ZeroBox

Network Service Enumeration: practice machines and key commands

Good enumeration of network services decides most boxes before any exploit is run. After a full TCP scan and a quick UDP check, visit each port by hand: anonymous FTP may expose files, NFS exports can be mounted, SNMP community strings reveal users and processes, and unauthenticated Redis can write SSH keys or web shells. Grab banners, note versions and search for matching advisories, then look at default credentials for the product. Keep scan output per host and re-scan after you gain internal access, because new ports appear on localhost. Do not skip uncommon ports. The machines below are solved through careful service enumeration rather than a single exploit. Re-run the scans once credentials are known, since authenticated views expose far more detail. Compare the results of different tools instead of trusting one.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Fast SYN Scan (Top 1000 Ports)

Speedy initial discovery of open TCP ports with version detection and default safe scripts.

nmap -sC -sV -Pn --min-rate 2000 -oN nmap_quick.txt {TARGET_IP}

All-Port TCP Exhaustive Scan

Scan all 65,535 TCP ports at a high packet rate, saving output to all formats.

nmap -p- -sC -sV -Pn --min-rate 3000 -oA nmap_full {TARGET_IP}

Top UDP Service Discovery Scan

Quick scan of the most common 20 UDP ports (SNMP, TFTP, DNS, NTP, DHCP).

sudo nmap -sU --top-ports 20 -Pn --open -oN nmap_udp.txt {TARGET_IP}

SNMPwalk v2c Community Enumeration

Query SNMP management information base using default public community string.

snmpwalk -v 2c -c public {TARGET_IP}

DNS Zone Transfer (AXFR) Audit

Attempt full DNS zone transfer from target nameserver to expose all subdomains.

dig axfr @{TARGET_IP} {DOMAIN}

Keep going

Network Service Enumeration machines (40)

7 of these are machines I solved myself and are listed first within each difficulty. Machines are matched by their technique tags. 34 Linux, 5 Windows, 1 Other.

Very Easy (5)

MachinePlatformOSTags
CrocodileHTBLinuxFTP, Admin Panel, Gobuster
FawnHTBLinuxFTP, Anonymous Login
MeowHTBLinuxTelnet, Default Credentials, Recon
RedeemerHTBLinuxRedis, Database, Unauthenticated
VaccineHTBLinuxFTP, SQLi, Sudo, Tar Wildcard

Easy (19)

MachinePlatformOSTags
Intermediate NmapTHMLinuxNmap, Reconnaissance, Port-Scanning
TakeOverTHMOtherSubdomain-Takeover, DNS
Active Directory BasicsTHMWindowsActive Directory, Domain Controller, Forests, Trusts
AnonforceTHMLinuxTHM, nmap, John The Ripper
AntiqueHTBLinuxHTB, SNMP
DavTHMLinuxTHM, nmap, gobuster
Fowsniff CTFTHMLinuxTHM, nmap, Metasploit
GamingServerTHMLinuxTHM, nmap, hydra, gobuster
IDETHMLinuxTHM, nmap, searchsploit, linPEAS
Lian_YuTHMLinuxSteganography, Gobuster, FTP, Sudo-Privesc
LibraryTHMLinuxTHM, nmap, gobuster, hydra
PandoraHTBLinuxHTB, SNMP
PostmanHTBLinuxHTB, Redis
ResTHMLinuxRedis, Unauthorized-Access, Webshell, SUID-Xxd
ThompsonTHMLinuxTHM, nmap, gobuster, Metasploit
ToolsRusTHMLinuxTHM, dirbuster, Hydra, Nmap
TShark Challenge I: TeamworkTHMLinuxTHM, Tshark
TShark Challenge II: DirectoryTHMLinuxTHM, Tshark
WhiteroseTHMLinuxTHM, nmap, gobuster, ffuf

Medium (12)

MachinePlatformOSTags
AnonymousTHMLinuxFTP, Cron, SUID
BrainstormTHMWindowsBuffer-Overflow, FTP, x86
CarrierHTBLinuxHTB, SNMP
CascadeHTBWindowsAD Recycle Bin, AES-Encryption, Active Directory, Active-Directory
ClickerHTBLinuxCPTS, NFS, Mass Assignment, SQL Injection
FormatHTBLinuxCPTS, LFI, Nginx Traversal, Redis
HA Joker CTFTHMLinuxTHM, nmap
Net Sec ChallengeTHMLinuxTHM, Nmap, hydra
SeeTwoTHMLinuxTHM, Wireshark, tshark, base64
SmolTHMLinuxTHM, nmap, wpscan, www.cyberchef.com
VulnNet: Active (Retired)THMWindowsActive Directory, Redis, GPP-Passwords, Kerberoast
WatcherTHMLinuxLFI, FTP, Cron, Sudo-Privesc

Hard (4)

MachinePlatformOSTags
CherryBlossomTHMLinuxTHM, nmap, smbclient, base64
Raz0rBlackTHMWindowsActive Directory, NFS, Kerberos, AS-REP Roasting
TartarusTHMLinuxFTP, Directory-Traversal, Cron, Sudo-Privesc
VulnNet: InternalTHMLinuxSMB, Redis, TeamCity, Tunneling

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox