nse-guide.md (66328B)
1 --- 2 title: "NSE Guide" 3 description: "nmap -sV -p21 --script=ftp-anon,ftp-bounce,ftp-syst <target>" 4 category: enumeration 5 tags: ["enumeration"] 6 tools: ["Nmap"] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/NSE Guide.md" 10 --- 11 # Safe FTP enumeration 12 nmap -sV -p21 --script=ftp-anon,ftp-bounce,ftp-syst <target> 13 14 # Check for anonymous access and list files 15 nmap -p21 --script=ftp-anon --script-args ftp-anon.maxlist=-1 <target> 16 17 # FTP vulnerability assessment 18 nmap -p21 --script=ftp-vuln-* <target> 19 20 # Check for backdoors 21 nmap -p21 --script=ftp-proftpd-backdoor,ftp-vsftpd-backdoor <target> 22 23 # FTP brute force (noisy) 24 nmap -p21 --script=ftp-brute --script-args userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt,passdb=/usr/share/seclists/Passwords/Common-Credentials/10-million-password-list-top-100.txt <target> 25 26 # FTP brute force with timeout control 27 nmap -p21 --script=ftp-brute --script-args ftp-brute.timeout=10s,brute.threads=2 <target> 28 29 # Comprehensive FTP assessment 30 nmap -sV -p21 --script="ftp-* and not brute" <target> 31 ``` 32 33 > [!info]+ Command Breakdown: FTP Enumeration 34 > 1. **ftp-anon**: Attempts login with username "anonymous" and email as password 35 > 2. **ftp-anon.maxlist**: Controls how many directory entries to list (-1 for unlimited) 36 > 3. **ftp-bounce**: Tests if FTP server allows bounce attacks (proxy port scans) 37 > 4. **ftp-vsftpd-backdoor**: Checks for backdoor in vsftpd 2.3.4 (smiley face backdoor) 38 > 5. **ftp-brute.timeout**: Delay between connection attempts to avoid blocking 39 40 > [!success]+ Expected FTP Output 41 > ``` 42 > PORT STATE SERVICE VERSION 43 > 21/tcp open ftp vsftpd 2.3.4 44 > | ftp-anon: Anonymous FTP login allowed (FTP code 230) 45 > |_drwxr-xr-x 2 0 0 4096 Mar 17 2010 pub 46 > | ftp-vsftpd-backdoor: 47 > | VULNERABLE: 48 > | vsFTPd version 2.3.4 backdoor 49 > | State: VULNERABLE (Exploitable) 50 > | IDs: CVE:CVE-2011-2523 BID:48539 51 > | vsFTPd version 2.3.4 backdoor, this was reported on 2011-07-04. 52 > | Disclosure date: 2011-07-03 53 > | Exploit results: 54 > | Shell command: id 55 > | Results: uid=0(root) gid=0(root) 56 > | References: 57 > | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2523 58 > ``` 59 60 > [!warning]+ FTP OPSEC Considerations 61 > 6. **Anonymous login attempts**: Logged in FTP server logs 62 > 7. **ftp-brute detection**: Extremely noisy, triggers fail2ban and IDS 63 > 8. **Backdoor checks**: May trigger AV/EDR alerts 64 > 9. **Safe scripts**: ftp-anon, ftp-syst generate normal FTP traffic 65 > 10. **Directory listing**: Large directories cause extended connection time 66 67 > [!failure]+ Common FTP Issues 68 > 11. **Connection timeout**: FTP firewall filtering or passive mode issues 69 > - Solution: Verify port 21 accessible, some scripts need port 20 open 70 > 12. **Anonymous access denied**: Expected on secure configurations 71 > - Solution: Not an error - indicates proper security 72 > 13. **ftp-brute IP blocking**: fail2ban blocks source IP after failed attempts 73 > - Solution: Reduce threads and add delays with `ftp-brute.timeout` 74 75 --- 76 77 ## Port 22 - SSH (Secure Shell) 78 79 > [!info]+ [SSH Service Overview](https://www.openssh.com/) 80 > Secure Shell provides encrypted remote access and file transfer. Critical service for Linux/Unix administration. Version detection, algorithm enumeration, and authentication testing reveal security posture. 81 82 **Key NSE Scripts for SSH**: 83 84 > [!info]+ SSH Enumeration Scripts 85 > 1. **[ssh-hostkey](https://nmap.org/nsedoc/scripts/ssh-hostkey.html)**: Retrieves SSH host keys and fingerprints 86 > 2. **[ssh-auth-methods](https://nmap.org/nsedoc/scripts/ssh-auth-methods.html)**: Lists supported authentication methods 87 > 3. **[ssh2-enum-algos](https://nmap.org/nsedoc/scripts/ssh2-enum-algos.html)**: Enumerates encryption algorithms and ciphers 88 > 4. **[sshv1](https://nmap.org/nsedoc/scripts/sshv1.html)**: Checks for deprecated SSHv1 support 89 > 5. **[ssh-brute](https://nmap.org/nsedoc/scripts/ssh-brute.html)**: Credential brute forcing 90 > 6. **[ssh-publickey-acceptance](https://nmap.org/nsedoc/scripts/ssh-publickey-acceptance.html)**: Tests public key authentication 91 > 7. **[ssh-run](https://nmap.org/nsedoc/scripts/ssh-run.html)**: Runs commands via SSH with credentials 92 93 ```bash 94 # Safe SSH enumeration 95 nmap -sV -p22 --script=ssh-hostkey,ssh-auth-methods,ssh2-enum-algos <target> 96 97 # Check for SSHv1 (insecure) 98 nmap -p22 --script=sshv1 <target> 99 100 # SSH host key fingerprinting 101 nmap -p22 --script=ssh-hostkey --script-args ssh_hostkey=full <target> 102 103 # Enumerate supported authentication methods 104 nmap -p22 --script=ssh-auth-methods <target> 105 106 # Enumerate encryption algorithms 107 nmap -p22 --script=ssh2-enum-algos <target> 108 109 # Check public key acceptance 110 nmap -p22 --script=ssh-publickey-acceptance <target> 111 112 # SSH brute force (VERY NOISY - triggers fail2ban) 113 nmap -p22 --script=ssh-brute --script-args userdb=users.txt,passdb=pass.txt <target> 114 115 # Slow SSH brute force to avoid blocking 116 nmap -p22 --script=ssh-brute --script-args ssh-brute.timeout=4m,brute.threads=1,brute.firstOnly=true <target> 117 118 # Execute command with known credentials 119 nmap -p22 --script=ssh-run --script-args ssh-run.cmd="uname -a",ssh-run.username=root,ssh-run.password=toor <target> 120 121 # Comprehensive SSH assessment 122 nmap -sV -p22 --script="ssh-* and not brute" <target> 123 ``` 124 125 > [!info]+ Command Breakdown: SSH Enumeration 126 > 1. **ssh-hostkey**: Extracts RSA, DSA, ECDSA, ED25519 public keys 127 > 2. **ssh_hostkey=full**: Shows complete public key, not just fingerprint 128 > 3. **ssh2-enum-algos**: Lists key exchange, encryption, MAC, compression algorithms 129 > 4. **ssh-brute.timeout**: Critical - delay between attempts (fail2ban typically bans after 3-5 failures) 130 > 5. **brute.firstOnly**: Stops after finding first valid credential (faster, less noisy) 131 132 > [!success]+ Expected SSH Output 133 > ``` 134 > PORT STATE SERVICE VERSION 135 > 22/tcp open ssh OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0) 136 > | ssh-hostkey: 137 > | 2048 8a:d3:22:e4:76:4e:6e:77:9f:8b:3e:3c:9f:2e:8c:3a (RSA) 138 > | 256 31:7d:99:2f:1f:2e:8e:6e:8f:9e:2e:3f:7e:8e:2f:3e (ECDSA) 139 > |_ 256 8e:2f:3e:7e:8e:2f:3e:7e:8e:2f:3e:7e:8e:2f:3e:7e (ED25519) 140 > | ssh-auth-methods: 141 > | Supported authentication methods: 142 > | publickey 143 > | password 144 > |_ keyboard-interactive 145 > | ssh2-enum-algos: 146 > | kex_algorithms: (6) 147 > | curve25519-sha256 148 > | curve25519-sha256@libssh.org 149 > | ecdh-sha2-nistp256 150 > | ecdh-sha2-nistp384 151 > | ecdh-sha2-nistp521 152 > | diffie-hellman-group-exchange-sha256 153 > | encryption_algorithms: (9) 154 > | chacha20-poly1305@openssh.com 155 > | aes128-ctr 156 > | aes192-ctr 157 > | aes256-ctr 158 > | aes128-gcm@openssh.com 159 > | aes256-gcm@openssh.com 160 > ``` 161 162 > [!warning]+ SSH OPSEC Considerations 163 > 6. **ssh-brute**: Extremely noisy - fail2ban typically bans after 3-5 failed attempts 164 > 7. **Failed auth logging**: All failed attempts logged in /var/log/auth.log 165 > 8. **Safe enumeration**: hostkey, auth-methods, algorithms are normal SSH handshake 166 > 9. **Detection**: Multiple connections from same IP triggers automated blocking 167 > 10. **Modern defenses**: Ubuntu/Debian commonly run fail2ban by default 168 169 > [!failure]+ Common SSH Issues 170 > 11. **IP banned after 3-5 attempts**: fail2ban or similar IPS blocking 171 > - Solution: Use `ssh-brute.timeout=4m` for 4-minute delays between attempts 172 > 12. **Connection reset**: Too many rapid connections 173 > - Solution: Reduce threads to 1, increase timeouts 174 > 13. **Public key scripts require proper key format**: PEM or OpenSSH format 175 > - Solution: Generate keys with `ssh-keygen -t rsa` 176 177 > [!tip]+ SSH Security Assessment Best Practices 178 > 14. **Check for SSHv1**: Ancient protocol with known vulnerabilities 179 > 15. **Weak algorithms**: Look for CBC ciphers, MD5 MACs, weak KEX 180 > 16. **Authentication methods**: Password auth less secure than publickey 181 > 17. **Host key analysis**: Same key across multiple servers may indicate cloning 182 > 18. **Version detection**: Older OpenSSH versions have known CVEs 183 184 --- 185 186 ## Port 23 - Telnet 187 188 > [!info]+ [Telnet Service Overview](https://en.wikipedia.org/wiki/Telnet) 189 > Unencrypted remote access protocol. Credentials transmitted in cleartext. Presence indicates legacy systems or IoT devices. Highly insecure and should be replaced with SSH. 190 191 **Key NSE Scripts for Telnet**: 192 193 > [!info]+ Telnet Enumeration Scripts 194 > 1. **[telnet-brute](https://nmap.org/nsedoc/scripts/telnet-brute.html)**: Credential brute forcing 195 > 