The nmap scan is launched in aggressive mode against the target. Disabling host discovery (-Pn) is necessary because ICMP pings are filtered in this environment:
nmap -v 10.129.7.25 -A -T4 -PnThe result reveals a Windows Server 2022 machine with a particularly extensive attack surface. Here are the open ports identified:
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH for_Windows_9.5 (protocol 2.0)
25/tcp open smtp hMailServer smtpd
| smtp-commands: JOB2, SIZE 20480000, AUTH LOGIN, HELP
|_ 211 DATA HELO EHLO MAIL NOOP QUIT RCPT RSET SAML TURN VRFY
80/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
111/tcp open rpcbind
135/tcp open msrpc Microsoft Windows RPC
139/tcp open netbios-ssn Microsoft Windows netbios-ssn
443/tcp open ssl/https?
| ssl-cert: Subject: commonName=www.job2.vl
| Subject Alternative Name: DNS:job2.vl, DNS:www.job2.vl
| Issuer: commonName=www.job2.vl
| Public Key bits: 2048
| Not valid before: 2023-05-09T13:31:40
445/tcp open microsoft-ds?
1063/tcp open rpcbind
2049/tcp open rpcbind
3389/tcp open ms-wbt-server Microsoft Terminal Services
| ssl-cert: Subject: commonName=JOB2
5985/tcp open http Microsoft HTTPAPI httpd 2.0 (SSDP/UPnP)
10001/tcp open msexchange-logcopier Microsoft Exchange 2010 log copier
10002/tcp open msexchange-logcopier Microsoft Exchange 2010 log copier
10003/tcp open storagecraft-image StorageCraft Image Manager
Running: Microsoft Windows 2022 (86%)
Service Info: Host: JOB2; OS: Windows
Host script results:
| smb2-security-mode:
| 3.1.1:
|_ Message signing enabled but not requiredAnalysis of the results highlights several points of interest:
- Port 25 (SMTP): The banner
hMailServer smtpdidentifies a classic Windows mail server. The hostnameJOB2is confirmed. - Ports 80/443 (HTTP/HTTPS): A web server is accessible. The SSL certificate for port 443 reveals the domains
job2.vlandwww.job2.vl— valuable information for later. - Port 5985 (WinRM): Windows Remote Management is active, a potential vector for remote access if valid credentials are obtained.
- Port 3389 (RDP): Remote Desktop is also available.
- Ports 10001–10003: These services are characteristic of a Veeam Backup & Replication installation, enterprise backup software often overlooked from a security perspective.
- SMB signing not enforced: SMB signing is enabled but not mandatory, which opens the door to NTLM relay attacks if credentials are captured.
We immediately add the DNS entries to /etc/hosts to resolve the domain names identified in the SSL certificate:
echo '10.129.7.25 job2.vl www.job2.vl' | sudo tee -a /etc/hosts