Tasks
NetBIOS Enumeration
Windows Command Line Utility
Name the shared folder/drive available on the Windows Server 2019 machine.
\WINDOWS11\CEH-Tools
NetBIOS Enumerator
Use the NetBIOS Enumerator to perform NetBIOS enumeration on the network (10.10.1.15 – 10.10.1.100). Enter the domain name associated with the IP address 10.10.1.22.
CEH
NSE Script
SNMP Enumeration
snmp-check
Use snmp-check to enumerate a target and find the hostname of the machine at the IP address 10.10.1.22.
Server2022.CEH.com
What is the domain name of the machine at the IP address 10.10.1.22?
CEH
Enumerate the machine at 10.10.1.22 using snmp-check and find the number of user accounts.
6
SoftPerfect Network Scanner
Perform SNMP enumeration using SoftPerfect Network Scanner and find the hostname of the machine at 10.10.1.9
ubuntu.local
Perform SNMP enumeration using SoftPerfect Network Scanner and find the hostname of the machine at 10.10.1.14
Android.local
Perform SNMP enumeration using SoftPerfect Network Scanner and find the Host Name of the machine at 10.10.1.22
SERVER2022
SnmpWalk
Use SnmpWalk to perform SNMP enumeration on the Windows Server 2022 machine. Enter the option that sets a community string.
-c
Nmap
Use various Nmap scripts to perform SNMP enumeration on the Windows Server 2022 machine. What is the option that is used to specify a UDP scan?
-sU
Use various Nmap scripts to perform SNMP enumeration on the Windows Server 2022 machine. Enter the option that specifies the port to be scanned.
-p
LDAP Enumeration
Active Directory Explorer
Perform LDAP Enumeration using Active Directory Explorer (AD Explorer) and find the Domain Controller machine's IP address.
10.10.1.22
Perform LDAP enumeration using Active Directory Explorer (AD Explorer) and find the userPrincipalName for the user named Jason.
jason@CEH.com
Python and Nmap
Use Nmap and Python commands to extract details on the LDAP server and connection. Enter the port number that is used by LDAP.
389
Username Enumeration
Using Python3
Use Python commands to extract details on the LDAP server and connection. Enter the command used in python shell to gather information such as naming context or domain name.
server.info
ldapsearch
Use ldapsearch to perform LDAP enumeration on the target system to gather details related to the naming contexts. Which option is used to specify simple authentication?
-x
-h : specifies the host
-x : specifies simple authentication
-s : specifies the scope
Use ldapsearch to perform LDAP enumeration on the target system to obtain more information about the primary domain. Which option is used to specify the base DN for search?
-b
NFS Enumeration
Perform NFS Enumeration using RPCScan and SuperEnum and find the port used by the NFS service on 10.10.1.19.
2049
SuperEnum
RPCScan
DNS Enumeration
Zone Transfer
Can you perform zone transfer on the primary host of certifiedhacker.com?
No
Perform DNS enumeration and find the “responsible mail address” for the domain certifiedhacker.com.
dnsadmin.box5331.bluehost.com
DNSSEC Zone Walking
Perform DNS enumeration using dnsrecon and find the IP address of the name server (ns2) for certifiedhacker.com.
162.159.25.175
Nmap
Use nmap to perform DNS enumeration on certifiedhacker.com to gather the list of all the available DNS services on the target host along with their associated ports. What is the rDNS record for 162.241.216.11?
box5331.bluehost.com
SMTP Enumeration
Nmap
Use the Nmap to perform SMTP enumeration to enumerate the list of all the possible mail users on the Windows Server 2019 machine. Enter the number of users enumerated on the target machine.
10
RPC, SMP, FTP Enumeration
NetScanTools Pro
Perform SMB enumeration using NetScanTools Pro. Is SMB version 1 (SMB 1) enabled on the machine at 10.10.1.19? (Yes/No)
No
Nmap
Enumerate the machine at 10.10.1.19 using Nmap and find its http-server-header.
Microsoft-IIS/10.0
Enumeration using various Tools
Global Network Inventory
Perform enumeration using Global Network Inventory and find the full name of the OS installed in the machine at 10.10.1.22.
Microsoft Windows Server 2022 Standard
Advanced IP Scanner
Enumerate network resources using Advanced IP Scanner and find the version of the Apache httpd service running on the machine at 10.10.1.9.
2.4.52
Enum4Linux
Enumerate users on the machine at 10.10.1.22 using Enum4linux and find the relative identifier (RID) for the user “shiela.”
0x451
Enumerate the machine at 10.10.1.22 using Enum4linux and find its Platform_ID.
500
Enumerate the machine at 10.10.1.22 using Enum4linux and find its server type.
0x84102f
Last updated