Active Information Gathering
Manual benner checking
nc <IP> <PORT>Nmap
Scan for open ports [TCP]
sudo nmap -sC -sV -p- <IP>nmap -sV -p- -oA output -Pn -A -T4 <IP>nmap -sV -p- -oA outputVuln -Pn --script vuln -T5 <IP>Scan for open ports [UDP]
nmap -sU -A -p- -oA outputUDP <IP>Run vuln scan
nmap <IP> -sV --script "vuln" -p<PORT>Nmap script listing
Import NSE script
(PowerShell NMAP alternative)
Windows port scanning
Windows subtnetwork scanning
SMTP Enumeration (23, 465, 587)
SNMP Enumeration (161, 162, 10161, 10162 / UDP)
Values
Paremeters
DNS Enumeration (53)
Zone transfer
Subdomain Enumeration
Whois Enumeration (43)
FTP Enumeration (21)
Upload files
Download files
NBT Enumeration (137)
SMB Enumeration (139, 445)
Enumerate Users, Groups and Logged on Users
Enumerate shares (alternative)
Connect to share
Download everything from share
Mount share (listing bypass, can search for hidden files)
MSSQL
NFS Enumeration (2049)
Show all mounts
Mount folder
LDAP (389, 636, 3268, 3269)
WEB (80, 443)
Information GatheringOracle TNS Listener (1521, 1522-1529)
Last updated