anonymous-null-testing.md (36765B)
1 --- 2 title: "Anonymous Null Testing" 3 description: "nxc smb <IP> -u '' -p '' # Test anonymous access nxc smb <IP> -u 'guest' -p '' # Test guest account nxc smb <IP> -u='' -p='' # Windows syntax" 4 category: enumeration 5 tags: ["enumeration", "privilege-escalation"] 6 tools: ["smbmap", "NetExec", "ldapsearch"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/Anonymous Null Testing.md" 10 --- 11 # Test null session 12 nxc smb <IP> -u '' -p '' # Test anonymous access 13 nxc smb <IP> -u 'guest' -p '' # Test guest account 14 nxc smb <IP> -u='' -p='' # Windows syntax 15 ``` 16 17 **Output interpretation**: 18 19 1. Green **[+]**: Authentication succeeded 20 2. Red **[-]**: Authentication failed 21 3. **Pwn3d!**: Administrative privileges obtained 22 4. **STATUS_LOGON_FAILURE**: Null session blocked 23 5. **STATUS_ACCESS_DENIED**: Authenticated but no privileges 24 25 ```bash 26 # Basic enumeration 27 nxc smb <IP> -u '' -p '' --shares # List shares 28 nxc smb <IP> -u '' -p '' --users # List users 29 nxc smb <IP> -u '' -p '' --groups # List groups 30 nxc smb <IP> -u '' -p '' --pass-pol # Password policy 31 nxc smb <IP> -u '' -p '' --sessions # Active sessions 32 nxc smb <IP> -u '' -p '' --loggedon-users # Logged on users 33 nxc smb <IP> -u '' -p '' --rid-brute # RID brute force (noisy) 34 nxc smb <IP> -u '' -p '' --disks # List disks 35 ``` 36 37 **RID brute force warning**: Generates hundreds of Windows Event ID 4625 (failed logon) events—extremely noisy 38 39 --- 40 41 ### SMB File Operations 42 43 ```bash 44 # List files in share 45 nxc smb <IP> -u '' -p '' --ls SHARENAME # List root of share 46 nxc smb <IP> -u '' -p '' --ls 'SHARENAME/folder' # List subdirectory 47 ``` 48 49 ```bash 50 # Download files 51 nxc smb <IP> -u '' -p '' --get-file 'SHARE\file.txt' ./local.txt # Download file 52 nxc smb <IP> -u '' -p '' --get-file 'C$\Windows\System32\drivers\etc\hosts' ./hosts # Download specific file 53 ``` 54 55 ```bash 56 # Upload files 57 nxc smb <IP> -u '' -p '' --put-file local.txt 'SHARE\remote.txt' # Upload file 58 ``` 59 60 ```bash 61 # Spider shares (search files) 62 nxc smb <IP> -u '' -p '' --spider SHARENAME # List all files 63 nxc smb <IP> -u '' -p '' --spider SHARENAME --pattern txt # Search by extension 64 nxc smb <IP> -u '' -p '' --spider SHARENAME --pattern 'password|secret' # Search by keyword 65 nxc smb <IP> -u '' -p '' --spider SHARENAME --regex '.*\.config' # Regex search 66 nxc smb <IP> -u '' -p '' --spider SHARENAME --depth 3 # Limit depth 67 nxc smb <IP> -u '' -p '' --spider SHARENAME --only-files # Files only 68 nxc smb <IP> -u '' -p '' --spider SHARENAME --content --pattern password # Search file content 69 ``` 70 71 **Spider options**: 72 73 1. **--pattern**: Match file names by keyword or extension 74 2. **--regex**: Match file names by regular expression 75 3. **--depth**: Limit recursion depth (reduces noise) 76 4. **--only-files**: Skip directories in output 77 5. **--content**: Search inside file contents (requires read access) 78 79 --- 80 81 ### SMB spider_plus Module 82 83 The spider_plus module provides advanced recursive file enumeration with JSON output for parsing and filtering. 84 85 **Output location**: `~/.nxc/logs/` or `/tmp/nxc_spider_plus/<IP>.json` 86 87 **Module requirements**: NetExec 1.0.0+ 88 89 ```bash 90 # List all files (creates JSON output) 91 nxc smb <IP> -u '' -p '' -M spider_plus # List files 92 nxc smb <IP> -u '' -p '' -M spider_plus -o DOWNLOAD_FLAG=True # Download all files 93 nxc smb <IP> -u '' -p '' -M spider_plus -o PATTERN='*.txt,*.xml,*.config' # Filter extensions 94 nxc smb <IP> -u '' -p '' -M spider_plus -o DEPTH=3 # Limit depth 95 nxc smb <IP> -u '' -p '' -M spider_plus -o EXCLUDE_EXTS='exe,dll' # Exclude types 96 ``` 97 98 **Module options**: 99 100 1. **DOWNLOAD_FLAG=True**: Download all enumerated files 101 2. **PATTERN='*.ext1,*.ext2'**: Filter by file extensions (comma-separated) 102 3. **DEPTH=<n>**: Control recursion depth 103 4. **EXCLUDE_EXTS='ext1,ext2'**: Exclude specific file types 104 105 ```bash 106 # Parse JSON output 107 cat /tmp/nxc_spider_plus/<IP>.json | jq '.' # Pretty print 108 cat ~/.nxc/logs/<output>.json | jq '.