Skip to content

Network Service Enumeration

After scanning (see Nmap in Depth) you know which ports are open; enumeration digs into each service to extract everything useful: exact versions, users, shared resources, configurations, default credentials, and known vulnerabilities. It’s the phase that decides the attack vector: an open port is a question, enumeration is the detailed answer.

Each service “speaks” a protocol and, well interrogated, leaks information. The goal is, per open port: identify the exact software and version, discover what it allows without authentication, enumerate users/resources, and cross-reference the version with known CVEs.

1. Banner grabbing: which software and version? (nc, nmap -sV)
2. Anonymous/default access: does it allow anything without credentials?
3. Protocol-specific enumeration (users, shares, databases, config)
4. Default / weak credentials
5. Version -> CVE (searchsploit, nuclei)
nc -nv 10.0.0.5 21 # connect and read the banner (FTP, SMTP, etc.)
curl -sI http://10.0.0.5 # HTTP headers
openssl s_client -connect 10.0.0.5:443 # TLS services
nmap -sV --script=banner 10.0.0.5

Key services and their port (where to go first)

Section titled “Key services and their port (where to go first)”
21 FTP -> anonymous? vulnerable version?
22 SSH -> version, auth methods, valid users
25 SMTP -> VRFY/EXPN (enumerate users), open relay
53 DNS -> zone transfer (see net-dnsattacks)
110/143 POP3/IMAP
111 RPC / 2049 NFS -> accessible exports
139/445 SMB -> shares, users, null session (the juiciest)
161 SNMP -> community strings (public/private) -> MIB dump
389 LDAP -> directory enumeration (AD, see ad-enum)
1433 MSSQL / 3306 MySQL / 5432 PostgreSQL -> databases
3389 RDP -> users, NLA, BlueKeep
5985 WinRM -> remote execution with credentials
# all-in-one
nmap --script=<proto>-* ; nxc (NetExec) smb/ldap/ssh/mssql/winrm/ftp
# SMB (the richest)
enum4linux-ng -A 10.0.0.5 ; smbclient -L //10.0.0.5 -N ; smbmap -H 10.0.0.5
nxc smb 10.0.0.5 -u '' -p '' --shares --users
# SNMP
snmpwalk -v2c -c public 10.0.0.5 ; onesixtyone -c communities.txt 10.0.0.5
# SMTP
smtp-user-enum -M VRFY -U users.txt -t 10.0.0.5
# NFS
showmount -e 10.0.0.5
# databases
mysql -h 10.0.0.5 -u root ; mssqlclient.py / nxc mssql

On Windows networks, SMB (445) is usually the goldmine: null sessions, readable shares, enumerable users, and the door to the domain.

nxc smb 10.0.0.0/24 # sweep: OS, name, signing, SMBv1
nxc smb 10.0.0.5 -u '' -p '' --shares # null session
enum4linux-ng -A 10.0.0.5 # users, groups, shares, policy
searchsploit <service> <version>
nmap --script=<service>-vuln* target
nuclei -t http/cves/ -u target

Reduce enumerability: don’t expose unnecessary services, disable anonymous access (FTP, SMB null sessions, SNMP public), change default credentials, hide/normalize version banners, enforce SMB signing and disable SMBv1, and segment so not everything is reachable. Monitor enumeration (many queries to a service from one source).

  • Banner grabbing of each open port
  • Anonymous/default access tested (FTP, SMB, SNMP)
  • SMB: shares, users, null session, signing (nxc/enum4linux-ng)
  • SNMP: community strings and MIB walk
  • SMTP: user enumeration (VRFY) and relay
  • NFS: accessible exports (showmount)
  • Databases: access with default credentials
  • Versions cross-referenced with CVEs (searchsploit/nuclei)