Network
İç ağ (internal) sızma testi; bir dayanak noktasından başlayıp ağdaki servisleri haritalamak, kimlik bilgisi toplamak ve yanal hareketle etki alanını genişletmeye odaklanır. Bu bölüm host keşfinden NTLM relay ve pivoting’e kadar temel teknikleri Türkçe olarak ele alır. Active Directory’ye özel saldırılar için Active Directory bölümüne bakın.
Bağlam
Section titled “Bağlam”Dayanak: VPN / phishing host / fiziksel / misafir Wi-Fi / cloud pivotHedef: canlı host → servis → kimlik → yanal → DA / kritik varlıkAraçlar: nmap, nxc, impacket, Responder, mitm6, ligolo, hashcatİç ağda çoğu kazanım yanlış yapılandırılmış servisler ve kimlik protokolü suistimali (LLMNR/NBT-NS/IPv6/WPAD + NTLM relay) üzerinden gelir. AD ortamında bu sayfalar AD teknikleriyle birlikte kullanılır.
Metodoloji
Section titled “Metodoloji”-
Keşif — canlı hostlar, açık portlar, servis/sürüm tespiti; segment ve VLAN haritası.
-
Enumeration — SMB/LDAP/SNMP/NFS/HTTP vb. servislerden bilgi ve anonim erişim.
-
Kimlik toplama — poisoning/relay, sniffing, zayıf/varsayılan parolalar, spray.
-
Yanal hareket — PsExec/WMI/WinRM/RDP, Pass-the-Hash, pivoting ve tünel.
-
Yükseltme & etki — yerel admin → DA / SCADA / backup / cloud connector.
Tipik iç ağ saldırı yüzeyi
Section titled “Tipik iç ağ saldırı yüzeyi”| Servis / protokol | Ne aranır |
|---|---|
| SMB 445 | Null session, share, signing off, MS17-010 |
| LLMNR / NBT-NS / mDNS | Responder hash / relay |
| IPv6 / DHCPv6 | mitm6 + LDAP relay |
| LDAP / LDAPS | Anonim bind, relay hedefi |
| SNMP | Community string → config/creds |
| NFS / FTP | Anonim / no_root_squash |
| RDP / WinRM / SSH | Spray, eski cipher |
| HTTP iç paneller | Default login, file read |
Bölümler
Section titled “Bölümler”- Host Keşfi & Port Tarama
- Ortak Servislerin Enumeration’ı
- SMB Enumeration & Saldırıları
- SSH Pentesting
- FTP Pentesting
- RDP Pentesting
- LLMNR/NBT-NS Poisoning & NTLM Relay
- MITM & Ağ Zehirleme
- Pivoting & Tünelleme
- Parola Saldırıları & Spraying
- VLAN Hopping
- Trafik Dinleme & Kimlik Toplama
Zincir örneği
Section titled “Zincir örneği”nmap ping sweep → SMB enum (signing off list) → Responder + ntlmrelayx → local admin on target → SAM/LSA dump → PtH → ligolo pivot → gizli VLAN → DCSync / kritik uygulamaTüm konu başlıkları
Section titled “Tüm konu başlıkları”- 10000 - Pentesting Network Data Management Protocol (ndmp)
- 1026 - Pentesting Rusersd
- 1080 - Pentesting Socks
- 1098/1099/1050 - Pentesting Java RMI - RMI-IIOP
- 11211 - Pentesting Memcache
- Memcache Commands
- 113 - Pentesting Ident
- 12346/udp - Pentesting Cisco Catalyst SD-WAN Control Plane
- 135, 593 - Pentesting MSRPC
- 137,138,139 - Pentesting NetBios
- 1414 - Pentesting IBM MQ
- 1521,1522-1529 - Pentesting Oracle TNS Listener
- 15672 - Pentesting RabbitMQ Management
- 1723 - Pentesting PPTP
- 1883 - Pentesting MQTT (Mosquitto)
- 2375, 2376 Pentesting Docker
- 24007,24008,24009,49152 - Pentesting GlusterFS
- 27017,27018 - Pentesting MongoDB
- 3128 - Pentesting Squid
- 32100 Udp - Pentesting Pppp Cs2 P2p Cameras
- 3260 - Pentesting ISCSI
- 3299 - Pentesting SAPRouter
- 3632 - Pentesting distcc
- 3690 - Pentesting Subversion (svn server)
- 3702/UDP - Pentesting WS-Discovery
- 403 & 401 Bypasses
- 4222 Pentesting Nats
- 43 - Pentesting WHOIS
- 4369 - Pentesting Erlang Port Mapper Daemon (epmd)
- 44134 - Pentesting Tiller (Helm)
- 44818/UDP/TCP - Pentesting EthernetIP
- 47808/udp - Pentesting BACNet
- 4786 - Cisco Smart Install
- 4840 - OPC Unified Architecture
- 49 - Pentesting TACACS+
- 5000 - Pentesting Docker Registry
- 50030,50060,50070,50075,50090 - Pentesting Hadoop
- 512 - Pentesting Rexec
- 515 - Pentesting Line Printer Daemon (LPD)
- 5353/UDP Multicast DNS (mDNS) and DNS-SD
- 5439 - Pentesting Redshift
- 554,8554 - Pentesting RTSP
- 5555 - Android Debug Bridge
- 5601 - Pentesting Kibana
- 5671,5672 - Pentesting AMQP
- 548 - Pentesting Apple Filing Protocol (AFP)
- 5984,6984 - Pentesting CouchDB
- 5985,5986 - Pentesting OMI
- 5985,5986 - Pentesting WinRM
- 6000 - Pentesting X11
- 623/UDP/TCP - IPMI
