01_scan

目的: IP、PORT、Service

Zone transfer

nslookup -type=ns zonetransfer.me
Server:		8.8.8.8
Address:	8.8.8.8#53

Non-authoritative answer:
zonetransfer.me	nameserver = ns12.zoneedit.com.
zonetransfer.me	nameserver = ns16.zoneedit.com.

Authoritative answers can be found from:
nslookup
> server ns12.zoneedit.com
> ls -d zonetransfer.me

Common port

Options

--open : 僅顯示開啟

-n : no dns

--packet-trace : 顯示封包傳輸

--reason : 詳細說明 port 狀態

xml2html

xsltproc <nmap-output.xml> -o <nmap-output.html>

sudo 差異

nmap -sn <ip> --packet-trace -n  
sudo nmap -sn <ip> --packet-trace -n 

Enum SNMP

snmp-check <ip>
nmap <ip> -sU -p161 --script=snmp-win32-users

Enum NetBIOS/SMB (網路芳鄰)

nbtscan

nbtscan 10.10.10.1-254

nmap

nmap 10.10.10.1 -p445 --script=smb-os-discovery

Enum Host Info

enum4linux <ip>
enum4linux -u <username> -p <passwd> -a <ip> 

Burte force SMB

hydra -L user.txt -P /usr/share/wordlists/nmap.lst smb://10.10.10.16

SMB Clinet

smbclient -L 10.10.10.16 -N
smbclient -L 10.10.10.16 -U martin%apple

LDAP Enum

nmap -p 389 --script ldap-search --script-args 'ldap.username="cn=user,cn=CEH,dc=com",ldap.password=,
ldap.qfilter=users,ldap.attrib=sAMAccountName' 10.10.10.25
nmap -p389 --script ldap-brute --script-args ldap.base='"cn=user,dc=CEH,dc=com"' 10.10.10.25
nmap -p 389 --script ldap-rootdse 10.10.10.25