|
11 | 11 | * 80 HTTP
|
12 | 12 | * 88 Kerberos
|
13 | 13 | * 110 POP3
|
14 |
| - * 111 SUNRPC(UnixRPC) |
| 14 | + * 111 SUNRPC (UnixRPC) |
15 | 15 | * 139 NetBIOS
|
16 | 16 | * 143 IMAP
|
17 | 17 | * 389 LDAP
|
18 | 18 | * 443 HTTPS
|
19 |
| - * 445 MicrosoftDS |
| 19 | + * 445 Microsoft DS |
20 | 20 | * 514 RSH
|
21 | 21 | * 515 Printers
|
22 | 22 | * 631 CUPS
|
23 |
| - * 1352 LotusNotes |
| 23 | + * 1352 Lotus Notes |
24 | 24 | * 2049 NFS
|
25 | 25 | * 3000 Webrick (Ruby Webserver)
|
26 | 26 | * 3389 RDP
|
27 | 27 | * 4949 Munin
|
28 | 28 | * 5060 SIP
|
29 | 29 | * 5631-5632 PCAnywhere
|
30 |
| - * 5666(evidence of Nagios server on network) NRPE(*nix)/NSCLIENT++(win) |
31 |
| - * 5900-5906 (Same as X11; display over VNC. SPICE is usually in this range as well) VNC |
32 |
| - * 6000-6009 (seexspy, xwd, xkeyforexploitation) X11 |
| 30 | + * 5666 Nagios server/NRPE(*nix)/NSCLIENT++(win) |
| 31 | + * 5900-5906 VNC (Same as X11; display over VNC. SPICE is usually in this range as well) |
| 32 | + * 6000-6009 Xll (seexspy, xwd, xkeyforexploitation) |
33 | 33 | * 8006 Proxmox
|
34 | 34 | * 8080 Alt-HTTP
|
35 |
| - * 8089(also on 8000) Splunk |
36 |
| - * 8000(mezzanine in development mode for example) AnotherHTTP |
| 35 | + * 8089 Splunk (also on 8000) |
| 36 | + * 8000 Another HTTP (mezzanine in development mode for example) |
37 | 37 | * 8834 Nessus HTTPS
|
38 | 38 | * 8443 AltHTTPS
|
39 | 39 | * 9080 Alt-HTTPtomcat
|
|
42 | 42 | * 17500 Dropbox lansync
|
43 | 43 |
|
44 | 44 | ## UDP Discovery: ##
|
45 |
| - * easy copy - `53,111,123,161,177,500,514,1194,1434,1900,17185` |
| 45 | + * easy copy - `53,111,123,161,177,500,514,623,1194,1434,1900,17185` |
46 | 46 | * 53 DNS
|
47 | 47 | * 111 SUNRPC (Unix RPC)
|
48 | 48 | * 123 Network Time Protocol (NTP)
|
49 | 49 | * 161 SNMP
|
50 | 50 | * 177 XDMCP (via NSE script --script broadcast-xdmcp-discover, discover *nix boxes hosting X)
|
51 | 51 | * 500 Isakmp (ike PSK Attack)
|
52 | 52 | * 514 syslog
|
| 53 | + * 623 IPMI (easy crack or auth bypass) |
53 | 54 | * 1194 OpenVPN
|
54 | 55 | * 1434 MSSQL Ping
|
55 | 56 | * 1900 UPNP
|
56 | 57 | * 17185 vxworks debug
|
57 | 58 |
|
58 | 59 | ## Authentication Ports: ##
|
59 | 60 | * easy copy - `80,902,1494,5985,5986,6129,8200,9084`
|
60 |
| - * Citrix: 1494 |
61 |
| - * WinRM: 80, 5985 (HTTP), 5986 (HTTPS) |
62 |
| - * VMware Server: 8200, 902, 9084 |
63 |
| - * DameWare: 6129 |
| 61 | + * 80,5985,5986 WinRM (5985 (HTTP), 5986 (HTTPS)) |
| 62 | + * 902,8200,9084 VMware Server |
| 63 | + * 1494 Citrix |
| 64 | + * 6129 DameWare |
64 | 65 |
|
65 | 66 | ## Easy-win Ports: ##
|
66 |
| - * Java RMI - 1099, 1098 |
67 |
| - * coldfusion default stand alone - 8500 |
68 |
| - * IPMI UDP(623) (easy crack or auth bypass) |
69 |
| - * 6002, 7002 (sentinel license monitor (reverse dir traversal, sometimes as SYSTEM)) |
70 |
| - * GlassFish: 4848 |
71 |
| - * easy copy - `9060` |
72 |
| - * IBM Web Sphere: 9060 |
73 |
| - * Webmin or BackupExec: 10000 |
74 |
| - * memcached: 11211 |
75 |
| - * DistCC: 3632 |
76 |
| - * SAP Router: 3299 |
| 67 | + * easy copy - `1098-1099,3299,3632,4848,6002,7002,8500,9060,10000,11211` |
| 68 | + * 1098-1099 Java RMI |
| 69 | + * 3299 SAP Router |
| 70 | + * 3632 DistCC |
| 71 | + * 4848 GlassFish |
| 72 | + * 6002,7002 (Sentinel license monitor (reverse dir traversal, sometimes as SYSTEM)) |
| 73 | + * 8500 Coldfusion default stand alone |
| 74 | + * 9060 IBM Web Sphere |
| 75 | + * 10000 Webmin or BackupExec |
| 76 | + * 11211 memcached |
77 | 77 |
|
78 | 78 | ## Database Ports: ##
|
79 |
| - * easy copy - `3306,1521-1527,5432,5433,1433,3050,3351,1583,8471,9471` |
80 |
| - * MySQL: 3306 |
81 |
| - * PostgreSQL: 5432 |
82 |
| - * PostgreSQL 9.2: 5433 |
83 |
| - * Oracle TNS Listener: 1521-1527 |
84 |
| - * Oracle XDB: 2100 |
85 |
| - * MSSQL: 1433 |
86 |
| - * Firebird / Interbase: 3050 |
87 |
| - * PervasiveSQL: 3351, 1583 |
88 |
| - * DB2/AS400 8471, 9471 |
89 |
| - * Sybase 5000 |
| 79 | + * easy copy - `1433,1521-1527,1583,3351,2100,3050,3306,5000,5432,5433,8471,9471` |
| 80 | + * 1433 MSSQL |
| 81 | + * 1521-1527 Oracle TNS Listener |
| 82 | + * 1583,3351 PervasiveSQL |
| 83 | + * 2100 Oracle XDB |
| 84 | + * 3050 Firebird/Interbase |
| 85 | + * 3306 MySQL |
| 86 | + * 5000 Sybase |
| 87 | + * 5432 PostgreSQL |
| 88 | + * 5433 PostgreSQL 9.2 |
| 89 | + * 8471,9471 DB2/AS400 |
90 | 90 |
|
91 | 91 | ## SCADA / ICS:##
|
92 | 92 | (source: http://www.digitalbond.com/tools/the-rack/control-system-port-list/ )
|
|
0 commit comments