- 6379 - Pentesting Redis
- 69/UDP TFTP/Bittorrent-tracker
- 7/tcp/udp - Pentesting Echo
- 700 - Pentesting EPP
- 8009 - Pentesting Apache JServ Protocol (AJP)
- 80,443 - Pentesting Web Methodology
- 8086 - Pentesting InfluxDB
- 8089 - Pentesting Splunkd
- 8333,18333,38333,18444 - Pentesting Bitcoin
- 873 - Pentesting Rsync
- 9000 - Pentesting FastCGI
- 9001 - Pentesting HSQLDB
- 9100 - Pentesting Raw Printing (JetDirect, AppSocket, PDL-datastream)
- 9200 - Pentesting Elasticsearch
- AEM - Adobe Experience Cloud
- Angular
- Apache
- Artifactory Hacking guide
- Bolt CMS
- Firebase Database
- Buckets
- 9042/9160 - Pentesting Cassandra
- CGI
- Source code Review / SAST Tools
- Custom Protocols
- Django
- Dotnet Soap Wsdl Client Exploitation
- DotNetNuke (DNN)
- Drupal RCE
- Drupal
- Electron contextIsolation RCE via Electron internal code
- Electron contextIsolation RCE via IPC
- Electron contextIsolation RCE via preload code
- Electron Desktop Apps
- Flask
- Fortinet Fortiweb
- Git
- Golang
- Grafana
- H2 - Java SQL database
- IIS - Internet Information Services
- ImageMagick Security
- 500/udp - Pentesting IPsec/IKE VPN
- Ispconfig
- JBOSS
- Jira & Confluence
- Joomla
- JSP
- Laravel
- MeshCentral
- Microsoft Sharepoint
- Moodle
- NextJS
- 2049 - Pentesting NFS Service
- Nginx
- NodeJS Express
- 264 - Pentesting Check Point FireWall-1
- 631 - Internet Printing Protocol(IPP)
- 2301,2381 - Pentesting Compaq/HP Insight Manager
- 53 - Pentesting DNS
- 79 - Pentesting Finger
- FTP Bounce attack - Scan
- FTP Bounce - Download 2ºFTP file
- 21 - Pentesting FTP
- 143,993 - Pentesting IMAP
- 194,6667,6660-7000 - Pentesting IRC
- Pentesting ISO 8583 Payment Sockets
- Pentesting JDWP - Java Debug Wire Protocol
- Harvesting tickets from Linux
- Harvesting tickets from Windows
- 88tcp/udp - Pentesting Kerberos
- 389, 636, 3268, 3269 - Pentesting LDAP
- 502 - Pentesting Modbus
- 1433 - Pentesting MSSQL - Microsoft SQL Server
- Types of MSSQL Users
- 3306 - Pentesting Mysql
- 123/udp - Pentesting NTP
- 110,995 - Pentesting POP
- 5432,5433 - Pentesting Postgresql
- 3389 - Pentesting RDP
- Pentesting Remote GdbServer
- 513 - Pentesting Rlogin
- 111/TCP/UDP - Pentesting Portmapper
- 514 - Pentesting Rsh
- Pentesting SAP
- 139,445 - Pentesting SMB
- Ksmbd Attack Surface And Fuzzing Syzkaller
- rpcclient enumeration
- 25,465,587 - Pentesting SMTP/s
- SMTP - Commands
- SMTP Smuggling
- Cisco SNMP
- 161,162,10161,10162/udp - Pentesting SNMP
- SNMP RCE
- 22 - Pentesting SSH/SFTP
- 23 - Pentesting Telnet
- 5800,5801,5900,5901 - Pentesting VNC
- Basic VoIP Protocols
- SIP (Session Initiation Protocol)
- Pentesting VoIP
- Perl Tricks
- PHP Tricks
- Php Rce Abusing Object Creation New Usd Get A Usd Get B
- PHP SSRF
- disable_functions bypass - dl function
- disable_functions bypass - Imagick (= 3.3.0 PHP )= 5.4 Exploit
- disable_functions bypass - mod_cgi
- disable_functions bypass - PHP 4 )= 4.2.0, PHP 5 pcntl_exec
- disable_functions bypass - PHP 5.2 - FOpen Exploit
- disable_functions bypass - PHP 5.2.3 - Win32std ext Protections Bypass
- disable_functions bypass - PHP 5.2.4 and 5.2.5 PHP cURL
- disable_functions bypass - PHP 7.0-7.4 (\\-nix only)
- disable_functions bypass - php-fpm/FastCGI
- disable_functions bypass - PHP (= 5.2.9 on windows
- disable_functions bypass - PHP Perl Extension Safe_mode Bypass Exploit
- disable_functions bypass - PHP safe_mode bypass via proc_open() and custom environment Exploit
- disable_functions bypass - via mem
- disable_functions - PHP 5.2.4 ionCube extension Exploit
- disable_functions - PHP 5.x Shellshock Exploit
- PHP - Useful Functions & disable_functions/open_basedir bypass
- PrestaShop
- WebDav
- Python
- Rocket Chat
- Roundcube
- Ruby Tricks
- ServiceNow
- Sitecore
- Special Http Headers
- Spring Actuators
- Symfony
- Telerik Ui Aspnet Ajax Unsafe Reflection Webresource Axd
- Tomcat
- Uncovering CloudFlare
- VMWare (ESX, VCenter…)
- Vuejs
- Web API Pentesting
- Werkzeug / Flask Debug
- Wordpress
- Wsgi
- Zabbix
- Zoneminder Motioneye Motion