46 Scanning and Enumeration – Banner Grabbing
Dante Rocca; Mathew J. Heath Van Horn, PhD; and Jacob Christensen
Banner grabbing is a technique to view services running on a network or device. This is an important tactic for hackers as it narrows the potential ways into the network and may even reveal vulnerable services that can be exploited.
Think of banner-grabbing as blindly knocking on doors in a neighborhood. Any response, including, no response, provides us with information. A knock on one door might be greeted with a dog barking, a man shouting at us to ‘go away’, or we might get lucky and someone will open the door and invite us in for tea and biscuits.
Estimated time for completion: 30 minutes
Learning Objectives
- Learn the value of banner grabbing by performing this act on a target machine in various ways
- Telnet
- netcat
- cURL
- Nmap
Prerequisites
Deliverables
- 4 screenshots are needed to earn credit for this exercise:
- Banner grab on port 21 using Telnet
- Banner grab on port 21 using netcat
- HTTP header grab on port 80 using cURL
- Banner grab of all ports using Nmap
Resources
- Kennedy Muthii – “6 Banner Grabbing Tools with Examples” – https://www.golinuxcloud.com/banner-grabbing/
- Steven Vona – “Banner Grabbing – Penetration Testing Basics” – https://www.putorius.net/banner-grabbing.html
- DRD_ – “Use Banner Grabbing to Aid in Reconnaissance & See What Services Are Running on a System” – https://null-byte.wonderhowto.com/how-to/use-banner-grabbing-aid-reconnaissance-see-what-services-are-running-system-0203486/
Contributors and Testers
- Bernard Correa, Cybersecurity Student, ERAU-Prescott
Phase I – Scanning with Telnet
The first tool we’ll look at is Telnet. Telnet (teletype network) is an application layer protocol for 8-bit bidirectional communications using a client-host configuration. Telnet was not an official protocol until 1973. We will use Telnet to ‘knock’ on a remote target and record the responses. It is recommended to open a text editor of your choice; you will collect a lot of information and need a place to document it.
However, before we can grab any banners, we first need to find our target.
- Using Eagle Net, start the following machines:
- DHCP Server
- Router
- Kali VM
- Metasploitable3-Linux
- From Kali, scan the Metasploitable3-Linux VM for potential points of entry
- Host Discovery – perform a Ping Scan (-sn) to find the target’s IP address (e.g. <IP_ADDRESS> as shown below)
> nmap -sn <IP_ADDRESS>/24
- Port Discovery – perform a port scan on Fast Mode (-F) to see what services the target is running
> nmap -F <IP_ADDRESS>
- Host Discovery – perform a Ping Scan (-sn) to find the target’s IP address (e.g. <IP_ADDRESS> as shown below)
- Once you have a list of the open ports on the target, we can start knocking on those doors and grab the banners of those services
- Start a new telnet session
> telnet
- Connect to the target over port 21 to view their FTP server banner
> open <IP_ADDRESS> 21
From this out