2. **[telnet-encryption](https://nmap.org/nsedoc/scripts/telnet-encryption.html)**: Checks for encryption support 196 > 3. **[telnet-ntlm-info](https://nmap.org/nsedoc/scripts/telnet-ntlm-info.html)**: Extracts Windows domain info via NTLM 197 > 4. **[tn3270-screen](https://nmap.org/nsedoc/scripts/tn3270-screen.html)**: Captures mainframe TN3270 screens 198 199 ```bash 200 # Basic Telnet enumeration 201 nmap -sV -p23 --script=telnet-encryption <target> 202 203 # Telnet NTLM information disclosure 204 nmap -p23 --script=telnet-ntlm-info <target> 205 206 # TN3270 mainframe enumeration 207 nmap -p23 --script=tn3270-screen <target> 208 209 # Telnet brute force (cleartext credentials) 210 nmap -p23 --script=telnet-brute --script-args userdb=users.txt,passdb=pass.txt <target> 211 212 # IoT device default credential testing 213 nmap -p23,2323 --script=telnet-brute --script-args userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt,passdb=/usr/share/seclists/Passwords/Default-Credentials/telnet-betterdefaultpasslist.txt <target> 214 215 # Comprehensive Telnet assessment 216 nmap -sV -p23 --script="telnet-*" <target> 217 ``` 218 219 > [!info]+ Command Breakdown: Telnet Enumeration 220 > 1. **telnet-encryption**: Tests if Telnet supports encryption extensions (rare) 221 > 2. **telnet-ntlm-info**: Forces NTLM authentication to leak domain/workgroup names 222 > 3. **tn3270-screen**: Captures IBM mainframe login screens 223 > 4. **telnet-brute**: Tests credentials over cleartext connection 224 > 5. *Telnet on IoT devices often on non-standard ports like 2323, 8023* 225 226 > [!success]+ Expected Telnet Output 227 > ``` 228 > PORT STATE SERVICE VERSION 229 > 23/tcp open telnet Linux telnetd 230 > | telnet-encryption: 231 > |_ Telnet server does not support encryption 232 > | telnet-ntlm-info: 233 > | Target_Name: WORKGROUP 234 > | NetBIOS_Domain_Name: WORKGROUP 235 > | NetBIOS_Computer_Name: SERVER01 236 > | DNS_Domain_Name: localdomain 237 > | DNS_Computer_Name: server01.localdomain 238 > |_ Product_Version: 5.0.2195 239 > ``` 240 241 > [!danger]+ Telnet Security Warnings 242 > 6. **Cleartext transmission**: All data including credentials sent unencrypted 243 > 7. **Network sniffing**: Wireshark/tcpdump can capture passwords 244 > 8. **No security**: Telnet provides no authentication security or confidentiality 245 > 9. **Replace with SSH**: Telnet should never be used on production systems 246 > 10. **IoT prevalence**: Routers, cameras, printers commonly have Telnet enabled 247 248 > [!warning]+ Telnet OPSEC Considerations 249 > 11. **Brute force highly visible**: Cleartext passwords logged on network 250 > 12. **Network monitoring**: Easily detected by IDS/packet analysis 251 > 13. **Authentication failures**: Logged in system logs 252 > 14. **Safe enumeration**: telnet-encryption, telnet-ntlm-info low risk 253 254 --- 255 256 ## Port 25/465/587 - SMTP (Simple Mail Transfer Protocol) 257 258 > [!info]+ [SMTP Service Overview](https://en.wikipedia.org/wiki/Simple_Mail_Transfer_Protocol) 259 > Email transmission protocol. Port 25 for unencrypted SMTP, 465 for SMTPS (deprecated), 587 for submission with STARTTLS. User enumeration via VRFY/EXPN commands, open relay testing, and vulnerability assessment. 260 261 **Key NSE Scripts for SMTP**: 262 263 > [!info]+ SMTP Enumeration Scripts 264 > 1. **[smtp-commands](https://nmap.org/nsedoc/scripts/smtp-commands.html)**: Lists supported SMTP commands 265 > 2. **[smtp-enum-users](https://nmap.org/nsedoc/scripts/smtp-enum-users.html)**: Enumerates users via VRFY/EXPN/RCPT 266 > 3. **[smtp-open-relay](https://nmap.org/nsedoc/scripts/smtp-open-relay.html)**: Tests for open relay misconfiguration 267 > 4. **[smtp-brute](https://nmap.org/nsedoc/scripts/smtp-brute.html)**: Credential brute forcing 268 > 5. **[smtp-vuln-cve2010-4344](https://nmap.org/nsedoc/scripts/smtp-vuln-cve2010-4344.html)**: Exim heap overflow 269 > 6. **[smtp-vuln-cve2011-1720](https://nmap.org/nsedoc/scripts/smtp-vuln-cve2011-1720.html)**: Postfix STARTTLS plaintext injection 270 > 7. **[smtp-vuln-cve2011-1764](https://nmap.org/nsedoc/scripts/smtp-vuln-cve2011-1764.html)**: Exim DKIM denial of service 271 > 8. **[smtp-ntlm-info](https://nmap.org/nsedoc/scripts/smtp-ntlm-info.html)**: Extracts Windows domain info via NTLM 272 > 9. **[smtp-strangeport](https://nmap.org/nsedoc/scripts/smtp-strangeport.html)**: Detects SMTP on unusual ports (malware indicator) 273 274 ```bash 275 # Safe SMTP enumeration 276 nmap -sV -p25,465,587 --script=smtp-commands,smtp-ntlm-info <target> 277 278 # Test for open relay 279 nmap -p25 --script=smtp-open-relay <target> 280 281 # User enumeration via VRFY and EXPN 282 nmap -p25 --script=smtp-enum-users --script-args smtp-enum-users.methods={VRFY,EXPN} <target> 283 284 # User enumeration with custom wordlist 285 nmap -p25 --script=smtp-enum-users --script-args userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt,smtp-enum-users.methods={VRFY,EXPN,RCPT} <target> 286 287 # SMTP NTLM information disclosure 288 nmap -p25,587 --script=smtp-ntlm-info <target> 289 290 # SMTP vulnerability assessment 291 nmap -p25 --script=smtp-vuln-* <target> 292 293 # SMTP brute force authentication 294 nmap -p25,587 --script=smtp-brute --script-args userdb=users.txt,passdb=pass.txt <target> 295 296 # Comprehensive SMTP assessment 297 nmap -sV -p25,465,587 --script="smtp-* and not brute" <target> 298 299 # Test multiple SMTP ports including submissions 300 nmap -sV -p25,465,587,2525 --script=smtp-commands,smtp-open-relay <target> 301 ``` 302 303 > [!info]+ Command Breakdown: SMTP Enumeration 304 > 1. **smtp-enum-users.methods**: Specifies enumeration technique (VRFY, EXPN, RCPT TO) 305 > 2. **smtp-open-relay**: Attempts to send email through server to external domain 306 > 3. **smtp-ntlm-info**: Forces NTLM auth to disclose domain/computer names 307 > 4. **smtp-commands**: Issues EHLO/HELO to enumerate extended commands 308 > 5. **VRFY**: Verifies if user exists (often disabled) 309 > 6. **EXPN**: Expands mailing list (rarely enabled) 310 > 7. **RCPT TO**: Tests email acceptance (slower but works when VRFY/EXPN blocked) 311 312 > [!success]+ Expected SMTP Output 313 > ``` 314 > PORT STATE SERVICE VERSION 315 > 25/tcp open smtp Postfix smtpd 316 > | smtp-commands: mail.example.com, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN 317 > |_ This server supports the following commands: HELO EHLO STARTTLS RCPT DATA RSET MAIL QUIT HELP AUTH NOOP 318 > | smtp-enum-users: 319 > | Accounts found: 320 > | admin - Valid user 321 > | user1 - Valid user 322 > | webmaster - Valid user 323 > | Statistics: Performed 50 guesses in 12 seconds 324 > | smtp-ntlm-info: 325 > | Target_Name: MAIL 326 > | NetBIOS_Domain_Name: CONTOSO 327 > | NetBIOS_Computer_Name: MAIL01 328 > | DNS_Domain_Name: contoso.local 329 > | DNS_Computer_Name: mail01.contoso.local 330 > |_ Product_Version: 6.1.7601 331 > | smtp-open-relay: Server is an open relay (16/16 tests) 332 > | MAIL FROM:<antispam@insecure.org> -> RCPT TO:<relaytest@insecure.org> 333 > | MAIL FROM:<antispam@insecure.org> -> RCPT TO:<relaytest%insecure.org@example.com> 334 > ``` 335 336 > [!warning]+ SMTP OPSEC Considerations 337 > 8. **User enumeration**: VRFY/EXPN attempts logged in mail server logs 338 > 9. **Open relay testing**: May generate email to external addresses (logged) 339 > 10. **Modern mail servers**: VRFY/EXPN commonly disabled on Exchange, Postfix 340 > 11. **RCPT TO enumeration**: Slower but more reliable, generates more logs 341 > 12. **smtp-brute**: Extremely noisy, triggers fail2ban and rate limiting 342 343 > [!failure]+ Common SMTP Issues 344 > 13. **VRFY/EXPN disabled**: Modern security practice blocks these commands 345 > - Solution: Use RCPT TO method with `smtp-enum-users.methods={RCPT}` 346 > 14. **Connection rate limiting**: Multiple connections blocked 347 > - Solution: Reduce threads and add delays 348 > 15. **TLS required**: Port 25 may require STARTTLS before allowing commands 349 > - Solution: Use port 587 for modern submission protocol 350 > 16. **False positives on user enum**: Some servers return "User unknown" for all users 351 > - Solution: Verify results manually with test account 352 353 > [!tip]+ SMTP Security Assessment Best Practices 354 > 17. **Open relay**: Critical misconfiguration allowing spam relay 355 > 18. **User enumeration**: Reveals valid email addresses for phishing 356 > 19. **NTLM info disclosure**: Leaks internal domain names 357 > 20. **Version detection**: Outdated Postfix/Exim/Sendmail may be vulnerable 358 > 21. **Strange ports**: SMTP on non-standard ports may indicate malware 359 360 --- 361 362 ## Port 53 - DNS (Domain Name System) 363 364 > [!info]+ [DNS Service Overview](https://www.cloudflare.com/learning/dns/what-is-dns/) 365 > Domain Name System translates domain names to IP addresses. Critical infrastructure service. Zone transfers, subdomain enumeration, recursion testing, and cache snooping reveal network topology and misconfigurations. 