Active reconnaissance — Guided walkthrough
One lab, three targets. We chain every scan layer, we read every output, we climb back to a clean attack plan at the end. Nothing destructive — we want the map, not the ashes.
Everything that follows happens in the host-only lab from module 1, extended to three machines. No command is legitimate outside a lab you own or a target under RoE.
What you will be able to do after this lesson
- Discover live hosts without using a known IP in advance.
- Map services and versions in three logical Nmap passes.
- Enumerate an SMB share with no password and extract a user list.
- Spot a forgotten UDP service (SNMP), with the default community string.
- Consolidate a 2-page reconnaissance report.
The extended set
Take the week 1 lab back and add a third vulnerable Linux VM.
| Machine | Role | IP |
|---|---|---|
| Kali | Attacker | 10.10.10.5 |
| Metasploitable 3 (Windows) | Target 1 | 10.10.10.12 |
| Metasploitable 2 (Linux) | Target 2 | 10.10.10.20 |
Metasploitable 2 downloads from SourceForge. Import it, put it on the same host-only network, force its IP to 10.10.10.20.
Create the mission folder:
mkdir -p ~/labs/semaine-04/{scans,captures,rapport}
cd ~/labs/semaine-04
Step 1 — Layer-2 discovery (ARP)
A discovery passive in its noise: ARP is native on the LAN; it does not attract IDS.
sudo arp-scan --interface=eth0 --localnet | tee scans/arp.txt
Output:
Interface: eth0, type: EN10MB, MAC: 08:00:27:aa:bb:cc, IPv4: 10.10.10.5
Starting arp-scan 1.9.7 with 256 hosts
10.10.10.1 0a:00:27:00:00:0a VirtualBox
10.10.10.12 08:00:27:c3:5f:1e PCS Systemtechnik GmbH (VirtualBox)
10.10.10.20 08:00:27:aa:12:34 PCS Systemtechnik GmbH (VirtualBox)
3 packets received by filter, 0 packets dropped by kernel
Three lines, two targets. 10.10.10.1 is the VirtualBox host (ignore it). Our test estate: .12 and .20.
Step 2 — Ping discovery (ICMP + TCP)
arp-scan does not work off the LAN. For a wider scan, nmap -sn combines ICMP echo, TCP SYN on 443 and 80, and ARP when it can.
sudo nmap -sn 10.10.10.0/24 -oA scans/hosts
cat scans/hosts.gnmap | grep Up
Output:
Host: 10.10.10.12 () Status: Up
Host: 10.10.10.20 () Status: Up
Confirms what ARP said. Good.
Step 3 — Full TCP port sweep
In one go, every port, but one machine at a time. We record:
sudo nmap -sS -Pn -p- --min-rate 2000 10.10.10.12 -oA scans/12-ports
sudo nmap -sS -Pn -p- --min-rate 2000 10.10.10.20 -oA scans/20-ports
Excerpt for .20 (Metasploitable 2):
PORT STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
25/tcp open smtp
53/tcp open domain
80/tcp open http
111/tcp open rpcbind
139/tcp open netbios-ssn
445/tcp open microsoft-ds
512/tcp open exec
513/tcp open login
514/tcp open shell
1099/tcp open rmiregistry
1524/tcp open ingreslock
2049/tcp open nfs
2121/tcp open ccproxy-ftp
3306/tcp open mysql
3632/tcp open distccd
5432/tcp open postgresql
5900/tcp open vnc
6000/tcp open X11
6667/tcp open irc
8009/tcp open ajp13
8180/tcp open unknown
Quick reading:
telnet(23),rsh/rexec/rlogin(512-514): cleartext protocols — mines of flaws; they would make any audit scream.distccd(3632): distributed compiler — historic RCE.ingreslock(1524): a known backdoor of the VM (direct root shell).X11(6000): graphical server exposed on the network.- MySQL and PostgreSQL exposed without going through a front end.
This VM was built to be destroyed — it has everything open. On a real target, such a list would be a signal of abandoned infrastructure.
