// port methodology

Port Tracker

Pick a service. Follow the checklist. Every command is copy-paste ready.

📂
SMB
port 139 / 445

Windows file sharing — enumerate shares, users, null sessions, and hunt for readable/writable shares.

5 steps →
🔐
SSH
port 22

Secure Shell — grab version, enumerate auth methods, spray creds, and hunt for weak keys.

4 steps →
🕸️
HTTP / HTTPS
port 80 / 443

Web servers — fingerprint, directory brute, parameter fuzz, and hunt for CVEs.

6 steps →
🎟️
Kerberos
port 88

AD authentication — enumerate users, AS-REP roast, Kerberoast, and ticket attacks.

4 steps →
🐬
MySQL
port 3306

MySQL/MariaDB — test weak creds, dump databases, and hunt for FILE privilege.

3 steps →
🗄️
MSSQL
port 1433

Microsoft SQL Server — enumerate, then xp_cmdshell / impersonation / linked servers for RCE.

3 steps →
🖱️
RDP
port 3389

Remote Desktop — check NLA, spray creds, and connect. Watch for BlueKeep.

3 steps →
🪟
WinRM
port 5985 / 5986

Windows Remote Management — the preferred lateral movement path. Evil-WinRM for shells.

3 steps →
🏛️
LDAP
port 389 / 636

Directory service — anonymous binds leak the whole AD tree: users, groups, descriptions.

3 steps →
📁
FTP
port 21

File Transfer Protocol — test anonymous login and check for writable dirs.

3 steps →
🌐
DNS
port 53

Domain Name System — zone transfers, subdomain brute, and reverse lookups.

2 steps →
📊
SNMP
port 161

Simple Network Management Protocol — brute community strings, then walk the MIB.

2 steps →
✉️
SMTP
port 25 / 465 / 587

Mail transfer — enumerate users via VRFY/EXPN/RCPT, test open relay.

2 steps →
🐘
PostgreSQL
port 5432

PostgreSQL — weak creds, then dump data or RCE via COPY ... PROGRAM.

3 steps →
🟥
Redis
port 6379

Redis KV store — unauthenticated by default. Dump keys or write files for RCE.

2 steps →
🔗
Rpcbind
port 111

RPC portmapper — lists RPC services, often reveals NFS.

2 steps →
💾
NFS
port 2049

Network File System — list exports, mount them, hunt for SUID privesc.

2 steps →