Service Enum
Port 21 - FTP
# Nmap to find known vulnerability and detailed scan
nmap --script ftp-anon,ftp-bounce,ftp-libopie,ftp-proftpd-backdoor,ftp-vsftpd-backdoor,ftp-vuln-cve2010-4221,tftp-enum -p 21 $ip
# try anonymous login
username -> anonymous
password ->
# download
Get file.txt
# upload
put file.txt
#Use binary mode
binary
put file.exePort 22 - SSH
Port 25/587/465 - SMTP
Sending Email - (using swaks)
Port 79 - Finger
Port 88 - Kerberos
Port 110/995 - Pop3
Port 135 - MSRPC
Port 139/445 - SMB
Port 143/993 IMAP
Port 161/162 UDP - SNMP
SNMP -> RCE
Port 389/636/3268/3269 - LDAP
Port 1433 - MSSQL
Port 3306 - MySQL
Port 3389 - RDP
Port 5432/5433 - PostgreSQL
Port 5985 - WinRM
Port 6379 - Redis
Webdav
Uploading a shell (Authenticated)
Davtest
Last updated