366 367 **Key NSE Scripts for DNS**: 368 369 > [!info]+ DNS Enumeration Scripts 370 > 1. **[dns-zone-transfer](https://nmap.org/nsedoc/scripts/dns-zone-transfer.html)**: Attempts AXFR zone transfer 371 > 2. **[dns-brute](https://nmap.org/nsedoc/scripts/dns-brute.html)**: Subdomain brute forcing 372 > 3. **[dns-recursion](https://nmap.org/nsedoc/scripts/dns-recursion.html)**: Tests for open DNS resolver 373 > 4. **[dns-service-discovery](https://nmap.org/nsedoc/scripts/dns-service-discovery.html)**: Discovers services via DNS-SD/mDNS 374 > 5. **[dns-nsid](https://nmap.org/nsedoc/scripts/dns-nsid.html)**: Retrieves DNS server identity 375 > 6. **[dns-cache-snoop](https://nmap.org/nsedoc/scripts/dns-cache-snoop.html)**: Checks DNS cache for specific domains 376 > 7. **[dns-nsec-enum](https://nmap.org/nsedoc/scripts/dns-nsec-enum.html)**: Enumerates DNSSEC NSEC records 377 > 8. **[dns-nsec3-enum](https://nmap.org/nsedoc/scripts/dns-nsec3-enum.html)**: Enumerates DNSSEC NSEC3 records 378 > 9. **[dns-random-srcport](https://nmap.org/nsedoc/scripts/dns-random-srcport.html)**: Checks for source port randomization 379 > 10. **[dns-random-txid](https://nmap.org/nsedoc/scripts/dns-random-txid.html)**: Checks for transaction ID randomization 380 381 ```bash 382 # Attempt DNS zone transfer 383 nmap -p53 --script=dns-zone-transfer --script-args dns-zone-transfer.domain=example.com <target> 384 385 # Subdomain brute force 386 nmap --script=dns-brute --script-args dns-brute.domain=example.com <target> 387 388 # Subdomain brute with custom wordlist 389 nmap --script=dns-brute --script-args dns-brute.domain=example.com,dns-brute.hostlist=/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt <target> 390 391 # Subdomain brute with thread control 392 nmap --script=dns-brute --script-args dns-brute.domain=example.com,dns-brute.threads=10 --script-timeout=30m <target> 393 394 # Check for open DNS resolver 395 nmap -sU -p53 --script=dns-recursion <target> 396 397 # DNS service discovery (multicast DNS) 398 nmap -p53 --script=dns-service-discovery <target> 399 400 # DNS server identification 401 nmap -p53 --script=dns-nsid <target> 402 403 # DNS cache snooping 404 nmap -sU -p53 --script=dns-cache-snoop --script-args 'dns-cache-snoop.mode=timed,dns-cache-snoop.domains={google.com,facebook.com,example.com}' <target> 405 406 # DNSSEC NSEC enumeration 407 nmap -p53 --script=dns-nsec-enum --script-args dns-nsec-enum.domains=example.com <target> 408 409 # Check DNS security (randomization) 410 nmap -sU -p53 --script=dns-random-srcport,dns-random-txid <target> 411 412 # Comprehensive DNS assessment (both UDP and TCP) 413 nmap -sU -sS -p53 --script="dns-* and not brute" <target> 414 415 # Internal DNS server enumeration 416 nmap -sU -p53 --script=dns-recursion,dns-nsid --script-args dns-nsid.identifier=version.bind <target> 417 ``` 418 419 > [!info]+ Command Breakdown: DNS Enumeration 420 > 1. **dns-zone-transfer.domain**: Target domain for AXFR request 421 > 2. **dns-brute.threads**: Parallelization (default 5, increase for speed, decrease for stealth) 422 > 3. **dns-brute.hostlist**: Custom subdomain wordlist path 423 > 4. **dns-cache-snoop.mode=timed**: Uses timing to detect cached vs uncached queries 424 > 5. **DNS requires both UDP and TCP**: Use `-sU -sS` for comprehensive scanning 425 > 6. **dns-nsid.identifier**: Custom NSID query (version.bind reveals BIND version) 426 427 > [!success]+ Expected DNS Output 428 > ``` 429 > PORT STATE SERVICE 430 > 53/udp open domain 431 > | dns-zone-transfer: 432 > | example.com. SOA ns1.example.com. admin.example.com. 433 > | example.com. NS ns1.example.com. 434 > | example.com. NS ns2.example.com. 435 > | example.com. A 192.0.2.1 436 > | www.example.com. A 192.0.2.2 437 > | mail.example.com. A 192.0.2.3 438 > | ftp.example.com. A 192.0.2.4 439 > | dev.example.com. A 192.0.2.10 440 > | admin.example.com. A 192.0.2.11 441 > |_ vpn.example.com. A 192.0.2.20 442 > | dns-brute: 443 > | DNS Brute-force hostnames: 444 > | www.example.com - 192.0.2.2 445 > | mail.example.com - 192.0.2.3 446 > | ftp.example.com - 192.0.2.4 447 > | dev.example.com - 192.0.2.10 448 > | admin.example.com - 192.0.2.11 449 > | vpn.example.com - 192.0.2.20 450 > | staging.example.com - 192.0.2.30 451 > |_ test.example.com - 192.0.2.40 452 > | dns-recursion: Recursion appears to be enabled 453 > ``` 454 455 > [!warning]+ DNS OPSEC Considerations 456 > 1. **Zone transfer attempts**: Always logged by DNS servers, often triggers security alerts 457 > 2. **dns-brute visibility**: Generates hundreds to thousands of queries, extremely obvious 458 > 3. **Query logging**: All DNS servers log queries (standard operational practice) 459 > 4. **Rate limiting**: Excessive queries trigger rate limiting or blocking 460 > 5. **Sequential patterns**: Brute force creates distinctive sequential query patterns 461 462 > [!failure]+ Common DNS Issues 463 > 6. **Zone transfer denied**: Expected result on properly configured servers 464 > - Solution: Modern DNS security best practice restricts AXFR to authorized secondaries 465 > 7. **dns-brute timeout**: Large wordlists timeout on default 5-minute script timeout 466 > - Solution: Increase with `--script-timeout=30m`, reduce threads 467 > 8. **UDP packet loss**: DNS over UDP may drop packets on congested networks 468 > - Solution: Reduce threads, try TCP zone transfer 469 > 9. **No response**: Firewall blocking UDP 53 or DNS server not recursive 470 > - Solution: Verify port accessibility with basic UDP scan 471 472 > [!tip]+ DNS Security Assessment Best Practices 473 > 10. **Zone transfer**: Exposes complete DNS zone (all subdomains, internal IPs) 474 > 11. **Open resolver**: Allows DNS amplification DDoS attacks 475 > 12. **Cache snooping**: Privacy violation, reveals browsing history 476 > 13. **Subdomain discovery**: Reveals dev/staging/admin environments 477 > 14. **DNSSEC validation**: Modern security feature, enumerate with NSEC/NSEC3 478 479 > [!example]+ DNS Wordlists for Subdomain Enumeration 480 > 15. `/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt` - Top 5000 common subdomains 481 > 16. `/usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt` - Top 20000 subdomains 482 > 17. `/usr/share/seclists/Discovery/DNS/fierce-hostlist.txt` - Fierce DNS scanner default wordlist 483 > 18. `/usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt` - Comprehensive 100k list 484 > 19. `/usr/share/seclists/Discovery/DNS/dns-Jhaddix.txt` - Jason Haddix's all-sources wordlist 485 486 --- 487 488 ## Port 80/443/8080/8443 - HTTP/HTTPS (Web Services) 489 490 > [!info]+ [HTTP/HTTPS Service Overview](https://developer.mozilla.org/en-US/docs/Web/HTTP) 491 > Hypertext Transfer Protocol and its encrypted variant HTTPS. Most common internet protocol. Web application enumeration, vulnerability detection, SSL/TLS analysis. Ports 8080/8443 commonly used for alternative web services, proxies, or application servers. 492 493 **Key NSE Scripts for HTTP/HTTPS**: 494 495 > [!info]+ HTTP/HTTPS Enumeration Scripts 496 > **Information Gathering**: 497 > 1. **[http-enum](https://nmap.org/nsedoc/scripts/http-enum.html)**: Directory and file enumeration 498 > 2. **[http-headers](https://nmap.org/nsedoc/scripts/http-headers.html)**: HTTP response headers 499 > 3. **[http-methods](https://nmap.org/nsedoc/scripts/http-methods.html)**: Supported HTTP methods 500 > 4. **[http-title](https://nmap.org/nsedoc/scripts/http-title.html)**: HTML page title extraction 501 > 5. **[http-robots.txt](https://nmap.org/nsedoc/scripts/http-robots.txt.html)**: Robots.txt retrieval 502 > 6. **[http-sitemap-generator](https://nmap.org/nsedoc/scripts/http-sitemap-generator.html)**: Crawls and generates sitemap 503 > 7. **[http-server-header](https://nmap.org/nsedoc/scripts/http-server-header.html)**: Server header extraction 504 > 8. **[http-generator](https://nmap.org/nsedoc/scripts/http-generator.html)**: Detects CMS/framework from meta generator tag 505 > 506 > **Authentication Testing**: 507 > 1. **[http-auth](https://nmap.org/nsedoc/scripts/http-auth.html)**: Authentication scheme enumeration 508 > 2. **[http-brute](https://nmap.org/nsedoc/scripts/http-brute.html)**: HTTP Basic/Digest brute force 509 > 3. **[http-default-accounts](https://nmap.org/nsedoc/scripts/http-default-accounts.html)**: Default credential testing 510 > 4. **[http-form-brute](https://nmap.org/nsedoc/scripts/http-form-brute.html)**: HTML form brute force 511 > 5. **[http-wordpress-brute](https://nmap.org/nsedoc/scripts/http-wordpress-brute.html)**: WordPress credential brute force 512 > 513 > **Vulnerability Detection**: 514 > 6. **[http-shellshock](https://nmap.org/nsedoc/scripts/http-shellshock.html)**: CVE-2014-6271 Bash vulnerability 515 > 