🔢Enumeration Cheatsheet
General Enumeration:
nmap -vv -Pn -A -sC -sS -T 4 -p- 10.0.0.1nmap -v -sS -A -T4 x.x.x.xnmap –script smb-check-vulns.nse –script-args=unsafe=1 -p445 [host]netdiscover -r 192.168.1.0/24
FTP Enumeration (21):
nmap –script ftp-anon,ftp-bounce,ftp-libopie,ftp-proftpd-backdoor,ftp-vsftpd-backdoor,ftp-vuln-cve2010-4221,tftp-enum -p 21 10.0.0.1
SSH (22):
ssh INSERTIPADDRESS 22
SMTP Enumeration (25):
nmap –script smtp-commands,smtp-enum-users,smtp-vuln-cve2010-4344,smtp-vuln-cve2011-1720,smtp-vuln-cve2011-1764 -p 25 10.0.0.1nc -nvv INSERTIPADDRESS 25telnet INSERTIPADDRESS 25
Finger Enumeration (79):
Web Enumeration (80/443):
Pop3 (110):
RPCBind (111):
SMB\RPC Enumeration (139/445):
SNMP Enumeration (161):
Oracle (1521):
Mysql Enumeration (3306):
DNS Zone Transfers:
Mounting File Share
Fingerprinting: Basic versioning / finger printing via displayed banner
Exploit Research
Compiling Exploits
Packet Inspection:
Last updated