Network Pentesting
Network services
By leveraging the inherent functionalities, vulnerabilities, and misconfiguration of network protocols and services, we may bypass security measures and gain initial access to a target system. This section explores the tactics employed by attackers to abuse various network protocols and services.
DNSPentesting DNS - TCP/UDP Port 53FastCGIPentesting FastCGI - TCP Port 9000FTPWIPHTTP & HTTPSPentesting HTTP & HTTP - TCP Ports 80,443LDAPPentesting LDAP - TCP Ports 389,3268,636,3269MS-RPCPentesting MS-RPC - TCP Ports 135,593MSSQLPentesting MSSQL - TCP Port 1433MySQLWIPNBT-NS (NetBIOS)Pentesting NBT-NS - TCP/UDP Ports 137,138,139NFSPentesting NFS - TCP/UDP Port 2049Oracle TNSPentesting Oracle TNS - TCP Ports 1521,1522-1529RDPPentesting RDP - TCP Port 3389RPC Port MapperWIPPort TCP/UDP 111RsyncPentesting RSync - TCP Ports 873SMBPentesting SMB - TCP Ports 445,139SMTPPentesting SMTP - TCP Ports 25,465,587SNMPPentesting SNMP - UDP Ports 161,162,10161,10162SSHPentesting SSH - TCP Port 22TelnetWIPWebDAVPentesting WebDAV - TCP Ports 80,443WinRMPentesting WinRM - TCP Ports 5985,5986XMPP/JabberPentesting XMPP/Jabber - TCP Ports 5222, 5269, 8010