7. **[http-sql-injection](https://nmap.org/nsedoc/scripts/http-sql-injection.html)**: SQL injection detection 516 > 8. **[http-stored-xss](https://nmap.org/nsedoc/scripts/http-stored-xss.html)**: Stored XSS detection 517 > 9. **[http-csrf](https://nmap.org/nsedoc/scripts/http-csrf.html)**: CSRF vulnerability detection 518 > 10. **[http-phpself-xss](https://nmap.org/nsedoc/scripts/http-phpself-xss.html)**: PHP_SELF XSS 519 > 11. **[http-vuln-cve2017-5638](https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html)**: Apache Struts2 RCE 520 > 12. **[http-vuln-cve2015-1635](https://nmap.org/nsedoc/scripts/http-vuln-cve2015-1635.html)**: IIS RCE 521 > 13. **[http-vuln-cve2013-7091](https://nmap.org/nsedoc/scripts/http-vuln-cve2013-7091.html)**: Zimbra LFI 522 > 14. **[http-vuln-cve2014-3704](https://nmap.org/nsedoc/scripts/http-vuln-cve2014-3704.html)**: Drupal SQL injection 523 > 15. **[http-vuln-cve2017-1001000](https://nmap.org/nsedoc/scripts/http-vuln-cve2017-1001000.html)**: WordPress 4.7.0/4.7.1 privilege escalation 524 > 525 > **Configuration Analysis**: 526 > 16. **[http-security-headers](https://nmap.org/nsedoc/scripts/http-security-headers.html)**: Security header analysis 527 > 17. **[http-config-backup](https://nmap.org/nsedoc/scripts/http-config-backup.html)**: Backup file detection 528 > 18. **[http-apache-server-status](https://nmap.org/nsedoc/scripts/http-apache-server-status.html)**: Apache status page access 529 > 19. **[http-apache-negotiation](https://nmap.org/nsedoc/scripts/http-apache-negotiation.html)**: Apache content negotiation 530 > 20. **[http-git](https://nmap.org/nsedoc/scripts/http-git.html)**: Exposed .git directory detection 531 > 21. **[http-svn-enum](https://nmap.org/nsedoc/scripts/http-svn-enum.html)**: SVN repository enumeration 532 > 22. **[http-backup-finder](https://nmap.org/nsedoc/scripts/http-backup-finder.html)**: Backup file discovery 533 > 534 > **CMS/Application Specific**: 535 > 23. **[http-wordpress-enum](https://nmap.org/nsedoc/scripts/http-wordpress-enum.html)**: WordPress enumeration 536 > 24. **[http-wordpress-users](https://nmap.org/nsedoc/scripts/http-wordpress-users.html)**: WordPress user enumeration 537 > 25. **[http-joomla-brute](https://nmap.org/nsedoc/scripts/http-joomla-brute.html)**: Joomla brute force 538 > 26. **[http-drupal-enum](https://nmap.org/nsedoc/scripts/http-drupal-enum.html)**: Drupal enumeration 539 > 27. **[http-frontpage-login](https://nmap.org/nsedoc/scripts/http-frontpage-login.html)**: FrontPage admin interface 540 > 541 > **Cloud/SSRF**: 542 > 28. **[http-aws-metadata](https://nmap.org/nsedoc/scripts/http-aws-metadata.html)**: AWS metadata SSRF 543 > 29. **[http-azure-metadata](https://nmap.org/nsedoc/scripts/http-azure-metadata.html)**: Azure metadata SSRF 544 545 > [!info]+ SSL/TLS Specific Scripts (Port 443/8443) 546 > 30. **[ssl-cert](https://nmap.org/nsedoc/scripts/ssl-cert.html)**: SSL certificate details 547 > 31. **[ssl-enum-ciphers](https://nmap.org/nsedoc/scripts/ssl-enum-ciphers.html)**: Cipher suite enumeration and grading 548 > 32. **[ssl-heartbleed](https://nmap.org/nsedoc/scripts/ssl-heartbleed.html)**: CVE-2014-0160 Heartbleed 549 > 33. **[ssl-poodle](https://nmap.org/nsedoc/scripts/ssl-poodle.html)**: CVE-2014-3566 POODLE 550 > 34. **[ssl-ccs-injection](https://nmap.org/nsedoc/scripts/ssl-ccs-injection.html)**: CVE-2014-0224 CCS injection 551 > 35. **[ssl-dh-params](https://nmap.org/nsedoc/scripts/ssl-dh-params.html)**: Diffie-Hellman parameter analysis 552 > 36. **[ssl-known-key](https://nmap.org/nsedoc/scripts/ssl-known-key.html)**: Compromised key detection 553 > 37. **[ssl-date](https://nmap.org/nsedoc/scripts/ssl-date.html)**: System time from TLS handshake 554 555 ```bash 556 # Safe HTTP enumeration 557 nmap -sV -p80,443,8080,8443 --script=http-title,http-headers,http-methods,http-robots.txt,http-server-header <target> 558 559 # Directory and file enumeration (noisy) 560 nmap -p80,443 --script=http-enum <target> 561 562 # HTTP enumeration with virtual host 563 nmap -p80 --script=http-enum --script-args http.host=example.com <target> 564 565 # Security headers analysis 566 nmap -p443 --script=http-security-headers <target> 567 568 # HTTP methods testing (PUT, DELETE, TRACE) 569 nmap -p80 --script=http-methods --script-args http-methods.url-path=/upload <target> 570 571 # Shellshock vulnerability 572 nmap -p80 --script=http-shellshock --script-args uri=/cgi-bin/status,cmd=ls <target> 573 574 # SQL injection detection 575 nmap -p80 --script=http-sql-injection --script-args http-sql-injection.maxdepth=3 <target> 576 577 # XSS vulnerability detection 578 nmap -p80 --script=http-stored-xss,http-phpself-xss <target> 579 580 # Web application vulnerability scan 581 nmap -p80,443 --script=http-vuln-* <target> 582 583 # Default credential testing 584 nmap -p80 --script=http-default-accounts <target> 585 586 # HTTP Basic/Digest brute force 587 nmap -p80 --script=http-brute --script-args http-brute.path=/admin/ <target> 588 589 # WordPress enumeration 590 nmap -p80,443 --script=http-wordpress-enum --script-args search-limit=100 <target> 591 592 # WordPress user enumeration 593 nmap -p80 --script=http-wordpress-users <target> 594 595 # Exposed Git repository 596 nmap -p80,443 --script=http-git <target> 597 598 # Backup file discovery 599 nmap -p80 --script=http-backup-finder,http-config-backup <target> 600 601 # Apache server-status page 602 nmap -p80 --script=http-apache-server-status <target> 603 604 # AWS metadata SSRF 605 nmap -p80 --script=http-aws-metadata --script-args http-aws-metadata.uri=/redirect?url= <target> 606 607 # SSL/TLS certificate extraction 608 nmap -p443,8443 --script=ssl-cert <target> 609 610 # SSL/TLS cipher enumeration and grading 611 nmap -p443 --script=ssl-enum-ciphers <target> 612 613 # SSL/TLS vulnerability assessment 614 nmap -p443 --script=ssl-heartbleed,ssl-poodle,ssl-ccs-injection,ssl-dh-params <target> 615 616 # Comprehensive HTTP enumeration (safe) 617 nmap -sV -p80,443,8080,8443 --script="http-* and safe" <target> 618 619 # Comprehensive HTTPS assessment 620 nmap -sV -p443,8443 --script="(http-* or ssl-*) and not brute" <target> 621 622 # Web application security audit 623 nmap -sV -p80,443 --script="http-enum,http-vuln-*,http-config-backup,http-git,http-security-headers" <target> 624 625 # Custom user agent 626 nmap -p80 --script=http-enum --script-args http.useragent="Mozilla/5.0 (Windows NT 10.0; Win64; x64)" <target> 627 628 # HTTP proxy through specific port 629 nmap -p8080 --script=http-open-proxy <target> 630 ``` 631 632 > [!info]+ Command Breakdown: HTTP/HTTPS Enumeration 633 > 1. **http.host**: Virtual host specification for shared hosting environments 634 > 2. **http.useragent**: Custom User-Agent header (WAF evasion, mobile testing) 635 > 3. **http-methods.url-path**: Specific path to test methods (upload directories) 636 > 4. **http-sql-injection.maxdepth**: How many links deep to crawl 637 > 5. **http-brute.path**: Authentication endpoint path 638 > 6. **http-aws-metadata.uri**: SSRF-vulnerable parameter or endpoint 639 > 7. **tls.servername**: SNI for HTTPS virtual hosting 640 641 > [!success]+ Expected HTTP/HTTPS Output 642 > ``` 643 > PORT STATE SERVICE VERSION 644 > 80/tcp open http Apache httpd 2.4.29 ((Ubuntu)) 645 > |_http-title: Welcome to Example.com 646 > | http-headers: 647 > | Date: Sat, 25 Jan 2026 14:30:00 GMT 648 > | Server: Apache/2.4.29 (Ubuntu) 649 > | X-Powered-By: PHP/7.2.24 650 > | Content-Type: text/html; charset=UTF-8 651 > |_ Connection: Keep-Alive 652 > | http-methods: 653 > | Supported Methods: GET HEAD POST OPTIONS 654 > |_ Potentially risky methods: PUT DELETE TRACE 655 > | http-enum: 656 > | /admin/: Admin login page 657 > | /backup/: Backup directory 658 > | /config.php.bak: Configuration backup file 659 > | /test.php: Test file 660 > | /.git/: Git repository 661 > |_ /phpmyadmin/: phpMyAdmin 662 > | http-robots.txt: 5 disallowed entries 663 > |_/admin/ /backup/ /private/ /test/ /uploads/ 664 > 665 > 443/tcp open ssl/http Apache httpd 2.4.29 666 > | ssl-cert: Subject: commonName=*.example.com/organizationName=Example Inc 667 > | Subject Alternative Name: DNS:*.example.com, DNS:example.com 668 > | Not valid before: 2025-01-01T00:00:00 669 > |_Not valid after: 2026-01-01T00:00:00 670 > | ssl-enum-ciphers: 671 > | TLSv1.2: 672 > | ciphers: 673 > | TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A 674 > | TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A 675 > | compressors: 676 > | NULL 677 > | cipher preference: server 678 > | least strength: A 679 > | http-security-headers: 680 > | Strict-Transport-Security: max-age=31536000; includeSubDomains 681 > | X-Frame-Options: DENY 682 > | X-Content-Type-Options: nosniff 683 > |_ Missing headers: Content-Security-Policy, X-XSS-Protection 684 > | http-shellshock: 685 > | VULNERABLE: 686 > | HTTP Shellshock vulnerability 687 > | State: VULNERABLE (Exploitable) 