daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

nse-guide.md (66328B)


      1 ---
      2 title: "NSE Guide"
      3 description: "nmap -sV -p21 --script=ftp-anon,ftp-bounce,ftp-syst <target>"
      4 category: enumeration
      5 tags: ["enumeration"]
      6 tools: ["Nmap"]
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/NSE Guide.md"
     10 ---
     11 # Safe FTP enumeration
     12 nmap -sV -p21 --script=ftp-anon,ftp-bounce,ftp-syst <target>
     13 
     14 # Check for anonymous access and list files
     15 nmap -p21 --script=ftp-anon --script-args ftp-anon.maxlist=-1 <target>
     16 
     17 # FTP vulnerability assessment
     18 nmap -p21 --script=ftp-vuln-* <target>
     19 
     20 # Check for backdoors
     21 nmap -p21 --script=ftp-proftpd-backdoor,ftp-vsftpd-backdoor <target>
     22 
     23 # FTP brute force (noisy)
     24 nmap -p21 --script=ftp-brute --script-args userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt,passdb=/usr/share/seclists/Passwords/Common-Credentials/10-million-password-list-top-100.txt <target>
     25 
     26 # FTP brute force with timeout control
     27 nmap -p21 --script=ftp-brute --script-args ftp-brute.timeout=10s,brute.threads=2 <target>
     28 
     29 # Comprehensive FTP assessment
     30 nmap -sV -p21 --script="ftp-* and not brute" <target>
     31 ```
     32 
     33 > [!info]+ Command Breakdown: FTP Enumeration
     34 > 1. **ftp-anon**: Attempts login with username "anonymous" and email as password
     35 > 2. **ftp-anon.maxlist**: Controls how many directory entries to list (-1 for unlimited)
     36 > 3. **ftp-bounce**: Tests if FTP server allows bounce attacks (proxy port scans)
     37 > 4. **ftp-vsftpd-backdoor**: Checks for backdoor in vsftpd 2.3.4 (smiley face backdoor)
     38 > 5. **ftp-brute.timeout**: Delay between connection attempts to avoid blocking
     39 
     40 > [!success]+ Expected FTP Output
     41 > ```
     42 > PORT   STATE SERVICE VERSION
     43 > 21/tcp open  ftp     vsftpd 2.3.4
     44 > | ftp-anon: Anonymous FTP login allowed (FTP code 230)
     45 > |_drwxr-xr-x    2 0        0            4096 Mar 17  2010 pub
     46 > | ftp-vsftpd-backdoor:
     47 > |   VULNERABLE:
     48 > |   vsFTPd version 2.3.4 backdoor
     49 > |     State: VULNERABLE (Exploitable)
     50 > |     IDs:  CVE:CVE-2011-2523  BID:48539
     51 > |       vsFTPd version 2.3.4 backdoor, this was reported on 2011-07-04.
     52 > |     Disclosure date: 2011-07-03
     53 > |     Exploit results:
     54 > |       Shell command: id
     55 > |       Results: uid=0(root) gid=0(root)
     56 > |     References:
     57 > |       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2523
     58 > ```
     59 
     60 > [!warning]+ FTP OPSEC Considerations
     61 > 6. **Anonymous login attempts**: Logged in FTP server logs
     62 > 7. **ftp-brute detection**: Extremely noisy, triggers fail2ban and IDS
     63 > 8. **Backdoor checks**: May trigger AV/EDR alerts
     64 > 9. **Safe scripts**: ftp-anon, ftp-syst generate normal FTP traffic
     65 > 10. **Directory listing**: Large directories cause extended connection time
     66 
     67 > [!failure]+ Common FTP Issues
     68 > 11. **Connection timeout**: FTP firewall filtering or passive mode issues
     69 >    - Solution: Verify port 21 accessible, some scripts need port 20 open
     70 > 12. **Anonymous access denied**: Expected on secure configurations
     71 >    - Solution: Not an error - indicates proper security
     72 > 13. **ftp-brute IP blocking**: fail2ban blocks source IP after failed attempts
     73 >    - Solution: Reduce threads and add delays with `ftp-brute.timeout`
     74 
     75 ---
     76 
     77 ## Port 22 - SSH (Secure Shell)
     78 
     79 > [!info]+ [SSH Service Overview](https://www.openssh.com/)
     80 > Secure Shell provides encrypted remote access and file transfer. Critical service for Linux/Unix administration. Version detection, algorithm enumeration, and authentication testing reveal security posture.
     81 
     82 **Key NSE Scripts for SSH**:
     83 
     84 > [!info]+ SSH Enumeration Scripts
     85 > 1. **[ssh-hostkey](https://nmap.org/nsedoc/scripts/ssh-hostkey.html)**: Retrieves SSH host keys and fingerprints
     86 > 2. **[ssh-auth-methods](https://nmap.org/nsedoc/scripts/ssh-auth-methods.html)**: Lists supported authentication methods
     87 > 3. **[ssh2-enum-algos](https://nmap.org/nsedoc/scripts/ssh2-enum-algos.html)**: Enumerates encryption algorithms and ciphers
     88 > 4. **[sshv1](https://nmap.org/nsedoc/scripts/sshv1.html)**: Checks for deprecated SSHv1 support
     89 > 5. **[ssh-brute](https://nmap.org/nsedoc/scripts/ssh-brute.html)**: Credential brute forcing
     90 > 6. **[ssh-publickey-acceptance](https://nmap.org/nsedoc/scripts/ssh-publickey-acceptance.html)**: Tests public key authentication
     91 > 7. **[ssh-run](https://nmap.org/nsedoc/scripts/ssh-run.html)**: Runs commands via SSH with credentials
     92 
     93 ```bash
     94 # Safe SSH enumeration
     95 nmap -sV -p22 --script=ssh-hostkey,ssh-auth-methods,ssh2-enum-algos <target>
     96 
     97 # Check for SSHv1 (insecure)
     98 nmap -p22 --script=sshv1 <target>
     99 
    100 # SSH host key fingerprinting
    101 nmap -p22 --script=ssh-hostkey --script-args ssh_hostkey=full <target>
    102 
    103 # Enumerate supported authentication methods
    104 nmap -p22 --script=ssh-auth-methods <target>
    105 
    106 # Enumerate encryption algorithms
    107 nmap -p22 --script=ssh2-enum-algos <target>
    108 
    109 # Check public key acceptance
    110 nmap -p22 --script=ssh-publickey-acceptance <target>
    111 
    112 # SSH brute force (VERY NOISY - triggers fail2ban)
    113 nmap -p22 --script=ssh-brute --script-args userdb=users.txt,passdb=pass.txt <target>
    114 
    115 # Slow SSH brute force to avoid blocking
    116 nmap -p22 --script=ssh-brute --script-args ssh-brute.timeout=4m,brute.threads=1,brute.firstOnly=true <target>
    117 
    118 # Execute command with known credentials
    119 nmap -p22 --script=ssh-run --script-args ssh-run.cmd="uname -a",ssh-run.username=root,ssh-run.password=toor <target>
    120 
    121 # Comprehensive SSH assessment
    122 nmap -sV -p22 --script="ssh-* and not brute" <target>
    123 ```
    124 
    125 > [!info]+ Command Breakdown: SSH Enumeration
    126 > 1. **ssh-hostkey**: Extracts RSA, DSA, ECDSA, ED25519 public keys
    127 > 2. **ssh_hostkey=full**: Shows complete public key, not just fingerprint
    128 > 3. **ssh2-enum-algos**: Lists key exchange, encryption, MAC, compression algorithms
    129 > 4. **ssh-brute.timeout**: Critical - delay between attempts (fail2ban typically bans after 3-5 failures)
    130 > 5. **brute.firstOnly**: Stops after finding first valid credential (faster, less noisy)
    131 
    132 > [!success]+ Expected SSH Output
    133 > ```
    134 > PORT   STATE SERVICE VERSION
    135 > 22/tcp open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
    136 > | ssh-hostkey:
    137 > |   2048 8a:d3:22:e4:76:4e:6e:77:9f:8b:3e:3c:9f:2e:8c:3a (RSA)
    138 > |   256 31:7d:99:2f:1f:2e:8e:6e:8f:9e:2e:3f:7e:8e:2f:3e (ECDSA)
    139 > |_  256 8e:2f:3e:7e:8e:2f:3e:7e:8e:2f:3e:7e:8e:2f:3e:7e (ED25519)
    140 > | ssh-auth-methods:
    141 > |   Supported authentication methods:
    142 > |     publickey
    143 > |     password
    144 > |_    keyboard-interactive
    145 > | ssh2-enum-algos:
    146 > |   kex_algorithms: (6)
    147 > |       curve25519-sha256
    148 > |       curve25519-sha256@libssh.org
    149 > |       ecdh-sha2-nistp256
    150 > |       ecdh-sha2-nistp384
    151 > |       ecdh-sha2-nistp521
    152 > |       diffie-hellman-group-exchange-sha256
    153 > |   encryption_algorithms: (9)
    154 > |       chacha20-poly1305@openssh.com
    155 > |       aes128-ctr
    156 > |       aes192-ctr
    157 > |       aes256-ctr
    158 > |       aes128-gcm@openssh.com
    159 > |       aes256-gcm@openssh.com
    160 > ```
    161 
    162 > [!warning]+ SSH OPSEC Considerations
    163 > 6. **ssh-brute**: Extremely noisy - fail2ban typically bans after 3-5 failed attempts
    164 > 7. **Failed auth logging**: All failed attempts logged in /var/log/auth.log
    165 > 8. **Safe enumeration**: hostkey, auth-methods, algorithms are normal SSH handshake
    166 > 9. **Detection**: Multiple connections from same IP triggers automated blocking
    167 > 10. **Modern defenses**: Ubuntu/Debian commonly run fail2ban by default
    168 
    169 > [!failure]+ Common SSH Issues
    170 > 11. **IP banned after 3-5 attempts**: fail2ban or similar IPS blocking
    171 >    - Solution: Use `ssh-brute.timeout=4m` for 4-minute delays between attempts
    172 > 12. **Connection reset**: Too many rapid connections
    173 >    - Solution: Reduce threads to 1, increase timeouts
    174 > 13. **Public key scripts require proper key format**: PEM or OpenSSH format
    175 >    - Solution: Generate keys with `ssh-keygen -t rsa`
    176 
    177 > [!tip]+ SSH Security Assessment Best Practices
    178 > 14. **Check for SSHv1**: Ancient protocol with known vulnerabilities
    179 > 15. **Weak algorithms**: Look for CBC ciphers, MD5 MACs, weak KEX
    180 > 16. **Authentication methods**: Password auth less secure than publickey
    181 > 17. **Host key analysis**: Same key across multiple servers may indicate cloning
    182 > 18. **Version detection**: Older OpenSSH versions have known CVEs
    183 
    184 ---
    185 
    186 ## Port 23 - Telnet
    187 
    188 > [!info]+ [Telnet Service Overview](https://en.wikipedia.org/wiki/Telnet)
    189 > Unencrypted remote access protocol. Credentials transmitted in cleartext. Presence indicates legacy systems or IoT devices. Highly insecure and should be replaced with SSH.
