Network Service Enumeration: practice machines and key commands
Good enumeration of network services decides most boxes before any exploit is run. After a full TCP scan and a quick UDP check, visit each port by hand: anonymous FTP may expose files, NFS exports can be mounted, SNMP community strings reveal users and processes, and unauthenticated Redis can write SSH keys or web shells. Grab banners, note versions and search for matching advisories, then look at default credentials for the product. Keep scan output per host and re-scan after you gain internal access, because new ports appear on localhost. Do not skip uncommon ports. The machines below are solved through careful service enumeration rather than a single exploit. Re-run the scans once credentials are known, since authenticated views expose far more detail. Compare the results of different tools instead of trusting one.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Fast SYN Scan (Top 1000 Ports)
Speedy initial discovery of open TCP ports with version detection and default safe scripts.
nmap -sC -sV -Pn --min-rate 2000 -oN nmap_quick.txt {TARGET_IP}All-Port TCP Exhaustive Scan
Scan all 65,535 TCP ports at a high packet rate, saving output to all formats.
nmap -p- -sC -sV -Pn --min-rate 3000 -oA nmap_full {TARGET_IP}Top UDP Service Discovery Scan
Quick scan of the most common 20 UDP ports (SNMP, TFTP, DNS, NTP, DHCP).
sudo nmap -sU --top-ports 20 -Pn --open -oN nmap_udp.txt {TARGET_IP}SNMPwalk v2c Community Enumeration
Query SNMP management information base using default public community string.
snmpwalk -v 2c -c public {TARGET_IP}DNS Zone Transfer (AXFR) Audit
Attempt full DNS zone transfer from target nameserver to expose all subdomains.
dig axfr @{TARGET_IP} {DOMAIN}
Keep going
- Methodology: Phase 02: Protocol & Service Enumeration
- Cheatsheet: Recon & Port Scanning
Network Service Enumeration machines (40)
7 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 34 Linux, 5 Windows, 1 Other.
Very Easy (5)
| Machine | Platform | OS |
|---|---|---|
| Crocodile | HTB | Linux |
| Fawn | HTB | Linux |
| Meow | HTB | Linux |
| Redeemer | HTB | Linux |
| Vaccine | HTB | Linux |
Easy (19)
| Machine | Platform | OS |
|---|---|---|
| Intermediate Nmap | THM | Linux |
| TakeOver | THM | Other |
| Active Directory Basics | THM | Windows |
| Anonforce | THM | Linux |
| Antique | HTB | Linux |
| Dav | THM | Linux |
| Fowsniff CTF | THM | Linux |
| GamingServer | THM | Linux |
| IDE | THM | Linux |
| Lian_Yu | THM | Linux |
| Library | THM | Linux |
| Pandora | HTB | Linux |
| Postman | HTB | Linux |
| Res | THM | Linux |
| Thompson | THM | Linux |
| ToolsRus | THM | Linux |
| TShark Challenge I: Teamwork | THM | Linux |
| TShark Challenge II: Directory | THM | Linux |
| Whiterose | THM | Linux |
Medium (12)
| Machine | Platform | OS |
|---|---|---|
| Anonymous | THM | Linux |
| Brainstorm | THM | Windows |
| Carrier | HTB | Linux |
| Cascade | HTB | Windows |
| Clicker | HTB | Linux |
| Format | HTB | Linux |
| HA Joker CTF | THM | Linux |
| Net Sec Challenge | THM | Linux |
| SeeTwo | THM | Linux |
| Smol | THM | Linux |
| VulnNet: Active (Retired) | THM | Windows |
| Watcher | THM | Linux |
Hard (4)
| Machine | Platform | OS |
|---|---|---|
| CherryBlossom | THM | Linux |
| Raz0rBlack | THM | Windows |
| Tartarus | THM | Linux |
| VulnNet: Internal | THM | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox