Pular para o conteúdo principal

Active reconnaissance — Guided walkthrough

One lab, three targets. We chain every scan layer, we read every output, we climb back to a clean attack plan at the end. Nothing destructive — we want the map, not the ashes.

Frame reminder

Everything that follows happens in the host-only lab from module 1, extended to three machines. No command is legitimate outside a lab you own or a target under RoE.

What you will be able to do after this lesson​

  • Discover live hosts without using a known IP in advance.
  • Map services and versions in three logical Nmap passes.
  • Enumerate an SMB share with no password and extract a user list.
  • Spot a forgotten UDP service (SNMP), with the default community string.
  • Consolidate a 2-page reconnaissance report.

The extended set​

Take the week 1 lab back and add a third vulnerable Linux VM.

MachineRoleIP
KaliAttacker10.10.10.5
Metasploitable 3 (Windows)Target 110.10.10.12
Metasploitable 2 (Linux)Target 210.10.10.20

Metasploitable 2 downloads from SourceForge. Import it, put it on the same host-only network, force its IP to 10.10.10.20.

Create the mission folder:

mkdir -p ~/labs/semaine-04/{scans,captures,rapport}
cd ~/labs/semaine-04

Step 1 — Layer-2 discovery (ARP)​

A discovery passive in its noise: ARP is native on the LAN; it does not attract IDS.

sudo arp-scan --interface=eth0 --localnet | tee scans/arp.txt

Output:

Interface: eth0, type: EN10MB, MAC: 08:00:27:aa:bb:cc, IPv4: 10.10.10.5
Starting arp-scan 1.9.7 with 256 hosts

10.10.10.1 0a:00:27:00:00:0a VirtualBox
10.10.10.12 08:00:27:c3:5f:1e PCS Systemtechnik GmbH (VirtualBox)
10.10.10.20 08:00:27:aa:12:34 PCS Systemtechnik GmbH (VirtualBox)

3 packets received by filter, 0 packets dropped by kernel

Three lines, two targets. 10.10.10.1 is the VirtualBox host (ignore it). Our test estate: .12 and .20.


Step 2 — Ping discovery (ICMP + TCP)​

arp-scan does not work off the LAN. For a wider scan, nmap -sn combines ICMP echo, TCP SYN on 443 and 80, and ARP when it can.

sudo nmap -sn 10.10.10.0/24 -oA scans/hosts
cat scans/hosts.gnmap | grep Up

Output:

Host: 10.10.10.12 () Status: Up
Host: 10.10.10.20 () Status: Up

Confirms what ARP said. Good.


Step 3 — Full TCP port sweep​

In one go, every port, but one machine at a time. We record:

sudo nmap -sS -Pn -p- --min-rate 2000 10.10.10.12 -oA scans/12-ports
sudo nmap -sS -Pn -p- --min-rate 2000 10.10.10.20 -oA scans/20-ports

Excerpt for .20 (Metasploitable 2):

PORT     STATE SERVICE
21/tcp open ftp
22/tcp open ssh
23/tcp open telnet
25/tcp open smtp
53/tcp open domain
80/tcp open http
111/tcp open rpcbind
139/tcp open netbios-ssn
445/tcp open microsoft-ds
512/tcp open exec
513/tcp open login
514/tcp open shell
1099/tcp open rmiregistry
1524/tcp open ingreslock
2049/tcp open nfs
2121/tcp open ccproxy-ftp
3306/tcp open mysql
3632/tcp open distccd
5432/tcp open postgresql
5900/tcp open vnc
6000/tcp open X11
6667/tcp open irc
8009/tcp open ajp13
8180/tcp open unknown

Quick reading:

  • telnet (23), rsh/rexec/rlogin (512-514): cleartext protocols — mines of flaws; they would make any audit scream.
  • distccd (3632): distributed compiler — historic RCE.
  • ingreslock (1524): a known backdoor of the VM (direct root shell).
  • X11 (6000): graphical server exposed on the network.
  • MySQL and PostgreSQL exposed without going through a front end.

This VM was built to be destroyed — it has everything open. On a real target, such a list would be a signal of abandoned infrastructure.