688 > | IDs: CVE:CVE-2014-6271 689 > | Check results: 690 > | Vulnerable CGI script: /cgi-bin/status 691 > ``` 692 693 > [!warning]+ HTTP/HTTPS OPSEC Considerations 694 > 8. **http-enum**: Generates hundreds of 404 errors, extremely visible in access logs 695 > 9. **Vulnerability scripts**: Trigger WAF/IDS signatures for attack patterns 696 > 10. **http-brute**: Massively noisy, causes authentication failures, may lock accounts 697 > 11. **http-sql-injection**: Injects SQL syntax, triggers WAF blocks 698 > 12. **Safe scripts**: headers, methods, title, robots.txt appear as normal browsing 699 > 13. **Modern WAFs**: Cloudflare, AWS WAF, Imperva block most vulnerability scripts 700 701 > [!failure]+ Common HTTP/HTTPS Issues 702 > 14. **WAF blocking**: HTTP 403/429 responses or connection resets 703 > - Solution: Reduce timing (`-T2`), customize user agent, add delays 704 > 15. **Virtual hosting**: Wrong Host header returns default site 705 > - Solution: Use `--script-args http.host=example.com` 706 > 16. **SSL/TLS errors**: HTTPS scripts fail without proper handshake 707 > - Solution: Use `-sV` or `--script-args http.ssl=true` for non-standard ports 708 > 17. **Timeouts**: Slow applications or WAF delays timeout scripts 709 > - Solution: Increase `--script-timeout=120s` 710 > 18. **Authentication required**: Scripts return empty results on protected resources 711 > - Solution: Provide credentials with http.username/http.password arguments 712 > 19. **http-enum false positives**: WAF may fake directory responses 713 > - Solution: Manually verify findings with browser or curl 714 715 > [!tip]+ HTTP/HTTPS Security Assessment Best Practices 716 > 20. **Security headers**: Missing HSTS, CSP, X-Frame-Options indicate weaknesses 717 > 21. **Dangerous methods**: PUT, DELETE, TRACE should be disabled 718 > 22. **Directory listing**: Exposed directories reveal sensitive files 719 > 23. **Backup files**: .bak, .old, .backup files contain credentials/configs 720 > 24. **Version disclosure**: Server/X-Powered-By headers aid vulnerability research 721 > 25. **SSL/TLS grading**: Grade B or below indicates weak cryptography 722 > 26. **WordPress/CMS**: Outdated versions have known RCE vulnerabilities 723 > 27. **Git exposure**: /.git/ directory allows source code download 724 725 > [!example]+ HTTP Script Arguments Reference 726 > 28. **http.host=<hostname>**: Virtual host specification 727 > 29. **http.useragent=<string>**: Custom User-Agent header 728 > 30. **http.max-pipeline=<num>**: HTTP pipelining depth 729 > 31. **http-brute.path=<path>**: Authentication endpoint 730 > 32. **http-brute.method=POST**: HTTP method for auth 731 > 33. **http-enum.displayall=true**: Show all tested paths 732 > 34. **http-sql-injection.maxdepth=<num>**: Crawl depth 733 > 35. **uri=<path>**: Script-specific URI path 734 > 36. **tls.servername=<name>**: SNI for virtual HTTPS hosts 735 736 --- 737 738 ## Port 88 - Kerberos 739 740 > [!info]+ [Kerberos Service Overview](https://web.mit.edu/kerberos/) 741 > Authentication protocol used by Active Directory and Unix systems. Port 88 TCP/UDP for Kerberos authentication. User enumeration reveals valid domain accounts without authentication. 742 743 **Key NSE Scripts for Kerberos**: 744 745 > [!info]+ Kerberos Enumeration Scripts 746 > 1. **[krb5-enum-users](https://nmap.org/nsedoc/scripts/krb5-enum-users.html)**: User account enumeration via Kerberos pre-authentication 747 748 ```bash 749 # Kerberos user enumeration 750 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=DOMAIN.COM <dc-ip> 751 752 # User enumeration with custom wordlist 753 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=CONTOSO.LOCAL,userdb=/usr/share/seclists/Usernames/xato-net-10-million-usernames.txt <dc-ip> 754 755 # Enumerate common service accounts 756 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=DOMAIN.COM,userdb=/usr/share/seclists/Usernames/cirt-default-usernames.txt <dc-ip> 757 758 # Fast user enumeration (limited wordlist) 759 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=DOMAIN.COM,userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt <dc-ip> 760 ``` 761 762 > [!info]+ Command Breakdown: Kerberos Enumeration 763 > 1. **krb5-enum-users.realm**: Active Directory domain name (FQDN) 764 > 2. **userdb**: Username wordlist path 765 > 3. *Script distinguishes valid from invalid users via Kerberos error codes* 766 > 4. *KRB5KDC_ERR_PREAUTH_REQUIRED = valid user* 767 > 5. *KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN = invalid user* 768 769 > [!success]+ Expected Kerberos Output 770 > ``` 771 > PORT STATE SERVICE 772 > 88/tcp open kerberos-sec 773 > | krb5-enum-users: 774 > | Discovered Kerberos principals: 775 > | administrator@CONTOSO.LOCAL 776 > | Administrator@CONTOSO.LOCAL 777 > | guest@CONTOSO.LOCAL 778 > | krbtgt@CONTOSO.LOCAL 779 > | sqlservice@CONTOSO.LOCAL 780 > | webadmin@CONTOSO.LOCAL 781 > |_ Statistics: Performed 500 guesses in 34 seconds 782 > ``` 783 784 > [!warning]+ Kerberos OPSEC Considerations 785 > 6. **Windows Event Logs**: Pre-auth failures logged (Event ID 4768, 4771) 786 > 7. **Detection**: Modern monitoring tools detect user enumeration patterns 787 > 8. **SIEM alerts**: Multiple pre-auth failures from single IP trigger alerts 788 > 9. **Account lockout**: Enumeration doesn't trigger lockout (pre-auth only) 789 > 10. **Noise level**: Moderate - generates authentication attempts but not full logins 790 791 > [!tip]+ Kerberos Security Assessment Notes 792 > 11. **User enumeration**: Reveals valid domain accounts for password spraying 793 > 12. **Service accounts**: Accounts ending in "service", "admin", "sql" are high-value 794 > 13. **Disabled accounts**: Script doesn't distinguish disabled from enabled accounts 795 > 14. **Case sensitivity**: Windows usernames case-insensitive, test lowercase variants 796 > 15. **Follow-up**: Valid users enable targeted password spraying attacks 797 798 --- 799 800 ## Port 110/995 - POP3/POP3S (Post Office Protocol) 801 802 > [!info]+ [POP3 Service Overview](https://en.wikipedia.org/wiki/Post_Office_Protocol) 803 > Email retrieval protocol. Port 110 for unencrypted POP3, 995 for POP3S (SSL/TLS). Commonly used for email client access to mailboxes. 804 805 **Key NSE Scripts for POP3**: 806 807 > [!info]+ POP3 Enumeration Scripts 808 > 1. **[pop3-capabilities](https://nmap.org/nsedoc/scripts/pop3-capabilities.html)**: Lists POP3 capabilities 809 > 2. **[pop3-brute](https://nmap.org/nsedoc/scripts/pop3-brute.html)**: Credential brute forcing 810 > 3. **[pop3-ntlm-info](https://nmap.org/nsedoc/scripts/pop3-ntlm-info.html)**: Domain disclosure via NTLM 811 812 ```bash 813 # POP3 capability enumeration 814 nmap -sV -p110,995 --script=pop3-capabilities <target> 815 816 # POP3 NTLM information disclosure 817 nmap -p110,995 --script=pop3-ntlm-info <target> 818 819 # POP3 brute force (noisy) 820 nmap -p110 --script=pop3-brute --script-args userdb=users.txt,passdb=pass.txt <target> 821 822 # Comprehensive POP3 assessment 823 nmap -sV -p110,995 --script="pop3-* and not brute" <target> 824 ``` 825 826 > [!success]+ Expected POP3 Output 827 > ``` 828 > PORT STATE SERVICE VERSION 829 > 110/tcp open pop3 Dovecot pop3d 830 > | pop3-capabilities: RESP-CODES CAPA SASL PLAIN LOGIN UIDL TOP PIPELINING 831 > |_ Capabilities: TOP UIDL RESP-CODES CAPA SASL(PLAIN LOGIN) PIPELINING 832 > | pop3-ntlm-info: 833 > | Target_Name: MAIL 834 > | NetBIOS_Domain_Name: CONTOSO 835 > | NetBIOS_Computer_Name: MAIL01 836 > | DNS_Domain_Name: contoso.local 837 > | DNS_Computer_Name: mail01.contoso.local 838 > ``` 839 840 > [!warning]+ POP3 OPSEC Considerations 841 > 1. **pop3-brute**: Extremely noisy, triggers fail2ban and account lockouts 842 > 2. **Capability queries**: Safe, normal POP3 client behavior 843 > 3. **NTLM info disclosure**: Reveals internal domain names without authentication 844 845 --- 846 847 ## Port 111 - RPCBind 848 849 > [!info]+ [RPCBind Service Overview](https://en.wikipedia.org/wiki/Portmap) 850 > Remote Procedure Call port mapper. Maps RPC program numbers to network ports. Common on Unix/Linux systems. Reveals running RPC services including NFS, NIS, and other distributed services. 