    190 
    191 **Key NSE Scripts for Telnet**:
    192 
    193 > [!info]+ Telnet Enumeration Scripts
    194 > 1. **[telnet-brute](https://nmap.org/nsedoc/scripts/telnet-brute.html)**: Credential brute forcing
    195 > 2. **[telnet-encryption](https://nmap.org/nsedoc/scripts/telnet-encryption.html)**: Checks for encryption support
    196 > 3. **[telnet-ntlm-info](https://nmap.org/nsedoc/scripts/telnet-ntlm-info.html)**: Extracts Windows domain info via NTLM
    197 > 4. **[tn3270-screen](https://nmap.org/nsedoc/scripts/tn3270-screen.html)**: Captures mainframe TN3270 screens
    198 
    199 ```bash
    200 # Basic Telnet enumeration
    201 nmap -sV -p23 --script=telnet-encryption <target>
    202 
    203 # Telnet NTLM information disclosure
    204 nmap -p23 --script=telnet-ntlm-info <target>
    205 
    206 # TN3270 mainframe enumeration
    207 nmap -p23 --script=tn3270-screen <target>
    208 
    209 # Telnet brute force (cleartext credentials)
    210 nmap -p23 --script=telnet-brute --script-args userdb=users.txt,passdb=pass.txt <target>
    211 
    212 # IoT device default credential testing
    213 nmap -p23,2323 --script=telnet-brute --script-args userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt,passdb=/usr/share/seclists/Passwords/Default-Credentials/telnet-betterdefaultpasslist.txt <target>
    214 
    215 # Comprehensive Telnet assessment
    216 nmap -sV -p23 --script="telnet-*" <target>
    217 ```
    218 
    219 > [!info]+ Command Breakdown: Telnet Enumeration
    220 > 1. **telnet-encryption**: Tests if Telnet supports encryption extensions (rare)
    221 > 2. **telnet-ntlm-info**: Forces NTLM authentication to leak domain/workgroup names
    222 > 3. **tn3270-screen**: Captures IBM mainframe login screens
    223 > 4. **telnet-brute**: Tests credentials over cleartext connection
    224 > 5. *Telnet on IoT devices often on non-standard ports like 2323, 8023*
    225 
    226 > [!success]+ Expected Telnet Output
    227 > ```
    228 > PORT   STATE SERVICE VERSION
    229 > 23/tcp open  telnet  Linux telnetd
    230 > | telnet-encryption:
    231 > |_  Telnet server does not support encryption
    232 > | telnet-ntlm-info:
    233 > |   Target_Name: WORKGROUP
    234 > |   NetBIOS_Domain_Name: WORKGROUP
    235 > |   NetBIOS_Computer_Name: SERVER01
    236 > |   DNS_Domain_Name: localdomain
    237 > |   DNS_Computer_Name: server01.localdomain
    238 > |_  Product_Version: 5.0.2195
    239 > ```
    240 
    241 > [!danger]+ Telnet Security Warnings
    242 > 6. **Cleartext transmission**: All data including credentials sent unencrypted
    243 > 7. **Network sniffing**: Wireshark/tcpdump can capture passwords
    244 > 8. **No security**: Telnet provides no authentication security or confidentiality
    245 > 9. **Replace with SSH**: Telnet should never be used on production systems
    246 > 10. **IoT prevalence**: Routers, cameras, printers commonly have Telnet enabled
    247 
    248 > [!warning]+ Telnet OPSEC Considerations
    249 > 11. **Brute force highly visible**: Cleartext passwords logged on network
    250 > 12. **Network monitoring**: Easily detected by IDS/packet analysis
    251 > 13. **Authentication failures**: Logged in system logs
    252 > 14. **Safe enumeration**: telnet-encryption, telnet-ntlm-info low risk
    253 
    254 ---
    255 
    256 ## Port 25/465/587 - SMTP (Simple Mail Transfer Protocol)
    257 
    258 > [!info]+ [SMTP Service Overview](https://en.wikipedia.org/wiki/Simple_Mail_Transfer_Protocol)
    259 > Email transmission protocol. Port 25 for unencrypted SMTP, 465 for SMTPS (deprecated), 587 for submission with STARTTLS. User enumeration via VRFY/EXPN commands, open relay testing, and vulnerability assessment.
    260 
    261 **Key NSE Scripts for SMTP**:
    262 
    263 > [!info]+ SMTP Enumeration Scripts
    264 > 1. **[smtp-commands](https://nmap.org/nsedoc/scripts/smtp-commands.html)**: Lists supported SMTP commands
    265 > 2. **[smtp-enum-users](https://nmap.org/nsedoc/scripts/smtp-enum-users.html)**: Enumerates users via VRFY/EXPN/RCPT
    266 > 3. **[smtp-open-relay](https://nmap.org/nsedoc/scripts/smtp-open-relay.html)**: Tests for open relay misconfiguration
    267 > 4. **[smtp-brute](https://nmap.org/nsedoc/scripts/smtp-brute.html)**: Credential brute forcing
    268 > 5. **[smtp-vuln-cve2010-4344](https://nmap.org/nsedoc/scripts/smtp-vuln-cve2010-4344.html)**: Exim heap overflow
    269 > 6. **[smtp-vuln-cve2011-1720](https://nmap.org/nsedoc/scripts/smtp-vuln-cve2011-1720.html)**: Postfix STARTTLS plaintext injection
    270 > 7. **[smtp-vuln-cve2011-1764](https://nmap.org/nsedoc/scripts/smtp-vuln-cve2011-1764.html)**: Exim DKIM denial of service
    271 > 8. **[smtp-ntlm-info](https://nmap.org/nsedoc/scripts/smtp-ntlm-info.html)**: Extracts Windows domain info via NTLM
    272 > 9. **[smtp-strangeport](https://nmap.org/nsedoc/scripts/smtp-strangeport.html)**: Detects SMTP on unusual ports (malware indicator)
    273 
    274 ```bash
    275 # Safe SMTP enumeration
    276 nmap -sV -p25,465,587 --script=smtp-commands,smtp-ntlm-info <target>
    277 
    278 # Test for open relay
    279 nmap -p25 --script=smtp-open-relay <target>
    280 
    281 # User enumeration via VRFY and EXPN
    282 nmap -p25 --script=smtp-enum-users --script-args smtp-enum-users.methods={VRFY,EXPN} <target>
    283 
    284 # User enumeration with custom wordlist
    285 nmap -p25 --script=smtp-enum-users --script-args userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt,smtp-enum-users.methods={VRFY,EXPN,RCPT} <target>
    286 
    287 # SMTP NTLM information disclosure
    288 nmap -p25,587 --script=smtp-ntlm-info <target>
    289 
    290 # SMTP vulnerability assessment
    291 nmap -p25 --script=smtp-vuln-* <target>
    292 
    293 # SMTP brute force authentication
    294 nmap -p25,587 --script=smtp-brute --script-args userdb=users.txt,passdb=pass.txt <target>
    295 
    296 # Comprehensive SMTP assessment
    297 nmap -sV -p25,465,587 --script="smtp-* and not brute" <target>
    298 
    299 # Test multiple SMTP ports including submissions
    300 nmap -sV -p25,465,587,2525 --script=smtp-commands,smtp-open-relay <target>
    301 ```
    302 
    303 > [!info]+ Command Breakdown: SMTP Enumeration
    304 > 1. **smtp-enum-users.methods**: Specifies enumeration technique (VRFY, EXPN, RCPT TO)
    305 > 2. **smtp-open-relay**: Attempts to send email through server to external domain
    306 > 3. **smtp-ntlm-info**: Forces NTLM auth to disclose domain/computer names
    307 > 4. **smtp-commands**: Issues EHLO/HELO to enumerate extended commands
    308 > 5. **VRFY**: Verifies if user exists (often disabled)
    309 > 6. **EXPN**: Expands mailing list (rarely enabled)
    310 > 7. **RCPT TO**: Tests email acceptance (slower but works when VRFY/EXPN blocked)
    311 
    312 > [!success]+ Expected SMTP Output
    313 > ```
    314 > PORT   STATE SERVICE VERSION
    315 > 25/tcp open  smtp    Postfix smtpd
    316 > | smtp-commands: mail.example.com, PIPELINING, SIZE 10240000, VRFY, ETRN, STARTTLS, ENHANCEDSTATUSCODES, 8BITMIME, DSN
    317 > |_ This server supports the following commands: HELO EHLO STARTTLS RCPT DATA RSET MAIL QUIT HELP AUTH NOOP
    318 > | smtp-enum-users:
    319 > |   Accounts found:
    320 > |     admin - Valid user
    321 > |     user1 - Valid user
    322 > |     webmaster - Valid user
    323 > |   Statistics: Performed 50 guesses in 12 seconds
    324 > | smtp-ntlm-info:
    325 > |   Target_Name: MAIL
    326 > |   NetBIOS_Domain_Name: CONTOSO
    327 > |   NetBIOS_Computer_Name: MAIL01
    328 > |   DNS_Domain_Name: contoso.local
    329 > |   DNS_Computer_Name: mail01.contoso.local
    330 > |_  Product_Version: 6.1.7601
    331 > | smtp-open-relay: Server is an open relay (16/16 tests)
    332 > |  MAIL FROM:<antispam@insecure.org> -> RCPT TO:<relaytest@insecure.org>
    333 > |  MAIL FROM:<antispam@insecure.org> -> RCPT TO:<relaytest%insecure.org@example.com>
    334 > ```
    335 
    336 > [!warning]+ SMTP OPSEC Considerations
    337 > 8. **User enumeration**: VRFY/EXPN attempts logged in mail server logs
    338 > 9. **Open relay testing**: May generate email to external addresses (logged)
    339 > 10. **Modern mail servers**: VRFY/EXPN commonly disabled on Exchange, Postfix
    340 > 11. **RCPT TO enumeration**: Slower but more reliable, generates more logs
    341 > 12. **smtp-brute**: Extremely noisy, triggers fail2ban and rate limiting
    342 
    343 > [!failure]+ Common SMTP Issues
    344 > 13. **VRFY/EXPN disabled**: Modern security practice blocks these commands
    345 >    - Solution: Use RCPT TO method with `smtp-enum-users.methods={RCPT}`
    346 > 14. **Connection rate limiting**: Multiple connections blocked
    347 >    - Solution: Reduce threads and add delays
    348 > 15. **TLS required**: Port 25 may require STARTTLS before allowing commands
    349 >    - Solution: Use port 587 for modern submission protocol
    350 > 16. **False positives on user enum**: Some servers return "User unknown" for all users
    351 >    - Solution: Verify results manually with test account
    352 
    353 > [!tip]+ SMTP Security Assessment Best Practices
    354 > 17. **Open relay**: Critical misconfiguration allowing spam relay
    355 > 18. **User enumeration**: Reveals valid email addresses for phishing
    356 > 19. **NTLM info disclosure**: Leaks internal domain names
    357 > 20. **Version detection**: Outdated Postfix/Exim/Sendmail may be vulnerable
    358 > 21. **Strange ports**: SMTP on non-standard ports may indicate malware
    359 
    360 ---
    361 
    362 ## Port 53 - DNS (Domain Name System)
    363 
    364 > [!info]+ [DNS Service Overview](https://www.cloudflare.com/learning/dns/what-is-dns/)
    365 > Domain Name System translates domain names to IP addresses. Critical infrastructure service. Zone transfers, subdomain enumeration, recursion testing, and cache snooping reveal network topology and misconfigurations.
