Skip to main content

UnCommon Ports



cPanel	2082
cPanel - SSL	2083
WHM	2086
WHM - SSL	2087
Webmail	2095
Webmail - SSL	2096

SFTP Shared/Reseller Servers	2222
Webdisk	2077
Webdisk - SSL	2078
SSH Shared/Reseller Servers	2222

Plesk Control Panel	8880
Plesk Control Panel - SSL	8443
Plesk Windows Webmail (SmarterMail)	9998**
DotNet Panel	9001
10000/tcp - WebAdmin; MiniServ 2.021(Has few vulns)
Port 5601, 9200 - Kibana


Port 10000 - NDMP
nmap -p 10000 --script ndmp-fs-info,vuln -sVC -d

Port 30000 - NDMPS
nmap -p 30000--script ndmp-fs-info,vuln -sVC -d

NetApp NDFS Common Ports  
Parallel Virtual File System (PVFS) 
TCP port 3334 - Heap Over flow
nmap --script "rdp-enum-encryption or rdp-vuln-ms12-020 or rdp-ntlm-info" -p 3389
Docker Port - 2375

2375: unencrypted docker socket, remote root passwordless access to the host
2376: tls encrypted socket, most likely this is your CI servers 4243 port as a modification of the https 443 port
2377: swarm mode socket, for swarm managers, not for docker clients
5000: docker registry service
4789 and 7946: overlay networking

docker -H run -it --rm --privileged -v /:/rootfs --net host --pid host busybox

check this out if you observer any issues
Java RMI Registry - Port 1616

nmap -Pn -sS -sV --script "rmi-dumpregistry or rmi-vuln-classloader" -p 1616

#Tools to test RMI 

java -jar BaRMIe.jar -enum 5000
java -jar BaRMIe.jar -attack 5000
java -jar rmg-3.0.0-jar-with-dependencies.jar 5000 enum
Prometheus - Port 9100,9104

Monitoring Tool, go to IP:9100/metrics --> check to see if you can find any info
Varnish HTTP Cache Server - Port 6081,6082

apt-get install varnish

#Access the server
varnishadm -T 

#Access with a secret key - bruteforce the key 
varnishadm -T -S SECRET_KEY

More info here

#VARNISH Request smuggling - CVE-2021-36740 
Redis - port 5460

redis-cli -h -p 5460
Tanium Client - Port 17472/tcp
SunOS RPC Vuln 

Get the exploit from here 

The program number 100083 exists on the host, then the service ttdbserverd is running. The TCP port number assigned for the portmapper to the ttdbserverd is 32775 - UDP

#find the service in nmap report 
grep -nr '100068  2,3,4,5    32800/udp   cmsd'

grep -nr '100083  1          32775/tcp   ttdbserverd'


Usually it runs on Port 80 -

Default Creds:
nagiosadmin  PASSW0RD
mysqladmin -u root -pnagiosxi password welcome

"user" => 'nagiosxi',
"pwd" => 'n@gweb',


Popular posts from this blog

SQL DB & SQL Injection Pentest Cheat Sheet

1) MSSQL Injection Cheat Sheet | pentestmonkey 2) xp_cmdshell | Red Team tales 3) PentesterMonkey SQL Injection Cheatsheet Use dbeaver for GUI Access 4) SQL Injection Explanation | Graceful Security Common Ports Microsoft SQL: 1433/TCP (default listener) 1434/UDP (browser service) 4022/TCP (service broker) 5022/TCP (AlwaysOn High Availability default) 135/TCP (Transaction SQL Debugger) 2383/TCP (Analysis Services) 2382/TCP (SQL Server Browser Service) 500,4500/UDP (IPSec) 137-138/UDP (NetBios / CIFS) 139/TCP (NetBios CIFS) 445/TCP (CIFS) Oracle SQL: 1521/TCP 1630/TCP 3938/HTTP MongoDB : 27017,27018,27019/TCP PostgreSQL: 8432/TCP MySQL: 3306/TCP SQL DB Enum with nmap: nmap -p 1433 —script ms-sql-info —script-args mssql.instance-port=1433 IP_ADDRESS nmap -Pn -n -sS —script=ms-sql-xp-cmdshell.nse IP_ADDRESS -p1433 —script-args mssql.username=sa,mssql.password=password,ms-sql-xp-cmdshell.cmd="net user bhanu bhanu123 /add" nmap -Pn -n -sS —script=ms-sql-xp-cmds...

Windows Priv Escallation

1.     Windows Privilege Escalation Commands  _ new 2.     Transferring Files to Windows 3.    Priv Esc Commands 4.    Priv Esc Guide  5.    Payload All the Things --> great Coverage 6.    WinRM -- Windows Priv Esc    7. Newb Guide - Windows Pentest    8. Kerberos Attacks Explained     9. How to Attack Kerberos 101    Use PowerSploit/PrivEsc/Powerup.ps1 to find some potential info check for Non-windows processes in windows using netstat Step 1: Check net user and admin and user rights Step 2: Check if we have access of powershell if yes then run powerup.ps1,sherlock.ps1 and JAWS.ps1. Step 3: Try to get Meterpreter. Step 4: Load mimikatz ,try bypass UAC , check SAM SYSTEM etc. Step 5: check for weird programs and registry. Step 6: If the box is Domain Controller - Enum - Enum SMB Users/Ldap Users/ Blood Hound - GUI AD En...

Forensics & Crypto

Online Decoder --> Encoding errors --> File Signatures List -->  Click here PCAP Analysis: --> Online Cipher Decryptors: CyberChef  - Cipher Decoder   Crack Station-Hash Cracke r Decrypt Any Kind of Hash 1)  Cipher Statistics 2)  Index of Coincidence Calculator - Online IC Cryptanalysis Tool 3)  Tools List (Awesome and Fantastic Tools) Available on dCode 4)  Solve an Aristocrat or Patristocrat 5)  RSA attack tool (mainly for ctf) - retreive private key from weak public key and/or uncipher data 5-1)  RSA - Find PQ using N 6)  BertNase's Own Hide content in a Image made of blocks - npiet fun! 7)  Vigenere Solver - 8)  Fernet (Decode) 9)  Unicode Text Steganography Encoders/Decoders 10)  All in ONE encoders and Decoders Tool 11) Cryptii - Decoder Image Forensics: 1)  Forensical...