[] | select(.name | endswith(".txt"))' # Filter .txt files 109 cat ~/.nxc/logs/<output>.json | jq '.[] | select(.size > 10000)' # Filter by size 110 ``` 111 112 **JSON structure**: Array of objects with fields: `name`, `path`, `size`, `atime` (access time), `ctime` (creation time), `mtime` (modification time) 113 114 --- 115 116 ### SMB Vulnerability Checks 117 118 ```bash 119 nxc smb <IP> -u '' -p '' -M ms17-010 # Check EternalBlue (CVE-2017-0144) 120 nxc smb <IP> -u '' -p '' -M zerologon # Check ZeroLogon (CVE-2020-1472) 121 nxc smb <IP> -u '' -p '' -M petitpotam # Check PetitPotam 122 nxc smb <IP> -u '' -p '' -M printnightmare # Check PrintNightmare (CVE-2021-34527) 123 nxc smb <IP> -u '' -p '' -M nopac # Check noPac (CVE-2021-42278/42287) 124 nxc smb <IP> -u '' -p '' -M spooler # Check print spooler status 125 nxc smb <IP> -u '' -p '' -M enum_av # Enumerate antivirus 126 nxc smb <IP> -u '' -p '' -M enum_ca # Enumerate ADCS (Certificate Authority) 127 nxc smb <IP> -u '' -p '' --gen-relay-list relay.txt # Check SMB signing (relay attacks) 128 ``` 129 130 **Vulnerability module notes**: 131 132 1. Modules check for vulnerability presence—do not exploit 133 2. **--gen-relay-list**: Identifies hosts without SMB signing (vulnerable to relay attacks) 134 3. Some modules require valid credentials (not anonymous) 135 136 --- 137 138 ### LDAP Anonymous Bind Testing 139 140 **Port**: 389/tcp (LDAP) or 636/tcp (LDAPS) 141 142 **Anonymous bind**: Authenticates with empty credentials to query directory information 143 144 ```bash 145 # Test anonymous bind 146 nxc ldap <IP> -u '' -p '' # Test anonymous LDAP 147 ``` 148 149 **Result codes**: 150 151 1. **LDAP Result Code 0 (success)**: Anonymous bind allowed 152 2. **LDAP Result Code 49 (invalidCredentials)**: Anonymous bind blocked 153 154 ```bash 155 # Basic enumeration 156 nxc ldap <IP> -u '' -p '' --users # List users 157 nxc ldap <IP> -u '' -p '' --groups # List groups 158 nxc ldap <IP> -u '' -p '' --computers # List computers 159 nxc ldap <IP> -u '' -p '' --get-sid # Get domain SID 160 ``` 161 162 ```bash 163 # LDAP modules 164 nxc ldap <IP> -u '' -p '' -M get-desc-users # Get user descriptions 165 nxc ldap <IP> -u '' -p '' -M maq # Machine Account Quota 166 nxc ldap <IP> -u '' -p '' -M ldap-checker # LDAP signing check 167 nxc ldap <IP> -u '' -p '' -M enum_trusts # Enumerate trusts 168 nxc ldap <IP> -u '' -p '' -M whoami # Current context 169 ``` 170 171 ```bash 172 # Custom LDAP queries 173 nxc ldap <IP> -u '' -p '' --query "(objectClass=user)" "sAMAccountName,description" 174 nxc ldap <IP> -u '' -p '' --query "(objectClass=group)" "name,member" 175 nxc ldap <IP> -u '' -p '' --query "(servicePrincipalName=*)" "servicePrincipalName" 176 nxc ldap <IP> -u '' -p '' --query "(adminCount=1)" "sAMAccountName" 177 ``` 178 179 **Custom query format**: `--query "<LDAP_FILTER>" "<ATTRIBUTES>"` 180 181 **Common LDAP filters**: 182 183 1. **(objectClass=user)**: All user objects 184 2. **(objectClass=group)**: All group objects 185 3. **(servicePrincipalName=*)**: Users with SPNs (Kerberoastable) 186 4. **(adminCount=1)**: Protected admin accounts 187 5. **(userAccountControl:1.2.840.113556.1.4.803:=8192)**: Domain controllers 188 189 --- 190 191 ### FTP Anonymous Access 192 193 **Port**: 21/tcp 194 195 **Anonymous credentials**: Username `anonymous` or empty; password empty or email address 196 197 ```bash 198 # Test anonymous login 199 nxc ftp <IP> -u '' -p '' # Empty credentials 200 nxc ftp <IP> -u 'anonymous' -p '' # Anonymous user 201 nxc ftp <IP> -u 'anonymous' -p 'user@example.com' # With email 202 ``` 203 204 **FTP response codes**: 205 206 1. **230 Login successful**: Anonymous login allowed 207 2. **530 Login incorrect**: Anonymous login blocked 208 209 ```bash 210 # List files 211 nxc ftp <IP> -u 'anonymous' -p '' --ls # List root 212 nxc ftp <IP> -u 'anonymous' -p '' --ls /pub # List directory 213 ``` 214 215 ```bash 216 # Download files 217 nxc ftp <IP> -u 'anonymous' -p '' --get file.txt # Download file 218 nxc ftp <IP> -u 'anonymous' -p '' --get /pub/data.txt # Download from path 219 ``` 220 221 --- 222 223 ### MSSQL Blank Password Testing 224 225 **Port**: 