    366 
    367 **Key NSE Scripts for DNS**:
    368 
    369 > [!info]+ DNS Enumeration Scripts
    370 > 1. **[dns-zone-transfer](https://nmap.org/nsedoc/scripts/dns-zone-transfer.html)**: Attempts AXFR zone transfer
    371 > 2. **[dns-brute](https://nmap.org/nsedoc/scripts/dns-brute.html)**: Subdomain brute forcing
    372 > 3. **[dns-recursion](https://nmap.org/nsedoc/scripts/dns-recursion.html)**: Tests for open DNS resolver
    373 > 4. **[dns-service-discovery](https://nmap.org/nsedoc/scripts/dns-service-discovery.html)**: Discovers services via DNS-SD/mDNS
    374 > 5. **[dns-nsid](https://nmap.org/nsedoc/scripts/dns-nsid.html)**: Retrieves DNS server identity
    375 > 6. **[dns-cache-snoop](https://nmap.org/nsedoc/scripts/dns-cache-snoop.html)**: Checks DNS cache for specific domains
    376 > 7. **[dns-nsec-enum](https://nmap.org/nsedoc/scripts/dns-nsec-enum.html)**: Enumerates DNSSEC NSEC records
    377 > 8. **[dns-nsec3-enum](https://nmap.org/nsedoc/scripts/dns-nsec3-enum.html)**: Enumerates DNSSEC NSEC3 records
    378 > 9. **[dns-random-srcport](https://nmap.org/nsedoc/scripts/dns-random-srcport.html)**: Checks for source port randomization
    379 > 10. **[dns-random-txid](https://nmap.org/nsedoc/scripts/dns-random-txid.html)**: Checks for transaction ID randomization
    380 
    381 ```bash
    382 # Attempt DNS zone transfer
    383 nmap -p53 --script=dns-zone-transfer --script-args dns-zone-transfer.domain=example.com <target>
    384 
    385 # Subdomain brute force
    386 nmap --script=dns-brute --script-args dns-brute.domain=example.com <target>
    387 
    388 # Subdomain brute with custom wordlist
    389 nmap --script=dns-brute --script-args dns-brute.domain=example.com,dns-brute.hostlist=/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt <target>
    390 
    391 # Subdomain brute with thread control
    392 nmap --script=dns-brute --script-args dns-brute.domain=example.com,dns-brute.threads=10 --script-timeout=30m <target>
    393 
    394 # Check for open DNS resolver
    395 nmap -sU -p53 --script=dns-recursion <target>
    396 
    397 # DNS service discovery (multicast DNS)
    398 nmap -p53 --script=dns-service-discovery <target>
    399 
    400 # DNS server identification
    401 nmap -p53 --script=dns-nsid <target>
    402 
    403 # DNS cache snooping
    404 nmap -sU -p53 --script=dns-cache-snoop --script-args 'dns-cache-snoop.mode=timed,dns-cache-snoop.domains={google.com,facebook.com,example.com}' <target>
    405 
    406 # DNSSEC NSEC enumeration
    407 nmap -p53 --script=dns-nsec-enum --script-args dns-nsec-enum.domains=example.com <target>
    408 
    409 # Check DNS security (randomization)
    410 nmap -sU -p53 --script=dns-random-srcport,dns-random-txid <target>
    411 
    412 # Comprehensive DNS assessment (both UDP and TCP)
    413 nmap -sU -sS -p53 --script="dns-* and not brute" <target>
    414 
    415 # Internal DNS server enumeration
    416 nmap -sU -p53 --script=dns-recursion,dns-nsid --script-args dns-nsid.identifier=version.bind <target>
    417 ```
    418 
    419 > [!info]+ Command Breakdown: DNS Enumeration
    420 > 1. **dns-zone-transfer.domain**: Target domain for AXFR request
    421 > 2. **dns-brute.threads**: Parallelization (default 5, increase for speed, decrease for stealth)
    422 > 3. **dns-brute.hostlist**: Custom subdomain wordlist path
    423 > 4. **dns-cache-snoop.mode=timed**: Uses timing to detect cached vs uncached queries
    424 > 5. **DNS requires both UDP and TCP**: Use `-sU -sS` for comprehensive scanning
    425 > 6. **dns-nsid.identifier**: Custom NSID query (version.bind reveals BIND version)
    426 
    427 > [!success]+ Expected DNS Output
    428 > ```
    429 > PORT   STATE SERVICE
    430 > 53/udp open  domain
    431 > | dns-zone-transfer:
    432 > |   example.com.      SOA     ns1.example.com. admin.example.com.
    433 > |   example.com.      NS      ns1.example.com.
    434 > |   example.com.      NS      ns2.example.com.
    435 > |   example.com.      A       192.0.2.1
    436 > |   www.example.com.  A       192.0.2.2
    437 > |   mail.example.com. A       192.0.2.3
    438 > |   ftp.example.com.  A       192.0.2.4
    439 > |   dev.example.com.  A       192.0.2.10
    440 > |   admin.example.com. A      192.0.2.11
    441 > |_  vpn.example.com.  A       192.0.2.20
    442 > | dns-brute:
    443 > |   DNS Brute-force hostnames:
    444 > |     www.example.com - 192.0.2.2
    445 > |     mail.example.com - 192.0.2.3
    446 > |     ftp.example.com - 192.0.2.4
    447 > |     dev.example.com - 192.0.2.10
    448 > |     admin.example.com - 192.0.2.11
    449 > |     vpn.example.com - 192.0.2.20
    450 > |     staging.example.com - 192.0.2.30
    451 > |_    test.example.com - 192.0.2.40
    452 > | dns-recursion: Recursion appears to be enabled
    453 > ```
    454 
    455 > [!warning]+ DNS OPSEC Considerations
    456 > 1. **Zone transfer attempts**: Always logged by DNS servers, often triggers security alerts
    457 > 2. **dns-brute visibility**: Generates hundreds to thousands of queries, extremely obvious
    458 > 3. **Query logging**: All DNS servers log queries (standard operational practice)
    459 > 4. **Rate limiting**: Excessive queries trigger rate limiting or blocking
    460 > 5. **Sequential patterns**: Brute force creates distinctive sequential query patterns
    461 
    462 > [!failure]+ Common DNS Issues
    463 > 6. **Zone transfer denied**: Expected result on properly configured servers
    464 >    - Solution: Modern DNS security best practice restricts AXFR to authorized secondaries
    465 > 7. **dns-brute timeout**: Large wordlists timeout on default 5-minute script timeout
    466 >    - Solution: Increase with `--script-timeout=30m`, reduce threads
    467 > 8. **UDP packet loss**: DNS over UDP may drop packets on congested networks
    468 >    - Solution: Reduce threads, try TCP zone transfer
    469 > 9. **No response**: Firewall blocking UDP 53 or DNS server not recursive
    470 >    - Solution: Verify port accessibility with basic UDP scan
    471 
    472 > [!tip]+ DNS Security Assessment Best Practices
    473 > 10. **Zone transfer**: Exposes complete DNS zone (all subdomains, internal IPs)
    474 > 11. **Open resolver**: Allows DNS amplification DDoS attacks
    475 > 12. **Cache snooping**: Privacy violation, reveals browsing history
    476 > 13. **Subdomain discovery**: Reveals dev/staging/admin environments
    477 > 14. **DNSSEC validation**: Modern security feature, enumerate with NSEC/NSEC3
    478 
    479 > [!example]+ DNS Wordlists for Subdomain Enumeration
    480 > 15. `/usr/share/seclists/Discovery/DNS/subdomains-top1million-5000.txt` - Top 5000 common subdomains
    481 > 16. `/usr/share/seclists/Discovery/DNS/subdomains-top1million-20000.txt` - Top 20000 subdomains
    482 > 17. `/usr/share/seclists/Discovery/DNS/fierce-hostlist.txt` - Fierce DNS scanner default wordlist
    483 > 18. `/usr/share/seclists/Discovery/DNS/bitquark-subdomains-top100000.txt` - Comprehensive 100k list
    484 > 19. `/usr/share/seclists/Discovery/DNS/dns-Jhaddix.txt` - Jason Haddix's all-sources wordlist
    485 
    486 ---
    487 
    488 ## Port 80/443/8080/8443 - HTTP/HTTPS (Web Services)
    489 
    490 > [!info]+ [HTTP/HTTPS Service Overview](https://developer.mozilla.org/en-US/docs/Web/HTTP)
    491 > Hypertext Transfer Protocol and its encrypted variant HTTPS. Most common internet protocol. Web application enumeration, vulnerability detection, SSL/TLS analysis. Ports 8080/8443 commonly used for alternative web services, proxies, or application servers.