Step 4 — Version detection
We ask for versions only on open ports. Take the list back:
sudo nmap -sV -p 21,22,23,25,53,80,111,139,445,512-514,1099,1524,2049,3306,3632,5432,5900,6000,6667,8009,8180 \
10.10.10.20 -oA scans/20-versions
Excerpt:
PORT STATE SERVICE VERSION
21/tcp open ftp vsftpd 2.3.4
22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)
23/tcp open telnet Linux telnetd
80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2)
445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
3306/tcp open mysql MySQL 5.0.51a-3ubuntu5
8180/tcp open http Apache Tomcat/Coyote JSP engine 1.1
The magic word: vsftpd 2.3.4. This exact version contains a public backdoor (the famous vsftpd 2.3.4 smiley face backdoor, CVE-2011-2523). Sending a login that contains :) is enough for a root shell to open on port 6200. We will touch that in module 5.
Same on Samba 3.x: a history of flaws (usermap script, EternalRed…). Confirmed target.
Step 5 — Targeted UDP scan
nmap -sU -p- is too long (10 h+). We target the UDP ports that often carry something:
sudo nmap -sU --top-ports 20 10.10.10.20 -oA scans/20-udp
Output:
PORT STATE SERVICE
53/udp open domain
69/udp open|filtered tftp
111/udp open rpcbind
137/udp open netbios-ns
161/udp open snmp
2049/udp open nfs
SNMP (161) open. SNMP over UDP, with the default public community, is the agent that discloses the complete inventory of the machine.
Check:
snmpwalk -v 2c -c public 10.10.10.20 sysDescr
snmpwalk -v 2c -c public 10.10.10.20 hrSWRunName | head
Output:
SNMPv2-MIB::sysDescr.0 = STRING: Linux metasploitable 2.6.24-16-server #1 SMP Thu Apr 10 13:58:00 UTC 2008 i686
HOST-RESOURCES-MIB::hrSWRunName.1 = STRING: "init"
HOST-RESOURCES-MIB::hrSWRunName.2 = STRING: "sshd"
HOST-RESOURCES-MIB::hrSWRunName.3 = STRING: "mysqld"
HOST-RESOURCES-MIB::hrSWRunName.4 = STRING: "apache2"
...
You now know the exact kernel, the distribution version, the list of running processes. No authentication. No exploit.
Step 6 — SMB enumeration with nxc
On 10.10.10.12 (Windows) and 10.10.10.20 (Linux with Samba), same tool:
nxc smb 10.10.10.12 10.10.10.20
Output:
SMB 10.10.10.12 445 METASPLOITABLE3 [*] Windows Server 2008 R2 SP1 (name:METASPLOITABLE3) (domain:METASPLOITABLE3) (signing:False) (SMBv1:True)
SMB 10.10.10.20 445 METASPLOITABLE [*] Unix (Samba 3.0.20-Debian) (name:METASPLOITABLE) (domain:WORKGROUP) (signing:False) (SMBv1:True)
Signing:False everywhere: SMB relay attacks will be possible. Note it for module 10.
Enumerate shares without authentication:
nxc smb 10.10.10.12 -u '' -p '' --shares
nxc smb 10.10.10.20 -u '' -p '' --shares
Output on .20:
SMB 10.10.10.20 445 METASPLOITABLE [+] METASPLOITABLE\:
SMB 10.10.10.20 445 METASPLOITABLE [*] Enumerated shares
SMB 10.10.10.20 445 METASPLOITABLE Share Permissions Remark
SMB 10.10.10.20 445 METASPLOITABLE ----- ----------- ------
SMB 10.10.10.20 445 METASPLOITABLE print$ READ Printer Drivers
SMB 10.10.10.20 445 METASPLOITABLE tmp READ,WRITE oh noes!
SMB 10.10.10.20 445 METASPLOITABLE opt READ
SMB 10.10.10.20 445 METASPLOITABLE IPC$ NO ACCESS IPC Service
Share tmp in READ,WRITE on a null session. An attacker can drop a payload there and execute it remotely (see module 8).