1433/tcp (default instance) or dynamic ports (named instances) 226 227 **Default accounts**: `sa` (system administrator), `MSSQLSERVER`, `admin` 228 229 ```bash 230 # Test blank passwords 231 nxc mssql <IP> -u 'sa' -p '' # Test sa account 232 nxc mssql <IP> -u users.txt -p '' # Test multiple users 233 ``` 234 235 ```bash 236 # Execute queries 237 nxc mssql <IP> -u 'sa' -p '' -q "SELECT @@version" # Version 238 nxc mssql <IP> -u 'sa' -p '' -q "SELECT name FROM sys.databases" # List databases 239 nxc mssql <IP> -u 'sa' -p '' -q "SELECT * FROM information_schema.tables" # List tables 240 ``` 241 242 ```bash 243 # File operations 244 nxc mssql <IP> -u 'sa' -p '' --get-file 'C:\backup\db.bak' ./db.bak # Download file 245 nxc mssql <IP> -u 'sa' -p '' --put-file payload.txt 'C:\temp\payload.txt' # Upload file 246 ``` 247 248 **File operations**: Require `xp_cmdshell` enabled or bulk insert privileges 249 250 --- 251 252 ### List NetExec Modules 253 254 ```bash 255 nxc smb -L # List SMB modules 256 nxc ldap -L # List LDAP modules 257 nxc mssql -L # List MSSQL modules 258 nxc ftp -L # List FTP modules 259 nxc winrm -L # List WinRM modules 260 nxc ssh -L # List SSH modules 261 nxc rdp -L # List RDP modules 262 263 nxc smb -M spider_plus --options # View module options 264 ``` 265 266 --- 267 268 ## Alternative Tools - Anonymous Access & Enumeration 269 270 ### smbclient - SMB File Operations 271 272 [smbclient](https://www.samba.org/samba/docs/current/man-html/smbclient.1.html) is the native SMB client from Samba. Pre-installed on most Linux distributions. 273 274 **UNC path syntax**: `\\\\IP\\SHARE` (Windows) or `//IP/SHARE` (Linux/macOS) 275 276 **List shares**: 277 278 ```bash 279 smbclient -N -L //<IP> # List shares (null session) 280 smbclient -N -U '' -L //<IP> # List shares (explicit) 281 smbclient -L //<IP> -U 'guest%' # List shares (guest) 282 ``` 283 284 **Options**: 285 286 1. **-N**: No password prompt (null session) 287 2. **-L**: List shares 288 3. **-U 'user%pass'**: Specify username and password 289 290 **Connect and browse files**: 291 292 ```bash 293 # Connect to share 294 smbclient -N //<IP>/SHARENAME # Connect with null session 295 smbclient //<IP>/SHARENAME -U 'guest%' # Connect as guest 296 ``` 297 298 **Interactive commands** (inside `smb: \>` prompt): 299 300 ```bash 301 smb: \> ls # List files 302 smb: \> cd folder # Change directory 303 smb: \> pwd # Print working directory 304 smb: \> dir # List files (alternative) 305 smb: \> get file.txt # Download single file 306 smb: \> mget *.txt # Download multiple files 307 smb: \> prompt OFF # Disable prompts 308 smb: \> recurse ON # Enable recursion 309 smb: \> mget * # Download everything 310 smb: \> put localfile.txt # Upload file 311 smb: \> mput *.txt # Upload multiple 312 smb: \> del file.txt # Delete file 313 smb: \> rm file.txt # Delete file (alternative) 314 smb: \> mkdir newfolder # Create directory 315 smb: \> rmdir oldfolder # Remove directory 316 smb: \> exit # Disconnect 317 ``` 318 319 **Non-interactive commands**: 320 321 ```bash 322 # List files in share 323 smbclient -N //<IP>/SHARENAME -c 'ls' # List files 324 smbclient -N //<IP>/SHARENAME -c 'cd Documents; ls' # List subdirectory 325 ``` 326 327 ```bash 328 # Download files 329 smbclient -N //<IP>/SHARENAME -c 'get file.txt' # Download file 330 smbclient -N //<IP>/SHARENAME -c 'cd backup; get db.bak' # Download from subdir 331 ``` 332 333 ```bash 334 # Recursive download all files 335 smbclient -N //<IP>/SHARENAME -c 'prompt OFF; recurse ON; mget *' 336 ``` 337 338 ```bash 339 # Download specific file types 340 smbclient -N //<IP>/SHARENAME -c 'prompt OFF; mget *.txt' 341 ``` 342 343 ```bash 344 # Upload file 345 smbclient -N //<IP>/SHARENAME -c 'put local.txt remote.txt' 346 ``` 347 348 ```bash 349 # Multiple commands 350 smbclient -N //<IP>/SHARENAME -c 'cd folder; ls; get file.txt' 351 ``` 352 353 **Command chaining**: Use `;` to separate multiple commands in `-c` flag 354 355 --- 356 357 ### rpcclient - RPC Enumeration 358 359 [rpcclient](https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html) enumerates domain information via MS-RPC with null session. Part of Samba suite. 