    492 
    493 **Key NSE Scripts for HTTP/HTTPS**:
    494 
    495 > [!info]+ HTTP/HTTPS Enumeration Scripts
    496 > **Information Gathering**:
    497 > 1. **[http-enum](https://nmap.org/nsedoc/scripts/http-enum.html)**: Directory and file enumeration
    498 > 2. **[http-headers](https://nmap.org/nsedoc/scripts/http-headers.html)**: HTTP response headers
    499 > 3. **[http-methods](https://nmap.org/nsedoc/scripts/http-methods.html)**: Supported HTTP methods
    500 > 4. **[http-title](https://nmap.org/nsedoc/scripts/http-title.html)**: HTML page title extraction
    501 > 5. **[http-robots.txt](https://nmap.org/nsedoc/scripts/http-robots.txt.html)**: Robots.txt retrieval
    502 > 6. **[http-sitemap-generator](https://nmap.org/nsedoc/scripts/http-sitemap-generator.html)**: Crawls and generates sitemap
    503 > 7. **[http-server-header](https://nmap.org/nsedoc/scripts/http-server-header.html)**: Server header extraction
    504 > 8. **[http-generator](https://nmap.org/nsedoc/scripts/http-generator.html)**: Detects CMS/framework from meta generator tag
    505 > 
    506 > **Authentication Testing**:
    507 > 1. **[http-auth](https://nmap.org/nsedoc/scripts/http-auth.html)**: Authentication scheme enumeration
    508 > 2. **[http-brute](https://nmap.org/nsedoc/scripts/http-brute.html)**: HTTP Basic/Digest brute force
    509 > 3. **[http-default-accounts](https://nmap.org/nsedoc/scripts/http-default-accounts.html)**: Default credential testing
    510 > 4. **[http-form-brute](https://nmap.org/nsedoc/scripts/http-form-brute.html)**: HTML form brute force
    511 > 5. **[http-wordpress-brute](https://nmap.org/nsedoc/scripts/http-wordpress-brute.html)**: WordPress credential brute force
    512 > 
    513 > **Vulnerability Detection**:
    514 > 6. **[http-shellshock](https://nmap.org/nsedoc/scripts/http-shellshock.html)**: CVE-2014-6271 Bash vulnerability
    515 > 7. **[http-sql-injection](https://nmap.org/nsedoc/scripts/http-sql-injection.html)**: SQL injection detection
    516 > 8. **[http-stored-xss](https://nmap.org/nsedoc/scripts/http-stored-xss.html)**: Stored XSS detection
    517 > 9. **[http-csrf](https://nmap.org/nsedoc/scripts/http-csrf.html)**: CSRF vulnerability detection
    518 > 10. **[http-phpself-xss](https://nmap.org/nsedoc/scripts/http-phpself-xss.html)**: PHP_SELF XSS
    519 > 11. **[http-vuln-cve2017-5638](https://nmap.org/nsedoc/scripts/http-vuln-cve2017-5638.html)**: Apache Struts2 RCE
    520 > 12. **[http-vuln-cve2015-1635](https://nmap.org/nsedoc/scripts/http-vuln-cve2015-1635.html)**: IIS RCE
    521 > 13. **[http-vuln-cve2013-7091](https://nmap.org/nsedoc/scripts/http-vuln-cve2013-7091.html)**: Zimbra LFI
    522 > 14. **[http-vuln-cve2014-3704](https://nmap.org/nsedoc/scripts/http-vuln-cve2014-3704.html)**: Drupal SQL injection
    523 > 15. **[http-vuln-cve2017-1001000](https://nmap.org/nsedoc/scripts/http-vuln-cve2017-1001000.html)**: WordPress 4.7.0/4.7.1 privilege escalation
    524 > 
    525 > **Configuration Analysis**:
    526 > 16. **[http-security-headers](https://nmap.org/nsedoc/scripts/http-security-headers.html)**: Security header analysis
    527 > 17. **[http-config-backup](https://nmap.org/nsedoc/scripts/http-config-backup.html)**: Backup file detection
    528 > 18. **[http-apache-server-status](https://nmap.org/nsedoc/scripts/http-apache-server-status.html)**: Apache status page access
    529 > 19. **[http-apache-negotiation](https://nmap.org/nsedoc/scripts/http-apache-negotiation.html)**: Apache content negotiation
    530 > 20. **[http-git](https://nmap.org/nsedoc/scripts/http-git.html)**: Exposed .git directory detection
    531 > 21. **[http-svn-enum](https://nmap.org/nsedoc/scripts/http-svn-enum.html)**: SVN repository enumeration
    532 > 22. **[http-backup-finder](https://nmap.org/nsedoc/scripts/http-backup-finder.html)**: Backup file discovery
    533 > 
    534 > **CMS/Application Specific**:
    535 > 23. **[http-wordpress-enum](https://nmap.org/nsedoc/scripts/http-wordpress-enum.html)**: WordPress enumeration
    536 > 24. **[http-wordpress-users](https://nmap.org/nsedoc/scripts/http-wordpress-users.html)**: WordPress user enumeration
    537 > 25. **[http-joomla-brute](https://nmap.org/nsedoc/scripts/http-joomla-brute.html)**: Joomla brute force
    538 > 26. **[http-drupal-enum](https://nmap.org/nsedoc/scripts/http-drupal-enum.html)**: Drupal enumeration
    539 > 27. **[http-frontpage-login](https://nmap.org/nsedoc/scripts/http-frontpage-login.html)**: FrontPage admin interface
    540 > 
    541 > **Cloud/SSRF**:
    542 > 28. **[http-aws-metadata](https://nmap.org/nsedoc/scripts/http-aws-metadata.html)**: AWS metadata SSRF
    543 > 29. **[http-azure-metadata](https://nmap.org/nsedoc/scripts/http-azure-metadata.html)**: Azure metadata SSRF
    544 
    545 > [!info]+ SSL/TLS Specific Scripts (Port 443/8443)
    546 > 30. **[ssl-cert](https://nmap.org/nsedoc/scripts/ssl-cert.html)**: SSL certificate details
    547 > 31. **[ssl-enum-ciphers](https://nmap.org/nsedoc/scripts/ssl-enum-ciphers.html)**: Cipher suite enumeration and grading
    548 > 32. **[ssl-heartbleed](https://nmap.org/nsedoc/scripts/ssl-heartbleed.html)**: CVE-2014-0160 Heartbleed
    549 > 33. **[ssl-poodle](https://nmap.org/nsedoc/scripts/ssl-poodle.html)**: CVE-2014-3566 POODLE
    550 > 34. **[ssl-ccs-injection](https://nmap.org/nsedoc/scripts/ssl-ccs-injection.html)**: CVE-2014-0224 CCS injection
    551 > 35. **[ssl-dh-params](https://nmap.org/nsedoc/scripts/ssl-dh-params.html)**: Diffie-Hellman parameter analysis
    552 > 36. **[ssl-known-key](https://nmap.org/nsedoc/scripts/ssl-known-key.html)**: Compromised key detection
    553 > 37. **[ssl-date](https://nmap.org/nsedoc/scripts/ssl-date.html)**: System time from TLS handshake
    554 
    555 ```bash
    556 # Safe HTTP enumeration
    557 nmap -sV -p80,443,8080,8443 --script=http-title,http-headers,http-methods,http-robots.txt,http-server-header <target>
    558 
    559 # Directory and file enumeration (noisy)
    560 nmap -p80,443 --script=http-enum <target>
    561 
    562 # HTTP enumeration with virtual host
    563 nmap -p80 --script=http-enum --script-args http.host=example.com <target>
    564 
    565 # Security headers analysis
    566 nmap -p443 --script=http-security-headers <target>
    567 
    568 # HTTP methods testing (PUT, DELETE, TRACE)
    569 nmap -p80 --script=http-methods --script-args http-methods.url-path=/upload <target>
    570 
    571 # Shellshock vulnerability
    572 nmap -p80 --script=http-shellshock --script-args uri=/cgi-bin/status,cmd=ls <target>
    573 
    574 # SQL injection detection
    575 nmap -p80 --script=http-sql-injection --script-args http-sql-injection.maxdepth=3 <target>
    576 
    577 # XSS vulnerability detection
    578 nmap -p80 --script=http-stored-xss,http-phpself-xss <target>
    579 
    580 # Web application vulnerability scan
    581 nmap -p80,443 --script=http-vuln-* <target>
    582 
    583 # Default credential testing
    584 nmap -p80 --script=http-default-accounts <target>
    585 
    586 # HTTP Basic/Digest brute force
    587 nmap -p80 --script=http-brute --script-args http-brute.path=/admin/ <target>
    588 
    589 # WordPress enumeration
    590 nmap -p80,443 --script=http-wordpress-enum --script-args search-limit=100 <target>
    591 
    592 # WordPress user enumeration
    593 nmap -p80 --script=http-wordpress-users <target>
    594 
    595 # Exposed Git repository
    596 nmap -p80,443 --script=http-git <target>
    597 
    598 # Backup file discovery
    599 nmap -p80 --script=http-backup-finder,http-config-backup <target>
    600 
    601 # Apache server-status page
    602 nmap -p80 --script=http-apache-server-status <target>
    603 
    604 # AWS metadata SSRF
    605 nmap -p80 --script=http-aws-metadata --script-args http-aws-metadata.uri=/redirect?url= <target>
    606 
    607 # SSL/TLS certificate extraction
    608 nmap -p443,8443 --script=ssl-cert <target>
    609 
    610 # SSL/TLS cipher enumeration and grading
    611 nmap -p443 --script=ssl-enum-ciphers <target>
    612 
    613 # SSL/TLS vulnerability assessment
    614 nmap -p443 --script=ssl-heartbleed,ssl-poodle,ssl-ccs-injection,ssl-dh-params <target>
    615 
    616 # Comprehensive HTTP enumeration (safe)
    617 nmap -sV -p80,443,8080,8443 --script="http-* and safe" <target>
    618 
    619 # Comprehensive HTTPS assessment
    620 nmap -sV -p443,8443 --script="(http-* or ssl-*) and not brute" <target>
    621 
    622 # Web application security audit
    623 nmap -sV -p80,443 --script="http-enum,http-vuln-*,http-config-backup,http-git,http-security-headers" <target>
    624 
    625 # Custom user agent
    626 nmap -p80 --script=http-enum --script-args http.useragent="Mozilla/5.0 (Windows NT 10.0; Win64; x64)" <target>
    627 
    628 # HTTP proxy through specific port
    629 nmap -p8080 --script=http-open-proxy <target>
    630 ```
    631 
    632 > [!info]+ Command Breakdown: HTTP/HTTPS Enumeration
    633 > 1. **http.host**: Virtual host specification for shared hosting environments
    634 > 2. **http.useragent**: Custom User-Agent header (WAF evasion, mobile testing)
    635 > 3. **http-methods.url-path**: Specific path to test methods (upload directories)
    636 > 4. **http-sql-injection.maxdepth**: How many links deep to crawl
    637 > 5. **http-brute.path**: Authentication endpoint path
    638 > 6. **http-aws-metadata.uri**: SSRF-vulnerable parameter or endpoint
    639 > 7. **tls.servername**: SNI for HTTPS virtual hosting
    640 
    641 > [!success]+ Expected HTTP/HTTPS Output
    642 > ```
    643 > PORT    STATE SERVICE  VERSION
    644 > 80/tcp  open  http     Apache httpd 2.4.29 ((Ubuntu))
    645 > |_http-title: Welcome to Example.com
    646 > | http-headers:
    647 > |   Date: Sat, 25 Jan 2026 14:30:00 GMT
    648 > |   Server: Apache/2.4.29 (Ubuntu)
    649 > |   X-Powered-By: PHP/7.2.24
    650 > |   Content-Type: text/html; charset=UTF-8
    651 > |_  Connection: Keep-Alive
    652 > | http-methods:
    653 > |   Supported Methods: GET HEAD POST OPTIONS
    654 > |_  Potentially risky methods: PUT DELETE TRACE
    655 > | http-enum:
    656 > |   /admin/: Admin login page
    657 > |   /backup/: Backup directory
    658 > |   /config.php.bak: Configuration backup file
    659 > |   /test.php: Test file
    660 > |   /.git/: Git repository
    661 > |_  /phpmyadmin/: phpMyAdmin
    662 > | http-robots.txt: 5 disallowed entries
    663 > |_/admin/ /backup/ /private/ /test/ /uploads/
    664 > 
    665 > 443/tcp open  ssl/http Apache httpd 2.4.29
    666 > | ssl-cert: Subject: commonName=*.example.com/organizationName=Example Inc
    667 > | Subject Alternative Name: DNS:*.example.com, DNS:example.com
    668 > | Not valid before: 2025-01-01T00:00:00
    669 > |_Not valid after:  2026-01-01T00:00:00
    670 > | ssl-enum-ciphers:
    671 > |   TLSv1.2:
    672 > |     ciphers:
    673 > |       TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (secp256r1) - A
    674 > |       TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (secp256r1) - A
    675 > |     compressors:
    676 > |       NULL
    677 > |     cipher preference: server
    678 > |   least strength: A
    679 > | http-security-headers:
    680 > |   Strict-Transport-Security: max-age=31536000; includeSubDomains
    681 > |   X-Frame-Options: DENY
    682 > |   X-Content-Type-Options: nosniff
    683 > |_  Missing headers: Content-Security-Policy, X-XSS-Protection
    684 > | http-shellshock:
    685 > |   VULNERABLE:
    686 > |   HTTP Shellshock vulnerability
    687 > |     State: VULNERABLE (Exploitable)
    688 > |     IDs:  CVE:CVE-2014-6271
    689 > |     Check results:
    690 > |       Vulnerable CGI script: /cgi-bin/status
    691 > ```
    692 
    693 > [!warning]+ HTTP/HTTPS OPSEC Considerations
    694 > 8. **http-enum**: Generates hundreds of 404 errors, extremely visible in access logs
    695 > 9. **Vulnerability scripts**: Trigger WAF/IDS signatures for attack patterns
    696 > 10. **http-brute**: Massively noisy, causes authentication failures, may lock accounts
    697 > 11. **http-sql-injection**: Injects SQL syntax, triggers WAF blocks
    698 > 12. **Safe scripts**: headers, methods, title, robots.txt appear as normal browsing
    699 > 13. **Modern WAFs**: Cloudflare, AWS WAF, Imperva block most vulnerability scripts
    700 
    701 > [!failure]+ Common HTTP/HTTPS Issues
    702 > 14. **WAF blocking**: HTTP 403/429 responses or connection resets
    703 >    - Solution: Reduce timing (`-T2`), customize user agent, add delays
    704 > 15. **Virtual hosting**: Wrong Host header returns default site
    705 >    - Solution: Use `--script-args http.host=example.com`
    706 > 16. **SSL/TLS errors**: HTTPS scripts fail without proper handshake
    707 >    - Solution: Use `-sV` or `--script-args http.ssl=true` for non-standard ports
    708 > 17. **Timeouts**: Slow applications or WAF delays timeout scripts
    709 >    - Solution: Increase `--script-timeout=120s`
    710 > 18. **Authentication required**: Scripts return empty results on protected resources
    711 >    - Solution: Provide credentials with http.username/http.password arguments
    712 > 19. **http-enum false positives**: WAF may fake directory responses
    713 >    - Solution: Manually verify findings with browser or curl
    714 
    715 > [!tip]+ HTTP/HTTPS Security Assessment Best Practices
    716 > 20. **Security headers**: Missing HSTS, CSP, X-Frame-Options indicate weaknesses
    717 > 21. **Dangerous methods**: PUT, DELETE, TRACE should be disabled
    718 > 22. **Directory listing**: Exposed directories reveal sensitive files
    719 > 23. **Backup files**: .bak, .old, .backup files contain credentials/configs
    720 > 24. **Version disclosure**: Server/X-Powered-By headers aid vulnerability research
    721 > 25. **SSL/TLS grading**: Grade B or below indicates weak cryptography
    722 > 26. **WordPress/CMS**: Outdated versions have known RCE vulnerabilities
    723 > 27. **Git exposure**: /.git/ directory allows source code download
    724 
    725 > [!example]+ HTTP Script Arguments Reference
    726 > 28. **http.host=<hostname>**: Virtual host specification
    727 > 29. **http.useragent=<string>**: Custom User-Agent header
    728 > 30. **http.max-pipeline=<num>**: HTTP pipelining depth
    729 > 31. **http-brute.path=<path>**: Authentication endpoint
    730 > 32. **http-brute.method=POST**: HTTP method for auth
    731 > 33. **http-enum.displayall=true**: Show all tested paths
    732 > 34. **http-sql-injection.maxdepth=<num>**: Crawl depth
    733 > 35. **uri=<path>**: Script-specific URI path
    734 > 36. **tls.servername=<name>**: SNI for virtual HTTPS hosts
    735 
    736 ---
    737 
    738 ## Port 88 - Kerberos
    739 
    740 > [!info]+ [Kerberos Service Overview](https://web.mit.edu/kerberos/)
    741 > Authentication protocol used by Active Directory and Unix systems. Port 88 TCP/UDP for Kerberos authentication. User enumeration reveals valid domain accounts without authentication.