851 852 **Key NSE Scripts for RPCBind**: 853 854 > [!info]+ RPCBind Enumeration Scripts 855 > 1. **[rpcinfo](https://nmap.org/nsedoc/scripts/rpcinfo.html)**: Lists registered RPC services 856 > 2. **[nfs-showmount](https://nmap.org/nsedoc/scripts/nfs-showmount.html)**: Lists NFS exports (if NFS available) 857 > 3. **[nfs-ls](https://nmap.org/nsedoc/scripts/nfs-ls.html)**: Lists NFS directory contents 858 > 4. **[nfs-statfs](https://nmap.org/nsedoc/scripts/nfs-statfs.html)**: NFS filesystem statistics 859 860 ```bash 861 # RPC service enumeration 862 nmap -sV -p111 --script=rpcinfo <target> 863 864 # NFS export enumeration 865 nmap -p111 --script=nfs-showmount <target> 866 867 # List NFS directory contents 868 nmap -p111 --script=nfs-ls --script-args nfs-ls.export=/share <target> 869 870 # NFS filesystem statistics 871 nmap -p111 --script=nfs-statfs <target> 872 873 # Comprehensive RPC/NFS assessment 874 nmap -sV -p111,2049 --script="rpc*,nfs*" <target> 875 ``` 876 877 > [!success]+ Expected RPCBind Output 878 > ``` 879 > PORT STATE SERVICE VERSION 880 > 111/tcp open rpcbind 2-4 (RPC #100000) 881 > | rpcinfo: 882 > | program version port/proto service 883 > | 100000 2,3,4 111/tcp rpcbind 884 > | 100000 2,3,4 111/udp rpcbind 885 > | 100003 2,3,4 2049/tcp nfs 886 > | 100003 2,3,4 2049/udp nfs 887 > | 100005 1,2,3 20048/tcp mountd 888 > |_ 100005 1,2,3 20048/udp mountd 889 > | nfs-showmount: 890 > | /home 192.168.1.0/24 891 > | /var/nfs * 892 > |_ /backups (everyone) 893 > ``` 894 895 > [!tip]+ RPCBind Security Assessment Notes 896 > 1. **rpcinfo**: Reveals all RPC services and ports 897 > 2. **NFS exports**: Shows shared filesystems and access controls 898 > 3. **Wildcard exports**: `*` or `(everyone)` indicates world-readable shares 899 > 4. **Sensitive paths**: /home, /root, /etc, /backup exports critical 900 901 --- 902 903 ## Port 135/593 - Microsoft RPC (MSRPC) 904 905 > [!info]+ [Microsoft RPC Overview](https://docs.microsoft.com/en-us/windows/win32/rpc/rpc-start-page) 906 > Microsoft Remote Procedure Call endpoint mapper. Port 135 for RPC endpoint mapper, 593 for RPC over HTTP. Critical Windows service for DCOM, WMI, and distributed services. 907 908 **Key NSE Scripts for MSRPC**: 909 910 > [!info]+ MSRPC Enumeration Scripts 911 > 1. **[msrpc-enum](https://nmap.org/nsedoc/scripts/msrpc-enum.html)**: Enumerates MSRPC endpoints 912 > 2. **[smb-os-discovery](https://nmap.org/nsedoc/scripts/smb-os-discovery.html)**: OS discovery via RPC (works on 135) 913 > 3. **[smb-enum-domains](https://nmap.org/nsedoc/scripts/smb-enum-domains.html)**: Domain enumeration 914 915 ```bash 916 # MSRPC endpoint enumeration 917 nmap -sV -p135,593 --script=msrpc-enum <target> 918 919 # OS discovery via RPC 920 nmap -p135 --script=smb-os-discovery <target> 921 922 # Comprehensive MSRPC assessment 923 nmap -sV -p135,139,445,593 --script="msrpc-enum,smb-os-discovery" <target> 924 ``` 925 926 > [!success]+ Expected MSRPC Output 927 > ``` 928 > PORT STATE SERVICE VERSION 929 > 135/tcp open msrpc Microsoft Windows RPC 930 > | msrpc-enum: 931 > | Endpoints: 932 > | uuid: 12345778-1234-abcd-ef00-0123456789ab ncacn_ip_tcp:192.168.1.10[49152] 933 > | uuid: 12345778-1234-abcd-ef00-0123456789ac ncacn_ip_tcp:192.168.1.10[49153] 934 > |_ uuid: 12345778-1234-abcd-ef00-0123456789ad ncacn_ip_tcp:192.168.1.10[49154] 935 > ``` 936 937 > [!tip]+ MSRPC Security Assessment Notes 938 > 1. **Endpoint mapper**: Reveals dynamic RPC ports 939 > 2. **High ports**: MSRPC services commonly on ports 49152-65535 940 > 3. **Authentication**: Most MSRPC services require Windows credentials 941 > 4. **WMI**: Uses MSRPC on port 135 for remote management 942 943 --- 944 945 ## Port 139/445 - SMB/NetBIOS (Covered in detail earlier, key reference) 946 947 > [!info]+ SMB/NetBIOS Quick Reference 948 > See **SMB/Windows Service Scripts Deep Dive** section above for comprehensive coverage. Port 139 for NetBIOS session service (legacy), 445 for SMB over TCP (modern). 949 950 **Essential SMB Commands**: 951 ```bash 952 # Quick SMB enumeration 953 nmap -p139,445 --script=smb-os-discovery,smb-security-mode,smb-enum-shares <target> 954 955 # EternalBlue check 956 nmap -p445 --script=smb-vuln-ms17-010 <target> 957 958 # Comprehensive SMB assessment 959 nmap -sV -p139,445 --script="smb-* and not brute" <target> 960 ``` 961 962 --- 963 964 ## Port 143/993 - IMAP/IMAPS (Internet Message Access Protocol) 965 966 > [!info]+ [IMAP Service Overview](https://en.wikipedia.org/wiki/Internet_Message_Access_Protocol) 967 > Email retrieval protocol with advanced features (folders, server-side search). Port 143 for unencrypted IMAP, 993 for IMAPS (SSL/TLS). More feature-rich than POP3. 968 969 **Key NSE Scripts for IMAP**: 970 971 > [!info]+ IMAP Enumeration Scripts 972 > 1. **[imap-capabilities](https://nmap.org/nsedoc/scripts/imap-capabilities.html)**: Lists IMAP capabilities 973 > 2. **[imap-brute](https://nmap.org/nsedoc/scripts/imap-brute.html)**: Credential brute forcing 974 > 3. **[imap-ntlm-info](https://nmap.org/nsedoc/scripts/imap-ntlm-info.html)**: Domain disclosure via NTLM 975 976 ```bash 977 # IMAP capability enumeration 978 nmap -sV -p143,993 --script=imap-capabilities <target> 979 980 # IMAP NTLM information disclosure 981 nmap -p143,993 --script=imap-ntlm-info <target> 982 983 # IMAP brute force (noisy) 984 nmap -p143 --script=imap-brute --script-args userdb=users.txt,passdb=pass.txt <target> 985 986 # Comprehensive IMAP assessment 987 nmap -sV -p143,993 --script="imap-* and not brute" <target> 988 ``` 989 990 > [!success]+ Expected IMAP Output 991 > ``` 992 > PORT STATE SERVICE VERSION 993 > 143/tcp open imap Dovecot imapd 994 > | imap-capabilities: IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN 995 > |_ Capabilities: IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE STARTTLS AUTH=PLAIN AUTH=LOGIN 996 > | imap-ntlm-info: 997 > | Target_Name: MAIL 998 > | NetBIOS_Domain_Name: CONTOSO 999 > | NetBIOS_Computer_Name: MAIL01 1000 > | DNS_Domain_Name: contoso.local 1001 > | DNS_Computer_Name: mail01.contoso.local 1002 > ``` 1003 1004 > [!warning]+ IMAP OPSEC Considerations 1005 > 1. **imap-brute**: Extremely noisy, triggers fail2ban and account lockouts 1006 > 2. **Capability queries**: Safe, normal IMAP client behavior 1007 > 3. **NTLM info disclosure**: Reveals internal domain names without authentication 1008 1009 --- 1010 1011 ## Port 161/162 - SNMP (Simple Network Management Protocol) 1012 1013 > [!info]+ SNMP Quick Reference 1014 > See **SNMP Service Scripts Deep Dive** section above for comprehensive coverage. Port 161 for queries (UDP), 162 for traps (UDP). 1015 1016 **Essential SNMP Commands**: 1017 ```bash 1018 # Quick SNMP enumeration 1019 nmap -sU -p161 --script=snmp-info,snmp-interfaces <target> 1020 1021 # SNMP community string brute force 1022 nmap -sU -p161 --script=snmp-brute <target> 1023 1024 # Comprehensive SNMP assessment 1025 nmap -sU -p161 --script="snmp-* and not brute" <target> 1026 ``` 1027 1028 --- 1029 1030 ## Port 389/636/3268/3269 - LDAP/LDAPS/Global Catalog 1031 1032 > [!info]+ [LDAP Service Overview](https://ldap.com/) 1033 > Lightweight Directory Access Protocol for directory services. Port 389 for LDAP, 636 for LDAPS (SSL/TLS), 3268 for Global Catalog (AD), 3269 for Global Catalog SSL. Active Directory primary protocol. 1034 1035 **Key NSE Scripts for LDAP**: 1036 1037 > [!info]+ LDAP Enumeration Scripts 1038 > 1. **[ldap-rootdse](https://nmap.org/nsedoc/scripts/ldap-rootdse.html)**: Anonymous directory enumeration 1039 > 2. **[ldap-search](https://nmap.org/nsedoc/scripts/ldap-search.html)**: LDAP object search (requires auth) 1040 > 3. **[ldap-brute](https://nmap.org/nsedoc/scripts/ldap-brute.html)**: Credential brute forcing 1041 1042 ```bash 1043 # Anonymous LDAP enumeration (rootDSE) 1044 nmap -p389,636 --script=ldap-rootdse <target> 1045 1046 # LDAP search with credentials 1047 nmap -p389 --script=ldap-search --script-args ldap.username="CN=user,DC=domain,DC=com",ldap.password=password <target> 1048 1049 # LDAP brute force (noisy) 1050 nmap -p389 --script=ldap-brute --script-args userdb=users.txt,passdb=pass.txt <target> 1051 1052 # Global Catalog enumeration 1053 nmap -p3268,3269 --script=ldap-rootdse <target> 1054 1055 # Comprehensive LDAP assessment 1056 nmap -sV -p389,636,3268,3269 --script="ldap-* and not brute" <target> 1057 ``` 1058 1059 > [!success]+ Expected LDAP Output 1060 > ``` 1061 > PORT STATE SERVICE VERSION 1062 > 389/tcp open ldap Microsoft Windows Active Directory LDAP (Domain: contoso.local, Site: Default-First-Site-Name) 1063 > | ldap-rootdse: 1064 > | LDAP Results 1065 > | domainFunctionality: 7 1066 > | forestFunctionality: 7 1067 > | domainControllerFunctionality: 7 1068 > | rootDomainNamingContext: DC=contoso,DC=local 1069 > | ldapServiceName: contoso.local:dc01$@CONTOSO.LOCAL 1070 > | isGlobalCatalogReady: TRUE 1071 > | supportedSASLMechanisms: GSSAPI, GSS-SPNEGO, EXTERNAL, DIGEST-MD5 1072 > | dnsHostName: dc01.contoso.local 1073 > | defaultNamingContext: DC=contoso,DC=local 1074 > | serverName: CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=local 1075 > ``` 1076 1077 > [!tip]+ LDAP Security Assessment Notes 1078 > 1. **ldap-rootdse**: Reveals domain structure, forest functional level, DC names 1079 > 2. **Anonymous binding**: Some LDAP servers allow anonymous rootDSE queries 1080 > 3. **Functional level**: Indicates Windows Server version (7 = Server 2016+) 1081 > 4. **Global Catalog**: Ports 3268/3269 indicate domain controller 1082 > 5. **LDAP signing**: Modern AD enforces LDAP signing and channel binding 1083 1084 --- 1085 1086 ## Port 443 - HTTPS (Covered in Port 80/443 section, SSL/TLS focus) 1087 1088 > [!info]+ HTTPS Quick Reference 1089 > See **Port 80/443/8080/8443 - HTTP/HTTPS** section above for comprehensive coverage. 