group)" "name,member"
    175 nxc ldap <IP> -u '' -p '' --query "(servicePrincipalName=*)" "servicePrincipalName"
    176 nxc ldap <IP> -u '' -p '' --query "(adminCount=1)" "sAMAccountName"
    177 ```
    178 
    179 **Custom query format**: `--query "<LDAP_FILTER>" "<ATTRIBUTES>"`
    180 
    181 **Common LDAP filters**:
    182 
    183 1. **(objectClass=user)**: All user objects
    184 2. **(objectClass=group)**: All group objects
    185 3. **(servicePrincipalName=*)**: Users with SPNs (Kerberoastable)
    186 4. **(adminCount=1)**: Protected admin accounts
    187 5. **(userAccountControl:1.2.840.113556.1.4.803:=8192)**: Domain controllers
    188 
    189 ---
    190 
    191 ### FTP Anonymous Access
    192 
    193 **Port**: 21/tcp
    194 
    195 **Anonymous credentials**: Username `anonymous` or empty; password empty or email address
    196 
    197 ```bash
    198 # Test anonymous login
    199 nxc ftp <IP> -u '' -p ''                                    # Empty credentials
    200 nxc ftp <IP> -u 'anonymous' -p ''                           # Anonymous user
    201 nxc ftp <IP> -u 'anonymous' -p 'user@example.com'           # With email
    202 ```
    203 
    204 **FTP response codes**:
    205 
    206 1. **230 Login successful**: Anonymous login allowed
    207 2. **530 Login incorrect**: Anonymous login blocked
    208 
    209 ```bash
    210 # List files
    211 nxc ftp <IP> -u 'anonymous' -p '' --ls                      # List root
    212 nxc ftp <IP> -u 'anonymous' -p '' --ls /pub                 # List directory
    213 ```
    214 
    215 ```bash
    216 # Download files
    217 nxc ftp <IP> -u 'anonymous' -p '' --get file.txt            # Download file
    218 nxc ftp <IP> -u 'anonymous' -p '' --get /pub/data.txt       # Download from path
    219 ```
    220 
    221 ---
    222 
    223 ### MSSQL Blank Password Testing
    224 
    225 **Port**: 1433/tcp (default instance) or dynamic ports (named instances)
    226 
    227 **Default accounts**: `sa` (system administrator), `MSSQLSERVER`, `admin`
    228 
    229 ```bash
    230 # Test blank passwords
    231 nxc mssql <IP> -u 'sa' -p ''                                # Test sa account
    232 nxc mssql <IP> -u users.txt -p ''                           # Test multiple users
    233 ```
    234 
    235 ```bash
    236 # Execute queries
    237 nxc mssql <IP> -u 'sa' -p '' -q "SELECT @@version"          # Version
    238 nxc mssql <IP> -u 'sa' -p '' -q "SELECT name FROM sys.databases"  # List databases
    239 nxc mssql <IP> -u 'sa' -p '' -q "SELECT * FROM information_schema.tables"  # List tables
    240 ```
    241 
    242 ```bash
    243 # File operations
    244 nxc mssql <IP> -u 'sa' -p '' --get-file 'C:\backup\db.bak' ./db.bak  # Download file
    245 nxc mssql <IP> -u 'sa' -p '' --put-file payload.txt 'C:\temp\payload.txt'  # Upload file
    246 ```
    247 
    248 **File operations**: Require `xp_cmdshell` enabled or bulk insert privileges
    249 
    250 ---
    251 
    252 ### List NetExec Modules
    253 
    254 ```bash
    255 nxc smb -L                                                  # List SMB modules
    256 nxc ldap -L                                                 # List LDAP modules
    257 nxc mssql -L                                                # List MSSQL modules
    258 nxc ftp -L                                                  # List FTP modules
    259 nxc winrm -L                                                # List WinRM modules
    260 nxc ssh -L                                                  # List SSH modules
    261 nxc rdp -L                                                  # List RDP modules
    262 
    263 nxc smb -M spider_plus --options                            # View module options
    264 ```
    265 
    266 ---
    267 
    268 ## Alternative Tools - Anonymous Access & Enumeration
    269 
    270 ### smbclient - SMB File Operations
    271 
    272 [smbclient](https://www.samba.org/samba/docs/current/man-html/smbclient.1.html) is the native SMB client from Samba. Pre-installed on most Linux distributions.