    742 
    743 **Key NSE Scripts for Kerberos**:
    744 
    745 > [!info]+ Kerberos Enumeration Scripts
    746 > 1. **[krb5-enum-users](https://nmap.org/nsedoc/scripts/krb5-enum-users.html)**: User account enumeration via Kerberos pre-authentication
    747 
    748 ```bash
    749 # Kerberos user enumeration
    750 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=DOMAIN.COM <dc-ip>
    751 
    752 # User enumeration with custom wordlist
    753 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=CONTOSO.LOCAL,userdb=/usr/share/seclists/Usernames/xato-net-10-million-usernames.txt <dc-ip>
    754 
    755 # Enumerate common service accounts
    756 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=DOMAIN.COM,userdb=/usr/share/seclists/Usernames/cirt-default-usernames.txt <dc-ip>
    757 
    758 # Fast user enumeration (limited wordlist)
    759 nmap -p88 --script=krb5-enum-users --script-args krb5-enum-users.realm=DOMAIN.COM,userdb=/usr/share/seclists/Usernames/top-usernames-shortlist.txt <dc-ip>
    760 ```
    761 
    762 > [!info]+ Command Breakdown: Kerberos Enumeration
    763 > 1. **krb5-enum-users.realm**: Active Directory domain name (FQDN)
    764 > 2. **userdb**: Username wordlist path
    765 > 3. *Script distinguishes valid from invalid users via Kerberos error codes*
    766 > 4. *KRB5KDC_ERR_PREAUTH_REQUIRED = valid user*
    767 > 5. *KRB5KDC_ERR_C_PRINCIPAL_UNKNOWN = invalid user*
    768 
    769 > [!success]+ Expected Kerberos Output
    770 > ```
    771 > PORT   STATE SERVICE
    772 > 88/tcp open  kerberos-sec
    773 > | krb5-enum-users:
    774 > |   Discovered Kerberos principals:
    775 > |     administrator@CONTOSO.LOCAL
    776 > |     Administrator@CONTOSO.LOCAL
    777 > |     guest@CONTOSO.LOCAL
    778 > |     krbtgt@CONTOSO.LOCAL
    779 > |     sqlservice@CONTOSO.LOCAL
    780 > |     webadmin@CONTOSO.LOCAL
    781 > |_  Statistics: Performed 500 guesses in 34 seconds
    782 > ```
    783 
    784 > [!warning]+ Kerberos OPSEC Considerations
    785 > 6. **Windows Event Logs**: Pre-auth failures logged (Event ID 4768, 4771)
    786 > 7. **Detection**: Modern monitoring tools detect user enumeration patterns
    787 > 8. **SIEM alerts**: Multiple pre-auth failures from single IP trigger alerts
    788 > 9. **Account lockout**: Enumeration doesn't trigger lockout (pre-auth only)
    789 > 10. **Noise level**: Moderate - generates authentication attempts but not full logins
    790 
    791 > [!tip]+ Kerberos Security Assessment Notes
    792 > 11. **User enumeration**: Reveals valid domain accounts for password spraying
    793 > 12. **Service accounts**: Accounts ending in "service", "admin", "sql" are high-value
    794 > 13. **Disabled accounts**: Script doesn't distinguish disabled from enabled accounts
    795 > 14. **Case sensitivity**: Windows usernames case-insensitive, test lowercase variants
    796 > 15. **Follow-up**: Valid users enable targeted password spraying attacks
    797 
    798 ---
    799 
    800 ## Port 110/995 - POP3/POP3S (Post Office Protocol)
    801 
    802 > [!info]+ [POP3 Service Overview](https://en.wikipedia.org/wiki/Post_Office_Protocol)
    803 > Email retrieval protocol. Port 110 for unencrypted POP3, 995 for POP3S (SSL/TLS). Commonly used for email client access to mailboxes.
    804 
    805 **Key NSE Scripts for POP3**:
    806 
    807 > [!info]+ POP3 Enumeration Scripts
    808 > 1. **[pop3-capabilities](https://nmap.org/nsedoc/scripts/pop3-capabilities.html)**: Lists POP3 capabilities
    809 > 2. **[pop3-brute](https://nmap.org/nsedoc/scripts/pop3-brute.html)**: Credential brute forcing
    810 > 3. **[pop3-ntlm-info](https://nmap.org/nsedoc/scripts/pop3-ntlm-info.html)**: Domain disclosure via NTLM
    811 
    812 ```bash
    813 # POP3 capability enumeration
    814 nmap -sV -p110,995 --script=pop3-capabilities <target>
    815 
    816 # POP3 NTLM information disclosure
    817 nmap -p110,995 --script=pop3-ntlm-info <target>
    818 
    819 # POP3 brute force (noisy)
    820 nmap -p110 --script=pop3-brute --script-args userdb=users.txt,passdb=pass.txt <target>
    821 
    822 # Comprehensive POP3 assessment
    823 nmap -sV -p110,995 --script="pop3-* and not brute" <target>
    824 ```
    825 
    826 > [!success]+ Expected POP3 Output
    827 > ```
    828 > PORT    STATE SERVICE VERSION
    829 > 110/tcp open  pop3    Dovecot pop3d
    830 > | pop3-capabilities: RESP-CODES CAPA SASL PLAIN LOGIN UIDL TOP PIPELINING
    831 > |_  Capabilities: TOP UIDL RESP-CODES CAPA SASL(PLAIN LOGIN) PIPELINING
    832 > | pop3-ntlm-info:
    833 > |   Target_Name: MAIL
    834 > |   NetBIOS_Domain_Name: CONTOSO
    835 > |   NetBIOS_Computer_Name: MAIL01
    836 > |   DNS_Domain_Name: contoso.local
    837 > |   DNS_Computer_Name: mail01.contoso.local
    838 > ```
    839 
    840 > [!warning]+ POP3 OPSEC Considerations
    841 > 1. **pop3-brute**: Extremely noisy, triggers fail2ban and account lockouts
    842 > 2. **Capability queries**: Safe, normal POP3 client behavior
    843 > 3. **NTLM info disclosure**: Reveals internal domain names without authentication
    844 
    845 ---
    846 
    847 ## Port 111 - RPCBind
    848 
    849 > [!info]+ [RPCBind Service Overview](https://en.wikipedia.org/wiki/Portmap)
    850 > Remote Procedure Call port mapper. Maps RPC program numbers to network ports. Common on Unix/Linux systems. Reveals running RPC services including NFS, NIS, and other distributed services.
    851 
    852 **Key NSE Scripts for RPCBind**:
    853 
    854 > [!info]+ RPCBind Enumeration Scripts
    855 > 1. **[rpcinfo](https://nmap.org/nsedoc/scripts/rpcinfo.html)**: Lists registered RPC services
    856 > 2. **[nfs-showmount](https://nmap.org/nsedoc/scripts/nfs-showmount.html)**: Lists NFS exports (if NFS available)
    857 > 3. **[nfs-ls](https://nmap.org/nsedoc/scripts/nfs-ls.html)**: Lists NFS directory contents
    858 > 4. **[nfs-statfs](https://nmap.org/nsedoc/scripts/nfs-statfs.html)**: NFS filesystem statistics
    859 
    860 ```bash
    861 # RPC service enumeration
    862 nmap -sV -p111 --script=rpcinfo <target>
    863 
    864 # NFS export enumeration
    865 nmap -p111 --script=nfs-showmount <target>
    866 
    867 # List NFS directory contents
    868 nmap -p111 --script=nfs-ls --script-args nfs-ls.export=/share <target>
    869 
    870 # NFS filesystem statistics
    871 nmap -p111 --script=nfs-statfs <target>
    872 
    873 # Comprehensive RPC/NFS assessment
    874 nmap -sV -p111,2049 --script="rpc*,nfs*" <target>
    875 ```
    876 
    877 > [!success]+ Expected RPCBind Output
    878 > ```
    879 > PORT    STATE SERVICE VERSION
    880 > 111/tcp open  rpcbind 2-4 (RPC #100000)
    881 > | rpcinfo:
    882 > |   program version    port/proto  service
    883 > |   100000  2,3,4        111/tcp   rpcbind
    884 > |   100000  2,3,4        111/udp   rpcbind
    885 > |   100003  2,3,4       2049/tcp   nfs
    886 > |   100003  2,3,4       2049/udp   nfs
    887 > |   100005  1,2,3      20048/tcp   mountd
    888 > |_  100005  1,2,3      20048/udp   mountd
    889 > | nfs-showmount:
    890 > |   /home 192.168.1.0/24
    891 > |   /var/nfs *
    892 > |_  /backups (everyone)
    893 > ```
    894 
    895 > [!tip]+ RPCBind Security Assessment Notes
    896 > 1. **rpcinfo**: Reveals all RPC services and ports
    897 > 2. **NFS exports**: Shows shared filesystems and access controls
    898 > 3. **Wildcard exports**: `*` or `(everyone)` indicates world-readable shares
    899 > 4. **Sensitive paths**: /home, /root, /etc, /backup exports critical
    900 
    901 ---
    902 
    903 ## Port 135/593 - Microsoft RPC (MSRPC)
    904 
    905 > [!info]+ [Microsoft RPC Overview](https://docs.microsoft.com/en-us/windows/win32/rpc/rpc-start-page)
    906 > Microsoft Remote Procedure Call endpoint mapper. Port 135 for RPC endpoint mapper, 593 for RPC over HTTP. Critical Windows service for DCOM, WMI, and distributed services.