Step 4 — Version detection​

We ask for versions only on open ports. Take the list back:

sudo nmap -sV -p 21,22,23,25,53,80,111,139,445,512-514,1099,1524,2049,3306,3632,5432,5900,6000,6667,8009,8180 \
10.10.10.20 -oA scans/20-versions

Excerpt:

PORT     STATE SERVICE     VERSION
21/tcp open ftp vsftpd 2.3.4
22/tcp open ssh OpenSSH 4.7p1 Debian 8ubuntu1 (protocol 2.0)
23/tcp open telnet Linux telnetd
80/tcp open http Apache httpd 2.2.8 ((Ubuntu) DAV/2)
445/tcp open netbios-ssn Samba smbd 3.X - 4.X (workgroup: WORKGROUP)
3306/tcp open mysql MySQL 5.0.51a-3ubuntu5
8180/tcp open http Apache Tomcat/Coyote JSP engine 1.1

The magic word: vsftpd 2.3.4. This exact version contains a public backdoor (the famous vsftpd 2.3.4 smiley face backdoor, CVE-2011-2523). Sending a login that contains :) is enough for a root shell to open on port 6200. We will touch that in module 5.

Same on Samba 3.x: a history of flaws (usermap script, EternalRed…). Confirmed target.


Step 5 — Targeted UDP scan​

nmap -sU -p- is too long (10 h+). We target the UDP ports that often carry something:

sudo nmap -sU --top-ports 20 10.10.10.20 -oA scans/20-udp

Output:

PORT     STATE         SERVICE
53/udp open domain
69/udp open|filtered tftp
111/udp open rpcbind
137/udp open netbios-ns
161/udp open snmp
2049/udp open nfs

SNMP (161) open. SNMP over UDP, with the default public community, is the agent that discloses the complete inventory of the machine.

Check:

snmpwalk -v 2c -c public 10.10.10.20 sysDescr
snmpwalk -v 2c -c public 10.10.10.20 hrSWRunName | head

Output:

SNMPv2-MIB::sysDescr.0 = STRING: Linux metasploitable 2.6.24-16-server #1 SMP Thu Apr 10 13:58:00 UTC 2008 i686
HOST-RESOURCES-MIB::hrSWRunName.1 = STRING: "init"
HOST-RESOURCES-MIB::hrSWRunName.2 = STRING: "sshd"
HOST-RESOURCES-MIB::hrSWRunName.3 = STRING: "mysqld"
HOST-RESOURCES-MIB::hrSWRunName.4 = STRING: "apache2"
...

You now know the exact kernel, the distribution version, the list of running processes. No authentication. No exploit.


Step 6 — SMB enumeration with nxc​

On 10.10.10.12 (Windows) and 10.10.10.20 (Linux with Samba), same tool:

nxc smb 10.10.10.12 10.10.10.20

Output:

SMB  10.10.10.12  445  METASPLOITABLE3  [*] Windows Server 2008 R2 SP1  (name:METASPLOITABLE3) (domain:METASPLOITABLE3) (signing:False) (SMBv1:True)
SMB 10.10.10.20 445 METASPLOITABLE [*] Unix (Samba 3.0.20-Debian) (name:METASPLOITABLE) (domain:WORKGROUP) (signing:False) (SMBv1:True)

Signing:False everywhere: SMB relay attacks will be possible. Note it for module 10.

Enumerate shares without authentication:

nxc smb 10.10.10.12 -u '' -p '' --shares
nxc smb 10.10.10.20 -u '' -p '' --shares

Output on .20:

SMB  10.10.10.20  445  METASPLOITABLE   [+] METASPLOITABLE\: 
SMB 10.10.10.20 445 METASPLOITABLE [*] Enumerated shares
SMB 10.10.10.20 445 METASPLOITABLE Share Permissions Remark
SMB 10.10.10.20 445 METASPLOITABLE ----- ----------- ------
SMB 10.10.10.20 445 METASPLOITABLE print$ READ Printer Drivers
SMB 10.10.10.20 445 METASPLOITABLE tmp READ,WRITE oh noes!
SMB 10.10.10.20 445 METASPLOITABLE opt READ
SMB 10.10.10.20 445 METASPLOITABLE IPC$ NO ACCESS IPC Service

Share tmp in READ,WRITE on a null session. An attacker can drop a payload there and execute it remotely (see module 8).