    273 
    274 **UNC path syntax**: `\\\\IP\\SHARE` (Windows) or `//IP/SHARE` (Linux/macOS)
    275 
    276 **List shares**:
    277 
    278 ```bash
    279 smbclient -N -L //<IP>                                      # List shares (null session)
    280 smbclient -N -U '' -L //<IP>                                # List shares (explicit)
    281 smbclient -L //<IP> -U 'guest%'                             # List shares (guest)
    282 ```
    283 
    284 **Options**:
    285 
    286 1. **-N**: No password prompt (null session)
    287 2. **-L**: List shares
    288 3. **-U 'user%pass'**: Specify username and password
    289 
    290 **Connect and browse files**:
    291 
    292 ```bash
    293 # Connect to share
    294 smbclient -N //<IP>/SHARENAME                               # Connect with null session
    295 smbclient //<IP>/SHARENAME -U 'guest%'                      # Connect as guest
    296 ```
    297 
    298 **Interactive commands** (inside `smb: \>` prompt):
    299 
    300 ```bash
    301 smb: \> ls                                                  # List files
    302 smb: \> cd folder                                           # Change directory
    303 smb: \> pwd                                                 # Print working directory
    304 smb: \> dir                                                 # List files (alternative)
    305 smb: \> get file.txt                                        # Download single file
    306 smb: \> mget *.txt                                          # Download multiple files
    307 smb: \> prompt OFF                                          # Disable prompts
    308 smb: \> recurse ON                                          # Enable recursion
    309 smb: \> mget *                                              # Download everything
    310 smb: \> put localfile.txt                                   # Upload file
    311 smb: \> mput *.txt                                          # Upload multiple
    312 smb: \> del file.txt                                        # Delete file
    313 smb: \> rm file.txt                                         # Delete file (alternative)
    314 smb: \> mkdir newfolder                                     # Create directory
    315 smb: \> rmdir oldfolder                                     # Remove directory
    316 smb: \> exit                                                # Disconnect
    317 ```
    318 
    319 **Non-interactive commands**:
    320 
    321 ```bash
    322 # List files in share
    323 smbclient -N //<IP>/SHARENAME -c 'ls'                       # List files
    324 smbclient -N //<IP>/SHARENAME -c 'cd Documents; ls'         # List subdirectory
    325 ```
    326 
    327 ```bash
    328 # Download files
    329 smbclient -N //<IP>/SHARENAME -c 'get file.txt'             # Download file
    330 smbclient -N //<IP>/SHARENAME -c 'cd backup; get db.bak'    # Download from subdir
    331 ```
    332 
    333 ```bash
    334 # Recursive download all files
    335 smbclient -N //<IP>/SHARENAME -c 'prompt OFF; recurse ON; mget *'
    336 ```
    337 
    338 ```bash
    339 # Download specific file types
    340 smbclient -N //<IP>/SHARENAME -c 'prompt OFF; mget *.txt'
    341 ```
    342 
    343 ```bash
    344 # Upload file
    345 smbclient -N //<IP>/SHARENAME -c 'put local.txt remote.txt'
    346 ```
    347 
    348 ```bash
    349 # Multiple commands
    350 smbclient -N //<IP>/SHARENAME -c 'cd folder; ls; get file.txt'
    351 ```
    352 
    353 **Command chaining**: Use `;` to separate multiple commands in `-c` flag
    354 
    355 ---
    356 
    357 ### rpcclient - RPC Enumeration
    358 
    359 [rpcclient](https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html) enumerates domain information via MS-RPC with null session. Part of Samba suite.