Enumerable users?
enum4linux-ng -U 10.10.10.20
Excerpt:
users:
user: games
user: msfadmin
user: postgres
user: user
user: service
msfadmin — the VM's default administrator account. On a real target, a user list from a null session is a major leak. Here, we note it and we move on.
Step 7 — Wireshark while we scan
Open Wireshark on Kali, capture on eth0, and launch a light scan:
sudo nmap -sS -p 22,80,445 10.10.10.20
In Wireshark, filter:
tcp.flags.syn == 1 and tcp.flags.ack == 0 and ip.dst == 10.10.10.20
You see:
- Three SYN from your IP to
.20:22,.20:80,.20:445. - Three SYN/ACK back (open ports) → each time, your Kali sends a RST (typical of the SYN scan).
You now see what the target would have seen in its own logs — same source IP, same sequence, same TCP window. That is your fingerprint. On a noisy pentest, we own it; on a red team, we disguise it (see module 8).
Step 8 — Scapy in demonstration
A Xmas scan of a single port, by hand:
from scapy.all import IP, TCP, sr1
for port in [22, 445, 3389, 8080]:
response = sr1(
IP(dst="10.10.10.12") / TCP(dport=port, flags="FPU"),
timeout=2, verbose=0
)
if response is None:
print(f"{port}/tcp open|filtered (no reply)")
elif response.haslayer(TCP):
flags = response[TCP].flags
if flags == 0x14: # RST+ACK
print(f"{port}/tcp closed (RST received)")
else:
print(f"{port}/tcp ? (flags={hex(int(flags))})")
Output:
22/tcp open|filtered (no reply)
445/tcp open|filtered (no reply)
3389/tcp open|filtered (no reply)
8080/tcp closed (RST received)
Interpretation: Windows ports return RST to ordinary packets, but Windows on a Xmas scan does not reply — behaviour that does not follow RFC 793. Useful to tell Windows from Linux, at a very low level. This is the kind of trick where Scapy outruns nmap.
Step 9 — Consolidate
Open ~/labs/semaine-04/rapport/reconnaissance.md and fill:
# Reconnaissance report — Week 4 lab (2026-04-16)
## 1. Live hosts
- 10.10.10.12 Windows Server 2008 R2 (Metasploitable 3)
- 10.10.10.20 Linux Ubuntu 8.04 (Metasploitable 2)
## 2. Target 10.10.10.12 — Windows
- Open TCP ports: 22, 80, 135, 139, 445, 3306, 3389, 4848, 8080
- SMB: SMBv1, signing:False, MS17-010 vulnerable (see week 1)
- Priority 1: re-exploit EternalBlue if unpatched.
## 3. Target 10.10.10.20 — Linux
- Open TCP ports: see scans/20-ports.gnmap (24 open ports)
- Notable UDP ports: 53, 161 (SNMP public), 2049 (NFS)
- Vulnerable services identified:
- CRITICAL : vsftpd 2.3.4 → backdoor CVE-2011-2523
- CRITICAL : Samba 3.0.20 → usermap script (CVE-2007-2447)
- CRITICAL : distccd → RCE (CVE-2004-2687)
- CRITICAL : ingreslock 1524 → direct root shell backdoor
- HIGH : SNMP community "public" → inventory leak
- SMB null session: user list obtained (msfadmin, user, service…)
- tmp share writable on a null session.
## 4. Plan for weeks 5-8
1. Verify each of the 4 CVEs on .20 via targeted NSE.
2. Confirm MS17-010 on .12.
3. Extract the full SNMP inventory of .20.
4. Prepare a vsftpd exploit (week 8, Metasploit).
## 5. Artifacts
- scans/*.gnmap, scans/*.xml, scans/*.nmap (12 files)
- captures/wireshark-syn-scan.pcapng
- rapport/reconnaissance.md (this file)
Wrap-up
In 45 minutes of well-run scanning, without taking a single service down:
- You have mapped two machines in depth.
- You have isolated five critical vulnerabilities confirmed or highly likely.
- You have a traffic fingerprint in Wireshark, which you can show the client ("here is what your IDS should have seen").
- You have a plan for weeks 5 to 8.
That is the end of reconnaissance. From module 5 onward, we enter exploitation.