Network Services Attacks¶
Enumerating and attacking common network services to find a foothold.
Why It Matters¶
Exposed network services are a frequent entry point. Many are misconfigured (anonymous access, default credentials, readable shares) or run outdated versions with known vulnerabilities. Thorough enumeration of each service is usually what reveals the way in.
Reference¶
Enumeration¶
Identify services and versions with Nmap -sV and its NSE scripts, and enum4linux for Windows and Samba hosts. The exact version is what maps to a known vulnerability on Exploit-DB or in CVE databases.
Services¶
| Service | Port | Enumeration and Notes |
|---|---|---|
| SMB | 445 | smbclient -L //IP -U user; list and access shares, check for anonymous access and readable shares |
| Telnet | 23 | telnet IP port; cleartext, often legacy; check for exposed banners and credentials |
| FTP | 21 | ftp IP; check for anonymous login and writable directories; cleartext credentials |
| NFS | 2049 | showmount -e IP to list exports; mount with sudo mount -t nfs IP:share /mnt -o nolock; check for no_root_squash |
| SMTP | 25 | Enumerate users with VRFY and EXPN; Metasploit auxiliary/scanner/smtp/smtp_version |
| MySQL | 3306 | mysql -h IP -u user -p; Metasploit mysql_version, mysql_schemadump, mysql_hashdump |
Common Issues to Check¶
- Anonymous or guest access (FTP, SMB, NFS)
- Default or weak credentials (test with Hydra)
- Readable or writable shares and exports
- Outdated versions with public exploits
no_root_squashon NFS exports, which allows writing files as root
How I Use It¶
I enumerate every open service fully before trying anything, because the foothold is usually a misconfiguration (an anonymous share, a writable export) rather than an exploit. Version numbers go straight to searchsploit. Anything requiring credentials gets a targeted, in-scope brute force only after the easy wins are exhausted.