    360 
    361 **Connect**:
    362 
    363 ```bash
    364 rpcclient -N -U '' <IP>                                     # Connect with null session
    365 rpcclient -U 'guest%' <IP>                                  # Connect as guest
    366 ```
    367 
    368 **Interactive commands** (inside `rpcclient $>` prompt):
    369 
    370 ```bash
    371 rpcclient $> srvinfo                                        # Server info
    372 rpcclient $> enumdomusers                                   # List users
    373 rpcclient $> enumdomgroups                                  # List groups
    374 rpcclient $> querydominfo                                   # Domain info
    375 rpcclient $> getdompwinfo                                   # Password policy
    376 rpcclient $> querydispinfo                                  # User details
    377 rpcclient $> netshareenumall                                # List all shares
    378 rpcclient $> netshareenum                                   # List shares
    379 rpcclient $> queryuser 500                                  # Query user by RID (500=Administrator)
    380 rpcclient $> querygroup 512                                 # Query group by RID (512=Domain Admins)
    381 rpcclient $> querygroupmem 512                              # List group members
    382 rpcclient $> enumalsgroups builtin                          # List local groups
    383 rpcclient $> queryaliasmem builtin 0x220                    # List admin group members
    384 rpcclient $> lookupnames Administrator                      # Get SID from name
    385 rpcclient $> lookupsids S-1-5-21-...-500                    # Get name from SID
    386 rpcclient $> enumprinters                                   # List printers
    387 rpcclient $> enumtrust                                      # List domain trusts
    388 rpcclient $> enumprivs                                      # List privileges
    389 ```
    390 
    391 **Common RIDs**:
    392 
    393 1. **500**: Administrator
    394 2. **501**: Guest
    395 3. **512**: Domain Admins
    396 4. **513**: Domain Users
    397 5. **514**: Domain Guests
    398 6. **515**: Domain Computers
    399 7. **516**: Domain Controllers
    400 8. **544**: Administrators (local)
    401 9. **1000+**: Domain user accounts
    402 
    403 **One-liner commands**:
    404 
    405 ```bash
    406 rpcclient -N -U '' <IP> -c 'enumdomusers'                   # List users
    407 rpcclient -N -U '' <IP> -c 'enumdomgroups'                  # List groups
    408 rpcclient -N -U '' <IP> -c 'querydominfo'                   # Domain info
    409 rpcclient -N -U '' <IP> -c 'netshareenumall'                # List shares
    410 rpcclient -N -U '' <IP> -c 'getdompwinfo'                   # Password policy
    411 rpcclient -N -U '' <IP> -c 'querydispinfo'                  # User details
    412 rpcclient -N -U '' <IP> -c 'srvinfo'                        # Server info
    413 ```
    414 
    415 ```bash
    416 # Chain multiple commands
    417 rpcclient -N -U '' <IP> -c 'enumdomusers;enumdomgroups;netshareenumall'
    418 ```
    419 
    420 **Command chaining**: Use `;` separator to execute multiple commands in single connection
    421 
    422 ---
    423 
    424 ### smbmap - File Enumeration
    425 
    426 [smbmap](https://github.com/ShawnDEvans/smbmap) is a Python-based SMB enumeration tool with recursive file listing and pattern-based auto-download.
    427 
    428 **List shares**:
    429 
    430 ```bash
    431 smbmap -u '' -p '' -H <IP>                                  # List shares (null session)
    432 smbmap -u 'guest' -p '' -H <IP>                             # List shares (guest)
    433 ```
    434 
    435 **Permissions displayed**: `READ ONLY`, `READ, WRITE`, `NO ACCESS`
    436 
    437 **List files**:
    438 
    439 ```bash
    440 smbmap -u '' -p '' -H <IP> -R                               # List all files recursively
    441 smbmap -u '' -p '' -H <IP> -r SHARENAME                     # List files in share
    442 smbmap -u '' -p '' -H <IP> -R -A '.*\.txt'                  # Auto-download .txt files
    443 smbmap -u '' -p '' -H <IP> -R -A '.*\.xml|.*\.config'       # Auto-download config files
    444 smbmap -u '' -p '' -H <IP> -R --depth 2                     # Limit recursion depth
    445 smbmap -u '' -p '' -H <IP> -R --exclude ADMIN$ C$           # Exclude shares
    446 smbmap -u '' -p '' -H <IP> -R --dir-only                    # List directories only
    447 ```
    448 
    449 **Options**:
    450 
    451 1. **-R**: Recursive listing (all shares)
    452 2. **-r SHARENAME**: Target specific share
    453 3. **-A <pattern>**: Auto-download files matching regex
    454 4. **--depth <n>**: Limit recursion depth
    455 5. **--exclude <shares>**: Exclude specific shares
    456 6. **--dir-only**: List directories only (no files)
    457 
    458 **Download files**:
    459 
    460 ```bash
    461 smbmap -u '' -p '' -H <IP> --download 'SHARE\file.txt'      # Download file
    462 smbmap -u '' -p '' -H <IP> --download 'C$\Windows\System32\drivers\etc\hosts'  # Download specific file
    463 ```
    464 
    465 **Upload files**:
    466 
    467 ```bash
    468 smbmap -u '' -p '' -H <IP> --upload 'local.txt' 'SHARE\remote.txt'  # Upload file
    469 ```
    470 
    471 **Search file content** (requires admin rights):
    472 
    473 ```bash
    474 smbmap -u '' -p '' -H <IP> -R -F 'password'                 # Search file content
    475 ```
    476 
    477 ---
    478 
    479 ### enum4linux - Comprehensive Enumeration
    480 
    481 [enum4linux](https://github.com/CiscoCXSecurity/enum4linux) is a Perl-based wrapper around smbclient, rpcclient, and other tools. [enum4linux-ng](https://github.com/cddmp/enum4linux-ng) is the newer Python rewrite.
