Network Service Enumeration
After scanning (see Nmap in Depth) you know which ports are open; enumeration digs into each service to extract everything useful: exact versions, users, shared resources, configurations, default credentials, and known vulnerabilities. It’s the phase that decides the attack vector: an open port is a question, enumeration is the detailed answer.
The principle
Section titled “The principle”Each service “speaks” a protocol and, well interrogated, leaks information. The goal is, per open port: identify the exact software and version, discover what it allows without authentication, enumerate users/resources, and cross-reference the version with known CVEs.
Per-service methodology
Section titled “Per-service methodology”1. Banner grabbing: which software and version? (nc, nmap -sV)2. Anonymous/default access: does it allow anything without credentials?3. Protocol-specific enumeration (users, shares, databases, config)4. Default / weak credentials5. Version -> CVE (searchsploit, nuclei)Manual banner grabbing
Section titled “Manual banner grabbing”nc -nv 10.0.0.5 21 # connect and read the banner (FTP, SMTP, etc.)curl -sI http://10.0.0.5 # HTTP headersopenssl s_client -connect 10.0.0.5:443 # TLS servicesnmap -sV --script=banner 10.0.0.5Key services and their port (where to go first)
Section titled “Key services and their port (where to go first)”21 FTP -> anonymous? vulnerable version?22 SSH -> version, auth methods, valid users25 SMTP -> VRFY/EXPN (enumerate users), open relay53 DNS -> zone transfer (see net-dnsattacks)110/143 POP3/IMAP111 RPC / 2049 NFS -> accessible exports139/445 SMB -> shares, users, null session (the juiciest)161 SNMP -> community strings (public/private) -> MIB dump389 LDAP -> directory enumeration (AD, see ad-enum)1433 MSSQL / 3306 MySQL / 5432 PostgreSQL -> databases3389 RDP -> users, NLA, BlueKeep5985 WinRM -> remote execution with credentialsPer-service enumeration tools
Section titled “Per-service enumeration tools”# all-in-onenmap --script=<proto>-* ; nxc (NetExec) smb/ldap/ssh/mssql/winrm/ftp# SMB (the richest)enum4linux-ng -A 10.0.0.5 ; smbclient -L //10.0.0.5 -N ; smbmap -H 10.0.0.5nxc smb 10.0.0.5 -u '' -p '' --shares --users# SNMPsnmpwalk -v2c -c public 10.0.0.5 ; onesixtyone -c communities.txt 10.0.0.5# SMTPsmtp-user-enum -M VRFY -U users.txt -t 10.0.0.5# NFSshowmount -e 10.0.0.5# databasesmysql -h 10.0.0.5 -u root ; mssqlclient.py / nxc mssqlSMB: the star service
Section titled “SMB: the star service”On Windows networks, SMB (445) is usually the goldmine: null sessions, readable shares, enumerable users, and the door to the domain.
nxc smb 10.0.0.0/24 # sweep: OS, name, signing, SMBv1nxc smb 10.0.0.5 -u '' -p '' --shares # null sessionenum4linux-ng -A 10.0.0.5 # users, groups, shares, policyFrom version to exploit
Section titled “From version to exploit”searchsploit <service> <version>nmap --script=<service>-vuln* targetnuclei -t http/cves/ -u targetFor the defense
Section titled “For the defense”Reduce enumerability: don’t expose unnecessary services, disable anonymous access (FTP, SMB null sessions, SNMP public), change default credentials, hide/normalize version banners, enforce SMB signing and disable SMBv1, and segment so not everything is reachable. Monitor enumeration (many queries to a service from one source).
Testing checklist
Section titled “Testing checklist”- Banner grabbing of each open port
- Anonymous/default access tested (FTP, SMB, SNMP)
- SMB: shares, users, null session, signing (nxc/enum4linux-ng)
- SNMP: community strings and MIB walk
- SMTP: user enumeration (VRFY) and relay
- NFS: accessible exports (showmount)
- Databases: access with default credentials
- Versions cross-referenced with CVEs (searchsploit/nuclei)