Enumerable users?

enum4linux-ng -U 10.10.10.20

Excerpt:

users:
user: games
user: msfadmin
user: postgres
user: user
user: service

msfadmin — the VM's default administrator account. On a real target, a user list from a null session is a major leak. Here, we note it and we move on.


Step 7 — Wireshark while we scan​

Open Wireshark on Kali, capture on eth0, and launch a light scan:

sudo nmap -sS -p 22,80,445 10.10.10.20

In Wireshark, filter:

tcp.flags.syn == 1 and tcp.flags.ack == 0 and ip.dst == 10.10.10.20

You see:

  • Three SYN from your IP to .20:22, .20:80, .20:445.
  • Three SYN/ACK back (open ports) → each time, your Kali sends a RST (typical of the SYN scan).

You now see what the target would have seen in its own logs — same source IP, same sequence, same TCP window. That is your fingerprint. On a noisy pentest, we own it; on a red team, we disguise it (see module 8).


Step 8 — Scapy in demonstration​

A Xmas scan of a single port, by hand:

from scapy.all import IP, TCP, sr1

for port in [22, 445, 3389, 8080]:
response = sr1(
IP(dst="10.10.10.12") / TCP(dport=port, flags="FPU"),
timeout=2, verbose=0
)
if response is None:
print(f"{port}/tcp open|filtered (no reply)")
elif response.haslayer(TCP):
flags = response[TCP].flags
if flags == 0x14: # RST+ACK
print(f"{port}/tcp closed (RST received)")
else:
print(f"{port}/tcp ? (flags={hex(int(flags))})")

Output:

22/tcp  open|filtered  (no reply)
445/tcp open|filtered (no reply)
3389/tcp open|filtered (no reply)
8080/tcp closed (RST received)

Interpretation: Windows ports return RST to ordinary packets, but Windows on a Xmas scan does not reply — behaviour that does not follow RFC 793. Useful to tell Windows from Linux, at a very low level. This is the kind of trick where Scapy outruns nmap.


Step 9 — Consolidate​

Open ~/labs/semaine-04/rapport/reconnaissance.md and fill:

# Reconnaissance report — Week 4 lab  (2026-04-16)

## 1. Live hosts
- 10.10.10.12 Windows Server 2008 R2 (Metasploitable 3)
- 10.10.10.20 Linux Ubuntu 8.04 (Metasploitable 2)

## 2. Target 10.10.10.12 — Windows
- Open TCP ports: 22, 80, 135, 139, 445, 3306, 3389, 4848, 8080
- SMB: SMBv1, signing:False, MS17-010 vulnerable (see week 1)
- Priority 1: re-exploit EternalBlue if unpatched.

## 3. Target 10.10.10.20 — Linux
- Open TCP ports: see scans/20-ports.gnmap (24 open ports)
- Notable UDP ports: 53, 161 (SNMP public), 2049 (NFS)
- Vulnerable services identified:
- CRITICAL : vsftpd 2.3.4 → backdoor CVE-2011-2523
- CRITICAL : Samba 3.0.20 → usermap script (CVE-2007-2447)
- CRITICAL : distccd → RCE (CVE-2004-2687)
- CRITICAL : ingreslock 1524 → direct root shell backdoor
- HIGH : SNMP community "public" → inventory leak
- SMB null session: user list obtained (msfadmin, user, service…)
- tmp share writable on a null session.

## 4. Plan for weeks 5-8
1. Verify each of the 4 CVEs on .20 via targeted NSE.
2. Confirm MS17-010 on .12.
3. Extract the full SNMP inventory of .20.
4. Prepare a vsftpd exploit (week 8, Metasploit).

## 5. Artifacts
- scans/*.gnmap, scans/*.xml, scans/*.nmap (12 files)
- captures/wireshark-syn-scan.pcapng
- rapport/reconnaissance.md (this file)

Wrap-up​

In 45 minutes of well-run scanning, without taking a single service down:

  • You have mapped two machines in depth.
  • You have isolated five critical vulnerabilities confirmed or highly likely.
  • You have a traffic fingerprint in Wireshark, which you can show the client ("here is what your IDS should have seen").
  • You have a plan for weeks 5 to 8.

That is the end of reconnaissance. From module 5 onward, we enter exploitation.