    482 
    483 **Basic usage**:
    484 
    485 ```bash
    486 enum4linux <IP>                                             # Basic enumeration
    487 enum4linux -a <IP>                                          # All enumeration (noisy)
    488 ```
    489 
    490 **Warning**: `-a` flag includes RID cycling which generates hundreds of Event ID 4625 (failed logon) events
    491 
    492 **Targeted enumeration**:
    493 
    494 ```bash
    495 enum4linux -U <IP>                                          # Users only
    496 enum4linux -S <IP>                                          # Shares only
    497 enum4linux -G <IP>                                          # Groups only
    498 enum4linux -P <IP>                                          # Password policy only
    499 enum4linux -o <IP>                                          # OS info only
    500 enum4linux -i <IP>                                          # Printer info only
    501 enum4linux -n <IP>                                          # NetBIOS info only
    502 ```
    503 
    504 ```bash
    505 # Combination
    506 enum4linux -U -S -P <IP>                                    # Users, shares, password policy
    507 ```
    508 
    509 **RID cycling** (noisy):
    510 
    511 ```bash
    512 enum4linux -r <IP>                                          # RID cycling (default range)
    513 enum4linux -R 500-600 <IP>                                  # RID cycling (custom range)
    514 enum4linux -R 500-550,1000-1050 <IP>                        # Multiple ranges
    515 ```
    516 
    517 **Verbose output**:
    518 
    519 ```bash
    520 enum4linux -v -a <IP>                                       # Verbose all enumeration
    521 ```
    522 
    523 ---
    524 
    525 ### FTP Client - Anonymous Access
    526 
    527 Native `ftp` command pre-installed on Linux/macOS/BSD/Windows.
    528 
    529 **Connect**:
    530 
    531 ```bash
    532 ftp <IP>                                                    # Connect (will prompt for credentials)
    533 # Username: anonymous
    534 # Password: (press Enter or type email)
    535 ```
    536 
    537 **Interactive commands** (inside `ftp>` prompt):
    538 
    539 ```bash
    540 ftp> ls                                                     # List files
    541 ftp> dir                                                    # List files (detailed)
    542 ftp> cd directory                                           # Change directory
    543 ftp> pwd                                                    # Print working directory
    544 ftp> binary                                                 # Binary mode (for non-text files)
    545 ftp> ascii                                                  # ASCII mode (for text files)
    546 ftp> get file.txt                                           # Download file
    547 ftp> mget *.txt                                             # Download multiple files
    548 ftp> prompt OFF                                             # Disable prompts
    549 ftp> mget *                                                 # Download all files
    550 ftp> put local.txt                                          # Upload file
    551 ftp> mput *.txt                                             # Upload multiple files
    552 ftp> delete file.txt                                        # Delete file
    553 ftp> mkdir newfolder                                        # Create directory
    554 ftp> rmdir oldfolder                                        # Remove directory
    555 ftp> bye                                                    # Disconnect
    556 ftp> quit                                                   # Disconnect (alternative)
    557 ```
    558 
    559 **Transfer modes**:
    560 
    561 1. **binary**: For executables, images, archives (prevents corruption)
    562 2. **ascii**: For text files (handles line ending conversions)
    563 
    564 **Non-interactive**:
    565 
    566 ```bash
    567 # List files
    568 echo -e "user anonymous\npass\nls\nquit" | ftp -n <IP>
    569 ```
    570 
    571 ```bash
    572 # Download file
    573 echo -e "user anonymous\npass\nbinary\nget file.txt\nquit" | ftp -n <IP>
    574 ```
    575 
    576 ```bash
    577 # Download all files
    578 echo -e "user anonymous\npass\nprompt OFF\nmget *\nquit" | ftp -n <IP>
    579 ```
    580 
    581 **-n flag**: Disables auto-login (required for scripting with piped commands)
    582 
    583 ---
    584 
    585 ### ldapsearch - LDAP Anonymous Queries
    586 
    587 [ldapsearch](https://linux.die.net/man/1/ldapsearch) is the native LDAP client from OpenLDAP. Pre-installed on most Linux distributions.