1090 1091 **Essential HTTPS Commands**: 1092 ```bash 1093 # SSL/TLS assessment 1094 nmap -p443 --script=ssl-cert,ssl-enum-ciphers,ssl-heartbleed,ssl-poodle <target> 1095 1096 # Comprehensive HTTPS security audit 1097 nmap -sV -p443 --script="(http-* or ssl-*) and not brute" <target> 1098 ``` 1099 1100 --- 1101 1102 ## Port 514 - Syslog 1103 1104 > [!info]+ [Syslog Service Overview](https://en.wikipedia.org/wiki/Syslog) 1105 > System logging protocol. Port 514 UDP for syslog. Centralized logging service commonly used by network devices and Unix/Linux systems. 1106 1107 **Key NSE Scripts for Syslog**: 1108 1109 > [!info]+ Syslog Enumeration Scripts 1110 > 1. **[syslog-detect](https://nmap.org/nsedoc/scripts/syslog-detect.html)**: Detects syslog service 1111 1112 ```bash 1113 # Syslog detection 1114 nmap -sU -p514 --script=syslog-detect <target> 1115 1116 # Test syslog message injection 1117 nmap -sU -p514 --script=syslog-detect --script-args syslog-detect.facility=user,syslog-detect.severity=info <target> 1118 ``` 1119 1120 > [!warning]+ Syslog Security Notes 1121 > 1. **Open syslog**: Allows log injection attacks 1122 > 2. **Information disclosure**: May reveal system details in error messages 1123 > 3. **DoS potential**: Log flooding can fill disk space 1124 1125 --- 1126 1127 ## Port 873 - Rsync 1128 1129 > [!info]+ [Rsync Service Overview](https://rsync.samba.org/) 1130 > File synchronization and transfer protocol. Port 873 for rsync daemon. Commonly used for backups and mirroring. 1131 1132 **Key NSE Scripts for Rsync**: 1133 1134 > [!info]+ Rsync Enumeration Scripts 1135 > 1. **[rsync-list-modules](https://nmap.org/nsedoc/scripts/rsync-list-modules.html)**: Lists available rsync modules 1136 > 2. **[rsync-brute](https://nmap.org/nsedoc/scripts/rsync-brute.html)**: Credential brute forcing 1137 1138 ```bash 1139 # List rsync modules 1140 nmap -p873 --script=rsync-list-modules <target> 1141 1142 # Rsync brute force 1143 nmap -p873 --script=rsync-brute --script-args userdb=users.txt,passdb=pass.txt <target> 1144 1145 # Comprehensive rsync assessment 1146 nmap -sV -p873 --script="rsync-*" <target> 1147 ``` 1148 1149 > [!success]+ Expected Rsync Output 1150 > ``` 1151 > PORT STATE SERVICE VERSION 1152 > 873/tcp open rsync (protocol version 31) 1153 > | rsync-list-modules: 1154 > | backup Backup files 1155 > | data Data directory 1156 > | home Home directories 1157 > |_ www Web root 1158 > ``` 1159 1160 > [!tip]+ Rsync Security Assessment Notes 1161 > 1. **Anonymous access**: Some rsync modules allow unauthenticated access 1162 > 2. **Sensitive paths**: backup, home, www modules may contain sensitive data 1163 > 3. **Write access**: Writable modules allow file upload/modification 1164 1165 --- 1166 1167 ## Port 1433/1434 - Microsoft SQL Server (MSSQL) 1168 1169 > [!info]+ MSSQL Quick Reference 1170 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. Port 1433 for SQL Server, 1434 UDP for SQL Server Browser. 1171 1172 **Essential MSSQL Commands**: 1173 ```bash 1174 # Quick MSSQL enumeration 1175 nmap -p1433 --script=ms-sql-info,ms-sql-ntlm-info <target> 1176 1177 # MSSQL brute force 1178 nmap -p1433 --script=ms-sql-brute <target> 1179 1180 # Comprehensive MSSQL assessment 1181 nmap -sV -p1433 --script="ms-sql-* and not brute" <target> 1182 ``` 1183 1184 --- 1185 1186 ## Port 1521 - Oracle Database 1187 1188 > [!info]+ Oracle Database Quick Reference 1189 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. 1190 1191 **Essential Oracle Commands**: 1192 ```bash 1193 # Oracle SID brute force 1194 nmap -p1521 --script=oracle-sid-brute <target> 1195 1196 # Oracle credential brute force 1197 nmap -p1521 --script=oracle-brute --script-args sid=ORCL <target> 1198 ``` 1199 1200 --- 1201 1202 ## Port 2049 - NFS (Network File System) 1203 1204 > [!info]+ [NFS Service Overview](https://en.wikipedia.org/wiki/Network_File_System) 1205 > Network File System for Unix/Linux file sharing. Port 2049 for NFSv3/v4. Requires RPCBind (port 111) for NFSv3. 1206 1207 **Key NSE Scripts for NFS**: 1208 1209 > [!info]+ NFS Enumeration Scripts 1210 > 1. **[nfs-showmount](https://nmap.org/nsedoc/scripts/nfs-showmount.html)**: Lists NFS exports 1211 > 2. **[nfs-ls](https://nmap.org/nsedoc/scripts/nfs-ls.html)**: Lists directory contents 1212 > 3. **[nfs-statfs](https://nmap.org/nsedoc/scripts/nfs-statfs.html)**: Filesystem statistics 1213 1214 ```bash 1215 # List NFS exports 1216 nmap -p111,2049 --script=nfs-showmount <target> 1217 1218 # List directory contents 1219 nmap -p2049 --script=nfs-ls --script-args nfs.export=/share <target> 1220 1221 # NFS filesystem statistics 1222 nmap -p2049 --script=nfs-statfs <target> 1223 1224 # Comprehensive NFS assessment 1225 nmap -sV -p111,2049 --script="nfs-*" <target> 1226 ``` 1227 1228 > [!success]+ Expected NFS Output 1229 > ``` 1230 > PORT STATE SERVICE VERSION 1231 > 2049/tcp open nfs 3-4 (RPC #100003) 1232 > | nfs-showmount: 1233 > | /home 192.168.1.0/24 1234 > | /var/nfs * 1235 > |_ /backups (everyone) 1236 > | nfs-ls: Volume /home 1237 > | access: Read Lookup NoModify NoExtend NoDelete NoExecute 1238 > | PERMISSION UID GID SIZE TIME FILENAME 1239 > | drwxr-xr-x 1000 1000 4096 2026-01-20T10:30:00 user1 1240 > | drwxr-xr-x 1001 1001 4096 2026-01-21T14:15:00 user2 1241 > |_ drwxr-xr-x 1002 1002 4096 2026-01-22T09:45:00 admin 1242 > ``` 1243 1244 > [!warning]+ NFS Security Considerations 1245 > 1. **Wildcard exports**: `*` or `(everyone)` allows world access 1246 > 2. **Sensitive paths**: /home, /root, /etc exports reveal user data 1247 > 3. **no_root_squash**: Allows client root to be server root (critical) 1248 > 4. **NFSv3 vs NFSv4**: NFSv4 has better security (Kerberos support) 1249 1250 --- 1251 1252 ## Port 3306 - MySQL/MariaDB 1253 1254 > [!info]+ MySQL Quick Reference 1255 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. 1256 1257 **Essential MySQL Commands**: 1258 ```bash 1259 # Quick MySQL enumeration 1260 nmap -p3306 --script=mysql-info,mysql-empty-password <target> 1261 1262 # MySQL brute force 1263 nmap -p3306 --script=mysql-brute <target> 1264 1265 # Comprehensive MySQL assessment 1266 nmap -sV -p3306 --script="mysql-* and not brute" <target> 1267 ``` 1268 1269 --- 1270 1271 ## Port 3389 - RDP (Remote Desktop Protocol) 1272 1273 > [!info]+ [RDP Service Overview](https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients) 1274 > Remote Desktop Protocol for Windows graphical remote access. Port 3389 TCP. Critical service for Windows administration. 1275 1276 **Key NSE Scripts for RDP**: 1277 1278 > [!info]+ RDP Enumeration Scripts 1279 > 1. **[rdp-enum-encryption](https://nmap.org/nsedoc/scripts/rdp-enum-encryption.html)**: Enumerates encryption methods 1280 > 2. **[rdp-ntlm-info](https://nmap.org/nsedoc/scripts/rdp-ntlm-info.html)**: Domain disclosure via NTLM 1281 > 3. **[rdp-vuln-ms12-020](https://nmap.org/nsedoc/scripts/rdp-vuln-ms12-020.html)**: MS12-020 vulnerability 1282 1283 ```bash 1284 # RDP encryption enumeration 1285 nmap -p3389 --script=rdp-enum-encryption <target> 1286 1287 # RDP NTLM information disclosure 1288 nmap -p3389 --script=rdp-ntlm-info <target> 1289 1290 # RDP vulnerability assessment 1291 nmap -p3389 --script=rdp-vuln-ms12-020 <target> 1292 1293 # Comprehensive RDP assessment 1294 nmap -sV -p3389 --script="rdp-*" <target> 1295 ``` 1296 1297 > [!success]+ Expected RDP Output 1298 > ``` 1299 > PORT STATE SERVICE VERSION 1300 > 3389/tcp open ms-wbt-server Microsoft Terminal Services 1301 > | rdp-enum-encryption: 1302 > | Security layer 1303 > | CredSSP (NLA): SUCCESS 1304 > | CredSSP with Early User Auth: SUCCESS 1305 > | Native RDP: SUCCESS 1306 > | SSL: SUCCESS 1307 > | RDP Encryption level: High 1308 > | 128-bit RC4: SUCCESS 1309 > |_ FIPS 140-1: SUCCESS 1310 > | rdp-ntlm-info: 1311 > | Target_Name: WORKSTATION 1312 > | NetBIOS_Domain_Name: CONTOSO 1313 > | NetBIOS_Computer_Name: WS01 1314 > | DNS_Domain_Name: contoso.local 1315 > | DNS_Computer_Name: ws01.contoso.local 1316 > | Product_Version: 10.0.17763 1317 > ``` 1318 1319 > [!tip]+ RDP Security Assessment Notes 1320 > 1. **NLA (Network Level Authentication)**: Modern security requiring auth before session 1321 > 2. **Encryption level**: High/FIPS better than Low/Medium 1322 > 3. **rdp-ntlm-info**: Reveals domain and computer names without authentication 1323 > 4. **MS12-020**: Denial of service vulnerability (Server 2008 and earlier) 1324 > 5. **BlueKeep (CVE-2019-0708)**: RCE vulnerability (pre-patch Server 2008/Windows 7) 1325 1326 --- 1327 1328 ## Port 5432 - PostgreSQL 1329 1330 > [!info]+ PostgreSQL Quick Reference 1331 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. 