    907 
    908 **Key NSE Scripts for MSRPC**:
    909 
    910 > [!info]+ MSRPC Enumeration Scripts
    911 > 1. **[msrpc-enum](https://nmap.org/nsedoc/scripts/msrpc-enum.html)**: Enumerates MSRPC endpoints
    912 > 2. **[smb-os-discovery](https://nmap.org/nsedoc/scripts/smb-os-discovery.html)**: OS discovery via RPC (works on 135)
    913 > 3. **[smb-enum-domains](https://nmap.org/nsedoc/scripts/smb-enum-domains.html)**: Domain enumeration
    914 
    915 ```bash
    916 # MSRPC endpoint enumeration
    917 nmap -sV -p135,593 --script=msrpc-enum <target>
    918 
    919 # OS discovery via RPC
    920 nmap -p135 --script=smb-os-discovery <target>
    921 
    922 # Comprehensive MSRPC assessment
    923 nmap -sV -p135,139,445,593 --script="msrpc-enum,smb-os-discovery" <target>
    924 ```
    925 
    926 > [!success]+ Expected MSRPC Output
    927 > ```
    928 > PORT    STATE SERVICE VERSION
    929 > 135/tcp open  msrpc   Microsoft Windows RPC
    930 > | msrpc-enum:
    931 > |   Endpoints:
    932 > |     uuid: 12345778-1234-abcd-ef00-0123456789ab ncacn_ip_tcp:192.168.1.10[49152]
    933 > |     uuid: 12345778-1234-abcd-ef00-0123456789ac ncacn_ip_tcp:192.168.1.10[49153]
    934 > |_    uuid: 12345778-1234-abcd-ef00-0123456789ad ncacn_ip_tcp:192.168.1.10[49154]
    935 > ```
    936 
    937 > [!tip]+ MSRPC Security Assessment Notes
    938 > 1. **Endpoint mapper**: Reveals dynamic RPC ports
    939 > 2. **High ports**: MSRPC services commonly on ports 49152-65535
    940 > 3. **Authentication**: Most MSRPC services require Windows credentials
    941 > 4. **WMI**: Uses MSRPC on port 135 for remote management
    942 
    943 ---
    944 
    945 ## Port 139/445 - SMB/NetBIOS (Covered in detail earlier, key reference)
    946 
    947 > [!info]+ SMB/NetBIOS Quick Reference
    948 > See **SMB/Windows Service Scripts Deep Dive** section above for comprehensive coverage. Port 139 for NetBIOS session service (legacy), 445 for SMB over TCP (modern).
    949 
    950 **Essential SMB Commands**:
    951 ```bash
    952 # Quick SMB enumeration
    953 nmap -p139,445 --script=smb-os-discovery,smb-security-mode,smb-enum-shares <target>
    954 
    955 # EternalBlue check
    956 nmap -p445 --script=smb-vuln-ms17-010 <target>
    957 
    958 # Comprehensive SMB assessment
    959 nmap -sV -p139,445 --script="smb-* and not brute" <target>
    960 ```
    961 
    962 ---
    963 
    964 ## Port 143/993 - IMAP/IMAPS (Internet Message Access Protocol)
    965 
    966 > [!info]+ [IMAP Service Overview](https://en.wikipedia.org/wiki/Internet_Message_Access_Protocol)
    967 > Email retrieval protocol with advanced features (folders, server-side search). Port 143 for unencrypted IMAP, 993 for IMAPS (SSL/TLS). More feature-rich than POP3.
    968 
    969 **Key NSE Scripts for IMAP**:
    970 
    971 > [!info]+ IMAP Enumeration Scripts
    972 > 1. **[imap-capabilities](https://nmap.org/nsedoc/scripts/imap-capabilities.html)**: Lists IMAP capabilities
    973 > 2. **[imap-brute](https://nmap.org/nsedoc/scripts/imap-brute.html)**: Credential brute forcing
    974 > 3. **[imap-ntlm-info](https://nmap.org/nsedoc/scripts/imap-ntlm-info.html)**: Domain disclosure via NTLM
    975 
    976 ```bash
    977 # IMAP capability enumeration
    978 nmap -sV -p143,993 --script=imap-capabilities <target>
    979 
    980 # IMAP NTLM information disclosure
    981 nmap -p143,993 --script=imap-ntlm-info <target>
    982 
    983 # IMAP brute force (noisy)
    984 nmap -p143 --script=imap-brute --script-args userdb=users.txt,passdb=pass.txt <target>
    985 
    986 # Comprehensive IMAP assessment
    987 nmap -sV -p143,993 --script="imap-* and not brute" <target>
    988 ```
    989 
    990 > [!success]+ Expected IMAP Output
    991 > ```
    992 > PORT    STATE SERVICE VERSION
    993 > 143/tcp open  imap    Dovecot imapd
    994 > | imap-capabilities: IMAP4rev1 SASL-IR LOGIN-REFERRALS ID ENABLE LITERAL+ STARTTLS AUTH=PLAIN AUTH=LOGIN
    995 > |_  Capabilities: IMAP4rev1 LITERAL+ SASL-IR LOGIN-REFERRALS ID ENABLE STARTTLS AUTH=PLAIN AUTH=LOGIN
    996 > | imap-ntlm-info:
    997 > |   Target_Name: MAIL
    998 > |   NetBIOS_Domain_Name: CONTOSO
    999 > |   NetBIOS_Computer_Name: MAIL01
   1000 > |   DNS_Domain_Name: contoso.local
   1001 > |   DNS_Computer_Name: mail01.contoso.local
   1002 > ```
   1003 
   1004 > [!warning]+ IMAP OPSEC Considerations
   1005 > 1. **imap-brute**: Extremely noisy, triggers fail2ban and account lockouts
   1006 > 2. **Capability queries**: Safe, normal IMAP client behavior
   1007 > 3. **NTLM info disclosure**: Reveals internal domain names without authentication
   1008 
   1009 ---
   1010 
   1011 ## Port 161/162 - SNMP (Simple Network Management Protocol)
   1012 
   1013 > [!info]+ SNMP Quick Reference
   1014 > See **SNMP Service Scripts Deep Dive** section above for comprehensive coverage. Port 161 for queries (UDP), 162 for traps (UDP).
   1015 
   1016 **Essential SNMP Commands**:
   1017 ```bash
   1018 # Quick SNMP enumeration
   1019 nmap -sU -p161 --script=snmp-info,snmp-interfaces <target>
   1020 
   1021 # SNMP community string brute force
   1022 nmap -sU -p161 --script=snmp-brute <target>
   1023 
   1024 # Comprehensive SNMP assessment
   1025 nmap -sU -p161 --script="snmp-* and not brute" <target>
   1026 ```
   1027 
   1028 ---
   1029 
   1030 ## Port 389/636/3268/3269 - LDAP/LDAPS/Global Catalog
   1031 
   1032 > [!info]+ [LDAP Service Overview](https://ldap.com/)
   1033 > Lightweight Directory Access Protocol for directory services. Port 389 for LDAP, 636 for LDAPS (SSL/TLS), 3268 for Global Catalog (AD), 3269 for Global Catalog SSL. Active Directory primary protocol.
   1034 
   1035 **Key NSE Scripts for LDAP**:
   1036 
   1037 > [!info]+ LDAP Enumeration Scripts
   1038 > 1. **[ldap-rootdse](https://nmap.org/nsedoc/scripts/ldap-rootdse.html)**: Anonymous directory enumeration
   1039 > 2. **[ldap-search](https://nmap.org/nsedoc/scripts/ldap-search.html)**: LDAP object search (requires auth)
   1040 > 3. **[ldap-brute](https://nmap.org/nsedoc/scripts/ldap-brute.html)**: Credential brute forcing
   1041 
   1042 ```bash
   1043 # Anonymous LDAP enumeration (rootDSE)
   1044 nmap -p389,636 --script=ldap-rootdse <target>
   1045 
   1046 # LDAP search with credentials
   1047 nmap -p389 --script=ldap-search --script-args ldap.username="CN=user,DC=domain,DC=com",ldap.password=password <target>
   1048 
   1049 # LDAP brute force (noisy)
   1050 nmap -p389 --script=ldap-brute --script-args userdb=users.txt,passdb=pass.txt <target>
   1051 
   1052 # Global Catalog enumeration
   1053 nmap -p3268,3269 --script=ldap-rootdse <target>
   1054 
   1055 # Comprehensive LDAP assessment
   1056 nmap -sV -p389,636,3268,3269 --script="ldap-* and not brute" <target>
   1057 ```
   1058 
   1059 > [!success]+ Expected LDAP Output
   1060 > ```
   1061 > PORT    STATE SERVICE VERSION
   1062 > 389/tcp open  ldap    Microsoft Windows Active Directory LDAP (Domain: contoso.local, Site: Default-First-Site-Name)
   1063 > | ldap-rootdse:
   1064 > |   LDAP Results
   1065 > |     domainFunctionality: 7
   1066 > |     forestFunctionality: 7
   1067 > |     domainControllerFunctionality: 7
   1068 > |     rootDomainNamingContext: DC=contoso,DC=local
   1069 > |     ldapServiceName: contoso.local:dc01$@CONTOSO.LOCAL
   1070 > |     isGlobalCatalogReady: TRUE
   1071 > |     supportedSASLMechanisms: GSSAPI, GSS-SPNEGO, EXTERNAL, DIGEST-MD5
   1072 > |     dnsHostName: dc01.contoso.local
   1073 > |     defaultNamingContext: DC=contoso,DC=local
   1074 > |     serverName: CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=contoso,DC=local
   1075 > ```
   1076 
   1077 > [!tip]+ LDAP Security Assessment Notes
   1078 > 1. **ldap-rootdse**: Reveals domain structure, forest functional level, DC names
   1079 > 2. **Anonymous binding**: Some LDAP servers allow anonymous rootDSE queries
   1080 > 3. **Functional level**: Indicates Windows Server version (7 = Server 2016+)
   1081 > 4. **Global Catalog**: Ports 3268/3269 indicate domain controller
   1082 > 5. **LDAP signing**: Modern AD enforces LDAP signing and channel binding
   1083 
   1084 ---
   1085 
   1086 ## Port 443 - HTTPS (Covered in Port 80/443 section, SSL/TLS focus)
   1087 
   1088 > [!info]+ HTTPS Quick Reference
   1089 > See **Port 80/443/8080/8443 - HTTP/HTTPS** section above for comprehensive coverage.
   1090 
   1091 **Essential HTTPS Commands**:
   1092 ```bash
   1093 # SSL/TLS assessment
   1094 nmap -p443 --script=ssl-cert,ssl-enum-ciphers,ssl-heartbleed,ssl-poodle <target>
   1095 
   1096 # Comprehensive HTTPS security audit
   1097 nmap -sV -p443 --script="(http-* or ssl-*) and not brute" <target>
   1098 ```
   1099 
   1100 ---
   1101 
   1102 ## Port 514 - Syslog
   1103 
   1104 > [!info]+ [Syslog Service Overview](https://en.wikipedia.org/wiki/Syslog)
   1105 > System logging protocol. Port 514 UDP for syslog. Centralized logging service commonly used by network devices and Unix/Linux systems.