    588 
    589 **Test anonymous bind**:
    590 
    591 ```bash
    592 ldapsearch -x -H ldap://<IP> -b '' -s base                  # Test anonymous bind
    593 ldapsearch -x -H ldap://<IP> -b '' -s base namingContexts   # Get base DN
    594 ```
    595 
    596 **Options**:
    597 
    598 1. **-x**: Simple authentication (required)
    599 2. **-H ldap://<IP>**: LDAP URI (use `ldaps://` for SSL on port 636)
    600 3. **-b 'base DN'**: Base DN to search
    601 4. **-s base**: Search scope = base object only
    602 5. **-LLL**: Reduce output verbosity
    603 
    604 **Enumerate users**:
    605 
    606 ```bash
    607 # All users
    608 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=user)' -LLL
    609 ```
    610 
    611 ```bash
    612 # Users with descriptions
    613 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=user)' sAMAccountName,description -LLL
    614 ```
    615 
    616 ```bash
    617 # Admin users
    618 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=user)(adminCount=1))' -LLL
    619 ```
    620 
    621 ```bash
    622 # Users with SPNs (Kerberoastable)
    623 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=user)(servicePrincipalName=*))' -LLL
    624 ```
    625 
    626 ```bash
    627 # Specific user
    628 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(sAMAccountName=Administrator)' -LLL
    629 ```
    630 
    631 **Enumerate groups**:
    632 
    633 ```bash
    634 # All groups
    635 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=group)' -LLL
    636 ```
    637 
    638 ```bash
    639 # Domain Admins
    640 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(cn=Domain Admins)' member -LLL
    641 ```
    642 
    643 ```bash
    644 # Privileged groups
    645 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=group)(adminCount=1))' -LLL
    646 ```
    647 
    648 **Enumerate computers**:
    649 
    650 ```bash
    651 # All computers
    652 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=computer)' -LLL
    653 ```
    654 
    655 ```bash
    656 # Domain controllers
    657 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(userAccountControl:1.2.840.113556.1.4.803:=8192)' -LLL
    658 ```
    659 
    660 ```bash
    661 # Servers
    662 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=computer)(operatingSystem=*Server*))' -LLL
    663 ```
    664 
    665 **LDAP filter operators**:
    666 
    667 1. **&**: AND operator (all conditions must match)
    668 2. **|**: OR operator (any condition matches)
    669 3. **!**: NOT operator (condition must not match)
    670 4. **=**: Equality match
    671 5. **~=**: Approximate match
    672 6. **>=**, **<=**: Greater/less than or equal
    673 7. **=***: Presence check (attribute exists)
    674 
    675 ---
    676 
    677 ### NFS - Mount and Browse
    678 
    679 [NFS](https://en.wikipedia.org/wiki/Network_File_System) typically has no authentication—access control based solely on IP restrictions.
    680 
    681 **List exports**:
    682 
    683 ```bash
    684 showmount -e <IP>                                           # List NFS exports
    685 showmount -a <IP>                                           # List mounted clients
    686 ```
    687 
    688 **Export format**: `/path (allowed_hosts)` where allowed_hosts can be `*` (all), `IP/subnet`, or specific hostnames
    689 
    690 **Mount and access**:
    691 
    692 ```bash
    693 # Mount share
    694 sudo mount -t nfs <IP>:/export /mnt/nfs                     # Mount NFS share
    695 sudo mount -t nfs -o vers=3 <IP>:/export /mnt/nfs           # Mount with NFSv3
    696 ```
    697 
    698 **Mount options**:
    699 
    700 1. **vers=3**: Force NFSv3
    701 2. **vers=4**: Force NFSv4
    702 3. **ro**: Read-only mount
    703 4. **rw**: Read-write mount
    704 5. **soft**: Soft mount (timeout on errors)
    705 6. **hard**: Hard mount (retry indefinitely)
    706 
    707 ```bash
    708 # Browse files
    709 cd /mnt/nfs                                                 # Change to mount point
    710 ls -la                                                      # List files
    711 find . -type f -name "*.txt"                                # Find files
    712 cat file.txt                                                # Read file
    713 cp file.txt /tmp/                                           # Copy file
    714 ```
    715 
    716 ```bash
    717 # Unmount
    718 sudo umount /mnt/nfs                                        # Unmount share
    719 ```
    720 
    721 **Create mount point** (if doesn't exist):
    722 
    723 ```bash
    724 sudo mkdir -p /mnt/nfs                                      # Create directory
    725 ```
    726 
    727 ---
    728 
    729 ### SNMP - Community String Testing
    730 
    731 [SNMP](https://en.wikipedia.org/wiki/Simple_Network_Management_Protocol) versions 1 and 2c use plaintext community strings. Default strings: `public` (read-only), `private` (read-write).