360 361 **Connect**: 362 363 ```bash 364 rpcclient -N -U '' <IP> # Connect with null session 365 rpcclient -U 'guest%' <IP> # Connect as guest 366 ``` 367 368 **Interactive commands** (inside `rpcclient $>` prompt): 369 370 ```bash 371 rpcclient $> srvinfo # Server info 372 rpcclient $> enumdomusers # List users 373 rpcclient $> enumdomgroups # List groups 374 rpcclient $> querydominfo # Domain info 375 rpcclient $> getdompwinfo # Password policy 376 rpcclient $> querydispinfo # User details 377 rpcclient $> netshareenumall # List all shares 378 rpcclient $> netshareenum # List shares 379 rpcclient $> queryuser 500 # Query user by RID (500=Administrator) 380 rpcclient $> querygroup 512 # Query group by RID (512=Domain Admins) 381 rpcclient $> querygroupmem 512 # List group members 382 rpcclient $> enumalsgroups builtin # List local groups 383 rpcclient $> queryaliasmem builtin 0x220 # List admin group members 384 rpcclient $> lookupnames Administrator # Get SID from name 385 rpcclient $> lookupsids S-1-5-21-...-500 # Get name from SID 386 rpcclient $> enumprinters # List printers 387 rpcclient $> enumtrust # List domain trusts 388 rpcclient $> enumprivs # List privileges 389 ``` 390 391 **Common RIDs**: 392 393 1. **500**: Administrator 394 2. **501**: Guest 395 3. **512**: Domain Admins 396 4. **513**: Domain Users 397 5. **514**: Domain Guests 398 6. **515**: Domain Computers 399 7. **516**: Domain Controllers 400 8. **544**: Administrators (local) 401 9. **1000+**: Domain user accounts 402 403 **One-liner commands**: 404 405 ```bash 406 rpcclient -N -U '' <IP> -c 'enumdomusers' # List users 407 rpcclient -N -U '' <IP> -c 'enumdomgroups' # List groups 408 rpcclient -N -U '' <IP> -c 'querydominfo' # Domain info 409 rpcclient -N -U '' <IP> -c 'netshareenumall' # List shares 410 rpcclient -N -U '' <IP> -c 'getdompwinfo' # Password policy 411 rpcclient -N -U '' <IP> -c 'querydispinfo' # User details 412 rpcclient -N -U '' <IP> -c 'srvinfo' # Server info 413 ``` 414 415 ```bash 416 # Chain multiple commands 417 rpcclient -N -U '' <IP> -c 'enumdomusers;enumdomgroups;netshareenumall' 418 ``` 419 420 **Command chaining**: Use `;` separator to execute multiple commands in single connection 421 422 --- 423 424 ### smbmap - File Enumeration 425 426 [smbmap](https://github.com/ShawnDEvans/smbmap) is a Python-based SMB enumeration tool with recursive file listing and pattern-based auto-download. 427 428 **List shares**: 429 430 ```bash 431 smbmap -u '' -p '' -H <IP> # List shares (null session) 432 smbmap -u 'guest' -p '' -H <IP> # List shares (guest) 433 ``` 434 435 **Permissions displayed**: `READ ONLY`, `READ, WRITE`, `NO ACCESS` 436 437 **List files**: 438 439 ```bash 440 smbmap -u '' -p '' -H <IP> -R # List all files recursively 441 smbmap -u '' -p '' -H <IP> -r SHARENAME # List files in share 442 smbmap -u '' -p '' -H <IP> -R -A '.*\.txt' # Auto-download .txt files 443 smbmap -u '' -p '' -H <IP> -R -A '.*\.xml|.*\.config' # Auto-download config files 444 smbmap -u '' -p '' -H <IP> -R --depth 2 # Limit recursion depth 445 smbmap -u '' -p '' -H <IP> -R --exclude ADMIN$ C$ # Exclude shares 446 smbmap -u '' -p '' -H <IP> -R --dir-only # List directories only 447 ``` 448 449 **Options**: 450 451 1. **-R**: Recursive listing (all shares) 452 2. **-r SHARENAME**: Target specific share 453 3. **-A <pattern>**: Auto-download files matching regex 454 4. **--depth <n>**: Limit recursion depth 455 5. **--exclude <shares>**: Exclude specific shares 456 6. **--dir-only**: List directories only (no files) 457 458 **Download files**: 459 460 ```bash 461 smbmap -u '' -p '' -H <IP> --download 'SHARE\file.txt' # Download file 462 smbmap -u '' -p '' -H <IP> --download 'C$\Windows\System32\drivers\etc\hosts' # Download specific file 463 ``` 464 465 **Upload files**: 466 467 ```bash 468 smbmap -u '' -p '' -H <IP> --upload 'local.txt' 'SHARE\remote.txt' # Upload file 469 ``` 470 471 **Search file content** (requires admin rights): 472 473 ```bash 474 smbmap -u '' -p '' -H <IP> -R -F 'password' # Search file content 475 ``` 476 477 --- 478 479 ### enum4linux - Comprehensive Enumeration 480 481 [enum4linux](https://github.com/CiscoCXSecurity/enum4linux) is a Perl-based wrapper around smbclient, rpcclient, and other tools. [enum4linux-ng](https://github.com/cddmp/enum4linux-ng) is the newer Python rewrite. 