   1106 
   1107 **Key NSE Scripts for Syslog**:
   1108 
   1109 > [!info]+ Syslog Enumeration Scripts
   1110 > 1. **[syslog-detect](https://nmap.org/nsedoc/scripts/syslog-detect.html)**: Detects syslog service
   1111 
   1112 ```bash
   1113 # Syslog detection
   1114 nmap -sU -p514 --script=syslog-detect <target>
   1115 
   1116 # Test syslog message injection
   1117 nmap -sU -p514 --script=syslog-detect --script-args syslog-detect.facility=user,syslog-detect.severity=info <target>
   1118 ```
   1119 
   1120 > [!warning]+ Syslog Security Notes
   1121 > 1. **Open syslog**: Allows log injection attacks
   1122 > 2. **Information disclosure**: May reveal system details in error messages
   1123 > 3. **DoS potential**: Log flooding can fill disk space
   1124 
   1125 ---
   1126 
   1127 ## Port 873 - Rsync
   1128 
   1129 > [!info]+ [Rsync Service Overview](https://rsync.samba.org/)
   1130 > File synchronization and transfer protocol. Port 873 for rsync daemon. Commonly used for backups and mirroring.
   1131 
   1132 **Key NSE Scripts for Rsync**:
   1133 
   1134 > [!info]+ Rsync Enumeration Scripts
   1135 > 1. **[rsync-list-modules](https://nmap.org/nsedoc/scripts/rsync-list-modules.html)**: Lists available rsync modules
   1136 > 2. **[rsync-brute](https://nmap.org/nsedoc/scripts/rsync-brute.html)**: Credential brute forcing
   1137 
   1138 ```bash
   1139 # List rsync modules
   1140 nmap -p873 --script=rsync-list-modules <target>
   1141 
   1142 # Rsync brute force
   1143 nmap -p873 --script=rsync-brute --script-args userdb=users.txt,passdb=pass.txt <target>
   1144 
   1145 # Comprehensive rsync assessment
   1146 nmap -sV -p873 --script="rsync-*" <target>
   1147 ```
   1148 
   1149 > [!success]+ Expected Rsync Output
   1150 > ```
   1151 > PORT    STATE SERVICE VERSION
   1152 > 873/tcp open  rsync   (protocol version 31)
   1153 > | rsync-list-modules:
   1154 > |   backup      Backup files
   1155 > |   data        Data directory
   1156 > |   home        Home directories
   1157 > |_  www         Web root
   1158 > ```
   1159 
   1160 > [!tip]+ Rsync Security Assessment Notes
   1161 > 1. **Anonymous access**: Some rsync modules allow unauthenticated access
   1162 > 2. **Sensitive paths**: backup, home, www modules may contain sensitive data
   1163 > 3. **Write access**: Writable modules allow file upload/modification
   1164 
   1165 ---
   1166 
   1167 ## Port 1433/1434 - Microsoft SQL Server (MSSQL)
   1168 
   1169 > [!info]+ MSSQL Quick Reference
   1170 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. Port 1433 for SQL Server, 1434 UDP for SQL Server Browser.
   1171 
   1172 **Essential MSSQL Commands**:
   1173 ```bash
   1174 # Quick MSSQL enumeration
   1175 nmap -p1433 --script=ms-sql-info,ms-sql-ntlm-info <target>
   1176 
   1177 # MSSQL brute force
   1178 nmap -p1433 --script=ms-sql-brute <target>
   1179 
   1180 # Comprehensive MSSQL assessment
   1181 nmap -sV -p1433 --script="ms-sql-* and not brute" <target>
   1182 ```
   1183 
   1184 ---
   1185 
   1186 ## Port 1521 - Oracle Database
   1187 
   1188 > [!info]+ Oracle Database Quick Reference
   1189 > See **Database Service Scripts Deep Dive** section for comprehensive coverage.
   1190 
   1191 **Essential Oracle Commands**:
   1192 ```bash
   1193 # Oracle SID brute force
   1194 nmap -p1521 --script=oracle-sid-brute <target>
   1195 
   1196 # Oracle credential brute force
   1197 nmap -p1521 --script=oracle-brute --script-args sid=ORCL <target>
   1198 ```
   1199 
   1200 ---
   1201 
   1202 ## Port 2049 - NFS (Network File System)
   1203 
   1204 > [!info]+ [NFS Service Overview](https://en.wikipedia.org/wiki/Network_File_System)
   1205 > Network File System for Unix/Linux file sharing. Port 2049 for NFSv3/v4. Requires RPCBind (port 111) for NFSv3.
   1206 
   1207 **Key NSE Scripts for NFS**:
   1208 
   1209 > [!info]+ NFS Enumeration Scripts
   1210 > 1. **[nfs-showmount](https://nmap.org/nsedoc/scripts/nfs-showmount.html)**: Lists NFS exports
   1211 > 2. **[nfs-ls](https://nmap.org/nsedoc/scripts/nfs-ls.html)**: Lists directory contents
   1212 > 3. **[nfs-statfs](https://nmap.org/nsedoc/scripts/nfs-statfs.html)**: Filesystem statistics
   1213 
   1214 ```bash
   1215 # List NFS exports
   1216 nmap -p111,2049 --script=nfs-showmount <target>
   1217 
   1218 # List directory contents
   1219 nmap -p2049 --script=nfs-ls --script-args nfs.export=/share <target>
   1220 
   1221 # NFS filesystem statistics
   1222 nmap -p2049 --script=nfs-statfs <target>
   1223 
   1224 # Comprehensive NFS assessment
   1225 nmap -sV -p111,2049 --script="nfs-*" <target>
   1226 ```
   1227 
   1228 > [!success]+ Expected NFS Output
   1229 > ```
   1230 > PORT     STATE SERVICE VERSION
   1231 > 2049/tcp open  nfs     3-4 (RPC #100003)
   1232 > | nfs-showmount:
   1233 > |   /home 192.168.1.0/24
   1234 > |   /var/nfs *
   1235 > |_  /backups (everyone)
   1236 > | nfs-ls: Volume /home
   1237 > |   access: Read Lookup NoModify NoExtend NoDelete NoExecute
   1238 > |   PERMISSION  UID  GID  SIZE  TIME                 FILENAME
   1239 > |   drwxr-xr-x  1000 1000 4096  2026-01-20T10:30:00  user1
   1240 > |   drwxr-xr-x  1001 1001 4096  2026-01-21T14:15:00  user2
   1241 > |_  drwxr-xr-x  1002 1002 4096  2026-01-22T09:45:00  admin
   1242 > ```
   1243 
   1244 > [!warning]+ NFS Security Considerations
   1245 > 1. **Wildcard exports**: `*` or `(everyone)` allows world access
   1246 > 2. **Sensitive paths**: /home, /root, /etc exports reveal user data
   1247 > 3. **no_root_squash**: Allows client root to be server root (critical)
   1248 > 4. **NFSv3 vs NFSv4**: NFSv4 has better security (Kerberos support)
   1249 
   1250 ---
   1251 
   1252 ## Port 3306 - MySQL/MariaDB
   1253 
   1254 > [!info]+ MySQL Quick Reference
   1255 > See **Database Service Scripts Deep Dive** section for comprehensive coverage.
   1256 
   1257 **Essential MySQL Commands**:
   1258 ```bash
   1259 # Quick MySQL enumeration
   1260 nmap -p3306 --script=mysql-info,mysql-empty-password <target>
   1261 
   1262 # MySQL brute force
   1263 nmap -p3306 --script=mysql-brute <target>
   1264 
   1265 # Comprehensive MySQL assessment
   1266 nmap -sV -p3306 --script="mysql-* and not brute" <target>
   1267 ```
   1268 
   1269 ---
   1270 
   1271 ## Port 3389 - RDP (Remote Desktop Protocol)
   1272 
   1273 > [!info]+ [RDP Service Overview](https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/clients/remote-desktop-clients)
   1274 > Remote Desktop Protocol for Windows graphical remote access. Port 3389 TCP. Critical service for Windows administration.
   1275 
   1276 **Key NSE Scripts for RDP**:
   1277 
   1278 > [!info]+ RDP Enumeration Scripts
   1279 > 1. **[rdp-enum-encryption](https://nmap.org/nsedoc/scripts/rdp-enum-encryption.html)**: Enumerates encryption methods
   1280 > 2. **[rdp-ntlm-info](https://nmap.org/nsedoc/scripts/rdp-ntlm-info.html)**: Domain disclosure via NTLM
   1281 > 3. **[rdp-vuln-ms12-020](https://nmap.org/nsedoc/scripts/rdp-vuln-ms12-020.html)**: MS12-020 vulnerability
   1282 
   1283 ```bash
   1284 # RDP encryption enumeration
   1285 nmap -p3389 --script=rdp-enum-encryption <target>
   1286 
   1287 # RDP NTLM information disclosure
   1288 nmap -p3389 --script=rdp-ntlm-info <target>
   1289 
   1290 # RDP vulnerability assessment
   1291 nmap -p3389 --script=rdp-vuln-ms12-020 <target>
   1292 
   1293 # Comprehensive RDP assessment
   1294 nmap -sV -p3389 --script="rdp-*" <target>
   1295 ```
   1296 
   1297 > [!success]+ Expected RDP Output
   1298 > ```
   1299 > PORT     STATE SERVICE VERSION
   1300 > 3389/tcp open  ms-wbt-server Microsoft Terminal Services
   1301 > | rdp-enum-encryption:
   1302 > |   Security layer
   1303 > |     CredSSP (NLA): SUCCESS
   1304 > |     CredSSP with Early User Auth: SUCCESS
   1305 > |     Native RDP: SUCCESS
   1306 > |     SSL: SUCCESS
   1307 > |   RDP Encryption level: High
   1308 > |     128-bit RC4: SUCCESS
   1309 > |_  FIPS 140-1: SUCCESS
   1310 > | rdp-ntlm-info:
   1311 > |   Target_Name: WORKSTATION
   1312 > |   NetBIOS_Domain_Name: CONTOSO
   1313 > |   NetBIOS_Computer_Name: WS01
   1314 > |   DNS_Domain_Name: contoso.local
   1315 > |   DNS_Computer_Name: ws01.contoso.local
   1316 > |   Product_Version: 10.0.17763
   1317 > ```
   1318 
   1319 > [!tip]+ RDP Security Assessment Notes
   1320 > 1. **NLA (Network Level Authentication)**: Modern security requiring auth before session
   1321 > 2. **Encryption level**: High/FIPS better than Low/Medium
   1322 > 3. **rdp-ntlm-info**: Reveals domain and computer names without authentication
   1323 > 4. **MS12-020**: Denial of service vulnerability (Server 2008 and earlier)
   1324 > 5. **BlueKeep (CVE-2019-0708)**: RCE vulnerability (pre-patch Server 2008/Windows 7)
   1325 
   1326 ---
   1327 
   1328 ## Port 5432 - PostgreSQL
   1329 
   1330 > [!info]+ PostgreSQL Quick Reference
   1331 > See **Database Service Scripts Deep Dive** section for comprehensive coverage.
   1332 
   1333 **Essential PostgreSQL Commands**:
   1334 ```bash
   1335 # PostgreSQL brute force
   1336 nmap -p5432 --script=pgsql-brute <target>
   1337 
   1338 # PostgreSQL with credentials
   1339 nmap -p5432 --script=pgsql-brute --script-args userdb=users.txt,passdb=pass.txt <target>
   1340 ```
   1341 
   1342 ---
   1343 
   1344 ## Port 5900-5909 - VNC (Virtual Network Computing)
   1345 
   1346 > [!info]+ [VNC Service Overview](https://en.wikipedia.org/wiki/Virtual_Network_Computing)
   1347 > Virtual Network Computing for graphical remote access. Ports 5900-5909 (display :0-:9). Cross-platform remote desktop protocol.