    732 
    733 **Test with onesixtyone**:
    734 
    735 [onesixtyone](https://github.com/trailofbits/onesixtyone) is a fast SNMP scanner for brute forcing community strings.
    736 
    737 ```bash
    738 onesixtyone <IP>                                            # Test default communities
    739 onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt <IP>
    740 onesixtyone -c community.txt -i targets.txt                 # Multiple hosts
    741 ```
    742 
    743 **Options**:
    744 
    745 1. **-c <file>**: Community string wordlist
    746 2. **-i <file>**: IP address list file
    747 3. **-w <n>**: Wait time in milliseconds (default 10)
    748 
    749 **Walk with snmpwalk**:
    750 
    751 [snmpwalk](https://linux.die.net/man/1/snmpwalk) queries SNMP MIB tree using valid community string.
    752 
    753 ```bash
    754 # Full walk (noisy - thousands of queries)
    755 snmpwalk -v2c -c public <IP>                                # Walk entire tree
    756 ```
    757 
    758 **Specific OIDs**:
    759 
    760 ```bash
    761 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.1                  # System info
    762 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.2                  # Network interfaces
    763 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.25.4.2             # Running processes
    764 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.25.6.3             # Installed software
    765 snmpwalk -v2c -c public <IP> 1.3.6.1.4.1.77.1.2.25          # User accounts (Windows)
    766 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.25.2.3             # Storage info
    767 ```
    768 
    769 **Common OIDs**:
    770 
    771 1. **1.3.6.1.2.1.1**: System (hostname, description, uptime, contact, location)
    772 2. **1.3.6.1.2.1.2**: Interfaces (names, MACs, IPs, statistics)
    773 3. **1.3.6.1.2.1.25.4.2**: Running processes
    774 4. **1.3.6.1.2.1.25.6.3**: Installed software
    775 5. **1.3.6.1.2.1.6.13**: TCP connections
    776 6. **1.3.6.1.2.1.7.5**: UDP endpoints
    777 
    778 ---
    779 
    780 ### Redis - Anonymous Access
    781 
    782 [Redis](https://redis.io/) is an in-memory data structure store. Default installations often have no authentication.
    783 
    784 **Port**: 6379/tcp
    785 
    786 **Connect and enumerate**:
    787 
    788 ```bash
    789 redis-cli -h <IP>                                           # Connect to Redis
    790 ```
    791 
    792 **Commands** (inside `<IP>:6379>` prompt):
    793 
    794 ```bash
    795 <IP>:6379> INFO                                             # Server info
    796 <IP>:6379> CONFIG GET *                                     # Get config
    797 <IP>:6379> KEYS *                                           # List all keys
    798 <IP>:6379> GET keyname                                      # Get key value
    799 <IP>:6379> DBSIZE                                           # Database size
    800 <IP>:6379> CLIENT LIST                                      # Connected clients
    801 <IP>:6379> SCAN 0                                           # Scan keys (non-blocking)
    802 ```
    803 
    804 **Authentication check**:
    805 
    806 1. If `INFO` succeeds: No authentication required
    807 2. If `(error) NOAUTH Authentication required`: Authentication enabled
    808 
    809 **Other data type commands**:
    810 
    811 1. **HGETALL <key>**: Get all hash fields
    812 2. **LRANGE <key> 0 -1**: Get all list elements
    813 3. **SMEMBERS <key>**: Get all set members
    814 4. **ZRANGE <key> 0 -1**: Get all sorted set members
    815 
    816 ---
    817 
    818 ### MongoDB - Anonymous Access
    819 
    820 [MongoDB](https://www.mongodb.com/) is a NoSQL document database. Older versions often allow anonymous access.