482 483 **Basic usage**: 484 485 ```bash 486 enum4linux <IP> # Basic enumeration 487 enum4linux -a <IP> # All enumeration (noisy) 488 ``` 489 490 **Warning**: `-a` flag includes RID cycling which generates hundreds of Event ID 4625 (failed logon) events 491 492 **Targeted enumeration**: 493 494 ```bash 495 enum4linux -U <IP> # Users only 496 enum4linux -S <IP> # Shares only 497 enum4linux -G <IP> # Groups only 498 enum4linux -P <IP> # Password policy only 499 enum4linux -o <IP> # OS info only 500 enum4linux -i <IP> # Printer info only 501 enum4linux -n <IP> # NetBIOS info only 502 ``` 503 504 ```bash 505 # Combination 506 enum4linux -U -S -P <IP> # Users, shares, password policy 507 ``` 508 509 **RID cycling** (noisy): 510 511 ```bash 512 enum4linux -r <IP> # RID cycling (default range) 513 enum4linux -R 500-600 <IP> # RID cycling (custom range) 514 enum4linux -R 500-550,1000-1050 <IP> # Multiple ranges 515 ``` 516 517 **Verbose output**: 518 519 ```bash 520 enum4linux -v -a <IP> # Verbose all enumeration 521 ``` 522 523 --- 524 525 ### FTP Client - Anonymous Access 526 527 Native `ftp` command pre-installed on Linux/macOS/BSD/Windows. 528 529 **Connect**: 530 531 ```bash 532 ftp <IP> # Connect (will prompt for credentials) 533 # Username: anonymous 534 # Password: (press Enter or type email) 535 ``` 536 537 **Interactive commands** (inside `ftp>` prompt): 538 539 ```bash 540 ftp> ls # List files 541 ftp> dir # List files (detailed) 542 ftp> cd directory # Change directory 543 ftp> pwd # Print working directory 544 ftp> binary # Binary mode (for non-text files) 545 ftp> ascii # ASCII mode (for text files) 546 ftp> get file.txt # Download file 547 ftp> mget *.txt # Download multiple files 548 ftp> prompt OFF # Disable prompts 549 ftp> mget * # Download all files 550 ftp> put local.txt # Upload file 551 ftp> mput *.txt # Upload multiple files 552 ftp> delete file.txt # Delete file 553 ftp> mkdir newfolder # Create directory 554 ftp> rmdir oldfolder # Remove directory 555 ftp> bye # Disconnect 556 ftp> quit # Disconnect (alternative) 557 ``` 558 559 **Transfer modes**: 560 561 1. **binary**: For executables, images, archives (prevents corruption) 562 2. **ascii**: For text files (handles line ending conversions) 563 564 **Non-interactive**: 565 566 ```bash 567 # List files 568 echo -e "user anonymous\npass\nls\nquit" | ftp -n <IP> 569 ``` 570 571 ```bash 572 # Download file 573 echo -e "user anonymous\npass\nbinary\nget file.txt\nquit" | ftp -n <IP> 574 ``` 575 576 ```bash 577 # Download all files 578 echo -e "user anonymous\npass\nprompt OFF\nmget *\nquit" | ftp -n <IP> 579 ``` 580 581 **-n flag**: Disables auto-login (required for scripting with piped commands) 582 583 --- 584 585 ### ldapsearch - LDAP Anonymous Queries 586 587 [ldapsearch](https://linux.die.net/man/1/ldapsearch) is the native LDAP client from OpenLDAP. Pre-installed on most Linux distributions. 588 589 **Test anonymous bind**: 590 591 ```bash 592 ldapsearch -x -H ldap://<IP> -b '' -s base # Test anonymous bind 593 ldapsearch -x -H ldap://<IP> -b '' -s base namingContexts # Get base DN 594 ``` 595 596 **Options**: 597 598 1. **-x**: Simple authentication (required) 599 2. **-H ldap://<IP>**: LDAP URI (use `ldaps://` for SSL on port 636) 600 3. **-b 'base DN'**: Base DN to search 601 4. **-s base**: Search scope = base object only 602 5. **-LLL**: Reduce output verbosity 603 604 **Enumerate users**: 605 606 ```bash 607 # All users 608 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=user)' -LLL 609 ``` 610 611 ```bash 612 # Users with descriptions 613 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=user)' sAMAccountName,description -LLL 614 ``` 615 616 ```bash 617 # Admin users 618 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=user)(adminCount=1))' -LLL 619 ``` 620 621 ```bash 622 # Users with SPNs (Kerberoastable) 623 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=user)(servicePrincipalName=*))' -LLL 624 ``` 625 626 ```bash 627 # Specific user 628 