   1348 
   1349 **Key NSE Scripts for VNC**:
   1350 
   1351 > [!info]+ VNC Enumeration Scripts
   1352 > 1. **[vnc-info](https://nmap.org/nsedoc/scripts/vnc-info.html)**: VNC server information
   1353 > 2. **[vnc-brute](https://nmap.org/nsedoc/scripts/vnc-brute.html)**: Password brute forcing
   1354 > 3. **[realvnc-auth-bypass](https://nmap.org/nsedoc/scripts/realvnc-auth-bypass.html)**: RealVNC authentication bypass
   1355 
   1356 ```bash
   1357 # VNC server information
   1358 nmap -sV -p5900 --script=vnc-info <target>
   1359 
   1360 # VNC authentication bypass check
   1361 nmap -p5900 --script=realvnc-auth-bypass <target>
   1362 
   1363 # VNC password brute force
   1364 nmap -p5900 --script=vnc-brute <target>
   1365 
   1366 # Scan VNC display range
   1367 nmap -p5900-5909 --script=vnc-info <target>
   1368 
   1369 # Comprehensive VNC assessment
   1370 nmap -sV -p5900-5909 --script="vnc-* and not brute" <target>
   1371 ```
   1372 
   1373 > [!success]+ Expected VNC Output
   1374 > ```
   1375 > PORT     STATE SERVICE VERSION
   1376 > 5900/tcp open  vnc     RealVNC 4.1.2 (protocol 3.8)
   1377 > | vnc-info:
   1378 > |   Protocol version: 3.8
   1379 > |   Security types:
   1380 > |     VNC Authentication (2)
   1381 > |_    Tight (16)
   1382 > ```
   1383 
   1384 > [!warning]+ VNC Security Considerations
   1385 > 1. **No encryption**: VNC transmits data unencrypted (use SSH tunnel)
   1386 > 2. **Password-only auth**: VNC typically uses single password, no usernames
   1387 > 3. **realvnc-auth-bypass**: Critical vulnerability in RealVNC 4.1.0/4.1.1
   1388 > 4. **vnc-brute throttling**: VNC servers often throttle connection attempts
   1389 > 5. **Default passwords**: Many VNC installations use weak or default passwords
   1390 
   1391 ---
   1392 
   1393 ## Port 6379 - Redis
   1394 
   1395 > [!info]+ Redis Quick Reference
   1396 > See **Database Service Scripts Deep Dive** section for comprehensive coverage.
   1397 
   1398 **Essential Redis Commands**:
   1399 ```bash
   1400 # Redis information gathering
   1401 nmap -p6379 --script=redis-info <target>
   1402 
   1403 # Redis brute force
   1404 nmap -p6379 --script=redis-brute <target>
   1405 ```
   1406 
   1407 ---
   1408 
   1409 ## Port 8080/8443 - Alternative HTTP/HTTPS
   1410 
   1411 > [!info]+ Alternative HTTP Ports Quick Reference
   1412 > See **Port 80/443/8080/8443 - HTTP/HTTPS** section for comprehensive coverage. Commonly used for web application servers, proxies, management interfaces.
   1413 
   1414 **Essential Commands**:
   1415 ```bash
   1416 # Quick web enumeration on alternative ports
   1417 nmap -sV -p8080,8443 --script=http-title,http-headers,http-methods <target>
   1418 
   1419 # Comprehensive assessment
   1420 nmap -sV -p8080,8443 --script="(http-* or ssl-*) and safe" <target>
   1421 ```
   1422 
   1423 ---
   1424 
   1425 ## Port 9200/9300 - Elasticsearch
   1426 
   1427 > [!info]+ Elasticsearch Quick Reference
   1428 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. Port 9200 for HTTP API, 9300 for node communication.
   1429 
   1430 **Essential Elasticsearch Commands**:
   1431 ```bash
   1432 # Elasticsearch cluster information
   1433 nmap -p9200 --script=elasticsearch-info <target>
   1434 
   1435 # Elasticsearch via HTTP enumeration
   1436 nmap -p9200 --script=http-title,http-headers <target>
   1437 ```
   1438 
   1439 ---
   1440 
   1441 ## Port 27017/27018 - MongoDB
   1442 
   1443 > [!info]+ MongoDB Quick Reference
   1444 > See **Database Service Scripts Deep Dive** section for comprehensive coverage. Port 27017 for MongoDB, 27018 for shard server.
   1445 
   1446 **Essential MongoDB Commands**:
   1447 ```bash
   1448 # MongoDB information gathering
   1449 nmap -p27017 --script=mongodb-info,mongodb-databases <target>
   1450 
   1451 # MongoDB brute force
   1452 nmap -p27017 --script=mongodb-brute <target>
   1453 ```
   1454 
   1455 ---
   1456 
   1457 ## Port Range Summary Table
   1458 
   1459 | Port(s) | Service | Safe Scripts | Vuln Scripts | Brute Scripts | OPSEC Risk |
   1460 |:---|:---|:---|:---|:---|:---|
   1461 | 20-21 | FTP | ftp-anon, ftp-syst | ftp-vuln-*, ftp-vsftpd-backdoor | ftp-brute | Medium |
   1462 | 22 | SSH | ssh-hostkey, ssh-auth-methods, ssh2-enum-algos | sshv1 | ssh-brute | Very High |
   1463 | 23 | Telnet | telnet-encryption, telnet-ntlm-info | - | telnet-brute | High |
   1464 | 25/587 | SMTP | smtp-commands, smtp-ntlm-info | smtp-vuln-* | smtp-brute, smtp-enum-users | High |
   1465 | 53 | DNS | dns-recursion, dns-nsid | - | dns-brute, dns-zone-transfer | Very High |
   1466 | 80/443 | HTTP/S | http-title, http-headers, ssl-cert | http-vuln-*, ssl-* | http-brute | Medium-High |
   1467 | 88 | Kerberos | - | - | krb5-enum-users | Medium |
   1468 | 110/995 | POP3 | pop3-capabilities, pop3-ntlm-info | - | pop3-brute | High |
   1469 | 111 | RPCBind | rpcinfo, nfs-showmount | - | - | Low |
   1470 | 135 | MSRPC | msrpc-enum | - | - | Low |
   1471 | 139/445 | SMB | smb-os-discovery, smb-security-mode | smb-vuln-* | smb-brute | Medium |
   1472 | 143/993 | IMAP | imap-capabilities, imap-ntlm-info | - | imap-brute | High |
   1473 | 161 | SNMP | snmp-info, snmp-interfaces | - | snmp-brute | Medium |
   1474 | 389/636 | LDAP | ldap-rootdse | - | ldap-brute | Medium |
   1475 | 514 | Syslog | syslog-detect | - | - | Low |
   1476 | 873 | Rsync | rsync-list-modules | - | rsync-brute | Medium |
   1477 | 1433 | MSSQL | ms-sql-info, ms-sql-ntlm-info | ms-sql-vuln-* | ms-sql-brute | Medium |
   1478 | 1521 | Oracle | - | - | oracle-sid-brute, oracle-brute | High |
   1479 | 2049 | NFS | nfs-showmount, nfs-ls | - | - | Low |
   1480 | 3306 | MySQL | mysql-info, mysql-empty-password | - | mysql-brute | High |
   1481 | 3389 | RDP | rdp-enum-encryption, rdp-ntlm-info | rdp-vuln-ms12-020 | - | Low |
   1482 | 5432 | PostgreSQL | - | - | pgsql-brute | High |
   1483 | 5900 | VNC | vnc-info | realvnc-auth-bypass | vnc-brute | Medium |
   1484 | 6379 | Redis | redis-info | - | redis-brute | Medium |
   1485 | 8080/8443 | Alt HTTP/S | http-title, http-headers | http-vuln-*, ssl-* | http-brute | Medium-High |
   1486 | 9200 | Elasticsearch | elasticsearch-info | - | - | Low |
   1487 | 27017 | MongoDB | mongodb-info, mongodb-databases | - | mongodb-brute | Medium |
   1488 
   1489 ---
   1490 
   1491 ## Multi-Port Scanning Strategies
   1492 
   1493 > [!tip]+ Efficient Multi-Service Enumeration
   1494 > Scan multiple related services simultaneously to build comprehensive target profile.
   1495 
   1496 ```bash
   1497 # Full TCP common port scan with default scripts
   1498 nmap -sC -sV -p- <target> -oA full_tcp_scan
   1499 
   1500 # Top 1000 ports with safe enumeration
   1501 nmap -sV --script="safe and not intrusive" --top-ports 1000 <target> -oA top1000_safe
   1502 
   1503 # All database ports
   1504 nmap -sV --script="(mysql-* or ms-sql-* or oracle-* or mongodb-* or redis-* or pgsql-*) and not brute" -p1433,1521,3306,5432,6379,9200,27017 <target> -oA databases
   1505 
   1506 # All Windows/AD ports
   1507 nmap -sV --script="(smb-* or ldap-* or msrpc-* or rdp-* or krb5-*) and not brute" -p88,135,139,389,445,636,3268,3269,3389 <target> -oA windows_ad
   1508 
   1509 # All mail ports
   1510 nmap -sV --script="(smtp-* or pop3-* or imap-*) and not brute" -p25,110,143,465,587,993,995 <target> -oA mail_services
   1511 
   1512 # All web ports
   1513 nmap -sV --script="(http-* or ssl-*) and safe" -p80,443,8080,8081,8443,8888,9090 <target> -oA web_services
   1514 
   1515 # Complete service enumeration (safe only, no brute)
   1516 nmap -sS -sU -sV --script="safe and not brute" -p T:21-23,25,53,80,88,110,111,135,139,143,389,443,445,636,1433,1521,2049,3306,3389,5432,5900,6379,8080,8443,9200,27017,U:53,161,514 <target> -oA complete_safe_enum
   1517 ```
   1518 
   1519 ---
   1520 
   1521 ## References
   1522 
   1523 1. [Nmap Official Documentation](https://nmap.org/book/)
   1524 2. [NSE Documentation Portal](https://nmap.org/nsedoc/)
   1525 3. [NSE Script Categories Reference](https://nmap.org/book/nse-usage.html)
   1526 4. [Port Number Registry (IANA)](https://www.iana.org/assignments/service-names-port-numbers/)
   1527 5. [Common Ports List](https://www.speedguide.net/ports.php)
   1528 6. [HackTricks - Network Service Pentesting](https://book.hacktricks.xyz/network-services-pentesting)
   1529 7. [MITRE ATT&CK Framework](https://attack.mitre.org/)
   1530 8. [SecLists Wordlist Repository](https://github.com/danielmiessler/SecLists)
   1531 9. [RFC Index](https://www.rfc-editor.org/rfc-index.html)
   1532 10. [CVE Database](https://cve.mitre.org/)
   1533 
   1534 ---
   1535 
   1536 #Nmap #NSE #NetworkEnumeration #ServiceDetection #VulnerabilityScanning #Reconnaissance #Pentesting #SecurityAssessment #NetworkSecurity #InfoSec #PortScanning #FTP #SSH #HTTP #HTTPS #SMB #DNS #LDAP #MySQL #MSSQL #PostgreSQL #MongoDB #Redis #Elasticsearch #SNMP #RDP #VNC #Kerberos