Enumeration (정보 수집 및 열거)
All you need to know about basic host-based enumeration for OSCP
Network Discovery
Common Nmap Scan
nmap -sV -sT -sC -T5 -v -A $targetipAll TCP port scan
nmap -p- -sT -v $targetipAll UDP Port Scan (With Service and Script Scan)
nmap -p- -sV -sU -sC $targetip100 most common ports
nmap $targetip -F 100Nmap Script Scan
Find the nse scripts
Scan using a specific NSE script
Service Discovery
Port 80 & 443 - Web Discovery
Find SSL Heartbleed Vulnerablity
Scan Web Servers
Dictionary Attacks for finding hidden web objects
Port 445 - SMB Discovery
To discover “All” of SMB
To discover the userlist
Bruteforce the share names
To find Password Policy
Alternative samba enumeration using smbmap
SMBCLIENT copying whole directory
Check the list of shares via SMB null session
Connect to a spefic share path you found
Port 135 - RPC Discovery
Port 389 & 636 for SSL - LDAP Discovery
Port 21 - FTP Discovery
Port 3306 - MySQL
SQL Password Storage
Port 3389 - RDP
Port 21 - FTP
Port 22 - SSH
Port 161 UDP - SNMP
Port 88 - Kerberos
Port 1433 -SQL
Telnet - 25
Finding known exploits from Exploit-DB
Local File inclusions
Last updated