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(sAMAccountName=Administrator)' -LLL 629 ``` 630 631 **Enumerate groups**: 632 633 ```bash 634 # All groups 635 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=group)' -LLL 636 ``` 637 638 ```bash 639 # Domain Admins 640 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(cn=Domain Admins)' member -LLL 641 ``` 642 643 ```bash 644 # Privileged groups 645 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=group)(adminCount=1))' -LLL 646 ``` 647 648 **Enumerate computers**: 649 650 ```bash 651 # All computers 652 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(objectClass=computer)' -LLL 653 ``` 654 655 ```bash 656 # Domain controllers 657 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(userAccountControl:1.2.840.113556.1.4.803:=8192)' -LLL 658 ``` 659 660 ```bash 661 # Servers 662 ldapsearch -x -H ldap://<IP> -b 'dc=example,dc=com' '(&(objectClass=computer)(operatingSystem=*Server*))' -LLL 663 ``` 664 665 **LDAP filter operators**: 666 667 1. **&**: AND operator (all conditions must match) 668 2. **|**: OR operator (any condition matches) 669 3. **!**: NOT operator (condition must not match) 670 4. **=**: Equality match 671 5. **~=**: Approximate match 672 6. **>=**, **<=**: Greater/less than or equal 673 7. **=***: Presence check (attribute exists) 674 675 --- 676 677 ### NFS - Mount and Browse 678 679 [NFS](https://en.wikipedia.org/wiki/Network_File_System) typically has no authentication—access control based solely on IP restrictions. 680 681 **List exports**: 682 683 ```bash 684 showmount -e <IP> # List NFS exports 685 showmount -a <IP> # List mounted clients 686 ``` 687 688 **Export format**: `/path (allowed_hosts)` where allowed_hosts can be `*` (all), `IP/subnet`, or specific hostnames 689 690 **Mount and access**: 691 692 ```bash 693 # Mount share 694 sudo mount -t nfs <IP>:/export /mnt/nfs # Mount NFS share 695 sudo mount -t nfs -o vers=3 <IP>:/export /mnt/nfs # Mount with NFSv3 696 ``` 697 698 **Mount options**: 699 700 1. **vers=3**: Force NFSv3 701 2. **vers=4**: Force NFSv4 702 3. **ro**: Read-only mount 703 4. **rw**: Read-write mount 704 5. **soft**: Soft mount (timeout on errors) 705 6. **hard**: Hard mount (retry indefinitely) 706 707 ```bash 708 # Browse files 709 cd /mnt/nfs # Change to mount point 710 ls -la # List files 711 find . -type f -name "*.txt" # Find files 712 cat file.txt # Read file 713 cp file.txt /tmp/ # Copy file 714 ``` 715 716 ```bash 717 # Unmount 718 sudo umount /mnt/nfs # Unmount share 719 ``` 720 721 **Create mount point** (if doesn't exist): 722 723 ```bash 724 sudo mkdir -p /mnt/nfs # Create directory 725 ``` 726 727 --- 728 729 ### SNMP - Community String Testing 730 731 [SNMP](https://en.wikipedia.org/wiki/Simple_Network_Management_Protocol) versions 1 and 2c use plaintext community strings. Default strings: `public` (read-only), `private` (read-write). 732 733 **Test with onesixtyone**: 734 735 [onesixtyone](https://github.com/trailofbits/onesixtyone) is a fast SNMP scanner for brute forcing community strings. 736 737 ```bash 738 onesixtyone <IP> # Test default communities 739 onesixtyone -c /usr/share/seclists/Discovery/SNMP/common-snmp-community-strings.txt <IP> 740 onesixtyone -c community.txt -i targets.txt # Multiple hosts 741 ``` 742 743 **Options**: 744 745 1. **-c <file>**: Community string wordlist 746 2. **-i <file>**: IP address list file 747 3. **-w <n>**: Wait time in milliseconds (default 10) 748 749 **Walk with snmpwalk**: 750 751 [snmpwalk](https://linux.die.net/man/1/snmpwalk) queries SNMP MIB tree using valid community string. 752 753 ```bash 754 # Full walk (noisy - thousands of queries) 755 snmpwalk -v2c -c public <IP> # Walk entire tree 756 ``` 757 758 **Specific OIDs**: 759 760 ```bash 761 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.1 # System info 762 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.2 # Network interfaces 763 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.25.4.2 # Running processes 764 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.25.6.3 # Installed software 765 snmpwalk -v2c -c public <IP> 1.3.6.1.4.1.77.1.2.25 # User accounts (Windows) 766 snmpwalk -v2c -c public <IP> 1.3.6.1.2.1.25.2.3 # Storage info 767 ``` 768 769 **Common OIDs**: 770 771 1. **1.3.6.1.2.1.1**: System (hostname, description, uptime, contact, location) 772 2. **1.3.6.1.2.1.2**: Interfaces (names, MACs, IPs, statistics) 773 3. **1.3.6.1.2.1.25.4.2**: Running processes 774 4. **1.3.6.1.2.1.25.6.3**: Installed software 775 5. **1.3.6.1.2.1.6.13**: TCP connections 776 6. **1.3.6.1.2.1.7.5**: UDP endpoints 777 778 --- 779 780 ### Redis - Anonymous Access 781 782 [Redis](https://redis.io/) is an in-memory data structure store. Default installations often have no authentication. 