    821 
    822 **Port**: 27017/tcp
    823 
    824 **Connect and enumerate**:
    825 
    826 ```bash
    827 mongo <IP>                                                  # Connect (legacy shell)
    828 mongosh <IP>                                                # Connect (new shell)
    829 ```
    830 
    831 **Commands** (inside `>` prompt):
    832 
    833 ```bash
    834 > show dbs                                                  # List databases
    835 > use admin                                                 # Select database
    836 > show collections                                          # List collections
    837 > db.users.find()                                           # Query collection
    838 > db.users.find().limit(10)                                 # Limit results
    839 > db.getUsers()                                             # List users
    840 > db.stats()                                                # Database stats
    841 ```
    842 
    843 **Authentication check**:
    844 
    845 1. If `show dbs` succeeds: No authentication required
    846 2. If `MongoServerError: command listDatabases requires authentication`: Authentication enabled
    847 
    848 **Common databases**:
    849 
    850 1. **admin**: Authentication/authorization data
    851 2. **config**: Sharding configuration
    852 3. **local**: Replication data
    853 4. Custom application databases
    854 
    855 ---
    856 
    857 ### PostgreSQL - Trust Auth
    858 
    859 [PostgreSQL](https://www.postgresql.org/) is a relational database. Trust authentication allows connections without password.
    860 
    861 **Port**: 5432/tcp
    862 
    863 **Default superuser**: `postgres`
    864 
    865 **Connect and enumerate**:
    866 
    867 ```bash
    868 psql -U postgres -h <IP>                                    # Connect with trust auth
    869 ```
    870 
    871 **Commands** (inside `postgres=#` prompt):
    872 
    873 ```bash
    874 postgres=# \l                                               # List databases
    875 postgres=# \c dbname                                        # Connect to database
    876 postgres=# \dt                                              # List tables
    877 postgres=# \du                                              # List users
    878 postgres=# SELECT version();                                # Version
    879 postgres=# SELECT * FROM users;                             # Query table
    880 postgres=# \q                                               # Quit
    881 ```
    882 
    883 **One-liner**:
    884 
    885 ```bash
    886 psql -U postgres -h <IP> -c "\l"                            # List databases
    887 psql -U postgres -h <IP> -d dbname -c "SELECT * FROM users;" # Query table
    888 ```
    889 
    890 **Psql meta-commands**:
    891 
    892 1. **\l**: List databases
    893 2. **\c <database>**: Connect to database
    894 3. **\dt**: List tables
    895 4. **\dt+**: List tables with sizes
    896 5. **\du**: List users/roles
    897 6. **\dn**: List schemas
    898 7. **\df**: List functions
    899 8. **\dv**: List views
    900 
    901 ---
    902 
    903 ### MySQL/MariaDB - No Password
    904 
    905 [MySQL](https://www.mysql.com/) and [MariaDB](https://mariadb.com/) are relational databases. Root account without password is a critical misconfiguration.
    906 
    907 **Port**: 3306/tcp
    908 
    909 **Default root account**: `root@localhost` (often restricted to localhost, but may allow remote)
    910 
    911 **Connect and enumerate**:
    912 
    913 ```bash
    914 mysql -h <IP> -u root                                       # Connect with no password
    915 ```
    916 
    917 **Commands** (inside `mysql>` prompt):
    918 
    919 ```bash
    920 mysql> SHOW DATABASES;                                      # List databases
    921 mysql> USE mysql;                                           # Select database
    922 mysql> SHOW TABLES;                                         # List tables
    923 mysql> SELECT user,host FROM mysql.user;                    # List users
    924 mysql> SELECT version();                                    # Version
    925 mysql> SELECT * FROM users;                                 # Query table
    926 mysql> exit;                                                # Quit
    927 ```
    928 
    929 **One-liner**:
    930 
    931 ```bash
    932 mysql -h <IP> -u root -e "SHOW DATABASES;"                  # List databases
    933 mysql -h <IP> -u root -e "USE mysql; SELECT user,host FROM mysql.user;"  # List users
    934 ```
    935 
    936 **Common databases**:
    937 
    938 1. **mysql**: System database (users, privileges)
    939 2. **information_schema**: Metadata (tables, columns, constraints)
    940 3. **performance_schema**: Performance metrics
    941 4. **sys**: System views (MySQL 5.7+)
    942 
    943 ---
    944 
    945 ### Elasticsearch - Anonymous API Access
    946 
    947 [Elasticsearch](https://www.elastic.co/) is a distributed search and analytics engine. Default installations often allow anonymous HTTP API access.
    948 
    949 **Port**: 9200/tcp (HTTP API)
    950 
    951 **Query with curl**:
    952 
    953 ```bash
    954 curl http://<IP>:9200/                                      # Cluster info
    955 curl http://<IP>:9200/_cat/indices?v                        # List indices
    956 curl http://<IP>:9200/_search?pretty                        # Search all
    957 curl http://<IP>:9200/index_name/_search?pretty             # Search index
    958 curl http://<IP>:9200/index_name/_mapping?pretty            # Index mapping
    959 curl http://<IP>:9200/_cluster/health?pretty                # Cluster health
    960 curl http://<IP>:9200/_nodes?pretty                         # Node info
    961 curl http://<IP>:9200/_count?pretty                         # Count documents
    962 ```
    963 
    964 **Search with query**:
    965 
    966 ```bash
    967 curl -X POST http://<IP>:9200/_search?pretty -H 'Content-Type: application/json' -d '
    968 {
    969   "query": {"match_all": {}}
    970 }'
    971 ```
    972 
    973 **Authentication check**:
    974 
    975 1. If cluster info returns: Anonymous access allowed
    976 2. If `401 Unauthorized` or `security_exception`: Authentication enabled (X-Pack Security)
    977 
    978 **Common indices**: `.kibana`, application-specific indices
    979 
    980 **API endpoints**:
    981 
    982 1. **/**: Cluster information
    983 2. **/_cat/indices**: List indices (human-readable)
    984 3. **/_search**: Search all indices
    985 4. **/<index>/_search**: Search specific index
    986 5. **/<index>/_mapping**: Index schema
    987 6. **/_cluster/health**: Cluster status
    988 7. **/_cluster/settings**: Cluster settings
    989 
    990 ---
    991 
    992 ## References
    993 
    994 1. [NetExec GitHub Repository](https://github.com/Pennyw0rth/NetExec)
    995 2. [NetExec Wiki Documentation](https://www.netexec.wiki/)
    996 3. [Samba smbclient Manual](https://www.samba.org/samba/docs/current/man-html/smbclient.1.html)
    997 4. [Samba rpcclient Manual](https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html)
    998 5. [smbmap GitHub Repository](https://github.com/ShawnDEvans/smbmap)
    999 6. [enum4linux GitHub Repository](https://github.com/CiscoCXSecurity/enum4linux)
   1000 7. [enum4linux-ng GitHub Repository](https://github.com/cddmp/enum4linux-ng)
   1001 8. [HackTricks - rpcclient Enumeration](https://book.hacktricks.xyz/network-services-pentesting/pentesting-smb/rpcclient-enumeration)
   1002 9. [HackTricks - LDAP Pentesting](https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap)
   1003 10. [OpenLDAP ldapsearch Manual](https://linux.die.net/man/1/ldapsearch)
   1004 11. [onesixtyone GitHub Repository](https://github.com/trailofbits/onesixtyone)
   1005 12. [snmpwalk Manual](https://linux.die.net/man/1/snmpwalk)
   1006 13. [Redis Security Guide](https://redis.io/docs/manual/security/)
   1007 14. [MongoDB Authentication Documentation](https://www.mongodb.com/docs/manual/core/authentication/)
   1008 15. [PostgreSQL pg_hba.conf Documentation](https://www.postgresql.org/docs/current/auth-pg-hba-conf.html)
   1009 16. [MySQL Connection Documentation](https://dev.mysql.com/doc/refman/8.0/en/connecting.html)
   1010 17. [Elasticsearch REST APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/rest-apis.html)
   1011 
   1012 ---
   1013 
   1014 #HTB #enumeration #NetExec #SMB #LDAP #FTP #SNMP #NFS #Redis #MongoDB #Elasticsearch #PostgreSQL #MySQL #null-session #anonymous-access #smbclient #rpcclient #smbmap #enum4linux #ldapsearch #pentesting #OSCP