1332 1333 **Essential PostgreSQL Commands**: 1334 ```bash 1335 # PostgreSQL brute force 1336 nmap -p5432 --script=pgsql-brute <target> 1337 1338 # PostgreSQL with credentials 1339 nmap -p5432 --script=pgsql-brute --script-args userdb=users.txt,passdb=pass.txt <target> 1340 ``` 1341 1342 --- 1343 1344 ## Port 5900-5909 - VNC (Virtual Network Computing) 1345 1346 > [!info]+ [VNC Service Overview](https://en.wikipedia.org/wiki/Virtual_Network_Computing) 1347 > Virtual Network Computing for graphical remote access. Ports 5900-5909 (display :0-:9). Cross-platform remote desktop protocol. 1348 1349 **Key NSE Scripts for VNC**: 1350 1351 > [!info]+ VNC Enumeration Scripts 1352 > 1. **[vnc-info](https://nmap.org/nsedoc/scripts/vnc-info.html)**: VNC server information 1353 > 2. **[vnc-brute](https://nmap.org/nsedoc/scripts/vnc-brute.html)**: Password brute forcing 1354 > 3. **[realvnc-auth-bypass](https://nmap.org/nsedoc/scripts/realvnc-auth-bypass.html)**: RealVNC authentication bypass 1355 1356 ```bash 1357 # VNC server information 1358 nmap -sV -p5900 --script=vnc-info <target> 1359 1360 # VNC authentication bypass check 1361 nmap -p5900 --script=realvnc-auth-bypass <target> 1362 1363 # VNC password brute force 1364 nmap -p5900 --script=vnc-brute <target> 1365 1366 # Scan VNC display range 1367 nmap -p5900-5909 --script=vnc-info <target> 1368 1369 # Comprehensive VNC assessment 1370 nmap -sV -p5900-5909 --script="vnc-* and not brute" <target> 1371 ``` 1372 1373 > [!success]+ Expected VNC Output 1374 > ``` 1375 > PORT STATE SERVICE VERSION 1376 > 5900/tcp open vnc RealVNC 4.1.2 (protocol 3.8) 1377 > | vnc-info: 1378 > | Protocol version: 3.8 1379 > | Security types: 1380 > | VNC Authentication (2) 1381 > |_ Tight (16) 1382 > ``` 1383 1384 > [!warning]+ VNC Security Considerations 1385 > 1. **No encryption**: VNC transmits data unencrypted (use SSH tunnel) 1386 > 2. **Password-only auth**: VNC typically uses single password, no usernames 1387 > 3. **realvnc-auth-bypass**: Critical vulnerability in RealVNC 4.1.0/4.1.1 1388 > 4. **vnc-brute throttling**: VNC servers often throttle connection attempts 1389 > 5. **Default passwords**: Many VNC installations use weak or default passwords 1390 1391 --- 1392 1393 ## Port 6379 - Redis 1394 1395 > [!info]+ Redis Quick Reference 1396 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. 1397 1398 **Essential Redis Commands**: 1399 ```bash 1400 # Redis information gathering 1401 nmap -p6379 --script=redis-info <target> 1402 1403 # Redis brute force 1404 nmap -p6379 --script=redis-brute <target> 1405 ``` 1406 1407 --- 1408 1409 ## Port 8080/8443 - Alternative HTTP/HTTPS 1410 1411 > [!info]+ Alternative HTTP Ports Quick Reference 1412 > See **Port 80/443/8080/8443 - HTTP/HTTPS** section for comprehensive coverage. Commonly used for web application servers, proxies, management interfaces. 1413 1414 **Essential Commands**: 1415 ```bash 1416 # Quick web enumeration on alternative ports 1417 nmap -sV -p8080,8443 --script=http-title,http-headers,http-methods <target> 1418 1419 # Comprehensive assessment 1420 nmap -sV -p8080,8443 --script="(http-* or ssl-*) and safe" <target> 1421 ``` 1422 1423 --- 1424 1425 ## Port 9200/9300 - Elasticsearch 1426 1427 > [!info]+ Elasticsearch Quick Reference 1428 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. Port 9200 for HTTP API, 9300 for node communication. 1429 1430 **Essential Elasticsearch Commands**: 1431 ```bash 1432 # Elasticsearch cluster information 1433 nmap -p9200 --script=elasticsearch-info <target> 1434 1435 # Elasticsearch via HTTP enumeration 1436 nmap -p9200 --script=http-title,http-headers <target> 1437 ``` 1438 1439 --- 1440 1441 ## Port 27017/27018 - MongoDB 1442 1443 > [!info]+ MongoDB Quick Reference 1444 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. Port 27017 for MongoDB, 27018 for shard server. 1445 1446 **Essential MongoDB Commands**: 1447 ```bash 1448 # MongoDB information gathering 1449 nmap -p27017 --script=mongodb-info,mongodb-databases <target> 1450 1451 # MongoDB brute force 1452 nmap -p27017 --script=mongodb-brute <target> 1453 ``` 1454 1455 --- 1456 1457 ## Port Range Summary Table 1458 1459 | Port(s) | Service | Safe Scripts | Vuln Scripts | Brute Scripts | OPSEC Risk | 1460 |:---|:---|:---|:---|:---|:---| 1461 | 20-21 | FTP | ftp-anon, ftp-syst | ftp-vuln-*, ftp-vsftpd-backdoor | ftp-brute | Medium | 1462 | 22 | SSH | ssh-hostkey, ssh-auth-methods, ssh2-enum-algos | sshv1 | ssh-brute | Very High | 1463 | 23 | Telnet | telnet-encryption, telnet-ntlm-info | - | telnet-brute | High | 1464 | 25/587 | SMTP | smtp-commands, smtp-ntlm-info | smtp-vuln-* | smtp-brute, smtp-enum-users | High | 1465 | 53 | DNS | dns-recursion, dns-nsid | - | dns-brute, dns-zone-transfer | Very High | 1466 | 80/443 | HTTP/S | http-title, http-headers, ssl-cert | http-vuln-*, ssl-* | http-brute | Medium-High | 1467 | 88 | Kerberos | - | - | krb5-enum-users | Medium | 1468 | 110/995 | POP3 | pop3-capabilities, pop3-ntlm-info | - | pop3-brute | High | 1469 | 111 | RPCBind | rpcinfo, nfs-showmount | - | - | Low | 1470 | 135 | MSRPC | msrpc-enum | - | - | Low | 1471 | 139/445 | SMB | smb-os-discovery, smb-security-mode | smb-vuln-* | smb-brute | Medium | 1472 | 143/993 | IMAP | imap-capabilities, imap-ntlm-info | - | imap-brute | High | 1473 | 161 | SNMP | snmp-info, snmp-interfaces | - | snmp-brute | Medium | 1474 | 389/636 | LDAP | ldap-rootdse | - | ldap-brute | Medium | 1475 | 514 | Syslog | syslog-detect | - | - | Low | 1476 | 873 | Rsync | rsync-list-modules | - | rsync-brute | Medium | 1477 | 1433 | MSSQL | ms-sql-info, ms-sql-ntlm-info | ms-sql-vuln-* | ms-sql-brute | Medium | 1478 | 1521 | Oracle | - | - | oracle-sid-brute, oracle-brute | High | 1479 | 2049 | NFS | nfs-showmount, nfs-ls | - | - | Low | 1480 | 3306 | MySQL | mysql-info, mysql-empty-password | - | mysql-brute | High | 1481 | 3389 | RDP | rdp-enum-encryption, rdp-ntlm-info | rdp-vuln-ms12-020 | - | Low | 1482 | 5432 | PostgreSQL | - | - | pgsql-brute | High | 1483 | 5900 | VNC | vnc-info | realvnc-auth-bypass | vnc-brute | Medium | 1484 | 6379 | Redis | redis-info | - | redis-brute | Medium | 1485 | 8080/8443 | Alt HTTP/S | http-title, http-headers | http-vuln-*, ssl-* | http-brute | Medium-High | 1486 | 9200 | Elasticsearch | elasticsearch-info | - | - | Low | 1487 | 27017 | MongoDB | mongodb-info, mongodb-databases | - | mongodb-brute | Medium | 1488 1489 --- 1490 1491 ## Multi-Port Scanning Strategies 1492 1493 > [!tip]+ Efficient Multi-Service Enumeration 1494 > Scan multiple related services simultaneously to build comprehensive target profile. 1495 1496 ```bash 1497 # Full TCP common port scan with default scripts 1498 nmap -sC -sV -p- <target> -oA full_tcp_scan 1499 1500 # Top 1000 ports with safe enumeration 1501 nmap -sV --script="safe and not intrusive" --top-ports 1000 <target> -oA top1000_safe 1502 1503 # All database ports 1504 nmap -sV --script="(mysql-* or ms-sql-* or oracle-* or mongodb-* or redis-* or pgsql-*) and not brute" -p1433,1521,3306,5432,6379,9200,27017 <target> -oA databases 1505 1506 # All Windows/AD ports 1507 nmap -sV --script="(smb-* or ldap-* or msrpc-* or rdp-* or krb5-*) and not brute" -p88,135,139,389,445,636,3268,3269,3389 <target> -oA windows_ad 1508 1509 # All mail ports 1510 nmap -sV --script="(smtp-* or pop3-* or imap-*) and not brute" -p25,110,143,465,587,993,995 <target> -oA mail_services 1511 1512 # All web ports 1513 nmap -sV --script="(http-* or ssl-*) and safe" -p80,443,8080,8081,8443,8888,9090 <target> -oA web_services 1514 1515 # Complete service enumeration (safe only, no brute) 1516 nmap -sS -sU -sV --script="safe and not brute" -p T:21-23,25,53,80,88,110,111,135,139,143,389,443,445,636,1433,1521,2049,3306,3389,5432,5900,6379,8080,8443,9200,27017,U:53,161,514 <target> -oA complete_safe_enum 1517 ``` 1518 1519 --- 1520 1521 ## References 1522 1523 1. [Nmap Official Documentation](https://nmap.org/book/) 1524 2. [NSE Documentation Portal](https://nmap.org/nsedoc/) 1525 3. [NSE Script Categories Reference](https://nmap.org/book/nse-usage.html) 1526 4. [Port Number Registry (IANA)](https://www.iana.org/assignments/service-names-port-numbers/) 1527 5. [Common Ports List](https://www.speedguide.net/ports.php) 1528 6. [HackTricks - Network Service Pentesting](https://book.hacktricks.xyz/network-services-pentesting) 1529 7. [MITRE ATT&CK Framework](https://attack.mitre.org/) 1530 8. [SecLists Wordlist Repository](https://github.com/danielmiessler/SecLists) 1531 9. [RFC Index](https://www.rfc-editor.org/rfc-index.html) 1532 10. [CVE Database](https://cve.mitre.org/) 1533 1534 --- 1535 1536 #Nmap #NSE #NetworkEnumeration #ServiceDetection #VulnerabilityScanning #Reconnaissance #Pentesting #SecurityAssessment #NetworkSecurity #InfoSec #PortScanning #FTP #SSH #HTTP #HTTPS #SMB #DNS #LDAP #MySQL #MSSQL #PostgreSQL #MongoDB #Redis #Elasticsearch #SNMP #RDP #VNC #Kerberos