783 784 **Port**: 6379/tcp 785 786 **Connect and enumerate**: 787 788 ```bash 789 redis-cli -h <IP> # Connect to Redis 790 ``` 791 792 **Commands** (inside `<IP>:6379>` prompt): 793 794 ```bash 795 <IP>:6379> INFO # Server info 796 <IP>:6379> CONFIG GET * # Get config 797 <IP>:6379> KEYS * # List all keys 798 <IP>:6379> GET keyname # Get key value 799 <IP>:6379> DBSIZE # Database size 800 <IP>:6379> CLIENT LIST # Connected clients 801 <IP>:6379> SCAN 0 # Scan keys (non-blocking) 802 ``` 803 804 **Authentication check**: 805 806 1. If `INFO` succeeds: No authentication required 807 2. If `(error) NOAUTH Authentication required`: Authentication enabled 808 809 **Other data type commands**: 810 811 1. **HGETALL <key>**: Get all hash fields 812 2. **LRANGE <key> 0 -1**: Get all list elements 813 3. **SMEMBERS <key>**: Get all set members 814 4. **ZRANGE <key> 0 -1**: Get all sorted set members 815 816 --- 817 818 ### MongoDB - Anonymous Access 819 820 [MongoDB](https://www.mongodb.com/) is a NoSQL document database. Older versions often allow anonymous access. 821 822 **Port**: 27017/tcp 823 824 **Connect and enumerate**: 825 826 ```bash 827 mongo <IP> # Connect (legacy shell) 828 mongosh <IP> # Connect (new shell) 829 ``` 830 831 **Commands** (inside `>` prompt): 832 833 ```bash 834 > show dbs # List databases 835 > use admin # Select database 836 > show collections # List collections 837 > db.users.find() # Query collection 838 > db.users.find().limit(10) # Limit results 839 > db.getUsers() # List users 840 > db.stats() # Database stats 841 ``` 842 843 **Authentication check**: 844 845 1. If `show dbs` succeeds: No authentication required 846 2. If `MongoServerError: command listDatabases requires authentication`: Authentication enabled 847 848 **Common databases**: 849 850 1. **admin**: Authentication/authorization data 851 2. **config**: Sharding configuration 852 3. **local**: Replication data 853 4. Custom application databases 854 855 --- 856 857 ### PostgreSQL - Trust Auth 858 859 [PostgreSQL](https://www.postgresql.org/) is a relational database. Trust authentication allows connections without password. 860 861 **Port**: 5432/tcp 862 863 **Default superuser**: `postgres` 864 865 **Connect and enumerate**: 866 867 ```bash 868 psql -U postgres -h <IP> # Connect with trust auth 869 ``` 870 871 **Commands** (inside `postgres=#` prompt): 872 873 ```bash 874 postgres=# \l # List databases 875 postgres=# \c dbname # Connect to database 876 postgres=# \dt # List tables 877 postgres=# \du # List users 878 postgres=# SELECT version(); # Version 879 postgres=# SELECT * FROM users; # Query table 880 postgres=# \q # Quit 881 ``` 882 883 **One-liner**: 884 885 ```bash 886 psql -U postgres -h <IP> -c "\l" # List databases 887 psql -U postgres -h <IP> -d dbname -c "SELECT * FROM users;" # Query table 888 ``` 889 890 **Psql meta-commands**: 891 892 1. **\l**: List databases 893 2. **\c <database>**: Connect to database 894 3. **\dt**: List tables 895 4. **\dt+**: List tables with sizes 896 5. **\du**: List users/roles 897 6. **\dn**: List schemas 898 7. **\df**: List functions 899 8. **\dv**: List views 900 901 --- 902 903 ### MySQL/MariaDB - No Password 904 905 [MySQL](https://www.mysql.com/) and [MariaDB](https://mariadb.com/) are relational databases. Root account without password is a critical misconfiguration. 