|
| 1 | +## Description |
| 2 | + |
| 3 | +The “udp_probe” module scans a given range of hosts for common UDP services. Note: This module is deprecated and may disappear at any time. |
| 4 | + |
| 5 | +## Verification Steps |
| 6 | + |
| 7 | +1. Do: ```use auxiliary/scanner/discovery/ipv6_neighbor``` |
| 8 | +2. Do: ```set RHOSTS [IP]``` |
| 9 | +3. Do: ```set THREADS [number of threads]``` |
| 10 | +4. Do: ```run``` |
| 11 | + |
| 12 | +There are very few required settings for this module so we just configure the RHOSTS and THREADS values and let it run. |
| 13 | + |
| 14 | +## Scenarios |
| 15 | + |
| 16 | +**Running the scanner** |
| 17 | +``` |
| 18 | +msf > use auxiliary/scanner/discovery/udp_probe |
| 19 | +
|
| 20 | +[!] ****************************************************************************************** |
| 21 | +[!] * The module scanner/discovery/udp_probe is deprecated! * |
| 22 | +[!] * It will be removed on or about 2016-11-23 * |
| 23 | +[!] * Use auxiliary/scanner/discovery/udp_sweep instead * |
| 24 | +[!] ****************************************************************************************** |
| 25 | +msf auxiliary(udp_probe) > show options |
| 26 | +
|
| 27 | +Module options (auxiliary/scanner/discovery/udp_probe): |
| 28 | +
|
| 29 | + Name Current Setting Required Description |
| 30 | + ---- --------------- -------- ----------- |
| 31 | + CHOST no The local client address |
| 32 | + RHOSTS yes The target address range or CIDR identifier |
| 33 | + THREADS 1 yes The number of concurrent threads |
| 34 | +
|
| 35 | +msf auxiliary(udp_probe) > set RHOSTS 192.168.1.2-254 |
| 36 | +RHOSTS => 192.168.1.2-254 |
| 37 | +msf auxiliary(udp_probe) > set THREADS 253 |
| 38 | +THREADS => 253 |
| 39 | +msf auxiliary(udp_probe) > run |
| 40 | +
|
| 41 | +[*] Discovered SNMP on 192.168.1.2:161 (GSM7224 L2 Managed Gigabit Switch) |
| 42 | +[*] Discovered SNMP on 192.168.1.2:161 (GSM7224 L2 Managed Gigabit Switch) |
| 43 | +[*] Discovered NetBIOS on 192.168.1.109:137 (SAMSUNG::U :SAMSUNG::U :00:15:99:3f:40:bd) |
| 44 | +[*] Discovered NetBIOS on 192.168.1.150:137 (XEN-WIN7-PROD::U :WORKGROUP::G :XEN-WIN7-PROD::U :WORKGROUP::G :aa:e3:27:6e:3b:a5) |
| 45 | +[*] Discovered SNMP on 192.168.1.109:161 (Samsung CLX-3160 Series; OS V1.01.01.16 02-25-2008;Engine 6.01.00;NIC V4.03.08(CLX-3160) 02-25-2008;S/N 8Y61B1GP400065Y.) |
| 46 | +[*] Discovered NetBIOS on 192.168.1.206:137 (XEN-XP-PATCHED::U :XEN-XP-PATCHED::U :HOTZONE::G :HOTZONE::G :12:fa:1a:75:b8:a5) |
| 47 | +[*] Discovered NetBIOS on 192.168.1.203:137 (XEN-XP-SPLOIT::U :WORKGROUP::G :XEN-XP-SPLOIT::U :WORKGROUP::G :3e:ff:3c:4c:89:67) |
| 48 | +[*] Discovered NetBIOS on 192.168.1.201:137 (XEN-XP-SP2-BARE::U :HOTZONE::G :XEN-XP-SP2-BARE::U :HOTZONE::G :HOTZONE::U :__MSBROWSE__::G :c6:ce:4e:d9:c9:6e) |
| 49 | +[*] Discovered SNMP on 192.168.1.109:161 (Samsung CLX-3160 Series; OS V1.01.01.16 02-25-2008;Engine 6.01.00;NIC V4.03.08(CLX-3160) 02-25-2008;S/N 8Y61B1GP400065Y.) |
| 50 | +[*] Discovered NTP on 192.168.1.69:123 (NTP v4) |
| 51 | +[*] Discovered NetBIOS on 192.168.1.250:137 (FREENAS::U :FREENAS::U :FREENAS::U :__MSBROWSE__::G :WORKGROUP::U :WORKGROUP::G :WORKGROUP::G :00:00:00:00:00:00) |
| 52 | +[*] Discovered NTP on 192.168.1.203:123 (Microsoft NTP) |
| 53 | +[*] Discovered MSSQL on 192.168.1.206:1434 (ServerName=XEN-XP-PATCHED InstanceName=SQLEXPRESS IsClustered=No Version=9.00.4035.00 tcp=1050 np=\\XEN-XP-PATCHED\pipe\MSSQL$SQLEXPRESS\sql\query ) |
| 54 | +[*] Discovered NTP on 192.168.1.206:123 (Microsoft NTP) |
| 55 | +[*] Discovered NTP on 192.168.1.201:123 (Microsoft NTP) |
| 56 | +[*] Scanned 029 of 253 hosts (011% complete) |
| 57 | +[*] Scanned 052 of 253 hosts (020% complete) |
| 58 | +[*] Scanned 084 of 253 hosts (033% complete) |
| 59 | +[*] Scanned 114 of 253 hosts (045% complete) |
| 60 | +[*] Scanned 140 of 253 hosts (055% complete) |
| 61 | +[*] Scanned 160 of 253 hosts (063% complete) |
| 62 | +[*] Scanned 184 of 253 hosts (072% complete) |
| 63 | +[*] Scanned 243 of 253 hosts (096% complete) |
| 64 | +[*] Scanned 250 of 253 hosts (098% complete) |
| 65 | +[*] Scanned 253 of 253 hosts (100% complete) |
| 66 | +[*] Auxiliary module execution completed |
| 67 | +msf auxiliary(udp_probe) > |
| 68 | +``` |
| 69 | + |
| 70 | +As you can see in the above output, our quick little scan discovered many services running on a wide variety of platforms. |
0 commit comments