906 907 **Port**: 3306/tcp 908 909 **Default root account**: `root@localhost` (often restricted to localhost, but may allow remote) 910 911 **Connect and enumerate**: 912 913 ```bash 914 mysql -h <IP> -u root # Connect with no password 915 ``` 916 917 **Commands** (inside `mysql>` prompt): 918 919 ```bash 920 mysql> SHOW DATABASES; # List databases 921 mysql> USE mysql; # Select database 922 mysql> SHOW TABLES; # List tables 923 mysql> SELECT user,host FROM mysql.user; # List users 924 mysql> SELECT version(); # Version 925 mysql> SELECT * FROM users; # Query table 926 mysql> exit; # Quit 927 ``` 928 929 **One-liner**: 930 931 ```bash 932 mysql -h <IP> -u root -e "SHOW DATABASES;" # List databases 933 mysql -h <IP> -u root -e "USE mysql; SELECT user,host FROM mysql.user;" # List users 934 ``` 935 936 **Common databases**: 937 938 1. **mysql**: System database (users, privileges) 939 2. **information_schema**: Metadata (tables, columns, constraints) 940 3. **performance_schema**: Performance metrics 941 4. **sys**: System views (MySQL 5.7+) 942 943 --- 944 945 ### Elasticsearch - Anonymous API Access 946 947 [Elasticsearch](https://www.elastic.co/) is a distributed search and analytics engine. Default installations often allow anonymous HTTP API access. 948 949 **Port**: 9200/tcp (HTTP API) 950 951 **Query with curl**: 952 953 ```bash 954 curl http://<IP>:9200/ # Cluster info 955 curl http://<IP>:9200/_cat/indices?v # List indices 956 curl http://<IP>:9200/_search?pretty # Search all 957 curl http://<IP>:9200/index_name/_search?pretty # Search index 958 curl http://<IP>:9200/index_name/_mapping?pretty # Index mapping 959 curl http://<IP>:9200/_cluster/health?pretty # Cluster health 960 curl http://<IP>:9200/_nodes?pretty # Node info 961 curl http://<IP>:9200/_count?pretty # Count documents 962 ``` 963 964 **Search with query**: 965 966 ```bash 967 curl -X POST http://<IP>:9200/_search?pretty -H 'Content-Type: application/json' -d ' 968 { 969 "query": {"match_all": {}} 970 }' 971 ``` 972 973 **Authentication check**: 974 975 1. If cluster info returns: Anonymous access allowed 976 2. If `401 Unauthorized` or `security_exception`: Authentication enabled (X-Pack Security) 977 978 **Common indices**: `.kibana`, application-specific indices 979 980 **API endpoints**: 981 982 1. **/**: Cluster information 983 2. **/_cat/indices**: List indices (human-readable) 984 3. **/_search**: Search all indices 985 4. **/<index>/_search**: Search specific index 986 5. **/<index>/_mapping**: Index schema 987 6. **/_cluster/health**: Cluster status 988 7. **/_cluster/settings**: Cluster settings 989 990 --- 991 992 ## References 993 994 1. [NetExec GitHub Repository](https://github.com/Pennyw0rth/NetExec) 995 2. [NetExec Wiki Documentation](https://www.netexec.wiki/) 996 3. [Samba smbclient Manual](https://www.samba.org/samba/docs/current/man-html/smbclient.1.html) 997 4. [Samba rpcclient Manual](https://www.samba.org/samba/docs/current/man-html/rpcclient.1.html) 998 5. [smbmap GitHub Repository](https://github.com/ShawnDEvans/smbmap) 999 6. [enum4linux GitHub Repository](https://github.com/CiscoCXSecurity/enum4linux) 1000 7. [enum4linux-ng GitHub Repository](https://github.com/cddmp/enum4linux-ng) 1001 8. [HackTricks - rpcclient Enumeration](https://book.hacktricks.xyz/network-services-pentesting/pentesting-smb/rpcclient-enumeration) 1002 9. [HackTricks - LDAP Pentesting](https://book.hacktricks.xyz/network-services-pentesting/pentesting-ldap) 1003 10. [OpenLDAP ldapsearch Manual](https://linux.die.net/man/1/ldapsearch) 1004 11. [onesixtyone GitHub Repository](https://github.com/trailofbits/onesixtyone) 1005 12. [snmpwalk Manual](https://linux.die.net/man/1/snmpwalk) 1006 13. [Redis Security Guide](https://redis.io/docs/manual/security/) 1007 14. [MongoDB Authentication Documentation](https://www.mongodb.com/docs/manual/core/authentication/) 1008 15. [PostgreSQL pg_hba.conf Documentation](https://www.postgresql.org/docs/current/auth-pg-hba-conf.html) 1009 16. [MySQL Connection Documentation](https://dev.mysql.com/doc/refman/8.0/en/connecting.html) 1010 17. [Elasticsearch REST APIs](https://www.elastic.co/guide/en/elasticsearch/reference/current/rest-apis.html) 1011 1012 --- 1013 1014 #HTB #enumeration #NetExec #SMB #LDAP #FTP #SNMP #NFS #Redis #MongoDB #Elasticsearch #PostgreSQL #MySQL #null-session #anonymous-access #smbclient #rpcclient #smbmap #enum4linux #ldapsearch #pentesting #OSCP